ALA Risk Management and Liability 2 — Questions and Answers
Question 1: A law firm's client data is exposed in a third-party vendor breach. Under which legal theory is the firm MOST likely to face liability?
- Respondeat superior
- Negligent supervision of a third-party contractor (Correct answer)
- Strict liability
- Assumption of risk
Correct answer: Negligent supervision of a third-party contractor
Firms have a duty to exercise reasonable care in selecting and overseeing vendors who handle confidential client data, making negligent supervision the most applicable theory.
Question 2: Which document formally transfers identified risks to an outside party and is commonly used in vendor agreements?
- Risk register
- Indemnification clause (Correct answer)
- Incident response plan
- Business continuity plan
Correct answer: Indemnification clause
An indemnification clause contractually shifts specified risks and associated losses from one party to another in a vendor or service agreement.
Question 3: A CLM candidate reviews a firm's insurance portfolio. Which coverage specifically protects against claims arising from professional errors or omissions by attorneys?
- Commercial general liability (CGL)
- Directors and officers (D&O) liability
- Legal malpractice / professional liability insurance (Correct answer)
- Employment practices liability (EPL)
Correct answer: Legal malpractice / professional liability insurance
Legal malpractice insurance, a form of professional liability coverage, protects attorneys and the firm against claims resulting from alleged errors, omissions, or negligent acts in legal representation.
Question 4: During a risk assessment, the team plots risks on a heat map. What two dimensions are typically used on the axes?
- Cost and time
- Likelihood and impact (Correct answer)
- Frequency and detectability
- Severity and duration
Correct answer: Likelihood and impact
A risk heat map plots risks along axes of likelihood (probability of occurrence) and impact (severity of consequences) to prioritize mitigation efforts.
Question 5: A law firm implements mandatory conflict-of-interest checks before accepting new matters. This practice BEST represents which risk management strategy?
- Risk transfer
- Risk avoidance (Correct answer)
- Risk acceptance
- Risk exploitation
Correct answer: Risk avoidance
Performing conflict checks before accepting a matter avoids taking on engagements that would expose the firm to ethical violations or liability, a risk avoidance strategy.
Question 6: Which regulatory body's rules most directly govern law firm trust account management and the risk of commingling funds?
- State bar association (Correct answer)
- Federal Reserve
- FINRA
- SEC
Correct answer: State bar association
State bar associations promulgate rules of professional conduct, including IOLTA/trust account regulations that prohibit commingling client and firm funds.
Question 7: A firm's risk committee decides to self-insure for small, predictable losses rather than purchasing coverage for them. This is an example of:
- Risk avoidance
- Risk mitigation
- Risk retention (Correct answer)
- Risk transfer
Correct answer: Risk retention
Risk retention means the organization consciously accepts responsibility for certain losses, often when the cost of insurance exceeds the expected loss.
A law firm's client data is exposed in a third-party vendor breach.
Under which legal theory is the firm MOST likely to face liability?