Any firm considering outsourced paralegal support, from any provider, should be asking the same handful of direct questions before signing anything.
What questions actually matter?
Who supervises the work before it reaches the firm. What happens to client data, and where it’s processed, addressed properly in our article on what a data processing agreement needs to say. How conflicts are checked and avoided across the provider’s other clients. And what the fixed-fee structure actually includes, in writing.
Why are vague answers the real warning sign?
A provider that cannot answer these plainly, with a written contract to back it up, is not a provider a regulated firm should be instructing, a standard reinforced by the supervision principles confirmed in Mazur v Charles Russell Speechlys LLP [2026] EWCA Civ 369.
What does a good answer sound like?
Specific: named supervision steps set out on our How It Works page, a stated data-handling approach, and a dedicated-team structure that avoids conflicts by design. If a provider can’t point to something concrete, that absence is itself the answer.
Should a firm ask where the delivery team is actually based?
Yes, directly, and a credible provider should answer plainly rather than deflect. Where work is delivered from matters for data protection compliance, and a firm is entitled to a clear answer before it decides anything.
What should happen if a provider avoids answering these questions?
That’s a reason to walk away, not to press harder for an answer. A provider comfortable with proper scrutiny answers these questions without friction, because the answers are already documented in how they operate.
Is it reasonable to ask for references or examples of similar work?
Reasonable to ask, though be cautious of anyone offering client names or testimonials as proof, since genuine client confidentiality usually limits what a provider can share. A provider that’s upfront about that limitation is more credible than one offering names too readily.
What does a proper due diligence checklist actually look like?
Confirmation the provider never holds client money, evidence of a dedicated-team structure that avoids conflicts by design, covered in our article on how conflicts of interest are avoided, and a signed confidentiality agreement before any file moves.
How does this connect to a COLP’s own review process?
These questions form the basis of the checklist a Compliance Officer for Legal Practice should apply, described fully in our COLP checklist article, before signing off any new arrangement.
What should a firm expect to see in a provider’s data processing agreement?
Article 28 UK GDPR terms, a proper international transfer mechanism where relevant, and clear deletion timescales, covered in full in our article on what a DPA actually needs to say.
Is price a reasonable first question to ask a new provider?
It matters, but it shouldn’t be first. Supervision, confidentiality, and conflicts safeguards determine whether a provider is safe to instruct at all; price only matters once those questions are answered satisfactorily.
How can a firm verify a provider’s claims rather than just accepting them?
Ask for the actual documents, the DPA, the confidentiality agreement, the supervision process, rather than a summary or a verbal assurance. A provider that hesitates to share these before an engagement begins is telling a firm something important.
What red flags should a firm watch for during initial conversations?
Vague answers about where work is actually delivered, reluctance to put terms in writing, and pricing that isn’t clearly explained upfront are all signs worth taking seriously before committing to anything.
Does firm size affect which questions matter most?
The core questions, supervision, data handling, conflicts, matter regardless of firm size, though smaller firms with less internal compliance capacity often benefit from asking them even more rigorously, since they have less room to absorb a mistake.
Should a firm ask about the provider’s own team structure?
Yes, specifically whether a dedicated paralegal or team works exclusively with that firm, or whether work is spread across a shared pool serving multiple clients. This distinction is the structural difference between conflict risk and conflict safety.
What’s a reasonable timeframe to expect answers to these questions?
A credible provider should be able to answer most of these directly, within a single conversation, without needing to check with someone else. Answers that take days to arrive, or arrive incomplete, are worth noting.
Does asking these questions slow down onboarding significantly?
No, if anything it speeds things up, since a firm that has clear answers upfront avoids the delays that come from discovering gaps later, once work has already started.
Is it reasonable to ask about a provider’s approach to quality control?
Absolutely. Ask how errors are caught before work reaches the firm, and what happens if something is missed anyway, covered in our article on what happens when an outsourced paralegal makes a mistake. A provider without a clear answer here likely doesn’t have a real process behind it.
Should a firm run a trial task before committing to an ongoing arrangement?
Strongly recommended. A defined first task, tested against a real deadline, is the clearest way to judge fit before any larger commitment, described in our article on what a trial-matter guarantee means in practice.
How does a firm assess a provider’s cost structure honestly?
Compare the flat-fee price against the true cost of the in-house alternative, not just the salary figure, using the full breakdown in our cost comparison article. A price that seems low in isolation only makes sense against a proper baseline.
What should happen if a provider can’t answer a specific question satisfactorily?
That’s useful information in itself. A firm doesn’t need to instruct any provider that can’t give clear, evidenced answers to reasonable due diligence questions, whatever else about the relationship seems appealing.
Does this due diligence process differ for a large versus small provider?
The questions stay the same regardless of provider size. A smaller, more personal provider often answers more directly and specifically than a larger one working from a generic script, though size alone tells a firm little about actual quality or compliance.
What’s the most overlooked question firms tend to skip?
Where the delivery team is actually based, and what that means for international data transfer compliance. It’s an uncomfortable question for some providers to answer plainly, which is exactly why it’s worth asking directly.
How should a firm document this due diligence process internally?
A short written record of the questions asked, the answers received, and the documents reviewed gives a firm something concrete to point to later, consistent with the documentation standard described in our article on documenting supervision for an SRA inspection.
Want the actual paperwork before you decide anything?
We can send over our supervision approach and data processing terms so your own review has something real to check.
Confidential · No obligation · Typically a 20-minute call
Frequently Asked Questions
What should a written contract with an outsourced provider cover?
Supervision arrangements, data handling and any international transfer mechanism, conflicts safeguards, and exactly what falls inside a fixed fee.
How can a firm check whether conflicts are genuinely avoided?
By asking whether the paralegal or team working its matters works for any other firm at the same time, and getting that answer in writing.
Is it reasonable to ask to see a provider’s actual DPA before committing?
Yes, and any properly run provider should be willing to share it. A DPA is what a proper answer to a data protection question looks like in writing.
Should pricing be agreed in writing before any work starts?
Always. A written scope avoids disputes later about what was and wasn’t included in a fixed fee.


