# Law Firm AI Governance: Policy, Training, and Client Consent

> Legal · AI Course · LEG-9
> Source: https://ibl.ai/solutions/legal/course/law-firm-ai-governance
> Last updated: 2026-08-25

**Stand up firm-wide AI governance — approved tools, mandatory training, client disclosure, outside counsel guidelines, and the audit trail an insurer will want.**

## The Short Answer

**Law firm AI governance must satisfy partners, client outside counsel guidelines, and a malpractice carrier at the same time. ibl.ai gives firms a governance-friendly deployment where you own all the code and the data, so approved-tool policy is enforceable at the infrastructure level rather than relying on partner compliance.**

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.

[Request Access](https://ibl.ai/contact) · [Explore Legal](https://ibl.ai/solutions/legal)

## Course facts

- **Level:** Intermediate
- **Duration:** 5 hours across 8 modules
- **Format:** Cohort workshop producing a governance package
- **Modules:** 8
- **Catalog code:** LEG-9
- **Frameworks covered:** ABA Model Rules, ISO/IEC 42001, Client outside counsel guidelines, NIST AI RMF

## What is this course about?

Firm AI governance has to survive three audiences: partners who resent process, clients whose outside counsel guidelines already restrict AI, and a malpractice carrier that will ask what controls exist. This course builds a governance structure addressing all three, including stopping shadow AI use without driving it further underground.

## Who is this course for?

- Firm general counsel and risk partners
- Managing partners and executive committee members
- Firm CIOs and innovation officers
- Professional responsibility committee members

### What do I need before starting?

- Firm leadership or risk responsibility
- Access to client outside counsel guidelines

## What will I be able to do afterwards?

- Establish an AI committee with authority partners will accept
- Maintain an approved tool list and stop shadow AI use
- Deliver mandatory training and document competence
- Meet client disclosure and outside counsel guideline requirements
- Produce the audit trail a malpractice carrier expects

## What does each module cover?

### Module 1 — Who sits on the AI committee?

Composition and authority that a partnership will actually respect. _(40 min)_

**Objectives**

- Define committee composition and authority
- Secure partnership buy-in for the authority
- Design a decision process that is fast enough

**Topics:** Committee composition · Authority · Partnership buy-in · Decision speed

**Activity:** Draft the committee charter and test it against three real decisions.

### Module 2 — How do you stop shadow AI without driving it underground?

Approved tool lists that work because the approved tools are good enough. _(45 min)_

**Objectives**

- Build and maintain an approved tool list
- Make approval fast enough that people wait for it
- Detect unapproved use without surveillance

**Topics:** Approved lists · Approval speed · Shadow AI detection · Non-punitive discovery

**Activity:** Survey actual tool use anonymously and compare against the approved list.

### Module 3 — What training is mandatory, and how do you prove it?

Training that discharges the competence duty and produces evidence it happened. _(45 min)_

**Objectives**

- Define mandatory training by role
- Document competence for each attorney
- Refresh training as tools and rules change

**Topics:** Mandatory training · Competence documentation · Role differentiation · Refresh cadence

**Activity:** Design the mandatory training program with competence documentation.

### Module 4 — What do client outside counsel guidelines already say?

The AI restrictions clients have already imposed, which most firms have not audited. _(45 min)_

**Objectives**

- Audit client guidelines for AI restrictions
- Track restrictions per client and matter
- Enforce restrictions technically where possible

**Topics:** Guideline audit · Per-client tracking · Technical enforcement · Conflict with firm policy

**Activity:** Audit your top ten clients' guidelines for AI restrictions.

### Module 5 — How do you obtain client consent?

Engagement letter language and the conversation with a client who asks hard questions. _(45 min)_

**Objectives**

- Draft engagement letter AI provisions
- Handle the client conversation
- Manage clients who decline

**Topics:** Engagement letter language · Client conversations · Declining clients · Matter-level variation

**Activity:** Draft the engagement letter provision and rehearse the client conversation.

### Module 6 — What does your malpractice carrier want to see?

Carrier expectations, and the controls that affect coverage and premium. _(40 min)_

**Objectives**

- Identify carrier expectations around AI
- Document controls in the form carriers request
- Understand coverage implications

**Topics:** Carrier expectations · Control documentation · Coverage implications · Renewal questions

**Activity:** Complete a carrier AI questionnaire honestly and identify the gaps.

### Module 7 — What does the audit trail need to contain?

Logging that supports a later inquiry without creating a discoverable liability. _(40 min)_

**Objectives**

- Specify audit trail contents
- Balance evidentiary value against discoverability
- Set retention appropriately

**Topics:** Audit trail contents · Discoverability · Retention · Incident support

**Activity:** Specify the audit trail and review it with litigation counsel for discoverability.

### Module 8 — Assembling the governance package

The workshop module: policy, consent, training, and audit assembled for adoption. _(50 min)_

**Objectives**

- Assemble the complete governance package
- Plan the partnership adoption path
- Set the review cadence

**Topics:** Package assembly · Adoption path · Review cadence · Communication

**Activity:** Assemble the package and plan the partnership meeting that adopts it.

## What is the capstone project?

**Firm AI governance package.** Produce the complete package: committee charter, approved tool list with a fast approval path, mandatory training with competence documentation, a client guideline audit, engagement letter provisions, carrier-ready control documentation, and an audit trail specification.

