TL;DR: Before you sign with a legal AI or legal research vendor, put questions in writing across eight areas: corpus and coverage, citation accuracy, good-law depth, data handling and DPDP obligations, data storage and model training, privilege, contract terms, and support. A vendor that answers in specifics, in writing, is a safer bet than one that answers in adjectives.
On this page
- Why this is a buying-committee decision, not a features comparison
- Corpus and coverage
- Citation accuracy and how the vendor proves it
- Good-law and citator depth
- Data handling and DPDP obligations
- Where the data sits, and whether it trains a model
- Privilege and confidentiality
- Contract terms
- Designing a trial that actually tells you something
- Support and training
- Roadmap risk
- Good answer versus deflection, at a glance
- The procurement sequence
- Frequently asked questions
Why this is a buying-committee decision, not a features comparison
A managing partner, general counsel, or practice head signing a legal AI or legal research contract is not buying software. They are committing the firm’s or the company’s confidential client material, its litigation strategy, and its research workflow to a third party for a fixed term, usually with an auto-renewal clause attached. The demo you saw is built to look good. The sales deck is built to close. Neither is the document you will be bound by.
This piece is a list of questions to ask before that signature goes on the page, organised by theme, with a note on what a substantive answer sounds like against what a deflection sounds like. It is deliberately not a comparison of named products, because most vendors do not publish enough of what a buyer needs on their public sites to make that comparison honest. Where a claim cannot be sourced from a vendor’s own published page, the right move is to ask the question, not to guess the answer. That includes asking it of Niyam.
The pressure to move fast on this decision is real. The Wolters Kluwer 2026 Future Ready Lawyer survey, based on interviews with 810 lawyers across the United States, China, and nine European countries, found that more than 90 percent already use at least one AI tool, with ethics and privacy concerns and a lack of training cited as barriers by 39 percent each. That survey covers those markets, not India, and the adoption curve here differs, but the underlying tension it describes, moving quickly on AI while the governance questions lag behind, applies just as much to a procurement decision made in Mumbai or Delhi as one made in London.
If your firm has already committed to a platform and is now reconsidering it, the sequencing problem is different and covered in a cutover checklist for switching legal research platforms. If the question in front of you is what a reasonable budget looks like before you get to a vendor conversation at all, see legal research software cost in India. This piece sits before both: it is what to ask while the contract is still open for negotiation.
Corpus and coverage
The first failure mode in legal tech procurement is buying a tool that does not cover the courts you actually appear before. A platform that indexes the Supreme Court and a handful of High Courts well can still be useless to a firm whose practice is concentrated in district courts, tribunals, or a High Court the vendor added last.
Questions to ask, specifically:
- Which courts and tribunals does the corpus cover: Supreme Court, each High Court by name, NCLT and NCLAT, consumer commissions, income tax appellate tribunal, and any state-specific forums relevant to your practice?
- What is the earliest year covered for each of those courts? Coverage that starts in 2015 is a different product from coverage that starts in 1950 for a firm that cites older Supreme Court precedent regularly.
- How fast does a new judgment appear in the platform after it is pronounced? Same day, same week, or on a monthly batch update?
- Is coverage of unreported or lower court orders included, or does the corpus stop at reported judgments?
- Does the vendor scrape or license the source data, and from where?
A good answer names the courts, gives a year range per court, and states an update cadence in days, not “regularly” or “frequently”. A deflection sounds like “we cover all major Indian courts” without naming which ones, or “we’re continuously updating” without a number attached. If the vendor cannot tell you when the last Bombay High Court judgment was added to the index, that is itself an answer.
This is also where the gap between free and paid tools shows up most sharply. Indian Kanoon’s limitations for legal research are a useful baseline to test any paid vendor’s coverage claim against, because Indian Kanoon’s corpus is publicly browsable and you can verify a specific citation yourself before you ever get on a sales call. If a paid vendor’s coverage of a court you rely on is thinner than what you can already see for free, that is worth surfacing before the meeting, not after the contract.
Citation accuracy and how the vendor proves it
Coverage tells you what is in the corpus. Accuracy tells you whether the tool retrieves and represents it correctly when you ask it a question, and whether an AI layer on top of the corpus generates text that is actually grounded in what the corpus contains.
