A senior associate at a mid-size Singapore firm has been running first drafts through a personal ChatGPT account since February. Nobody told her to, and nobody has told her to stop, because nobody has written anything down. The partner who read the MinLaw guide the week it launched filed the PDF, meant to circulate a policy, and has not opened it since. That gap, between having read the guide and having anything in writing, is where most Singapore law firms sit in the middle of 2026.
That gap is what a MinLaw GenAI compliance checklist closes. The decision in front of a managing partner is not whether to adopt GenAI. Staff have already decided that. It is whether the firm can produce, on a day’s notice, the documents the guide and the Law Society would expect to see: a policy, a use-case list with risk scores against it, a vendor due-diligence file, and a record of who signed off on what left the building. What follows works through that checklist in the order the guide sets out, most of it before engaging anyone.
A MinLaw GenAI compliance checklist for a Singapore law firm has five parts, one for each step in the Ministry of Law’s Guide for Using Generative AI in the Legal Sector (published 6 March 2026, verified July 2026): a governance framework and policy, a scored use-case register, tool and vendor due diligence, a reviewed rollout with training, and a review cadence. None of the five is optional, though a firm on basic tools needs a lighter version of each step than a firm running a custom build.
The three principles behind every item below, and what in the guide actually binds a firm versus what it only asks for, are covered in what Singapore’s GenAI guide asks of law firms. This piece is the checklist version: work down it in order, and stop wherever the firm genuinely cannot answer yet.
Step 1: the governance framework and policy checklist
- A written internal AI-use policy exists, separate from the general IT policy, naming which tools staff may use for which class of matter.
- An external, client-facing version of the same policy exists, or can go out on request within a day.
- One person is named as accountable: an AI lead for a small practice, a committee for a larger one.
- A data-classification scheme sorts matters into at least public, internal, confidential, and highly confidential, with a tool tier stated for each.
- Procurement criteria are written down, so the next vendor pitch is measured against a standard rather than a demo.
- An incident-response protocol names the triggers, a fabricated citation, an unexpected disclosure, output that looks wrong, the escalation path, and how that lines up with PDPC’s breach-notification rules.
- An engagement-letter clause discloses GenAI use and offers the client an opt-out. Annex C of the guide ships a sample clause to start from.
Step 2: the needs and use-case checklist
- The firm has written down its objectives for adopting GenAI, agreed with the partner group, not just with the person who read the guide.
- Every candidate use case, drafting, first-pass review, research, client correspondence, sits in one document: a use-case register.
- Each entry on the register carries a score on the guide’s four axes: how confidential the data is, the risk an error carries and the oversight that risk demands, the cost against the benefit, and how ready the team is for the change.
- The firm has placed itself on one of the guide’s three adoption stages, scored against what staff are already doing rather than what the firm intends to do.
- Use cases that do not clear a conservative payback bar are parked in writing, not left ambiguous.
Step 3: the tool and vendor due-diligence checklist
- Every candidate tool has been checked against the four areas in Annex E: data security and confidentiality, technical capability, model performance and output quality, and vendor credentials.
- The vendor confirms in writing that client data is not used to train the model, or that training is switched off by default, not just available as a setting.
- Data residency and access controls match what the firm’s clients actually need, not what the vendor ships as the default.
- Confidential matter is scoped to run on the firm’s own tenant, the guide’s default recommendation, unless there is a documented reason to do otherwise.
- For higher-risk deployments, the vendor has been checked against the Cyber Security Agency’s guidelines on securing AI systems.
steps in MinLaw's implementation framework, from the governance framework in step one to the review cadence in step five
MinLaw, Guide for Using Generative AI in the Legal Sector, 6 March 2026
Step 4: the implementation and training checklist
- A pilot scope, a named AI lead, a staged rollout timeline, and success metrics are agreed before anything goes live.
- Human-in-the-loop review gates sit wherever the step 2 risk score calls for them, not applied the same way across every task.
- Guardrails, PII and secret detectors, content filters, catch what a reviewer might miss under deadline pressure.
