AI Readiness Assessment for Law Firms: What Five Days Should Tell You
At a Glance
- Who this is for: Managing Partners, COOs and Heads of IT or Innovation at UK firms that have AI licences in place and cannot yet point to a workflow that runs differently because of them.
- The problem: Most AI readiness assessments were written for businesses that sell products. They score strategy, data, infrastructure and people, and skip the places a law firm's risk actually sits: matter permissions, client terms and the supervision chain.
- What is changing: The SRA published a warning notice on the misuse of AI on 17 August 2026, after receiving 42 reports of potential misuse between July 2025 and July 2026.
- The takeaway: A useful assessment ends with a costed plan for named workflows, a list of blockers with owners, and a written list of work AI will not touch. A maturity score on its own changes very little.

An AI readiness assessment for a law firm should answer one commercial question: which pieces of work can AI take on in the next 90 days, safely, and what will it cost to get there. Most firms that commission one get something else back, usually a score out of five for each of several pillars and a recommendation to improve data quality. That output is accurate and very hard to act on, because it describes the firm in general and none of its matters in particular.
What an AI Readiness Assessment is
An AI readiness assessment is a short, structured review of whether an organisation can adopt AI safely and get a return from it. It normally tests strategy, data, infrastructure, governance and people, then sets out what needs to change first. For a law firm, the same review has to test three things a generic version leaves out: who can see which matter data, what clients have agreed to, and how AI output gets supervised before it leaves the building.
Why Generic Assessments Miss What Matters in a Law Firm
Generic readiness frameworks treat data as one estate to be cleaned and connected. A firm's data sits in matters, behind ethical walls and document management permissions that were set up for people, and an AI tool that indexes across those boundaries can surface one client's work to a team acting against them. Testing whether a firm's data is ready for AI means testing whether the permissions a tool inherits are the ones the risk team believes exist.
Client terms are the second gap. Outside counsel guidelines and engagement letters can restrict how a firm uses AI on a client's work, from requiring notice to excluding it on certain matters. A readiness review that never reads them can recommend a use case the firm is contractually unable to run.
Supervision is the third, and the regulator has made it the most pressing. On 17 August 2026 the SRA published a warning notice on the misuse of AI, naming inaccurate information in research and court submissions, and confidential client data entered into tools without safeguards, as its main concerns. The SRA said it had received 42 reports of potential AI misuse between July 2025 and July 2026, and that in June it added AI sections to its guidance on effective supervision. An assessment that treats governance as a policy to be written later is now out of step with the regulator.
What a Five-Day Assessment Should Cover
Five working days is enough to answer the questions that matter, provided the firm puts the right people in the room for the week: a partner who owns a practice area, the head of IT, whoever runs risk and compliance, and someone from finance who can price the current process. The table sets out what each area should test and what good evidence looks like by the end of the week.
| Area | What to test | Evidence you should have by day five |
|---|---|---|
| Infrastructure and tenancy | Where prompts, documents and outputs are processed and stored, and whether AI runs inside the firm's own Microsoft tenant or sends data to a third party | A data-flow diagram for each tool in use or under evaluation, signed off by IT and risk |
| Matter data and permissions | Whether document management security, ethical walls and matter-level access carry through to an AI tool | A sample of matters where inherited permissions were checked against what the risk team expects |
| Process | Which workflows consume the most fee-earner and support time, and what each one costs today | Baseline hours and cost for three to five candidate workflows |
| Governance and supervision | Who reviews AI output, what gets logged, which work is excluded, and how the COLP stays accountable | A named reviewer per workflow and a draft exclusion list agreed with a risk partner |
| Client terms | What outside counsel guidelines and engagement letters permit | A register of client restrictions mapped against the candidate workflows |
The process row is the one firms tend to skip, and it decides whether the plan survives budget review. Without a baseline for how long a task takes today, nobody can show the Managing Partner or the Finance Director what AI changed, and the programme drifts into licence renewals with no measured return.
What the Firm Should Hold at the End
A readiness score by pillar is the least useful thing an assessment produces. What a Managing Partner and a Head of IT can both act on is shorter and more specific:
- A ranked list of workflows, each with its current cost, the expected effect of AI on it, and the risk that comes with it.
- A list of blockers, each with a named owner and a date, such as permissions that need fixing before any tool is connected.
- A written exclusion list of work that AI will not touch without a change in policy.
- A costed 90-day plan that starts with the workflow carrying the best balance of return and risk.
- A view on whether each workflow needs a bought tool, a build inside the firm's own tenant, or nothing yet.
The last item matters more than it looks. Firms that skip it tend to buy a platform first and look for work to point it at afterwards, a pattern our piece on build versus buy for legal AI sets out in more detail.
Signs a Firm is Not Ready Yet
Some findings mean the plan should start with foundations before any pilot. The common ones:
- Nobody can say which AI tools fee earners already use, including consumer tools on personal devices.
- Document management permissions have not been reviewed since the last system migration.
- Time recording is too coarse to show how long a task takes, so no baseline exists.
- An AI policy exists, but no system enforces any part of it.
- Matter data is split across systems that disagree about who the client is.
These findings set the order of work, and permissions and matter data are usually the cheapest to fix first. Our article on data quality as the first layer of law firm AI governance covers the data side, and what a CTO actually has to build for AI governance covers the controls.
How 3Rive Approaches This
AI Readiness in Five Days is our Tech Advisory assessment for law firms and legal teams. It is a structured maturity assessment across infrastructure, process and governance, and it ends with a costed 90-day plan the firm can take to its management board. The same team then builds what the plan recommends through our AI and Data service lines, so the plan is written by the people who will be held to it. For how that discipline carries into delivery, see our case management consolidation for a global law firm, where reconciliation steps were agreed before the migration ran.
Key Takeaways
- Generic AI readiness assessments score strategy, data, infrastructure, governance and people, and miss matter permissions, client terms and supervision.
- The SRA's August 2026 warning notice followed 42 reports of potential AI misuse in a year, with inaccurate information and client confidentiality as its main concerns.
- Five days is enough when a practice partner, IT, risk and finance are all available for the week.
- The outputs worth paying for are a ranked list of costed workflows, named blockers, an exclusion list and a 90-day plan.
- A baseline cost for each workflow decides whether the programme can show a return at budget review.