Can Your Law Firm Prove Its Compliance?
Why Law Firms of Every Size Benefit from Treating ICT Policy as an Integrated Architecture
Clients, insurers and regulators no longer accept a firm’s word that client information is safe and obligations are met. They want to see the evidence. An integrated approach to ICT policy development makes producing that evidence routine, not a scramble.
Context for Every Firm, Whatever Its Size or Practice Mix
It is tempting to read the developments described below and conclude they belong to someone else: conveyancing and trust practices, firms large enough to employ a CIO, or litigators. In practice, the obligations of 2025 and 2026 reach well beyond the firms they name directly, and they overlap in ways that make a document-by-document approach to ICT policy increasingly hard to defend.
Size is no longer a reliable shelter. Many smaller firms have sat outside the Privacy Act under the small business exemption for businesses with annual turnover of $3 million or less (OAIC, 2026). However, a small firm that becomes an AUSTRAC reporting entity must comply with the Privacy Act for the personal information it handles for AML/CTF purposes, regardless of turnover (Privacy Act 1988 (Cth) s 6E(1A); OAIC, 2026). Firms at or above the $3 million threshold must also report any ransomware or cyber extortion payment to the Government within 72 hours (Cyber Security Act 2024 (Cth) pt 3; Department of Home Affairs, 2025).
Practice mix is no shelter either. A firm that provides no designated services still acts for clients who do, and still answers to insurers, panels and corporate clients who increasingly ask for evidence rather than assurances (Upcover, 2026). Litigators face AI rules of their own: in NSW, Practice Note SC Gen 23 sets out how generative AI may and may not be used in material put before the Supreme Court, including affidavits, witness statements and expert reports (Supreme Court of NSW, 2025).
Obligations also pull against each other. AML/CTF rules require firms to verify and record client identity (OAIC, 2026), while the Australian Privacy Principles require them to collect only what is necessary and to destroy what they no longer need (APPs 3 and 11). The OAIC cautions reporting entities against keeping full copies of identity documents where the AML/CTF regime does not require them (OAIC, 2026). Reconciling tensions like these, and being able to prove the reconciliation, is precisely the work an integrated ICT policy architecture is designed to do. The rest of this article explains how.
The Question Facing Law Firms Has Changed
Law firms hold some of the most sensitive information in the economy, and the obligations around it are multiplying. Since 1 July 2026, lawyers who provide designated services such as property transactions, company and trust formation or managing client funds have been AUSTRAC reporting entities, with an AML/CTF program, customer due diligence and record-keeping to evidence (Law Society of NSW, 2026). From 10 December 2026, organisations bound by the Australian Privacy Principles that use personal information in automated decisions that significantly affect individuals must disclose this in their privacy policies (Office of the Australian Information Commissioner [OAIC], 2025). Small firms under the $3 million threshold that are not AUSTRAC reporting entities are generally outside this duty. The legal, accounting and management services sector, which lodged 81 of a record 1,205 notifications, was again among the five sectors notifying the most data breaches in 2025 (OAIC, 2026). The profession’s regulators have urged practitioners using AI to develop clear, risk-based policies to minimise data and security breaches (Law Society of NSW, Legal Practice Board of Western Australia and Victorian Legal Services Board + Commissioner, 2024).
Taken together, these pressures change the question firms must answer. It is no longer ‘do we have a policy?’ but ‘can we trace every obligation to a control, an owner and evidence?’ Many firms find that hard because they wrote policies one at a time, in different formats, by different owners, on different review cycles. One area is current while another is years out of date; exceptions exist but are not recorded; AI tools are in use before any governance model is in place.
An Integrated Architecture Links Obligation, Policy, Control and Evidence
The alternative is to manage ICT policy as a connected system rather than a document library. Drawing on established governance and architecture practice such as COBIT (ISACA, 2018) and TOGAF (The Open Group, 2022), an integrated framework is built from a small number of instruments that work as one:
| Instrument | What it does for the firm |
| Requirements register | Holds every obligation in one place (legislation, privacy and AML/CTF rules, standards such as ISO/IEC 27001 (ISO, 2022), client contract terms and internal governance) and maps each to the policy statement, control and evidence that discharges it. |
| Development register | Tracks every policy through drafting, subject-matter review, legal review, approval, publication and scheduled review, with a named owner, deadline and version history. |
| Policy hierarchy | Gives each document a place and a parent: charter, framework, policy, standard and procedure, with clear approval paths and review triggers. |
| Standard template | One structure for every policy: purpose, scope, policy statement, roles, requirements, exceptions, compliance and monitoring, related documents. |
| AI-assisted obligation scanning | Reads new and amended instruments, extracts obligations and proposes register entries for a qualified reviewer to confirm (Law Society of NSW et al., 2024), keeping coverage current without re-reading every instrument by hand. |
Because the links run in both directions, a firm can trace a new obligation forward to the policies and controls it affects or trace any control back to the reason it exists. When a regulation changes, impact analysis becomes a query rather than a rework project.
