You get a map of the rules your firm is captured by, checked against the systems you actually run. Legal profession rules for your state. The Privacy Act. AUSTRAC from 2026 where the firm provides designated services. The cyber-insurance conditions that now read like audit checklists. We name the gaps, cost the remediation and stage the work, so what you show an auditor is a program rather than a panic.
Most of the weight is in three places. Identity and access, so the people with matter access are the people who should have it. Offboarding happens the day someone leaves, not the month after. Logging and retention, so when a regulator or an insurer asks what happened to a file, you have an answer that stands up. And evidence generation, so every control you claim is one we can produce a report from. Firms that treat compliance as a reporting problem pass audits. Firms that treat it as a culture statement do not.
The cycle then runs continuously rather than once a year. Gap analysis at the start, monitoring throughout, remediation when something drifts, and evidence that produces the artefact on demand. A standing program, not a project with a finish line.
We write none of your legal documents. We set up the document management, identity, monitoring and retention your legal and compliance work depends on. You own the interpretation. We own the machinery.