Law Firm Compliance Checklist

Annual compliance review for small-to-mid law firms covering professional conduct, IOLTA trust accounting, conflicts management, client data protection, and records retention. Run by the firm administrator with partner sign-off on each phase.

5 sections 24 steps Collects data
1

Professional Conduct and Ethics

  1. Refresh state Rules of Professional Conduct updates
    • Pull the current state bar Rules of Professional Conduct and any amendments adopted since the last review. Note changes to Rule 1.6 (confidentiality / tech competence), Rule 5.5 (UPL across state lines), and any new advertising rules under Rule 7.x. Circulate a one-page summary to all attorneys.

  2. Audit attorney advertising and website disclaimers
    • Check the firm website, attorney bios, social media, and any paid advertising against Rule 7.1 (no false or misleading communications) and state-specific disclaimer requirements. Common gotchas: outdated practice area listings, unverified specialist claims, and missing "prior results do not guarantee" language.

  3. Verify CLE compliance for every attorney
    • Pull each attorney's CLE transcript from the state bar. Confirm general hours, ethics hours, and any mandatory diversity or mental-health hours separately — they're not interchangeable. Flag anyone within 60 days of their reporting deadline.

    Collects file
  4. Confirm malpractice insurance declarations are current
    • Check the carrier's declarations page for renewal date, per-claim and aggregate limits, and that all current attorneys are listed. If the firm is in a state requiring disclosure of non-coverage to clients, verify that disclosure is in the engagement letter template.

  5. Review supervisory attorney sign-off logs
    • Under Rule 5.1 and 5.3, partners are responsible for associate and non-lawyer staff conduct. Spot-check that pre-bills, court filings, and outgoing client correspondence carry the supervising attorney's sign-off. Common gap: paralegal-drafted client letters going out without attorney review.

2

IOLTA and Trust Account Compliance

  1. Run the three-way trust reconciliation
    • Reconcile bank statement balance, book balance, and the sum of individual client ledgers — all three must agree to the penny. Pull the report from Clio Trust, Tabs3 Trust, CosmoLex, or whichever PMS holds the trust ledger. Any discrepancy is investigated before partner sign-off.

    Collects list
  2. Investigate the reconciliation discrepancy
    • Trace every transaction since the last clean reconciliation. Common causes: bank fees posted to IOLTA instead of operating, deposits credited to the wrong client ledger, or a stale outstanding check. Document the cause and the correcting entry. If commingling is suspected, escalate to managing partner same day.

  3. Confirm no client ledger has a negative balance
    • An overdraft on any individual client matter is a Rule 1.15 violation, even if the aggregate IOLTA balance is positive. In most states the bank notifies the disciplinary counsel automatically. Sort the client ledger report by balance ascending and review every line at or below zero.

  4. Audit trust-to-operating transfers against earned fees
    • For each transfer from IOLTA to operating during the period, match it to a delivered invoice with sufficient earned fees on that client matter. Transfers ahead of an invoice or in excess of earned fees are improper, even with retainer authorization in the engagement letter.

  5. Capture partner sign-off on the reconciliation
    Collects file Collects signature
3

Conflicts of Interest

  1. Refresh the conflicts database with new parties
    • Sweep matters opened since the last review and confirm every client, related entity, opposing party, and material witness is indexed in the conflicts system (Clio Conflicts, IntApp Open, NetDocuments + ConflictChex). Names captured only in the matter narrative but missing from the parties list cause false-clean conflict checks.

  2. Audit recent matter opens for conflicts-check completion
    • Pull every matter opened in the period and confirm the conflicts search was run and documented before the engagement letter went out. Flag any matter opened without a clearance memo. Note any hit that required waiver under Rule 1.7(b) for follow-up below.

    Collects list
  3. Confirm waiver letters are on file for every hit
    • For each conflict hit cleared by waiver, verify a written informed-consent letter signed by every affected client is in the matter file. Oral consents are not sufficient under Rule 1.7(b)(4). If a waiver is missing, draft and send before continuing representation.

  4. Review lateral-hire screening walls
    • For any attorney or paralegal hired in the period, confirm the screening protocol under Rule 1.10: written acknowledgment from the new hire, system-level access blocks on screened matters, and the required notice to former-firm clients where applicable.

4

Client Data Protection and Confidentiality

  1. Inventory systems holding client confidential data
    • List every system that touches client matter data: DMS (NetDocuments, iManage, Worldox), email, PMS, eDiscovery platforms, e-signature, file-share. Map each to a vendor, a data-residency location, and the matter types it holds. Rule 1.6(c) requires reasonable safeguards proportional to the sensitivity of the data.

  2. Verify MFA on DMS and firm email
    • Pull the admin reports from Microsoft 365 / Google Workspace and the DMS to confirm 100% MFA enrollment for attorneys and staff. Departing-employee accounts should be disabled, not merely password-reset. Document any exceptions and the compensating control.

  3. Test client portal access controls
    • Pick three closed matters and confirm the former client's portal access was revoked at file close. A common breach pattern is a lapsed client retaining indefinite access to the portal because no one revoked credentials at close-out.

  4. Review vendor confidentiality and BAA agreements
    • Every vendor that processes client data needs a written confidentiality agreement consistent with Rule 1.6 — DMS, eDiscovery, transcription, virtual paralegal services, document destruction. Health-related matters may also need a BAA. Flag any vendor onboarded in the period without an executed agreement.

  5. Confirm litigation hold procedures are documented
    • For active litigation matters, verify a written litigation hold has been issued to all custodians, custodian acknowledgments are on file, and auto-delete on email and Teams chat is suspended for those custodians. Missed custodians are the most common spoliation finding.

5

Records Retention and File Closing

  1. Review the retention schedule by matter type
    • Confirm the firm's schedule still matches the state bar minimum (commonly 5–7 years post-close) and any longer matter-specific requirements: estate planning files often kept for the life of the testator, real estate files for the life of the title, IOLTA records typically 7+ years.

  2. Identify closed files past retention
    • Run the closed-matter report and filter for files whose retention clock expired in the period. Cross-check against any active litigation hold — a file under hold is never destroyed even if past retention. Produce the destruction list for partner approval.

  3. Confirm closed matters have client closing letters
    • Spot-check matters closed in the period for the closing letter, final invoice, trust-balance disposition (refund or transfer), and original-document return receipt. Missing closing letters cause fee disputes years later when the client claims the engagement never ended.

  4. Run annual destruction with witness sign-off
    • Coordinate with the certified destruction vendor for paper files and the IT team for electronic. A second person witnesses each batch — destruction without a witness is a chain-of-custody gap if a former client later subpoenas the file.

  5. File the destruction certificate with retention records
    • The vendor's certificate of destruction lists every matter destroyed, the date, and the method. File it with the permanent retention records — not in the matter files themselves, since those no longer exist. The certificate is the firm's defense if a former client questions disposition.

    Collects file

Use this template

Copy it to your account, customize the steps, and run it with your team in minutes.


Sections 5
Steps 24
Category Law Firm
Price Free to start
Need a different process

Browse hundreds of free templates across every team and industry.

Back to template library

Run Law Firm Compliance Checklist with your team

Customize the steps, assign roles, set a schedule, and keep a complete record for every run.