AI Readiness Assessment for law firms
Your firm already has AI in it. Two weeks to find out where client information is going, and what to do first.
Most readiness assessments ask whether a firm is ready to adopt AI. That is the wrong question. Staff adopted it a year ago, inside tools the firm already pays for and inside accounts it does not know about. The useful question is what that exposure looks like and how to bring it under a policy people will follow.
Evidence comes from tracing paths, not from a software survey.
A survey asks people what tools they use. Tracing follows a piece of client information from intake to billing and records every system it touches on the way. The second method finds the routes the first one never hears about.
What the two weeks do.
Week one: trace the paths
Interviews across roles, from reception to partner, and a walk through the tools the firm already licenses. The output is one drawing: every route client information can currently take out of the firm, including the routes nobody sanctioned.
Week two: test against the guidance
Each path is set against the professional guidance that applies in your jurisdiction, and against the vendor terms that actually govern the tools in use. What is fine, what needs a control, and what needs to stop.
- Where is client information going today?
- Does that hold up against the guidance that applies to us?
- What should we build first?
Twelve questions you can answer before you call anyone.
Answer honestly. A firm that can answer all twelve does not need the assessment. The questions you cannot answer are where the exposure sits, and they are the first ones the two weeks go after.
Where client information goes
- Can you name every AI tool a member of staff used on client material last month, including the ones inside Microsoft 365, the research platform and the practice-management system?
- For each tool, do you know whether the vendor may use your content to train its models, and where the content is stored?
- Has anyone at the firm pasted client material into a consumer AI account on a personal login?
Governance
- Is there a written AI policy, and does it say what is prohibited, what needs review and what is allowed by default?
- Do engagement letters say anything about AI use, and does the answer match what actually happens?
- Is there a named person who decides whether a new AI tool may be used, and a register of the decisions?
Review and verification
- Before an AI-assisted draft leaves the firm, is there a named review step, and does it include checking every citation resolves and supports the proposition?
- When an AI output is wrong, is there somewhere to record it, so the same failure is not rediscovered by the next person?
People
- Has every lawyer had training that covered instructing a model, reading its output critically and the confidentiality rules that apply?
- Could a partner explain to a client, in two minutes, how the firm uses AI and how it protects the client’s information?
Workflows
- Is there one workflow, at task level, where the firm knows what AI changed and can measure it?
- If the firm stopped every AI pilot tomorrow, would anyone notice within a week?
- Decision support and operating design, not legal advice
- Workflow and information-path review, distinct from a full IT security audit
- Vendor-neutral: the outcome is an action plan, not a product recommendation
- Examines paths, not case files. No privileged material is ingested.
- A firm of roughly 20 to 75 lawyers, or an in-house legal team of five or more
- The decision-maker is on the kickoff call, and five or more staff can be interviewed across roles
- There is already AI in the building, whether or not leadership knows where
Teams with no current AI use start withfluency. Teams with active use start here. Independent firms of one to five lawyers start withthe site and the phone.
After the assessment, the first build has a name.
The action plan sequences what to stop, what to control and what to build. The build, when there is one, isone workflow taken all the way.