An unfollowed policy is a liability in a professional negligence context
It documents that the firm knew the risk and specifies a control that demonstrably did not operate.
A control that depends on partners behaving differently from how they demonstrably behave is not a control — and in a negligence context it is worse than none.
Every firm has a policy about personal devices. In most firms the policy is that they should not be used for client work, and the practice is that a partner in an airport reads a matter email on their own phone.
This paper argues that the gap between policy and practice is itself a professional risk, that the productive response is to protect the data rather than manage the device, and that the departure scenario is where the arrangement proves its worth.
If you read nothing else, read these. The analysis that follows sets out the evidence for each.
It documents that the firm knew the risk and specifies a control that demonstrably did not operate.
Application protection controls corporate data inside the app without enrolment, which is the difference between a control partners accept and one they resist.
A partner leaving for a competitor with firm data on an unprotected personal phone is a problem with no good technical answer after the fact.
Policy says required; the compliance report says applied. The gap between them is usually meaningful and it is what an insurer asks about.
Partners read matter correspondence on personal phones. This is not going to stop, and a policy that pretends otherwise creates a specific professional risk: it establishes that the firm identified the exposure and relied on a control that was not operating.
Rewriting the policy to match observed behaviour, and then controlling that behaviour technically, converts a liability into a defensible position. It is also considerably easier to achieve than changing how senior people work.
The firms that handle this well include partners and senior staff in scope explicitly, because the exemption is usually where the most sensitive matters are.
Application protection policies apply controls to the corporate data inside an application — preventing copy to personal apps, requiring a PIN, encrypting the application's data, and allowing selective wipe of firm data without touching anything personal.
This is the difference between asking a partner to enrol their phone into firm management, which they will resist, and applying protection to firm data on it, which they will barely notice.
Five controls carry most of the benefit, and keeping the requirement proportionate matters: an aggressive PIN policy on a personal phone generates support tickets and workarounds rather than security.
This is where the arrangement proves itself and it is the argument that persuades partners.
A partner leaves for a competitor. On an unprotected personal device, firm data remains on the phone and there is nothing to be done about it that does not involve lawyers and considerable awkwardness.
With application protection, firm data is removed and their photographs stay. The conversation is straightforward, there is a record that it happened, and the firm can evidence it to a client or an insurer who asks. Demonstrating that wipe on a real device before deployment is what makes partners comfortable with the arrangement in the first place.
Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.
Five steps, in the order that produces adoption.
Establish how many personal devices actually reach firm data. Not estimate — report.
Align the policy with observed practice, including partners and senior staff.
Application protection rather than enrolment. Five controls carry most of the benefit.
Show a selective wipe on a real device. This is what makes it acceptable.
Report protection status rather than assuming it, and check it matches your questionnaire answers.
The same argument lands differently across an executive team. These are the three versions worth separating.
Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.
On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.
We will assess your current position against what your professional indemnity insurer asks, and demonstrate application protection working on a real personal phone before you commit to anything.
Most firms have a conflicts policy and a matter site structure. Very few have tested whether the wall exists anywhere other than in the site.
For a firm holding client confidences across jurisdictions, residency is a professional obligation before it is a technical constraint.
Describe the situation in your own words.