Skip to main content

Procurement · governance · legal AI

Legal AI procurement audit for French-law work: evidence to request before signing

Buying legal AI for French-law work is not a matter of asking a supplier for a “compliance” badge. The useful first step is to document the intended workflow, the people and data involved, the organisation’s role, and the evidence the supplier can actually provide. This checklist turns that into a procurement record: GDPR processing and supplier terms where personal data is involved, security assurance, model-change controls, governance, staff literacy and AI Act questions. Its result only identifies evidence gaps and cases for specialist review. It does not certify a tool, classify the system, or approve an organisation’s deployment.

Checked 27 August 2026 · EUR-Lex, CNIL, EDPB, ANSSI and CNBAlphaDeep legal editorial team

No live data before review. Sensitive data, professional secrecy, public interaction or person-affecting use needs DPO, security and qualified specialist review.

The ten procurement evidence lanes

Labels separate potential obligations, case-dependent review and procurement recommendations. Collecting every item does not make a deployment compliant.

Supplier evidence record—to date, assign and revisit.
LaneEvidence requestWhy it mattersStatusesOwner
1. Intended useOne sentence per workflow, users and affected peopleControls follow actual purposeNamed · too broad · absentBusiness + legal
2. Roles and chainSupplier, models, processing, hosting and customer roleDo not presume dutiesMapped · partial · unknownLegal + procurement
3. Data boundaryCategories, secrecy, prohibited input and minimisationGDPR and professional dutiesDocumented · sensitive · absentDPO + business
4. GDPR packDPA, subprocessors, transfers, retention, deletion and rightsHosting copy is insufficientSupplied · review · missingDPO + procurement
5. AI Act scopeUse, roles, literacy, transparency and escalationStaged and role-dependent rulesScoped · escalate · absentLegal + compliance
6. SecurityAccess, stated encryption, logs, incidents and vulnerabilitiesRisk-proportionate assuranceSupplied · partial · missingSecurity lead
7. Quality and human controlTests, sources, prohibited reliance and reviewVersioned operational controlSet · test · absentLegal owner
8. Professional boundarySecrecy, independence, responsibility or sector rulesContext-specific dutiesReviewed · specialist · unassignedPartner or legal
9. Contract and exitChanges, suspension, export, deletion and cooperationControl continues after signingNegotiated · open · absentProcurement + legal + DPO
10. Decision recordApprovers, exceptions, residual risk, review and literacyA purchase order is not governanceReview-ready · conditional · incompleteAccountable executive

Classify evidence readiness without a compliance score

Choose categories only. No supplier name, document, client fact or sensitive data is requested.

Organisation
Intended use
Planned data
Supplier evidence
Governance
Output effect

Complete all six categories to show a decision route.

Specialist review required

The use or data exceeds a standard procurement check. This page does not classify the system.

Core evidence missing

Essential evidence or ownership is missing before any live-data trial.

Evidence pack to complete

You have a starting point, not a validation. Record gaps and residual risk.

Ready for decision review

Keep dated evidence and use limits. This does not mean “compliant”.

Worked example — not a certification. An in-house team plans internal research with human review but has only a security summary and no training owner. Result: Core evidence missing. Request the supplier pack and assign owners before any live-data trial.

What business and French-law workflow is the legal AI expected to support?

Define one workflow, its users, affected people and intended output. Roles, data controls and safeguards depend on actual use, not the product category printed on a sales page.

Who is the provider, deployer, controller and processor in this arrangement?

Map the supplier, model, hosting and processing chain. These roles are factual and legal questions; neither a contract label nor marketing copy settles them automatically.

What personal data, confidential information and professional-secrecy constraints are in scope?

Inventory personal data, sensitive categories, criminal-offence data, client material and professional-secrecy content. Until the input rule is approved, test without live data.

Which GDPR evidence should be requested before any personal data is shared?

Request the processing map, applicable DPA, subprocessors, transfers, retention and deletion facts, security, rights support and accountable contact. “EU hosted” is not a complete record.

Does this proposed use call for a DPIA or a DPO-led assessment?

That depends on the processing and likely risk to people. Record the use and take it to the DPO; this checklist neither grants an exemption nor reaches a DPIA conclusion.

Which AI Act duties are already relevant to this procurement?

Some duties already apply while others follow staged dates. Intended use, role and system matter; this page does not classify a generic legal-AI service as high risk.

How should the organisation evidence AI literacy for the people using the tool?

Name the audience, owner, content and evidence of context-appropriate training. Article 4 requires measures for sufficient literacy, but this questionnaire does not grade it.

When do transparency or high-risk questions require specialist classification?

Public or client interaction, external content, person-affecting recommendations and justice-related contexts need specialist analysis. A product name cannot resolve the classification.

What proportionate security and incident-response assurance should a supplier provide?

Request access design, logging, vulnerability and change handling, supplier-chain visibility and an incident route. Assurance should match risk; this page does not require one universal certificate.

How can the buyer govern model, subcontractor and feature changes after signing?

Record notice rights, versions, reassessment triggers, suspension and exit. A procurement decision should be revisited when the service or intended scope materially changes.

How should a team test source quality, output limits and human oversight without inventing a score?

Use representative cases, a citation-check method, prohibited reliance and a named human reviewer. Version the evidence instead of claiming a universal hallucination rate.

What belongs in a sign-off record before purchase, renewal or expansion?

Keep dated evidence, open points, exceptions, residual risks, approvers, training ownership and a review trigger. The record supports a human decision; it is not a certification.

Official sources

Related reading

Compare tools after defining criteriaAI audit definition in FrenchFrench-law AI tools for lawyers

This tool prepares an evidence request and procurement record. It does not legally classify a system, confirm GDPR or AI Act compliance, replace a DPIA, or replace advice from the DPO, security lead, procurement, qualified counsel or a competent authority.