This question has stopped being theoretical. In Pooja Ramesh Singh v. Jammu and Kashmir Bank Ltd., 2026 INSC 668, Civil Appeal No. 11950 of 2025, decided 2 July 2026, the Supreme Court bench of Justice P.S. Narasimha and Justice A.S. Aradhe addressed reliance on AI-generated and hallucinated case law in a matter before it. A vendor’s tool generating a citation that does not exist, or misstating the holding of a case that does, is not a hypothetical risk to plan around. It has already reached the Supreme Court’s docket. The background is covered in more depth in AI hallucinated citations in India and the Supreme Court’s rules on AI-generated case law.
Questions to ask:
- Does every answer link back to the specific paragraph or section of the source judgment or statute, so you can verify it independently in one click?
- If the tool uses a large language model to summarise or answer questions, is the answer generated from retrieved source text, or does the model draw on its general training data as well? These are different failure profiles, and the vendor should be able to explain which one their architecture uses.
- What is the vendor’s own hallucination or citation-error rate, and how is it measured? Ask for the methodology, not just a percentage.
- What happens when the tool cannot find a source for a claim? Does it say so, or does it generate a plausible-sounding answer anyway?
A good answer walks you through the retrieval architecture and shows you, live, a case where the tool declines to answer rather than inventing a source. It will also point you to a citation-linked answer you can click through to the underlying judgment paragraph, the way Niyam links every answer back to the specific statute section or judgment paragraph it draws from, which is the verification step how to vet legal AI citation accuracy recommends running on every new tool before you rely on it in a filing. A deflection sounds like “our accuracy is over 95%” with no stated denominator, no methodology, and no example you can check yourself. Vendors that cannot show a wrong answer live are usually vendors that have not tested for one.
The duty here does not shift to the vendor once you sign. A lawyer’s duty to verify AI output exists independent of whatever the vendor claims about its own accuracy, and a verification workflow for AI output is worth building into your practice regardless of which vendor you choose.
Good-law and citator depth
A search tool tells you a case exists. A citator tells you whether it is still good law: whether it has been followed, distinguished, doubted, or overruled by a later bench, and by which court. This distinction is the difference between finding a precedent and being able to safely cite it in a filing.
Questions to ask:
- Does the tool track subsequent treatment of a judgment: followed, distinguished, referred, or overruled, and does it show which later decision did the treating?
- Is the treatment history generated automatically from case text, or curated manually, and how current is it?
- Does the citator flag a case as doubtful or overruled prominently at the point where you are about to cite it, or is that information buried on a separate page you have to think to check?
- How does the tool handle a Supreme Court decision that has been referred to a larger bench but not yet overruled, which is a common and genuinely unsettled state in Indian constitutional litigation?
A citator that surfaces treatment history automatically at the point of citation, rather than requiring a separate manual check, removes a step that is otherwise easy to skip under deadline pressure. This is a specific capability Niyam’s citator is built around: automatic good-law signals shown against the judgment you are reading, not a separate lookup. Whichever vendor you choose, confirm this exists before you rely on it, because good law checking is the single most consequential accuracy question in legal research software, and it is the one most often glossed over in a sales demo that only shows you search results.
A good answer from any vendor describes the treatment-history mechanism concretely and shows you a case that has been overruled, live, with the flag visible. A deflection sounds like “we have the most comprehensive citator in India” without demonstrating it on a case you name yourself, on the spot.
Data handling and DPDP obligations
The Digital Personal Data Protection Act, 2023 was notified in phases starting 13 November 2025, and the Digital Personal Data Protection Rules, 2025 were gazetted the same day, with the fuller operating obligations phasing in over roughly eighteen months. A firm that uploads client documents, correspondence, or matter data containing personal information into a legal AI tool is a data fiduciary under that Act with respect to that data, and the vendor processing it on the firm’s behalf is typically a data processor. The phased timeline and what it means for a business handling personal data is set out in the DPDP Rules 2025 and DPDP compliance deadlines for 2026 and 2027.
Questions to ask the vendor:
- Does the vendor’s processing agreement identify it as a data processor and the firm as the data fiduciary, with obligations allocated accordingly?
- What personal data does the tool collect from uploaded documents, and can that be scoped down or excluded?