_Deliverable:_ A governance package ready for partnership adoption.

## How are learners assessed?

- Anonymous tool survey completed and compared against the approved list
- Client guideline audit covering the firm's largest clients
- Audit trail specification reviewed by litigation counsel for discoverability

## What ships with the course?

- **Facilitator guide.** Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
- **Learner workbook.** Exercises, checklists, and the templates each module's activity produces.
- **Hands-on lab environment.** A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
- **Assessment bank.** Scenario questions and rubric criteria mapped to each stated learning outcome.
- **Source bibliography.** Every primary regulation and standard cited on this page, linked and dated.

## Which AI agents does this course use?

- [Compliance Agent](https://ibl.ai/solutions/legal/agent/compliance-agent)
- [Training Agent](https://ibl.ai/solutions/legal/agent/training-agent)
- [Knowledge Agent](https://ibl.ai/solutions/legal/agent/knowledge-agent)
- [Conflicts Check Agent](https://ibl.ai/solutions/legal/agent/conflicts-check-agent)

## Where does the course material come from?

Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

- [Model Rules of Professional Conduct](https://www.americanbar.org/groups/professional_responsibility/publications/model_rules_of_professional_conduct/) — American Bar Association. The duties the governance package must discharge.
- [AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) — NIST. Control framework the governance package maps to.
- [ISO/IEC 42001, AI management systems](https://www.iso.org/standard/42001) — ISO. Management system structure for firms seeking formal certification.
- [OWASP Top 10 for LLM Applications](https://owasp.org/www-project-top-10-for-large-language-model-applications/) — OWASP. Technical control requirements informing the approved tool criteria.

## Delivery notes

Binding guidance for anyone preparing and delivering this course:

- Module 2's approval speed is the whole shadow-AI strategy. If approval takes six weeks, partners will use unapproved tools regardless of policy, and the governance is theatre.
- The anonymous survey must be genuinely anonymous and non-punitive. Attorneys will not disclose unapproved use to a process that could sanction them.
- Module 7's discoverability question is real and under-considered. An audit trail built for governance can become a plaintiff's exhibit, and litigation counsel should shape it.
- Module 4 will surprise most firms. Many large clients already restrict AI in their guidelines and firms have been non-compliant without knowing it.
- Coordinate with LEG-6 — the policy content comes from there, and this course is about the governance structure that operates it.

## Why run AI training on a platform you own?

- **You own the course, not a licence to it.** Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
- **Model-agnostic delivery.** Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
- **No per-seat training licences.** Usage-based or self-hosted, so cost tracks actual use rather than headcount.
- **Deploy anywhere.** Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.

## Frequently asked questions

### What does the Law Firm AI Governance: Policy, Training, and Client Consent course cover?

Firm AI governance has to survive three audiences: partners who resent process, clients whose outside counsel guidelines already restrict AI, and a malpractice carrier that will ask what controls exist. This course builds a governance structure addressing all three, including stopping shadow AI use without driving it further underground. It runs 5 hours across 8 modules across 8 modules, at intermediate level, and closes with a capstone: Firm AI governance package.

### Who should take Law Firm AI Governance: Policy, Training, and Client Consent?

It is written for Firm general counsel and risk partners, Managing partners and executive committee members, Firm CIOs and innovation officers, Professional responsibility committee members. Prerequisites: Firm leadership or risk responsibility; Access to client outside counsel guidelines.

### Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for legal teams that cannot send work to a public AI tool.

### How do we get access to Law Firm AI Governance: Policy, Training, and Client Consent?

Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

### How much does AI training for legal cost on ibl.ai?

There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

## More Legal courses

- [AI and Attorney-Client Privilege: The Architecture Question](https://ibl.ai/solutions/legal/course/ai-and-attorney-client-privilege): Whether sending client material to a third-party AI service waives privilege — the confidentiality analysis, the reasonable-efforts standard, and the deployment that avoids the question.
- [Verifying AI Legal Research: Never Cite a Hallucination](https://ibl.ai/solutions/legal/course/verifying-ai-legal-research): A verification protocol for AI-assisted research — why fabricated citations happen, how to catch them every time, and the supervision structure that makes it non-optional.
- [Contract Review with AI: Redlining, Risk, and Playbooks](https://ibl.ai/solutions/legal/course/contract-review-with-ai): Encode your firm's negotiating positions into an AI review workflow — clause extraction, deviation detection, risk scoring, and where a partner still reads every word.
- [AI in eDiscovery: TAR, Privilege Screening, and Defensibility](https://ibl.ai/solutions/legal/course/ai-in-ediscovery): Use AI across the discovery lifecycle while keeping the process defensible — technology-assisted review, privilege screening, validation, and the meet-and-confer record.
- [Client Intake and Conflicts Checking with AI](https://ibl.ai/solutions/legal/course/client-intake-conflicts-with-ai): Faster intake without a missed conflict — entity resolution across a matter history, adverse party detection, and why the conflicts decision stays human.
- [Ethical AI Use Under the ABA Model Rules](https://ibl.ai/solutions/legal/course/ethical-ai-under-aba-model-rules): A rule-by-rule walk through AI in practice — competence, confidentiality, supervision, fees, and communication — with a firm policy you can adopt.
