Let’s get your team trained and using Microsoft Copilot and moving your business forward. Click here to book +61 3 4803 4915Client PortalRemote Support
Belton IT Nexus
Belton IT Nexus · Est. 2004 · Newmarket, AucklandAbout us ›
Home/ Resources/ Law Firm IT Risk Self-Assessment

NZ law firm IT risk check.

A practitioner-grade self-assessment for partners and practice managers, covering AML/CFT, the Privacy Act 2020, NZLS rules of conduct, e-discovery, trust account audit-readiness, and secure file sharing.

12Risk areas
PDFPrintable
FreeNo cost
The self-assessment
§01

What it covers.

12 areas

For partners, practice managers, and operations leads at small-to-mid Australian law firms. It is the same control set we work through with our own legal clients before AML audits, trust account reviews, NZLS practice inspections, and cyber insurance renewals. Each area is grounded in a specific NZ obligation, a specific NZLS rule, or a specific failure mode we see in legal practices.

  • AML/CFT obligations for the legal sector DIA supervision of captured activities, and the IT evidence that stands up at an on-site review.
  • Privacy Act 2020 for client data Mandatory breach notification and the Information Privacy Principles applied to legal files and trust records.
  • NZLS rules of conduct as they intersect with technology The technology side of confidentiality (Rule 8) and competence (Rule 3) under the Conduct and Client Care Rules.
  • E-discovery and document management Handling large volumes of opposing-party data and keeping your DMS defensible.
  • Trust account audit-readiness Access control and audit trails on the ledgers an inspector or auditor will ask to see.
  • Secure file sharing with clients and courts Moving sensitive documents without email attachments leaking privilege.
  • Confidentiality and privilege in the cloud Where your data lives, who can reach it, and how privilege survives a cloud migration.
  • Encrypted email and secure messaging Practical encryption for partner mail and the out-of-band verification that stops settlement fraud.
  • Staff onboarding and offboarding controls Disabling identity, revoking tokens, and removing access in dependency order when people move on.
  • BYOD risk for legal staff Personal devices holding cached client files, and the controls that contain them.
  • Ransomware impact on litigation deadlines Continuity planning when an attack is timed to a court deadline.
  • Cyber insurance for legal practices The underwriter questions, and the evidence to keep so a claim is paid rather than disputed.

Printable PDF covering twelve risk areas. Use it in your next partner meeting or AML audit prep session.

You will receive the download immediately. We may send occasional emails about NZ legal IT and compliance. Unsubscribe any time. Prefer a direct link? Download the PDF →

Want the controls
implemented, not just listed?

We work with Australian law firms on the full stack: identity, document management, trust accounting, e-discovery, and compliance evidence.

NEW ZEALAND OWNED & OPERATED EST. 2004
Sovereign by design

New Zealand owned and operated.

Sovereign data centres across New Zealand and Australia, with your data kept onshore wherever it's required. Our team understands New Zealand, and our leaders have built, scaled and secured businesses right across the New Zealand landscape.

Sovereign data centres · New Zealand & Australia
  • Auckland
  • Christchurch
  • Sydney
  • Melbourne
  • Brisbane
  • Perth
International data-centre operations
  • Singapore
  • Germany
  • Netherlands
  • USA

Servers available in minutes, not days.

Explore data centres & hosting →
Accredited partners
Microsoft Solutions Partner Fortinet Partner Lenovo Partner HP Partner Apple Business Manager