K Kept
← Insights

guides

How to vet a legal AI vendor in Singapore

How to vet a legal AI vendor in Singapore: MinLaw's four-part checklist, the PDPA questions to ask, and the red flags that should end a pitch.

20 August 2026

Three vendors have pitched the same managing partner in the same month, and each answered the training-data question differently. One said “we don’t train on your data, obviously.” One said “that’s configurable.” One didn’t answer at all and moved to the pricing slide. None of those is a due-diligence process, and picking wrong here is not a small mistake: a law firm’s AI vendor sees the same client documents the firm has a professional duty to protect.

How to vet a legal AI vendor in Singapore comes down to one structured checklist, not a gut call on the demo. MinLaw’s Guide for Using Generative AI in the Legal Sector, published 6 March 2026, sets out four categories a firm should score every vendor against before signing: security and confidentiality, technical capability, model performance, and vendor credentials, verified on mlaw.gov.sg. This piece walks through what each category actually asks, the exact questions to put to a vendor, and where the Personal Data Protection Act adds its own bar on top.

Why vendor vetting is a distinct step, not a footnote to procurement

Buying a case-management system and buying a legal AI tool are not the same decision. A case-management vendor stores files. An AI vendor’s tool reads them, and in most products, some version of that reading passes through a model the vendor does not fully control either. The Legal Profession (Professional Conduct) Rules 2015 put the duty of confidentiality on the lawyer, not the vendor, so a bad vendor pick is the firm’s exposure, not something a service agreement quietly absorbs.

MinLaw’s guide treats this as its own step for exactly that reason. Step 3 of the five-step procedure, identify and evaluate GenAI tools, comes after a firm has already scoped which workflow needs an AI system (Step 2) and before anything gets built (Step 4). Skipping straight from “we need an AI tool” to a signed contract skips the one step designed to catch the vendor whose sales deck is stronger than its data practices.

4

categories the MinLaw guide's Annex E checklist scores every legal AI vendor against before a firm signs: security and confidentiality, technical capability, model performance, and vendor credentials

MinLaw, Guide for Using Generative AI in the Legal Sector, 6 March 2026, Annex E

Each category in the guide’s Annex E checklist has a plain-language version a partner can run without a technical background.

Security and confidentiality comes first. Ask whether the vendor trains its models on the firm’s inputs, and get the answer as a contract clause, not a settings page that can revert on the next update. Ask how long documents and prompts sit in the vendor’s storage after a session ends, and whether deleting something from the firm’s interface actually deletes it from the vendor’s backend. Ask where the data is processed and who can see it, then confirm the firm’s own access controls sit on top, restricted to the lawyers working that matter.

Technical capability is next. A generalist AI tool and a legal-specific one solve different problems. Ask what the tool is actually built for, whether it fits the volume the firm’s real matters produce, and what support looks like when something breaks mid-deal rather than in a demo environment.

Model performance and output quality matter more than a slick interface. Ask for the output to show its work: which source passage or clause a finding came from, so a lawyer can check it against the original document instead of trusting a summary on faith. A vendor that cannot point back to source is asking the firm to skip the human-in-the-loop review that MinLaw’s guide requires for anything with legal or client consequence.

Vendor credentials close the list. Ask who else in Singapore’s legal sector uses the product, and ask to speak to one of them. Ask how long the vendor has operated and whether the company could plausibly still exist in three years, since a firm’s workflow ends up built around whichever tool survives. A public statement on responsible AI use is a reasonable signal. A vendor that has never made one is not automatically disqualified, but it puts more weight on every other answer.

Where PDPA Section 26 adds a bar the sales deck won’t mention

The MinLaw checklist covers professional conduct. Separately, the Personal Data Protection Act’s Transfer Limitation Obligation, Section 26, applies whenever a vendor processes personal data, which most legal AI tools do the moment a document contains a name, an NRIC number, or a counterparty’s details. The obligation asks for protection comparable to the PDPA from wherever the vendor processes that data, not physical storage inside Singapore. A vendor that leads with “our servers are in Singapore” and stops there has answered the wrong question. What the firm needs in writing is the contractual data-protection terms that flow down to the vendor: permitted purposes, data minimisation, breach notification, and an audit right the firm can actually exercise, not just a location claim on a slide.

Two of Kept’s own pieces work through this in more depth: what MinLaw’s guide asks of Singapore law firms covers the full five-step framework this checklist sits inside, and legal AI client confidentiality in Singapore walks through the three tiers of tool protection, public, enterprise, and own-tenant, and the exact clauses to get into a master services agreement.

Red flags that should end the pitch

A few answers are worth treating as a stop, not a note to follow up on later.

