AIthical.Pro Solutions · Legal · Self-Audit

Is your firm ready to govern AI, or just using it?

A 10 to 15 minute self-audit across nine governance pillars, from acceptable-use policy and confidentiality to agent autonomy, observability, and data sovereignty. Weighted scoring, your weakest pillars, and prioritized next steps, computed on your device.

Nine pillars · 35 checksGenAI and agentic AI controlsNo signup required
Professional boundary

This self-audit is an operational decision aid. It is not legal advice, an ethics opinion, a compliance determination, or a certification, and completing it creates no attorney-client or advisory relationship.

How it is scored

Weighted by consequence, not by question count.

Each of the 35 checks is rated on a four-level maturity scale and weighted by risk. Pillar scores roll up into one readiness score, with confidentiality, agent trust, observability, and data sovereignty weighted heaviest, because that is where exposure concentrates as firms move from generative AI into agents that act.

0 / 35 answered

Pillar 01 · Policy & Oversight

Formal AI use policies, ownership, and decision rights.

POL-1Does the firm have a written AI acceptable-use policy approved by leadership?

Covers which tools may be used, prohibited uses, and escalation paths.

POL-2Is there a named owner or committee accountable for AI governance?

For example the GC, COO, CISO, innovation partner, or a cross-functional AI committee.

POL-3Does the firm maintain an inventory of AI tools in active use?

Includes generative AI, legal research AI, drafting tools, and embedded AI features.

POL-4Are high-risk AI use cases subject to pre-approval before firmwide rollout?

Pillar 02 · Confidentiality & Privilege

Client data handling, privilege, and matter confidentiality.

CONF-1Are attorneys prohibited from pasting client confidential data into unapproved public AI tools?
CONF-2Does the firm have clear rules for when AI outputs may enter the client file or work product?
CONF-3Are data retention, training, and model-improvement settings reviewed for each approved AI tool?

Especially whether prompts and outputs are used to train third-party models.

CONF-4Is there a process for handling potential privilege or confidentiality incidents involving AI?

Pillar 03 · Technology Controls

Approved tools, access controls, logging, and security.

TECH-1Does the firm maintain an approved list of AI tools with security review before use?
TECH-2Are SSO, MFA, and role-based access applied to AI platforms where available?
TECH-3Can the firm audit or log significant AI usage for sensitive matters?
TECH-4Are shadow AI tools monitored or blocked on firm devices and networks?

Pillar 04 · Training & Culture

Attorney and staff enablement, expectations, and accountability.

TRAIN-1Have attorneys and staff completed mandatory AI risk and responsible-use training?
TRAIN-2Does onboarding cover AI policy expectations for new hires and lateral attorneys?
TRAIN-3Are practice groups given role-specific guidance (for example litigation versus transactional use)?
TRAIN-4Is there a safe channel to report AI concerns or near-misses without blame?

Pillar 05 · Vendors & Third Parties

Due diligence, contracts, and ongoing vendor risk management.

VEND-1Does vendor due diligence specifically address AI data use, subprocessors, and model training?
VEND-2Do AI vendor contracts include confidentiality, breach notice, and audit or SOC report rights?
VEND-3Is there periodic re-review of AI vendors after material product or policy changes?

Pillar 06 · Ethics & Client Duties

Competence, supervision, disclosure, and professional responsibility.

ETH-1Does the firm require human review of AI-assisted legal work before client delivery?
ETH-2Are attorneys guided on competence duties when relying on AI (accuracy, hallucinations, citations)?
ETH-3Does the firm have a position on client disclosure when AI materially assists on a matter?
ETH-4Are supervisory lawyers accountable for AI use by associates, staff, and contract attorneys?

Pillar 07 · Agentic Trust & Autonomy

Agent permissions, human gates, kill switches, and irreversible-action controls.

TRUST-1Are agent autonomy levels defined (suggest-only, draft-with-approval, limited-execute, full-execute)?

Clear tiers prevent agents from taking irreversible actions without an intentional authorization model.

TRUST-2Do agent tool permissions whitelist what systems an agent may call (DMS, email, billing, e-filing, CRM)?

Least-privilege tool access for agents that can act, not only generate text.

TRUST-3Is human-in-the-loop required before irreversible or client-facing agent actions?

For example sending email, filing, changing matter status, moving money, or publishing external work product.

TRUST-4Is there a documented kill switch and stop path to halt runaway or misbehaving agent workflows?

Pillar 08 · Agentic Observability

Traces, decision logs, matter-level replay, and monitoring of agent runs.

OBS-1Can the firm capture end-to-end agent traces (inputs, tool calls, intermediate steps, final actions)?

Required for incident review, ethics supervision, and client and matter reconstruction.

OBS-2Are agent decision logs retained at matter level with enough detail to replay what happened?
OBS-3Is there monitoring for agent failures, drift, unusual tool use, or anomalous activity?
OBS-4Are roles defined for who may inspect agent runs (supervising attorney, GC, IT and security, client)?

Pillar 09 · Data Sovereignty

Residency, matter isolation, memory boundaries, and custody of firm and client data.

SOV-1Does the firm enforce data residency and region controls for AI and agent platforms handling client data?

Including where prompts, embeddings, memory, and logs are stored and processed.

SOV-2Is client-matter isolation enforced so agent memory and context cannot bleed across matters or clients?
SOV-3Are agent memory, embeddings, and scratchpads subject to retention, deletion, and legal-hold rules?
SOV-4Does the firm control encryption keys and custody (or equivalent) so agent data cannot leave the firm trust boundary unchecked?

Includes BYOK or CMEK where available, private networking, and contractual limits on subprocessors.

You’ll see a weighted readiness score, your weakest pillars, and prioritized next steps, instantly and on this device only.

From score to operating model

The audit finds the gaps. G.A.V.E.L. closes them.

AIthical.Pro's G.A.V.E.L. framework turns these same nine pillars into a firm operating model: leadership and accountability, matter-level decisioning, data and access governance, AI workflow controls, and evidence and response.

Bring your score. Leave with a plan.

A 30-minute working session maps your weakest pillars to a practical remediation sequence, sized for the firm you actually run.

Book a governance working session
Book a strategy call