The Three-Question Procurement Test Law Firms Should Run
A single breached matter can cost a firm more than a partner earns in a decade. The average price tag on a law firm data breach hit $5.08 million in 2024, up more than 10% year over year, and the invoice usually shows up long after the purchase order that made the breach possible got waved through. That purchase order is where this article lives.
Firms are spending on technology faster than ever, and spending faster is not the same thing as spending better. The buying decisions that hurt most are almost always the ones a managing partner approved in ten minutes because the quote looked reasonable. A short, disciplined test at the point of approval catches most of them before they cost you.
Before the Quote Arrives, Decide What You're Actually Buying
Run the test before anyone has emotional investment in a vendor. Once a partner has sat through the demo and pictured the dashboards on their own screen, questions get softer and objections get filed under "we'll figure that out later." Later is where the cost lives.
Most firms make the same mistake at this stage: they treat the purchase as a line item to be minimized rather than a capability to be defined. A 60 Second Marketer piece has a rundown of where law firms go wrong with technology, and the mistakes share a common thread. Someone optimized for the sticker price and inherited every hidden cost that came with it.
Cheap laptops that die in eighteen months. Backup software that no one has ever tested. Practice management tools bought as an expense to be tolerated rather than a system that could win work. Before the quote arrives, write down what the tool is supposed to make possible, and be specific about the outcome rather than the feature list.
Question One, at the Point of Approval: What Breaks If This Fails Mid-Filing
Hardware buys are where this question sorts good decisions from expensive ones. A laptop chosen because it was three hundred dollars cheaper is not a savings if the associate on it loses half a day of billable work every time it hangs during a video deposition. Multiply that across a floor of attorneys and the math turns ugly fast.
The right frame is total cost of ownership across the useful life of the device, including the warranty tier, the loaner policy, and the hours of billable time both are meant to protect. Ask what happens on the worst realistic day the device will see. If the answer involves a paralegal driving to a big-box store at 4 p.m. before a filing, the cheap option was not cheap.
Apply the same question to software. If the practice management system goes down mid-morning, does the firm keep working, or does everything stop? A tool the firm cannot operate without deserves scrutiny that a tool the firm merely likes does not.
Question Two, During Vendor Evaluation: Who Holds the Keys, and Where Do the Backups Actually Live
Security and backups are the two questions most firms answer with a shrug and a hope. Both should be answered on paper, by the vendor, before signing. The federal government's own vendor management guidance under NIST 800-53 organizes this around System and Services Acquisition and Supply Chain Risk Management controls. A small firm does not need a defense-contractor program, but the questions those controls force a buyer to ask are the right ones for any firm.
Question Three, Before Signing: Does This Buy Us Capability, or Just Cover Expense
Firms skip the last question most often. Software should be evaluated as capability, meaning what the firm can now do that it could not do before, and at what unit economics. A document automation platform is not a cost if it turns a six-hour drafting task into a forty-minute review. A conflicts system is not a cost if it lets a partner clear a new matter the same afternoon it walks in the door.
Frame every purchase against a specific outcome the firm wants: faster intake, cleaner billing, fewer write-offs, more matters handled per associate. If no one in the room can name the outcome, the tool is being bought to fit in, not to change anything. That is the purchase most likely to become shelfware.
Run the Test the Same Way Every Time
A three-question test only works if it is applied consistently, by the same small group, to every purchase above a set threshold. Firms that leave technology approval to whoever happens to be free that week end up with a stack that no one designed. Firms that route every buy through the same review, using the same three questions, end up with a stack that reflects how they actually practice.
Write the questions down. Put them at the top of the approval form. Refuse to sign anything that does not answer all three.



