AI governance for small firms
The minimum viable AI governance set for a small law firm
Governance for AI in a small firm does not have to mean a committee, a 40-page policy or a new hire. The SRA Code of Conduct for Firms sets two relevant duties: paragraph 2.1 requires effective governance structures, arrangements, and systems and controls to comply with regulatory and legislative requirements, and paragraph 2.1(a) specifically requires maintaining client information securely and in line with timeframes specified in relevant data protection legislation. Paragraph 6.3 separately requires keeping the affairs of current and former clients confidential. What follows is Margo Legal's recommended starting set for a 2-20 fee-earner firm: six working documents we think are a proportionate way to organise towards those duties. It is our recommendation, not a statement of what the SRA considers sufficient - every firm's obligations are its own to assess.
1. The usage policy - suggested format: one page
What is allowed, what is not, and who decides the grey area. The SRA's warning notice on AI misuse records concerns relating particularly to inaccurate information and to client confidentiality, so the two lines that matter most are: no client-confidential information into unapproved tools, and every AI-assisted output gets checked before it leaves the firm. We publish a one-page template (/insights/one-page-ai-policy-template-small-law-firms/). The failure mode to avoid is a policy nobody has read since induction.
2. The tool register - suggested format: one table
Every AI tool in use, approved or tolerated, with owner, purpose, the data it touches and renewal date. If the register does not include the tools people actually use - including free ones - it is fiction. A structured discovery pass (the two-hour shadow AI method, /insights/shadow-ai-audit-law-firms-two-hour-method/) establishes actual usage before the register is written.
3. The data-flow map - suggested format: one diagram per tool
For each tool on the register: what client data goes in, where it is processed and stored, who the subprocessors are, and what happens on deletion. This map is evidence a firm can use to assess its position against the confidentiality duty in para 6.3, the secure-information requirement in para 2.1(a) and data protection law - it supports that assessment; it does not by itself prove compliance. The ICO's guidance on AI and data protection is the data-protection reference. The failure mode is a map drawn from the vendor's marketing page instead of its terms and settings.
4. The verification standard - suggested format: a short section per AI-assisted workflow
For each AI-assisted task: who checks the output, against what source, before it reaches a client or a court. The warning notice's first recorded concern is court or other documents containing false or incorrect information, including citations, as a result of AI misuse; it notes reports of potential breaches received from senior members of the judiciary and instances of solicitors self-reporting. Lawyers remain responsible for what they submit, whatever tool produced the first draft. Research is one workflow where this risk arises - the standard should cover every AI-assisted task, not only research.
5. The vendor terms review - suggested format: one page per tool
The warning notice states that both paid and free AI tools may not provide the contractual and technical safeguards needed to maintain client confidentiality, and that firms should understand the safeguards that apply and ensure they are appropriate to the nature and sensitivity of the information being processed. For each tool, someone should read the actual terms - retention, training use, subprocessors, deletion, breach notice - and record the conclusion. Our standing question set (/insights/legal-ai-vendor-data-security-questions/) is the checklist.
6. The incident route - suggested format: a few lines, easy to find
What happens when something goes wrong: who is told internally, what gets switched off, and who assesses the duties that arise in the actual incident - what clients are owed, and whether notification obligations to the firm's insurer, the SRA or the ICO apply. The test of the document is that a fee earner can find it quickly outside office hours.
Keeping the set alive
We suggest reviewing the set twice a year, tied to the tool register - a light, recurring task rather than an annual project. What makes it governance rather than paperwork is the measurement underneath: knowing your workflows and volumes first (the twelve-question readiness score at /readiness/ is a quick baseline) keeps the documents anchored to how the firm actually works. Our implementation kit for the warning notice (/insights/sra-ai-warning-implementation-kit-managing-partners/) walks through putting this into practice.
For firms that want outside help: Margo Legal's readiness-audit scope and price are not yet published; the page currently describes the Workflow Value Workshop at GBP 2,500 fixed - one workflow, one half-day, ending in a written recommendation: fix, buy, pilot or stop (/consultancy/). Margo, the product, is in controlled development; nothing above depends on it.