- Does the vendor support the consent and notice obligations a data fiduciary law firm needs to meet under the DPDP framework, particularly once the Consent Manager provisions come into force? The DPDP Consent Manager framework explains what that mechanism will require operationally.
- What is the vendor’s breach notification commitment, in writing, including the timeline within which it will notify the firm of a security incident affecting the firm’s data?
- Does the vendor have a documented data retention and deletion policy, and can the firm request deletion of a specific matter’s data on demand?
A good answer names the specific clauses in the vendor’s terms or a separate data processing agreement, offers to share that document before signature, and can explain in plain terms how the firm stays compliant while using the tool. A deflection sounds like “we are DPDP compliant” as a bare assertion, with no document offered to back it, or a claim that compliance is entirely the vendor’s problem once you have signed. It is not. The Act’s obligations run to the data fiduciary, which in most engagements is the firm or the in-house legal function, not the vendor.
Where the data sits, and whether it trains a model
This is a separate question from DPDP compliance, and vendors sometimes answer one when asked the other.
Questions to ask:
- Where are the servers physically located that store the firm’s uploaded data and query history: in India, or overseas?
- If data is processed overseas at any point, even transiently, is that disclosed, and under what safeguard?
- Are prompts, uploaded documents, or query history used to train or fine-tune the vendor’s models, whether its own model or a third-party model it calls?
- If training on customer data happens by default, is there an opt-out, and is it available at the account level or only per-prompt?
- Does the vendor use a third-party large language model provider, and if so, does that provider’s own data-use terms apply to what the firm sends through the tool?
A good answer states a specific hosting location, states plainly whether prompts train any model, and if training does happen, explains exactly what a firm needs to do to opt out before its first upload. A deflection sounds like “your data is secure with us”, which answers a question about security, not about where the data sits or whether it feeds a training set. Security and data residency are not the same question, and a vendor that answers residency questions with security language is worth pressing further. The broader mechanics of how legal AI vendors in India handle this, including what falls short of a real answer, are covered in legal AI data residency in India and in the fuller checklist at the legal AI security checklist for law firms in India, which goes deeper into encryption, access control, and sub-processors than this procurement-stage list needs to.
Privilege and confidentiality
Uploading privileged client material into a third-party tool raises a question that predates AI: does routing that material through an external processor waive privilege, or expose it to disclosure risk in a way that matters in litigation.
Privilege over legal advice today sits in section 132 of the Bharatiya Sakshya Adhiniyam, 2023, the successor provision to section 126 of the erstwhile Indian Evidence Act, following the replacement of the Evidence Act, the Indian Penal Code, and the Code of Criminal Procedure by the BSA, the Bharatiya Nyaya Sanhita, and the Bharatiya Nagarik Suraksha Sanhita respectively on 1 July 2024. Section 132 protects communications made to a legal adviser in a professional capacity; whether that protection reaches a salaried in-house counsel the same way it reaches an independently briefed advocate is not settled by any binding Indian ruling on point. This matters directly to procurement: until that question is authoritatively resolved, an in-house legal team routing internal legal analysis through a vendor’s tool should not assume it is automatically covered by the same privilege protection a law firm’s external-advocate communications carry, and that uncertainty should shape what an in-house buyer is comfortable uploading.
Questions to ask:
- Does the vendor’s contract include a confidentiality undertaking specific to client and matter data, separate from its general terms of service?
- Who at the vendor, and at any sub-processor, has technical access to uploaded documents, and is that access logged?
- Does the vendor assert or disclaim any position on whether use of its tool affects privilege over the material processed? Most reputable vendors will decline to give a legal opinion on this and will instead point to their confidentiality and access-control terms, which is the correct posture; a vendor asserting it has “solved” privilege by contract is overstating what a data processing agreement can do.
- Is there a way to redact or exclude specific client-identifying fields before a document is uploaded for research or drafting assistance?
A good answer is specific about access control and honest about the limits of what a vendor’s contract can guarantee on privilege, a question of substantive law that a processing agreement cannot settle by itself. A deflection sounds like a blanket assurance that using the tool “does not affect privilege in any way,” stated as if it were a settled legal conclusion rather than a fact-specific question that depends on your engagement and the material involved.