- The system has been through adversarial testing, prompt-injection and jailbreak attempts, before go-live, not after the first complaint.
- Staff have signed off on user-acceptance testing, and training covers tool use, prompt technique, and the incident-response protocol from step one, not a single demo session.
Step 5: the review checklist
- A review cadence is diarised, not left to whoever remembers to raise it.
- Outcomes are measured against the objectives set in step two, on the firm’s own numbers.
- The policy gets reviewed whenever the conduct rules or the guide itself changes.
- New use cases are scanned for on the same cadence, so the register from step two does not go stale within a year.
Where the MinLaw GenAI compliance checklist runs out
A checklist tells a firm what is missing. It does not build the missing thing. Steps 1, 2, and most of step 3 are paperwork and judgment a partner and an IT lead can produce in-house, given a week set aside for it and a template to start from. Step 4 is different. A reviewed workflow with risk-based gates, PII guardrails, and adversarial testing behind it is a build, not a document, and most firms do not have a technologist on staff who has done one.
The other gap is time. Scoring every use case on four axes and running full due diligence on every vendor pitch takes hours a fee-earning team does not have free during a live matter load. Firms that get through the checklist tend to run steps 1 to 3 as a short, deliberate project rather than something squeezed between files, and bring in the build for step 4 rather than leaving it to whoever is free. Our AI document review for Singapore law firms piece and AI due diligence for Singapore law firms piece both show what a step 4 build actually looks like once the checklist above is done.
The grant path for the compliance work
Most Singapore law firms clear the SME test the Enterprise Development Grant uses: Singapore-registered, at least 30% local equity, group turnover of S$100 million or less, or group headcount of 200 or fewer. EDG covers up to 50% of a qualifying project, consultancy fees, software, and internal manpower included, verified July 2026 on enterprisesg.gov.sg, subject to EnterpriseSG approval and never guaranteed. A diagnostic that produces the step 1 to 3 artifacts, and a Build & Train engagement that delivers step 4, both fall inside a qualifying project scope. The full process, timeline, and the consultant-certification rule that trips up some law firm applications, are in our EDG grant guide for AI projects.
Whatever gets built to close step 4 has to stay usable after the vendor leaves, or the firm is back to an unwritten policy within a year. The argument for training the firm’s own people to run the system, rather than renting it back on every matter, is in why AI projects fail, and the full cost breakdown for a diagnostic-plus-build engagement is in what AI consulting costs in Singapore.
Common questions
What does the MinLaw GenAI compliance checklist cover for a Singapore law firm?
Five parts, one per step of the Ministry of Law's Guide for Using Generative AI in the Legal Sector: a governance framework and policy, a scored use-case register, tool and vendor due diligence, a reviewed rollout with training, and a review cadence. A firm can work through most of the first three before it hires anyone.
Do we need a written AI policy before staff use GenAI tools?
In practice, yes. Staff are almost certainly using GenAI tools already, and under the Legal Profession Act a lawyer is responsible for their work product regardless of how it was produced. Rule 5 of the Legal Profession (Professional Conduct) Rules 2015 adds duties of honesty, competence, and diligence on top of that. A written policy is what lets the firm show, if asked, that it matched oversight to risk instead of leaving the question open.
What should be on a law firm's GenAI vendor due-diligence checklist?
Four areas, from Annex E of the MinLaw guide: data security and confidentiality (training-use terms, data residency, access controls), technical capability, model performance and output quality, and vendor credentials. Confirm in writing that the vendor does not train on the firm's data before signing anything.
How do we know which MinLaw adoption stage our firm is at?
The guide sorts firms into three stages: Stage 1 uses basic tools like Copilot or LawNet AI on personal logins with no framework behind them, Stage 2 runs off-the-shelf legal AI for core tasks such as review or research, and Stage 3 runs a custom-built workflow on the firm's own tenant. Most firms land at Stage 1 once they score what staff are actually doing, not what the firm intends to do.