Case studyFortune 100: 80% less compliance workRead the Story
RiskWatch

For Law Firms + In-house Legal + ALSPs

One platform for client-data risk, ABA + ISO compliance, and outside-counsel security across every matter.

Law firms hold the most sensitive data their clients have. ABA Model Rule 1.6 requires reasonable efforts to protect it. ABA Formal Opinions 477R, 483, and 498 set the floor. Banks, healthcare, and government clients add outside-counsel guidelines on top. RiskWatch handles all of it as one survey-based assessment platform sized for risk partners + IG + IT + GC offices.

Trusted by AmLaw, mid-size, and boutique firms managing ABA Model Rules, ISO 27001, SOC 2, and outside-counsel guidelines across litigation, transactional, IP, regulatory, and government-contracts practices.

TWGWorldAwareBoseJohnson & JohnsonPfizerPuma North America
4.8G2 Crowd·108+
4.7Capterra·76+
4.8Gartner Peer Insights·Voice of Customer

Why Risk + IG + IT Partners Pick RiskWatch

RiskWatch turns ABA, ISO 27001, SOC 2, and OCGs into one program.

RiskWatch runs ABA Model Rules tech-competence, ISO 27001, SOC 2 Type II, outside-counsel guideline responses, and client questionnaire workflows as one program on one platform, scored against the same controls library, and tracked through a single client-audit-ready evidence trail. Built for law firms where one risk partner covers four frameworks, dozens of OCGs, and hundreds of client questionnaires a year, without enterprise-bank GRC overhead.

OCG response built-in, not bolt-on

Bank, healthcare, and government client OCGs map to the same controls library. Respond to each new OCG in days by referencing existing evidence, not weeks of fresh assessments.

ABA + state bar expectations cross-mapped

Model Rules 1.1 tech competence, 1.6 confidentiality, 5.3 supervision plus ABA Formal Opinions 477R/483/498 mapped to the controls library. State bar variations tracked as overlays.

Sized for partner + IG + IT teams

Risk partner, IG director, CISO, and CIO see the same evidence. Pre-built libraries cut prep time. White-glove implementation in 30 days, not 6 months.

The Legal Services Risk Landscape

Legal-services risk is client-driven. The numbers prove it.

ABA Formal Opinion 483 made breach-notification a Model Rule obligation. The ABA's 2024 Cybersecurity TechReport found 29% of firms had experienced a breach. Bank and healthcare clients impose OCGs that read like ISO 27001 audits. Government-client work pulls in CMMC 2.0 + ITAR + EAR. State privacy laws (CCPA + 17 others) layer on top. Each client wants its own evidence package.

Op. 483
ABA Formal Opinion making breach response a Model Rules obligation
29%
of US law firms reported a security breach (ABA 2024 TechReport)
Comment 8
Model Rule 1.1 (Competence) explicit duty to keep abreast of technology
Op. 477R
ABA opinion on securing communication of protected client information

Three Domains, One Platform

Legal-services risk lives in three concrete domains

RiskWatch covers all three. Each domain has a dedicated workflow, scoring model, and remediation queue. They share data so a single access-review event satisfies ABA 1.6 confidentiality, ISO 27001 A.9, SOC 2 CC6, and an OCG access-control clause simultaneously.

Risk

Client-data + Practice Risk

Survey-based risk assessment across confidentiality, conflicts, supervision, OCG exposure, and matter-level risk, scored against ABA Model Rules + state bar standards.

  • ABA 1.6 confidentiality scoring
  • OCG exposure register per client
  • Conflicts + supervision evidence
Explore Risk Management
Compliance

ABA + ISO + SOC 2 + State Bar

ABA Model Rules tech-competence, ISO 27001, SOC 2 Type II, ABA Formal Opinions 477R/483/498, NY/CA/IL state bar guidance in one cross-mapped library.

  • ISO 27001 + SOC 2 cross-mapped
  • ABA Formal Opinions tracked
  • State bar overlays per office
Explore ISO 27001 + SOC 2
Security

Outside-Counsel + Client Audits

OCG responses, client questionnaire automation (CSA STAR, SIG Lite/Core, Schellman), CMMC 2.0 + ITAR + EAR for government-matter exposure.