Contract terms
The commercial terms are where a good product can still become a bad decision. Read the actual document, not the sales summary of it.
Questions to ask:
- Does the contract auto-renew, and if so, what is the notice period required to cancel before it does?
- Is pricing locked for the initial term, and what mechanism, if any, governs an increase at renewal?
- How is a “seat” defined: named user, concurrent user, or something else, and what happens if the firm’s headcount changes mid-term?
- What happens to the firm’s saved searches, matter data, and citation history if the firm terminates: is export supported, in what format, and within what window after termination?
- Is there a minimum commitment period, and can the firm negotiate a shorter initial term with the option to extend?
A good answer points you to the specific clause number in the agreement for each of these, and offers a redline conversation if the firm’s requirements do not match the standard terms. A deflection sounds like “that’s fairly standard across the industry” without pointing to the clause, or a verbal assurance that a term will be honoured even though the signed document says otherwise. General principles of offer, acceptance, and enforceable terms under the Indian Contract Act, 1872 govern the document you sign, not the conversation that preceded it, which is the reason to insist on seeing every material term in writing before signature, not after. A fuller treatment of the specific clauses to negotiate on the way out of an existing contract, which overlaps significantly with what to negotiate on the way in, is in the switching checklist’s contract section.
Designing a trial that actually tells you something
Most vendors will offer a trial. Most trials, as designed by the vendor, are built to make the product look its best rather than to surface where it fails. A buying committee should design its own trial rather than accepting the vendor’s default script.
A trial that tells you something specific includes:
- Ten to fifteen authorities the firm already relies on regularly, tested for coverage, currency of treatment history, and correct citation format, rather than authorities the vendor’s demo already knows will work well.
- At least one matter type the firm handles that is outside the vendor’s obvious specialism, to test breadth rather than a curated strength.
- A parallel run on a live, non-critical matter for two to four weeks, with the outgoing tool still available as a check, rather than a sandboxed demo environment disconnected from real work.
- Direct involvement from the associates or paralegals who will use the tool daily, not only the partner evaluating the purchase, because usability failures show up in daily use before they show up in a demo.
- A defined evaluation scorecard agreed before the trial starts, covering coverage, accuracy, speed, and interface friction, so the decision is not made on impression alone at the end.
A scorecard matters because measuring return after signature is where most firms fall short, not just in India. Thomson Reuters’ 2026 AI in Professional Services report found that only 18 percent of respondents track return on investment from AI tools formally, while 40 percent said they do not know whether their organisation tracks it at all. Deciding what “working” looks like before the trial starts, rather than after the contract is signed, is the only way to avoid becoming part of that 40 percent.
A good vendor accommodates a buyer-designed trial without resistance, because a product that performs well under real conditions has nothing to lose by being tested on the buyer’s terms. A deflection sounds like insistence on a fixed demo script, reluctance to let the firm test its own authorities, or a trial period too short to run a real matter through, typically under a week.
Support and training
A tool that a firm’s associates do not actually use is a wasted line item regardless of how capable it is. Support and training determine whether adoption happens.
Questions to ask:
- Is onboarding training included in the contract price, or billed separately, and how many sessions are covered?
- What is the support channel and response time commitment for a query that blocks work during business hours, and is that commitment written into the contract or only described verbally?
- Is there a dedicated account contact for the firm, or a general support queue shared across all customers?
- Does the vendor provide updated training when it ships a significant new feature, or does the firm have to discover new capability on its own?
This question matters more for junior associates than for partners, since training junior associates on legal research is where adoption either sticks or quietly fails after the first month. A good answer names a specific response-time commitment in the contract and describes a concrete onboarding plan with a session count. A deflection sounds like “our support is excellent” with no written commitment attached to it anywhere in the agreement.
Roadmap risk
The tool the firm buys today is not necessarily the tool it will be using in eighteen months. Vendors get acquired, pivot, deprioritise features, or shut down. A buying committee should ask about the vendor’s stability and direction, not only its current feature set.
Questions to ask:
- How long has the vendor operated in the Indian legal market specifically, as distinct from a broader legal-tech history elsewhere?
- Has the vendor raised funding, and from whom, or is it self-funded? Either can be stable; the point is to know which, since the risk profile differs.
