Professional Services2 min read

When a Client Audits Your Security

Corporate clients increasingly review their advisors' security before renewing. For a firm whose product is confidentiality, failing that review is a commercial event, not an IT one.

A general counsel at one of your larger clients forwards a vendor security assessment. It asks about encryption, about access control, about how you handle their data if a partner leaves. There is a deadline, and there is a line about it being a condition of the panel review.

For a firm that sells expertise and confidentiality, this is not an IT request. It is a commercial one, and it should be handled by whoever handles commercial risk.

Why this is happening to firms now

Large corporates have spent a decade tightening their own security and have discovered that their advisors are the softest remaining route to their information. Your firm holds their litigation strategy, their transaction documents, their financials, their employee data.

Their own regulators and insurers now expect them to assess that exposure. So the questionnaire arrives, and it will keep arriving, from more clients, in more formats, with less notice.

What they are actually assessing

Underneath the format, the questions cluster into five areas, and knowing them lets you prepare rather than react.

Who can reach client data, how access is granted and, more pointedly, how it is removed when somebody leaves or a matter closes.

How data is protected at rest and in transit, including on the laptop a partner takes to a hearing and the phone a paralegal reads mail on.

Whether client information is separated between matters and clients, which is a live question for firms that store everything in one document system with generous permissions.

What happens when something goes wrong: an incident plan, a notification commitment, and evidence that somebody has thought about it before the day it is needed.

Whether anyone owns this. They will ask who is responsible for information security. "Our IT provider" is a weak answer, because your provider is not accountable to your clients.

The two failure modes

The first is the scramble: a questionnaire answered under deadline by whoever is available, with optimistic answers that create representations the firm cannot support. That is worse than a slow honest answer, because the representation persists.

The second is quieter. The firm answers accurately, discovers three genuine gaps, and does nothing about them because no partner owns the follow-up. The next questionnaire finds the same three gaps, and the client notices that nothing changed.

Prepare once, answer many times

The firms that handle this well maintain a standing evidence set rather than a stack of completed questionnaires: a current risk register with named owners, an access control procedure that reflects reality, an incident response plan, encryption and retention documentation, and a short architecture description.

Assembled once, it answers most of what any client asks. Kept current, it converts a two-week fire drill into a two-hour translation job.

There is a further benefit worth naming. A firm that can answer these questions well, quickly, wins work from firms that cannot. Increasingly the assessment is not a hurdle at renewal, it is a differentiator at pitch.

The obligation nobody maps

One last thing, because it comes up and it is uncomfortable. Most professional bodies impose a duty of confidentiality and competence that extends to how you hold client information. Very few firms have mapped that duty against their actual technology.

That mapping is a short exercise and it is worth doing before a client does it for you.