  • OCG library cross-referenced
  • SIG Lite + Core + STAR ready
  • CMMC + ITAR + EAR for gov work
Explore Cybersecurity

The Coverage Gap

Most legal-services software covers one domain

Practice management covers matter intake. iManage + NetDocuments cover documents + ethical walls. Trust-center vendors cover SOC 2 evidence. Each does one job. Law firm risk + IG + IT teams still operate four parallel programs.

Platform CategoryABA RulesISO 27001SOC 2OCGClient auditsMulti-office
Practice Management PlatformsAderant, Elite 3EPartial··Partial·Yes
Document + DMS PlatformsiManage, NetDocumentsPartialPartialPartialPartial·Yes
Trust Center / SOC 2 ToolsDrata, Vanta, Secureframe·YesYes·Partial·
Internal Audit / ERMWorkiva, AuditBoard·PartialPartial··Partial
Questionnaire SpecialtyProcessUnity, OneTrust···YesYes·
Spreadsheets & Email······
RiskWatchThe unified client-audit-ready platformYesYesYesYesYesYes

RiskWatch is the only platform covering all six legal-services compliance domains: ABA Model Rules + Formal Opinions, ISO 27001:2022, SOC 2 Type II, outside-counsel guideline (OCG) responses, client questionnaires (SIG / CSA STAR / Schellman), and multi-office coordination. Trust-center vendors cover ISO + SOC 2. Practice management covers matter intake. Each does one job. RiskWatch unifies all six in one survey-based assessment workflow.

How It Works

One platform. Continuous compliance across every framework.

RiskWatch is a survey-based assessment platform. The work is structured around questionnaires that capture confidentiality, security, supervision, and matter-risk evidence in a consistent format, then scored against every framework you align to.

For law firms, that workflow runs continuously across ABA Model Rules tech-competence, ISO 27001, SOC 2 Type II, OCG response, and client questionnaire (SIG / CSA STAR / Schellman) cycles. A single access-review record scores against ABA 1.6, ISO 27001 A.9, SOC 2 CC6, and dozens of OCG access-control clauses simultaneously.

The same platform runs all of it, surfaces gaps before client audits arrive, assigns remediation owners, and tracks completion. Replace the four parallel tools and the spreadsheet bridge between them.

The Workflow

  1. 01
    Assess
    Survey-based questionnaires capture confidentiality, security, supervision, OCG, and client-audit posture across the firm + every office.
  2. 02
    Score
    Responses score against your chosen framework: ABA Model Rules + Formal Opinions, ISO 27001:2022, SOC 2 Type II, NIST CSF 2.0, CMMC 2.0, or custom OCG scorecards.
  3. 03
    Remediate
    Gaps become assigned tasks. Owners get deadlines. Vendor + cloud-DMS tasks cascade to the supplier portal automatically.
  4. 04
    Audit
    Evidence trails export to PDF, ISO 27001 SoA, SOC 2 management response, OCG attestation, or SIG Lite/Core spreadsheet. Client-audit-ready in minutes.
ConfidentialityConflictsOCGClient auditsState bar

Built For Your Role

Who uses RiskWatch in a law firm or in-house legal team

Risk Partner / General Counsel

Owns ABA Model Rules tech-competence, ABA Formal Opinions 477R/483/498, breach-response duty, and firm-wide risk register.

ABA-aligned scoring continuous. Breach-response readiness captured. Risk dashboard surfaces the matters and clients driving exposure.

Information Governance Director

Owns matter mobility, ethical walls, document classification, retention, and outside-counsel guideline mapping.

OCG library mapped per client. Ethical-wall + DMS evidence captured. IG audit-ready year-round.

Firm CISO / Director of IT Security

Owns ISO 27001, SOC 2 Type II, vendor risk, client questionnaire response, and firm-wide cybersecurity posture.

ISO 27001 SoA live. SOC 2 evidence captured year-round. Client questionnaires answered in days, not weeks.

