Procurement · governance · legal AI
Legal AI procurement audit for French-law work: evidence to request before signing
Buying legal AI for French-law work is not a matter of asking a supplier for a “compliance” badge. The useful first step is to document the intended workflow, the people and data involved, the organisation’s role, and the evidence the supplier can actually provide. This checklist turns that into a procurement record: GDPR processing and supplier terms where personal data is involved, security assurance, model-change controls, governance, staff literacy and AI Act questions. Its result only identifies evidence gaps and cases for specialist review. It does not certify a tool, classify the system, or approve an organisation’s deployment.
No live data before review. Sensitive data, professional secrecy, public interaction or person-affecting use needs DPO, security and qualified specialist review.
The ten procurement evidence lanes
Labels separate potential obligations, case-dependent review and procurement recommendations. Collecting every item does not make a deployment compliant.
| Lane | Evidence request | Why it matters | Statuses | Owner |
|---|---|---|---|---|
| 1. Intended use | One sentence per workflow, users and affected people | Controls follow actual purpose | Named · too broad · absent | Business + legal |
| 2. Roles and chain | Supplier, models, processing, hosting and customer role | Do not presume duties | Mapped · partial · unknown | Legal + procurement |
| 3. Data boundary | Categories, secrecy, prohibited input and minimisation | GDPR and professional duties | Documented · sensitive · absent | DPO + business |
| 4. GDPR pack | DPA, subprocessors, transfers, retention, deletion and rights | Hosting copy is insufficient | Supplied · review · missing | DPO + procurement |
| 5. AI Act scope | Use, roles, literacy, transparency and escalation | Staged and role-dependent rules | Scoped · escalate · absent | Legal + compliance |
| 6. Security | Access, stated encryption, logs, incidents and vulnerabilities | Risk-proportionate assurance | Supplied · partial · missing | Security lead |
| 7. Quality and human control | Tests, sources, prohibited reliance and review | Versioned operational control | Set · test · absent | Legal owner |
| 8. Professional boundary | Secrecy, independence, responsibility or sector rules | Context-specific duties | Reviewed · specialist · unassigned | Partner or legal |
| 9. Contract and exit | Changes, suspension, export, deletion and cooperation | Control continues after signing | Negotiated · open · absent | Procurement + legal + DPO |
| 10. Decision record | Approvers, exceptions, residual risk, review and literacy | A purchase order is not governance | Review-ready · conditional · incomplete | Accountable executive |
Classify evidence readiness without a compliance score
Choose categories only. No supplier name, document, client fact or sensitive data is requested.
Complete all six categories to show a decision route.
Specialist review required
The use or data exceeds a standard procurement check. This page does not classify the system.
Core evidence missing
Essential evidence or ownership is missing before any live-data trial.
Evidence pack to complete
You have a starting point, not a validation. Record gaps and residual risk.
Ready for decision review
Keep dated evidence and use limits. This does not mean “compliant”.
What business and French-law workflow is the legal AI expected to support?
Define one workflow, its users, affected people and intended output. Roles, data controls and safeguards depend on actual use, not the product category printed on a sales page.
Who is the provider, deployer, controller and processor in this arrangement?
Map the supplier, model, hosting and processing chain. These roles are factual and legal questions; neither a contract label nor marketing copy settles them automatically.
What personal data, confidential information and professional-secrecy constraints are in scope?
Inventory personal data, sensitive categories, criminal-offence data, client material and professional-secrecy content. Until the input rule is approved, test without live data.
Which GDPR evidence should be requested before any personal data is shared?
Request the processing map, applicable DPA, subprocessors, transfers, retention and deletion facts, security, rights support and accountable contact. “EU hosted” is not a complete record.
Does this proposed use call for a DPIA or a DPO-led assessment?
That depends on the processing and likely risk to people. Record the use and take it to the DPO; this checklist neither grants an exemption nor reaches a DPIA conclusion.
Which AI Act duties are already relevant to this procurement?
Some duties already apply while others follow staged dates. Intended use, role and system matter; this page does not classify a generic legal-AI service as high risk.
How should the organisation evidence AI literacy for the people using the tool?
Name the audience, owner, content and evidence of context-appropriate training. Article 4 requires measures for sufficient literacy, but this questionnaire does not grade it.
When do transparency or high-risk questions require specialist classification?
Public or client interaction, external content, person-affecting recommendations and justice-related contexts need specialist analysis. A product name cannot resolve the classification.
What proportionate security and incident-response assurance should a supplier provide?
Request access design, logging, vulnerability and change handling, supplier-chain visibility and an incident route. Assurance should match risk; this page does not require one universal certificate.
How can the buyer govern model, subcontractor and feature changes after signing?
Record notice rights, versions, reassessment triggers, suspension and exit. A procurement decision should be revisited when the service or intended scope materially changes.
How should a team test source quality, output limits and human oversight without inventing a score?
Use representative cases, a citation-check method, prohibited reliance and a named human reviewer. Version the evidence instead of claiming a universal hallucination rate.
What belongs in a sign-off record before purchase, renewal or expansion?
Keep dated evidence, open points, exceptions, residual risks, approvers, training ownership and a review trigger. The record supports a human decision; it is not a certification.