SRA GenAI Exposure Audit:
Confidentiality, Legal Professional Privilege, and Shadow AI
Most UK law firms now have an AI policy. Fewer can show that GenAI in regulated legal work is tested, monitored, and proved — not only written down. That gap is where Shadow AI, data leakage, and privilege risk quietly grow.
This free SRA-aligned GenAI exposure self-audit maps where ChatGPT, Claude, Gemini, Copilot, and similar tools can expose client confidential information, Legal Professional Privilege (LPP), and duties under the SRA Codes of Conduct.
Twelve questions · Yes / Partial / No / Unknown · about 3–4 minutes.
You receive an exposure band and a six-axis control-strength profile — a plain-English snapshot for Managing Partners, COLPs, Risk leaders, and GCs. It scores exposure only.

Start the self-audit
Twelve questions. Answer Yes / Partial / No / Unknown. Then unlock your exposure band and six-axis control-strength profile.
Also available: FCA GenAI Exposure Self-Audit
Scores exposure only. Not SRA certification, not legal advice, and not a funding eligibility check. Does not intercept a live prompt.
Also available: FCA GenAI Exposure Self-Audit · EU AI Act Exposure Check · UK GDPR GenAI Exposure Check
What to do next
Your exposure band is a starting point. Keep the snapshot, share it with COLP / Risk / partners, then close gaps on paper — or move to a board-ready review and, where needed, runtime proof that GenAI use is tested, monitored, and proved.
SRA AI compliance, Shadow AI, and Legal Professional Privilege
This pillar section gives search engines and human readers the plain-English context behind the audit above. It explains where GenAI exposure sits for UK law firms, why privilege and confidentiality still dominate the risk picture, and why policy alone is not proof.
Why SRA AI compliance is really an exposure problem
UK law firms are adopting generative AI faster than most governance packs can keep up. Public tools, browser assistants, and firm Copilot rollouts all sit on the same path: a fee earner, a prompt, and a model that may retain, train on, or mishandle matter content.
The sharper question for COLPs, Risk leaders, and partners is simple: can you show that GenAI use involving client work is tested, monitored, and proved — or only that a policy says it should be?
Paper controls catalogue risk. They do not sit between a browser and a large language model at the moment a risky prompt is about to leave the firm. That is why this page starts with a free exposure audit, then explains the duties and failure modes behind the score.
Shadow AI in UK law firms
Shadow AI means staff using ChatGPT, Claude, Gemini, Copilot, or similar tools for firm work without a clear approved list, supervision model, or evidence trail.
Typical patterns include pasting client emails into a chatbot to tidy wording, summarising counsel opinions in a consumer LLM, or drafting advice notes with matter facts still in the prompt.
A ban without visibility is not control. If COLP, Risk, and IT cannot list which tools touch which matters, the firm cannot evidence confidentiality, supervision, or privilege protection when a client or insurer asks.
Legal Professional Privilege and generative AI
Legal Professional Privilege is not an IT setting. It is a protected status of communications and materials that can be weakened through careless disclosure.
When privileged content is pasted into a public or poorly governed GenAI tool, the firm may create uncontrolled third-party processing, weak records of what left the perimeter, and later difficulty showing who saw what and under which authority.
Firms often assume an enterprise assistant closes this. It may reduce some risk, but it does not automatically answer the SRA-facing question: was a risky prompt stopped before execution, and can you prove it?
SRA Codes of Conduct duties GenAI can touch
Confidentiality, including Rule 6.3
Solicitors must keep the affairs of clients confidential. GenAI tools that receive matter details can create confidentiality exposure even when nothing visibly goes wrong in the moment.
Competence, service, and supervision
AI-drafted text can look fluent while inventing citations, missing facts, or misstating the law. Human review before advice leaves the firm is how competence and supervision survive GenAI drafting.
Accountability and ownership
Someone should own GenAI exposure — typically COLP or Risk with IT — and the partnership should have been briefed in the last year.
Why traditional IT dashboards fail on GenAI execution
DLP, email security, endpoint tools, and Microsoft Purview-class controls matter. They are still not the same as pre-execution governance of LLM prompts.
An acceptable-use policy does not stop a prompt at the moment it is sent. Training slides do not produce evidence that a bad prompt was blocked. Email DLP does not automatically see browser LLM pastes. That is why "we already have Microsoft" is not a complete answer to SRA GenAI exposure.
The missing layer is often execution: what actually crossed the perimeter, whether policy survived run-time, and whether you can prove it afterwards.
Hallucinations and client risk
Even when no confidential data leaves the firm, GenAI can still harm clients through hallucination: confident false citations, invented case law, or misleading procedural steps.
For solicitors, that is a competence and service risk as much as a technology risk. Controls that only focus on data leakage miss half the problem.
What tested, monitored, and proved means for a practice
For a law firm, that usually means three things: a deliberate bad-prompt test, ongoing visibility of tools and material GenAI use, and evidence of allow, block, or escalate decisions you can show a client, insurer, or auditor.
A free exposure audit is step zero: honesty about gaps. A board pack turns that into an accountable plan. Runtime controls are where proof becomes technical rather than aspirational.
How to use this free SRA GenAI exposure audit
Complete the 12-question self-audit above, unlock your exposure band and six-axis profile, and share the snapshot with COLP, Risk, and IT.
If Evidence or Assurance scores weakly, treat that as a priority. If you need something board-ready, the next step is a facilitated review, board pack, and one-hour consultation. If you need run-time proof, discuss an inline intercept and ledger path.
Frequently asked questions
Is this an official SRA audit?
No. It is an educational exposure self-assessment for UK practices. It is not SRA certification or legal advice.
Does completing the audit make my firm compliant?
No. It maps gaps. Closing gaps — and proving controls at run-time where needed — is a separate programme of work.
Will the audit see our live prompts?
No. The interactive tool does not intercept LLM traffic or write an audit ledger. That is a product and pilot capability, not part of the free quiz.
Related GenAI exposure checks
Also see FCA GenAI Exposure Self-Audit, EU AI Act Exposure Check, and UK GDPR GenAI Exposure Check.
