01
Data handling & residency
Asks where inputs are stored, whether they're used for training, how long they're retained, and which jurisdictions they transit — so the team knows what data the vendor may see and whether cross-border transfer rules apply before anything is sent.
02
Model & training governance
Surfaces what model powers the tool, whether the vendor fine-tunes on customer data, whether outputs can be attributed, and how the vendor handles hallucination and drift — the governance questions that separate a real vendor from a wrapper.
03
Security & access controls
Maps certifications (SOC 2, ISO 27001), encryption at rest and in transit, access logging, and tenant isolation — so the tool meets the firm's baseline before it's even considered for sensitive work.
04
Confidentiality & contractual terms
Checks whether the vendor's terms grant training rights, limit liability, protect client confidences, and allow audit — flagging paper that gives the vendor more than the firm would give a counterparty.
05
Human-in-the-loop & output review
Assesses whether the tool is designed for attorney review of outputs or to act autonomously, what logging exists, and how errors are surfaced — so the tool slots into the firm's review workflow instead of routing around it.
06
Decision record & re-assessment
Records the assessment outcome — approved, approved with conditions, or blocked — with the rationale and owner, and schedules a re-assessment when the vendor's model, terms, or scope change so approvals don't age into silent risk.