The vendor cannot say plainly whether it trains on client data, or answers with “industry standard” instead of a yes or no. Singapore data residency is offered as the whole answer to the confidentiality question, when it is one input to a comparable-protection test, not a substitute for one. No named legal-sector reference exists, in Singapore or elsewhere, that the firm can actually call. The vendor won’t run a pilot on the firm’s own matter type, real documents with sensitive details redacted, and instead only offers a demo on their own sample data. The contract has no export path: if the firm leaves, the work product, the prompt history, the configuration, none of it comes with them.

That last one matters more than it looks. A tool the firm cannot leave without losing everything it built is not a vendor relationship, it is a dependency, and it is worth weighing against tools that leave the firm owning what it paid to build.

The margin math
Legal AI subscription signed without vendor due diligence, cancelled after 6 months (representative)
S$9,000
Associate hours spent piloting and then unwinding it, at loaded rate (representative)
S$4,500
Representative cost of skipping the vetting step
S$13,500
Representative arithmetic, not a client result. A Diagnostic that runs the full vendor due-diligence workstream costs S$5,000 to S$15,000 by firm size, over 2 to 3 weeks.

That comparison is the practical case for doing the checklist properly the first time: the cost of a wrong pick and the cost of a proper evaluation land in roughly the same range, and only one of them leaves the firm with an answer it can defend if a client or the Law Society asks how the vendor was chosen.

Run a real pilot before signing anything long

A checklist answers whether a vendor’s practices are acceptable on paper. A pilot answers whether the tool actually works on this firm’s documents. Before committing to more than a short trial term, run three to five of the firm’s own matters, with sensitive details redacted where needed, through each finalist and have the associates who would use it daily judge the output against what they would have produced themselves. A tool that scores well on the checklist but loses the pilot has failed the test that matters most: whether the people doing the work will trust it enough to actually use it.

Where this fits the Diagnostic, and the grant path

Kept’s Diagnostic runs this exact evaluation as its tooling workstream, Step 3 of the MinLaw procedure, alongside Step 1 (the governance framework a vendor decision needs to sit inside) and Step 2 (confirming the use case is worth solving before a vendor is chosen at all). The output is a due-diligence report scored against the checklist above plus a recommended architecture, own-tenant by default for anything confidential. The Diagnostic runs S$5,000 to S$15,000 by firm size, over 2 to 3 weeks. Once a vendor is chosen and the Build & Train phase begins, S$25,000 to S$45,000 fixed scope, it can qualify for EDG support of up to 50% for an SME clearing the eligibility test, subject to EnterpriseSG approval, verified July 2026 on enterprisesg.gov.sg. Management-consultancy scopes need a SAC-accredited TR 43 or SS 680 certified consultant. Technical implementation scopes carry carve-outs from that rule. The exact eligibility test and a worked example are in the EDG grant guide for law firms.

A vendor that survives all four checklist categories, the PDPA questions, and a real pilot on the firm’s own files is a defensible pick, the kind a firm can explain to a client or the Law Society if either asks. That is a higher bar than most pitches clear on the first meeting, which is the point of running the checklist before the contract, not after.

Common questions

How do I vet a legal AI vendor in Singapore?

Run the vendor against the four categories MinLaw's Guide for Using Generative AI in the Legal Sector sets out in Annex E, verified 6 March 2026: security and confidentiality (training-use terms, retention, storage location, access controls), technical capability (fit for the actual task, scalability, support), model performance and output quality (benchmarks, explainability, auditability), and vendor credentials (track record, references, financial stability). Get every answer in writing before a document reaches the tool.

What questions should I ask a legal AI vendor before signing?

Does the vendor train on our inputs, and can we get that barred in the contract rather than a settings toggle. How long are documents and prompts retained, and where are they processed. Can the output show which source passage it drew from, so a lawyer can verify it. Who else has used this for legal work in Singapore, and can we speak to them. What does the firm actually own if the contract ends.

What are red flags when evaluating a legal AI vendor?

A vendor that cannot say plainly whether it trains on client data. A sales deck that claims Singapore data residency as if that alone satisfies the law, when PDPA Section 26 asks for comparable protection, not a local address. No named legal-sector reference the firm can call. A refusal to run a pilot on the firm's own matter type. A contract that locks the firm into the vendor's platform with no export path for the work product.

Does the EDG grant cover legal AI vendor evaluation?

The evaluation itself sits inside a Diagnostic, S$5,000 to S$15,000 by firm size. The Build & Train phase that follows, once a vendor and architecture are chosen, can qualify for EDG support of up to 50% for an eligible SME, subject to EnterpriseSG approval, verified July 2026. Management-consultancy scopes need a SAC-accredited TR 43 or SS 680 consultant. Technical implementation scopes carry carve-outs.

Start here

A 30-minute discovery call. A written assessment within 24 hours.

You bring the problem. We bring the analysis. You leave with a document, not a pitch: no slide deck, no follow-up sequence unless you ask for one.

Book a discovery call hello@keptsg.com