The Benefits Hold for Small and Large Firms Alike
| Benefit | For a small or mid-sized firm | For a large or national firm |
| Due diligence on demand | Answer client, insurer and panel security questionnaires from one evidence base instead of rebuilding answers each time. | Respond consistently across offices and practice groups, with every answer traceable to an approved control. |
| Faster response to change | See in hours which policies a new obligation touches, without a dedicated compliance team. | Run impact analysis across a large policy estate as a register query rather than a rework project. |
| Clear accountability | A named owner for every policy and obligation, even when partners wear several hats. | Ownership, approval paths and review cycles that hold across domains, offices and jurisdictions. |
| Visible risk | Exceptions recorded, time-limited and reviewed rather than agreed informally and forgotten. | Exceptions risk-assessed and reported to the board, giving a clear view of accepted risk. |
| Governed use of AI | Simple, proportionate rules for generative AI tools before they reach client matters. | A risk-tiered AI policy stack with oversight, disclosure and incident paths that auditors can test. |
AI Governance Belongs Inside the Framework, Not Beside It
Generative AI is already in everyday legal work, and regulators expect lawyers to use it consistently with their duties of competence, confidentiality and supervision (Law Society of NSW et al., 2024). An integrated framework treats AI governance as a policy domain in its own right, with sub-policies covering acceptable use, risk management, data, human oversight, transparency, third-party tools and incidents. Mapped to a management-system standard such as ISO/IEC 42001 (ISO, 2023), it gives a firm a defensible answer when a client asks how AI is used on their matter. Firms that already trace obligations to owners and evidence find this step far easier, because AI governance depends on exactly those foundations.
Audit Readiness Becomes a Standing Condition
When evidence is defined at the moment a requirement is written, it no longer has to be assembled when an auditor, insurer, regulator or client asks. Decision logs, approvals, training records and review minutes are captured as the policy moves through its lifecycle, so one evidence library can answer internal review, AUSTRAC, the privacy regulator and client due diligence alike. Policies become comparable across practice areas and easier for staff to follow. The first review under this model takes the most effort; every review after that is routine.
For a sole practitioner or small firm, the same architecture can start small: a single register, a handful of core policies, and a shared template that grows as the firm does. A concrete starting point is the Australian Signals Directorate’s Essential Eight, eight mitigation strategies it recommends organisations implement as a baseline (Australian Signals Directorate [ASD], 2023). The most tangible small-firm risk is business email compromise and payment redirection, in which a fraudster intercepts email between a firm and its client and substitutes false bank details for trust or settlement funds. The Law Society of NSW has described it as the most common scam affecting legal practitioners (Law Society of NSW, 2023). A first entry in the requirements register might therefore call for multi-factor authentication on email (one of the Essential Eight) and telephone verification of payment instructions against contact details already on file. For a large firm, it replaces parallel spreadsheets and inconsistent documents with one governed system that scales across offices and jurisdictions.
Where to Start
- Inventory your obligations. List the laws, client contract terms and insurer requirements that apply to your firm in one requirements register.
- List the AI tools in use. Record every generative AI tool your people use, approved or not, and what client information reaches it.
- Name owners. Assign every obligation and policy an owner, even if one partner holds several.
- Set one template. Adopt one structure for every policy (see the standard template above) and use it for each new or revised policy.
- Record exceptions. Log each departure from policy with a reason, an approver and a review date, so it is reviewed rather than forgotten.
Coming Next: The Same Capability for Your Clients
A future article will look at how the same integrated capability can serve a firm’s clients, from small businesses to large and global organisations. Because the architecture is built around obligations rather than any single industry, it applies wherever regulatory obligations or standards must be managed, giving firms a practical way to help clients move from legal advice to demonstrable compliance.
Take the Next Step with CTO Consulting
If you would like help building this architecture for your firm, CTO Consulting can help you set up the requirements register, policy hierarchy and template described above, sized to your practice. To start a conversation, visit ctoconsulting.com.au or contact info@ctoconsulting.com.au.
By Karim Khalifa
Karim Khalifa is a Business Analyst Practice Lead with CTO Consulting, specialising in ICT Policy and Governance, Enterprise Architecture and Transformation. His current work focuses on designing integrated governance architectures that align regulatory obligations, policy authorship and technical assurance into single, traceable operating models.
Disclaimer: This article provides general information only and does not constitute legal, regulatory, cyber security or other professional advice. It reflects legislation, regulatory guidance and court practice notes as of September 2026, which may change, and does not address the circumstances of any firm or matter. Readers should obtain advice specific to their own obligations before acting and should consult the primary sources cited. The views expressed are those of the author and do not necessarily reflect those of CTO Consulting, Future State Ambition or Legal Practice Intelligence. References to standards, frameworks, regulators and third-party sources are for information only and do not imply endorsement or affiliation.