- What is the vendor’s public roadmap for the next twelve months, and how much of what the firm is being sold on today is shipped versus planned?
- If the vendor is acquired or shuts down, what happens to the firm’s data and its ability to export it, and is that answer in the contract or only a verbal assurance?
- Does the vendor build on a proprietary model and infrastructure, or does it wrap a third-party general-purpose model, and what does that mean if that third-party relationship changes? Native legal AI versus generic GPT wrappers and sovereign AI for Indian legal tech both go into why this distinction affects long-term reliability, not just current output quality.
A good answer is honest about what is shipped versus planned, discloses funding status without prompting twice, and has a data-portability answer written into the contract rather than promised verbally. A deflection sounds like a roadmap presented entirely in the future tense, with no shipped date attached to any of it, or an unwillingness to discuss what happens to the firm’s data if the vendor’s business changes.
Good answer versus deflection, at a glance
| Procurement checklist item | ✓ Good answer looks like | ✗ Deflection looks like |
|---|---|---|
| Court coverage | ✓ Named courts, year ranges, update cadence in days | ✗ “All major Indian courts,” no names or dates |
| Citation accuracy | ✓ Live demonstration of a source-linked, verifiable answer | ✗ A bare accuracy percentage with no methodology |
| Good-law tracking | ✓ Live demo of a flagged overruled or doubted case | ✗ “Most comprehensive citator,” not shown |
| DPDP obligations | ✓ Named clauses, a processing agreement offered for review | ✗ “We are DPDP compliant,” no document offered |
| Data residency | ✓ A specific hosting location and a stated model-training policy | ✗ “Your data is secure with us” |
| Model training on customer data | ✓ A clear yes or no, with an opt-out path if yes | ✗ Silence on the specific question when asked directly |
| Privilege | ✓ Specific access-control and confidentiality terms, no overclaiming | ✗ A blanket assurance that privilege is unaffected |
| Contract terms | ✓ Clause numbers cited for renewal, pricing, and export rights | ✗ “That’s standard,” without pointing to the clause |
| Trial design | ✓ Accommodates the firm’s own authorities and a live parallel run | ✗ A fixed demo script, no live-matter access |
| Support commitment | ✓ Written response-time commitment in the contract | ✗ “Our support is excellent,” undocumented |
| Roadmap and stability | ✓ Honest shipped-versus-planned breakdown, funding disclosed | ✗ Future-tense roadmap only, funding undisclosed |
Where a vendor’s public materials genuinely do not cover a claim in this table, mark it “not published” in your own notes rather than assuming it fails the question. The absence of a published answer is a reason to ask directly, not a reason to guess at either a good or a bad one.
The procurement sequence
flowchart TD
A[Define what your team actually needs] --> B[Shortlist vendors covering your courts]
B --> C[Send the written question set]
C --> D{Written answers received?}
D -->|No, only verbal| E[Escalate or drop vendor]
D -->|Yes, in writing| F[Design your own trial]
F --> G[Run parallel trial on live matter]
G --> H[Score against your ten authorities]
H --> I{Passes coverage and accuracy bar?}
I -->|No| E
I -->|Yes| J[Review contract clause by clause]
J --> K[Negotiate renewal, seats, export rights]
K --> L[Legal and compliance sign-off on DPDP terms]
L --> M[Sign with exit terms documented]
Frequently asked questions
Who on the buying committee should own the DPDP due diligence?
Whoever holds data protection or compliance responsibility internally, which in most firms and in-house teams is general counsel or a designated compliance lead, not the practice partner sponsoring the purchase. The Digital Personal Data Protection Act, 2023 places obligations on the data fiduciary, and that role needs someone accountable for reading the vendor’s data processing terms before signature, not after an incident.
Is it reasonable to ask a vendor for its citation accuracy rate?
Yes, and a reputable vendor will have an answer beyond a marketing number. Ask for the methodology behind any stated figure: what was tested, against what benchmark, and how recently. A vendor unable to describe how it measures its own accuracy has likely not measured it rigorously, which is itself useful information for the decision.
Should a trial be run on live matters or only sandbox data?
