Skip to content

Compliance pressure on law firms, and how to answer it.

Trust accounts, privilege, client confidentiality, and now anti-money-laundering reporting. None of it is a project with a finish line. Your systems either support those obligations every day or quietly undermine them, and the difference shows when someone asks for proof.

Live right now ·  law firms

What's hitting law firms right now.

Regulatory changes with dates already set, and what each one asks of you.

AUSTRAC Tranche 2 AML/CTF

In force since 1 July 2026

Captures law firms providing designated services, including trust account operations and real estate conveyancing. AUSTRAC enrolment closed on 29 July 2026, so your AML/CTF programme has to be in operation now.

Read the full guide

What's being asked of you ·  law firms

What law firms have to prove on compliance in 2026.

Your obligations have stacked up faster than the firm has grown. Trust accounting rules have always been there. From 1 July 2026, firms providing designated services also enrol with AUSTRAC, the financial-crime regulator, under the Tranche 2 anti-money-laundering reforms. That reaches into matter intake, client identification, record-keeping, suspicious-matter reporting and the audit trails behind all of it. The Privacy Act already covers the client data you hold, whatever happens to the small-business exemption.

Underneath every one of those rules is the same demand for evidence. Someone asks to see your anti-money-laundering program, your privacy program, your incident-response runbook, your access-review schedule. They want the document and proof it is being followed, not a verbal assurance. Most mid-size firms cannot produce that today. The work to be able to is mostly IT and process work, underneath the legal substance.

The third front comes from your own clients. Larger corporates and listed companies now send supplier security questionnaires before they renew an engagement letter. The questions are not legal ones. They ask about multi-factor authentication coverage, offboarding, patch cycles, backup testing and vendor management. A firm that cannot answer in writing within a week starts losing the work.

What we do ·  Map, build, maintain

What law firms get from a compliance engagement.

You get a map of the rules your firm is captured by, checked against the systems you actually run. Legal profession rules for your state. The Privacy Act. AUSTRAC from 2026 where the firm provides designated services. The cyber-insurance conditions that now read like audit checklists. We name the gaps, cost the remediation and stage the work, so what you show an auditor is a program rather than a panic.

Most of the weight is in three places. Identity and access, so the people with matter access are the people who should have it. Offboarding happens the day someone leaves, not the month after. Logging and retention, so when a regulator or an insurer asks what happened to a file, you have an answer that stands up. And evidence generation, so every control you claim is one we can produce a report from. Firms that treat compliance as a reporting problem pass audits. Firms that treat it as a culture statement do not.

The cycle then runs continuously rather than once a year. Gap analysis at the start, monitoring throughout, remediation when something drifts, and evidence that produces the artefact on demand. A standing program, not a project with a finish line.

We write none of your legal documents. We set up the document management, identity, monitoring and retention your legal and compliance work depends on. You own the interpretation. We own the machinery.

The tools and the role ·  the operational toolkit

The capabilities most law firms need at once, and rarely have in-house.

Whichever framework you are measured against, it asks for roughly the same operational set. These five we run as a service, so the framework cycle is a continuing operation rather than an annual scramble.

  • Trouble shows up while it is still recoverable

    Security information and event management, or SIEM, collects logs from your devices, identity, network and cloud services. The alerting answers 'are we under attack right now' rather than 'were we under attack last quarter'.

  • Unapproved software never gets to run

    Allowlisting stops unauthorised executables running on managed devices. One of the highest-impact Essential Eight controls, and one of the hardest for in-house IT to operate without breaking the business. We run it as a service, exception handling included.

  • Known vulnerabilities get closed, not just listed

    Most providers run a scanner and email you a list. We run the scanner and do the labour-intensive remediation work that actually closes the vulnerabilities inside the thirty-day window most frameworks expect.

  • Staff finish the training, and you can prove it

    Annual training your staff actually complete, plus phishing simulations that escalate rather than scold. Your compliance officer gets the completion reporting they can show an auditor or an insurer.

  • Someone senior owns the roadmap, without the salary

    Strategic IT advice, framework gap analysis, board-level reporting, risk register maintenance and vendor management oversight. That is the virtual chief information officer, or vCIO, role most firms our size cannot resource internally.

    More on our vCIO service

What goes wrong ·  for law firms

The compliance risk that actually costs law firms work.

The risk you are probably picturing is saying no to something you should have said yes to. The one that actually bites runs the other way. You answered yes to a control question on an insurer renewal or a client questionnaire, because you believed the control was there. Then a breach happens and someone asks for the evidence. If it does not exist, the insurer can decline the claim and the client can end the engagement.

Already included ·  baseline plan

What your managed IT engagement already covers.

Most of what compliance needs is already in the controls every CCP client is on. Multi-factor authentication on anything that matters, application control, vulnerability management, tested backups and offboarding discipline. That is the minimum, not the ceiling.

Where a specific rule asks for more, we add it for your engagement. Retention labels for anti-money-laundering records. Privileged-access logging on trust-account work. Sensitivity labels on matter files under privilege. Compliance is an overlay on the same baseline, not a separate product.

Some of it stays with you. The legal interpretation, the partner-level risk decisions, the anti-money-laundering program document itself, the law-society reporting. We do not replace your compliance officer, your in-house counsel or your anti-money-laundering adviser. What we bring is the IT and process capability most firms cannot resource internally.

Common questions

The framework questions law firms ask us first.

Can a managed IT provider help with our AUSTRAC Tranche 2 obligations?
Do we need ISO 27001 to win larger corporate clients?
What is the difference between an Essential Eight assessment and a compliance program?
How is this different from hiring a compliance officer?
Can you help us answer client security questionnaires?
What evidence will we be able to produce afterwards?
What about PEXA and conveyancing-specific risk?

Next step ·  start with the evidence

Find out what your Essential Eight maturity actually is.

Ten minutes of questions gives you a PDF report on your Essential Eight maturity. Hand it to your compliance officer, your insurer or your board the same day. If you want to check we are the right shop for the work, start with the fit check.

See if we're a fit