Legal AI readiness

What a legal AI readiness audit should actually cover

If your firm is considering an AI readiness audit, the useful question is not "do we need one" but "what should it actually examine". This is the scope we would hold any audit to - including our own - plus the red flags that separate an audit from a sales call.

What an audit is, and is not

A readiness audit is a measured look at a firm's current position: which workflows exist, whether and where AI touches them - including any unapproved uses - what obligations attach to that use, and what a sensible first move looks like. It is not a vendor demo, a maturity score for its own sake, or a procurement decision dressed up as analysis. If the output is a recommendation to buy the auditor's own product, you did not get an audit - you got a sales call with a findings section.

The seven things it should examine

1. A workflow inventory with real numbers. Which repeated workflows exist, who does them, monthly volume, hands-on time, turnaround, correction cycles. Without a baseline, later claims about improvement are unverifiable. Our own readiness score (/readiness/) applies the same measurement discipline, and an auditor who skips the baseline is guessing.

2. Current AI use, including unapproved use. The SRA's warning notice on AI misuse opens from the fact that "solicitors and law firms are increasingly using AI in their day-to-day work" and that these tools "have become commonplace in the workplace". In any given firm, some of that use may be unapproved - consumer tools used on work material without any terms review. A structured discovery pass (our two-hour shadow AI method, /insights/shadow-ai-audit-law-firms-two-hour-method/, is the DIY version) establishes what is actually happening before any policy conversation can be honest.

3. Confidentiality and data flows. For each tool in use: what client data goes in, where it is processed, what the supplier does with it. The duties that attach here are distinct and worth separating. Paragraph 6.3 of the SRA Code of Conduct for Firms requires keeping the affairs of current and former clients confidential. Paragraph 2.1 is the governance duty: effective governance structures, arrangements, and systems and controls to comply with regulatory and legislative requirements. Paragraph 2.1(a), within that, specifically requires maintaining client information securely and in line with timeframes specified in relevant data protection legislation. The ICO's guidance on AI and data protection is the data-protection reference for that assessment. An audit that does not map data flows cannot give a firm the evidence to assess its own position against any of these.

4. Output verification standards. The SRA's warning notice records two concerns in particular. The first is court or other documents containing false or incorrect information, including citations, as a result of AI misuse; the notice says the SRA has received reports of potential breaches of its Code of Conduct from senior members of the judiciary, and that several solicitors have self-reported after relying on tools that generated inaccurate or misleading content. So the audit should answer: for each AI-assisted task, who checks the output, against what source, and what happens when the check fails. "The lawyer looks it over" is not a standard.

5. Supervision and accountability. The para 2.1 governance duty is about arrangements, not software. Who owns AI use in the firm? Who approves a new tool? Who is accountable when something goes wrong? If the honest answer is "no one in particular", the audit should make the answer explicit and written.

6. Vendor safeguard adequacy. The warning notice makes a point worth quoting in full: "Both paid for and free-to-use AI tools may not provide the contractual and technical safeguards needed to maintain client confidentiality. Firms should understand the safeguards that apply and ensure they are appropriate to the nature and sensitivity of the information being processed." The audit should therefore read the actual terms - retention, training use, subprocessors, deletion - and record the conclusion. Our standing list of vendor data-security questions (/insights/legal-ai-vendor-data-security-questions/) is the checklist version of this review.

7. A decision, with costs. The deliverable is a short written set of options for one or two named workflows - fix the process, buy a tool, run a small supervised pilot, or stop - with the measured baseline attached so the chosen route can be checked later.

What you should physically receive

A written report you own: the inventory and numbers, the discovery findings, a data-flow map, a risk register tied to the duties above, and the decision options with evidence. If a finding cannot be traced to a document, a configuration or an interview, it should be marked as unverified rather than asserted.

Red flags when buying an audit

The honest middle ground

A first pass is possible without paying anyone: the shadow-AI method, the twelve-question readiness score and the ten-question systems check (/systems-readiness/) are free and ungated, and the maturity model (/insights/law-firm-ai-readiness-maturity-model/) helps place the results. A paid audit earns its fee when a firm wants the numbers verified, the vendor terms actually read, and a written decision a partnership can sign off.

Margo Legal's readiness-audit scope and price are not yet published and this article deliberately describes the standard we think any audit should meet, not the contents of that product. The current consultancy page describes the Workflow Value Workshop at GBP 2,500 fixed - one workflow, one half-day, ending in a written recommendation: fix, buy, pilot or stop (/consultancy/). Margo, the product, remains in controlled development and nothing in this article depends on it.