Chief Information Officer

Owns DMS + practice management + cloud-services posture, business continuity, and tech roadmap risk.

Vendor + cloud risk register live. BCM/DR evidence captured. Roadmap aligned to ISO 27001 + SOC 2 + OCG demands.

In-house Legal Ops

Owns outside-counsel-program oversight, OCG enforcement, panel firm reviews, and matter-level risk.

OCG attestation captured per panel firm. Firm-side risk visible per matter. Panel reviews evidence-driven.

Practice Group Leader

Owns practice-group level conflict checks, supervision, sub-contracting + ALSP relationships, and matter-team training.

Supervision evidence (Rule 5.3) captured. Practice-group risk benchmarked. Subcontractor + ALSP risk visible.

Built For Your Segment

Legal-services segments we serve

AmLaw 200 Firms

Multi-office, multi-jurisdiction firms with ISO 27001 + SOC 2 + OCG-driven client demands across every practice group.

Mid-Size Regional Firms

100–500 attorney firms balancing practice-management + IG + IT with leaner risk teams and growing OCG exposure.

Boutique + Specialty Firms

Litigation, IP, regulatory, and tax boutiques where client-data sensitivity + bar discipline risk are concentrated.

In-house Legal Departments

Corporate GC offices managing outside-counsel programs, panel firm oversight, and OCG enforcement.

Government Contracts Practices

Firms representing DoD + intel + civilian agency contractors under CMMC 2.0 + ITAR + EAR exposure.

ALSPs + Legal Tech

Alternative Legal Service Providers and managed-services teams with their own ISO 27001 + SOC 2 expectations from law firm + client buyers.

Frameworks We Cover

Legal-services frameworks built into the library

RiskWatch ships with pre-built libraries for every major legal-services rule, opinion, and standard. Map controls once. Score against the framework that matters this audit cycle.

Professional Responsibility

ABA Model Rule 1.1
Competence, Comment 8 explicitly extends to technology.
ABA Model Rule 1.6
Confidentiality, Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure.
ABA Formal Op. 477R
Securing communication of protected client information (revised 2017).
ABA Formal Op. 483
Lawyers' obligations after an electronic data breach or cyberattack (2018).
ABA Formal Op. 498
Virtual practice, security expectations for remote and hybrid work (2021).
ABA Model Rule 5.3
Responsibilities regarding nonlawyer assistance, extends to vendors + ALSPs.

Industry + Security Frameworks

ISO/IEC 27001:2022
Information security management system, the firm-side baseline most OCGs reference.
SOC 2 Type II
AICPA Trust Services Criteria, the US-default firm trust report.
CSA STAR
Cloud Security Alliance STAR self-assessment + 3rd-party attestation for cloud-heavy firms.
SIG Lite + Core
Shared Assessments SIG questionnaire, the US-default outside-counsel + vendor audit.
CMMC 2.0
Cybersecurity Maturity Model Certification, required for firms supporting DoD contractors.
NIST CSF 2.0
Cybersecurity Framework 2.0 (Feb 2024), the cross-sector reference firms align to.

Trusted across legal services

TWGWorldAwareBoseJohnson & JohnsonPfizerPuma North AmericaThe Coca-Cola Company
Our clients sent us 60+ outside-counsel-guideline questionnaires last year. Each used to mean a fresh assessment. Now we map the OCG to our controls library once, and the firm produces a tailored evidence package per client in days. ISO 27001 surveillance, SOC 2 fieldwork, and the next OCG cycle all run from the same evidence vault.
M. Roth
General Counsel + Risk Partner, AmLaw 200 firm · 1,400 attorneys · 12 offices
60+ → 1OCGs consolidated to one shared evidence trail
ISO + SOC 2audits running in parallel from the same vault
30 daysfrom kickoff to first ABA + ISO scoring live
FAQ

Frequently asked questions

Law Firms · In-house Legal · ALSPs

See RiskWatch run an ABA + ISO 27001 + OCG cycle live

30-minute walkthrough of the legal-services library, your client-audit cycle inputs, and the single evidence-trail output. No slideware, no consulting upsell.

Or call US: +1 401 884 5236

Request a Demo