A short parallel run on a real, non-critical matter tells you more than a sandboxed demo, because usability and coverage failures surface under real conditions that a curated demo is built to avoid. Keep the outgoing tool or workflow available during the trial period as a check, and limit the parallel run to a matter where an error would not be catastrophic.
What is the single biggest contract term firms overlook?
The auto-renewal notice period. Many contracts require cancellation notice well before the renewal date, not on it, and missing that window commits the firm to another full term by default. Read the specific clause, not a sales summary of it, before you sign.
Does DPDP compliance mean privileged client material is automatically safe to upload?
No. DPDP governs personal data protection obligations; it does not settle whether uploading material to a third-party processor affects legal professional privilege, which is a separate question under section 132 of the Bharatiya Sakshya Adhiniyam, 2023. Treat the two as distinct questions requiring separate answers from the vendor.
Are in-house counsel’s communications privileged the same way an external advocate’s are?
Not necessarily, or at least not certainly. Section 132 of the Bharatiya Sakshya Adhiniyam protects communications made to a legal adviser in a professional capacity, but no binding Indian ruling has settled whether that protection extends to a salaried in-house counsel’s communications with their employer the same way it covers an independently briefed advocate. In-house teams should factor that open question into what they route through any third-party tool, rather than assuming section 132 covers internal legal communications by default.
How much of a legal AI vendor’s roadmap should a buyer trust?
Trust the shipped features you can test in a trial, and treat the rest as a stated intention rather than a commitment, unless the vendor puts a specific delivery date in the contract. A roadmap presented entirely in the future tense with no dates attached is not a basis for a purchase decision.
What should happen to our data if we terminate the contract?
The contract should state, in writing, whether the firm can export its saved searches, matter data, and citation history after termination, in what format, and within what window. If this is not addressed in the document, raise it before signature; it is far harder to negotiate after the relationship has already ended.
Is a vendor that will not disclose its funding status a red flag?
Not automatically. Some stable, well-run legal tech vendors are self-funded or privately held and simply do not publicise funding rounds. The concern is a vendor that avoids the question entirely rather than giving a direct answer either way, since that avoidance tells you more about how the vendor communicates under scrutiny than the funding status itself would.
Should we test the vendor’s coverage of a High Court we rely on before or after the demo?
Before. Bring the ten to fifteen citations your firm actually relies on into the first substantive conversation, not the trial that follows weeks later. A vendor’s demo will naturally feature what it does well; testing your own authorities on the spot tells you whether that strength extends to what your practice actually needs.
What does “not published” mean when checking a vendor claim, and why does it matter?
It means the vendor has not made the specific claim publicly verifiable, which is different from the claim being false. Treat “not published” as an open question to ask directly, not as a mark against the vendor by default and not as confirmation either way. Assuming an answer in either direction without asking is where procurement due diligence usually breaks down.
Do we need a lawyer to review the vendor contract, or is procurement review enough?
Have whoever normally reviews vendor contracts with data-processing implications review this one too, typically general counsel or an external counsel engaged for the purpose. The clauses that matter most here, auto-renewal, data export rights, and the DPDP processor allocation, are the same category of terms a firm would not sign in any other vendor relationship without legal review, and a legal AI vendor is not an exception.
What is a reasonable minimum trial length before committing to an annual contract?
Two to four weeks of parallel use on live, non-critical matters is enough to surface coverage gaps and workflow friction that a shorter trial will not. A trial period under a week, particularly one confined to a vendor-scripted demo, is not long enough to test the tool against your own authorities and daily workflow.
How does citator depth differ from search coverage, and why does the distinction matter for procurement?
Search coverage tells you whether a case is in the corpus. Citator depth tells you whether that case is still valid authority, showing whether it has been followed, distinguished, or overruled by a later decision. A tool can have excellent search coverage and a thin or stale citator, which means a case appears in results without any warning that it has since been overruled, so ask about both separately rather than assuming one implies the other.
Should the same procurement questions apply if we are only trialling a free tool alongside a paid one?
Yes, though the emphasis shifts. Free tools rarely have a negotiable contract, so the priority questions become coverage, currency, and citator depth rather than contract terms. Comparing a specific free tool’s limitations against a paid vendor’s claims, as in an Indian Kanoon limitations review, is a useful independent check before paying for coverage or accuracy you may already be able to verify for free.