Client-matter data segregation: the ISO 27001 evidence law firms demand
Law firms buying legaltech products want documented evidence that client-matter data cannot bleed across matters or tenants. ISO 27001 access reviews, need-to-know controls and DMS sub-processor records are the artefacts that answer the question.
By Kellwick Team · August 21, 2026 · 6 min read
Law firms hold some of the most sensitive information in the economy - client communications protected by legal privilege, transaction details subject to confidentiality obligations, and matter data where a conflict of interest could carry professional consequences. When a firm evaluates a legaltech product, their information security requirements are not generic buyer diligence. They are shaped by professional conduct rules, insurance requirements, and the firm's own obligations to clients. The question "how do you segregate client-matter data?" is not a checkbox - it is a threshold question, and the answer has to be evidenced, not verbal.
ISO 27001 is increasingly the framework firms use to evaluate whether a vendor has the controls in place to handle matter data appropriately. But the certificate alone is not enough. Sophisticated buyers at law firms will ask follow-up questions that probe whether the controls actually work as described, and they will re-audit at contract renewal. The evidence burden does not end at certification.
What client-matter segregation means in practice
Client-matter segregation is the requirement that data belonging to one matter cannot be accessed by users working on a different matter, and that data belonging to one client cannot be visible in another client's context. This has both technical and procedural dimensions.
On the technical side, it means that the product's access control model must support matter-level or client-level isolation - not just firm-level tenancy. A product that segregates between law firms but allows anyone inside a firm to access all matters within that firm will fail this requirement for any firm that handles competing client interests or requires matter-level conflicts checks.
On the procedural side, it means that access is granted on a need-to-know basis and that there is a documented process for provisioning and deprovisioning access to specific matters. If a fee earner leaves a matter team, their access to that matter's data should be removed promptly and that removal should be recorded.
The access review evidence that buyers ask for
When a law firm's IT security team asks "can you show us evidence of access reviews?", they are asking specifically about matter-level access - not just whether the vendor conducts periodic user access reviews in aggregate.
The evidence that satisfies this question has several components:
A record of who had access to what, at a point in time. This means a user-access matrix or equivalent export that shows, for a given period, which users had access to which matters or client workspaces.
A documented decision for each entry. Generating a list of users and their access is not an access review. A review requires that a named person with authority over that matter looked at each entry and affirmed that the access was appropriate - or initiated a change where it was not.
Evidence that changes were made. If the review identified any access that should be removed, the audit record should show that the removal happened, and approximately when.
A completion record. Who performed the review, the date of completion, and the sign-off. A spreadsheet of access without a completion record is audit output without audit evidence.
For ISO 27001 purposes, Annex A control A.8.2 on privileged access rights and A.8.3 on information access restriction both apply. Access reviews are expected to be periodic and documented. For legaltech products where the risk of inappropriate access is particularly high, the auditor may probe whether the review frequency is proportionate to the risk.
Need-to-know provisioning and the conflict-of-interest problem
Law firms operate with formal conflicts-checking processes before opening a matter. When a fee earner is confirmed to have no conflict of interest and is assigned to a matter, their access to that matter's data in the legaltech platform should follow automatically - or through a controlled provisioning request - rather than being granted ad-hoc or inherited from a broad role.
The need-to-know principle is explicit in ISO 27001 and it maps directly to how law firms think about matter access. A product architecture where access is granted at the firm level and then filtered by the product's application logic - but not enforced at the data layer - is harder to evidence than one where access is controlled at a more granular level from the outset. Buyers will ask which model applies.
If the product uses a shared search index, a shared vector database, or a shared inference context across matters, the controls that prevent cross-matter retrieval need to be documented and testable. "The product is designed to segregate" is not sufficient. The evidence should show how segregation is implemented and what the vendor's procedure is for detecting and responding to a segregation failure.
Legal-hold and retention controls
Law firms also need to be able to apply legal holds to matter data - preserving it against modification or deletion when litigation is anticipated or active. For legaltech products that are part of the document or communication workflow, this is a functional requirement. From an ISO 27001 perspective it intersects with information classification and retention policies.
The questions buyers typically ask:
- Can a legal hold be applied to specific matter data within the product?
- When a hold is applied, what prevents deletion by the matter team or by automated retention rules?
- When a hold is released, does standard retention policy resume, and is that transition logged?
- If data subject to a hold is backed up, does the hold status persist in the backup?
These are not questions that ISO 27001 mandates the vendor to answer in a specific way - the standard requires appropriate controls proportionate to the risk. But they are questions that buyers in regulated legal markets will ask, and the answers need to be documented in the vendor's information handling procedures.
Document management sub-processors
Most legaltech products integrate with or operate alongside document management systems - iManage, NetDocuments, SharePoint in legal configurations, or proprietary DMS environments. When the legaltech product accesses or indexes matter documents from a DMS, the DMS becomes part of the data-flow scope for ISO 27001 purposes.
Buyers who understand their own security posture will ask whether the legaltech vendor has documented the DMS integration as a supplier relationship, whether there is a contractual basis for the data access, and whether the vendor has reviewed the DMS provider's security assurance. The supplier management controls in Annex A (5.19 to 5.22) apply, and the sub-processor register should include the DMS integrations used in production.
This is a gap that emerges frequently: the vendor has a strong internal security posture and can evidence its own controls well, but has not mapped the DMS integration as a formal supplier relationship because it feels like a standard integration rather than a sub-processor arrangement. A buyer's security team that reads the data flow carefully will identify this.
Re-audit at contract renewal
One feature of law firm procurement that distinguishes it from many other enterprise buyers is the re-audit cycle. Firms that have gone through a rigorous initial vendor assessment will often schedule a review at contract renewal - sometimes annually, sometimes every two years. This review typically asks whether the controls documented at initial assessment are still in place, whether there have been any significant changes to the product architecture or sub-processor relationships, and whether any incidents occurred in the intervening period.
An ISO 27001 certificate is useful evidence for re-audit, but only if it is current and if the scope of the certification covers the product features the firm actually uses. A vendor whose certificate expired or whose certification scope was reduced during the contract period will face harder questions at renewal.
The practical implication is that maintaining a clean ISO 27001 posture is not a one-time cost for a legaltech vendor - it is an ongoing operational requirement. The management review cadence, the internal audit programme, and the supplier review process all need to be genuinely operational, not paused after the initial certification audit.
Where Kellwick fits
Kellwick works with legaltech vendors to build and evidence the matter-level access controls, need-to-know provisioning records, and supplier management documentation that law firms expect from their technology partners. If you are preparing for a firm's security assessment or working toward ISO 27001 certification in the legal market, learn more about how we support legaltech and regtech companies.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.