Residency requirements reach firms through clients, not regulators
Which means they arrive at procurement stage on somebody else's timetable, and a firm that cannot answer quickly loses the engagement rather than failing an audit.
For a firm holding client confidences across jurisdictions, residency is a professional obligation before it is a technical constraint.
Most organizations treat data residency as a compliance box. For a law firm it is a professional obligation with regulatory consequences, and it arrives from clients rather than from regulators — usually in a procurement questionnaire, late.
This paper argues that residency should be established per matter type rather than firm-wide, examines why the question is cheaper to answer at design time than at contract stage, and sets out what a firm should be able to evidence when a client asks.
If you read nothing else, read these. The analysis that follows sets out the evidence for each.
Which means they arrive at procurement stage on somebody else's timetable, and a firm that cannot answer quickly loses the engagement rather than failing an audit.
Different matter types carry genuinely different obligations. A blanket statement rules out services unnecessarily or asserts something that does not hold.
It is one of the clearest examples of a design decision that is cheap before workloads land and a project afterwards.
Not whether the control exists, but whether the firm can demonstrate it operated over a period.
A bank asks its regulator what is required. A law firm is asked by its client, and the client's requirement derives from their regulator, their jurisdiction and their own risk appetite.
This means the requirement is not knowable in advance from any single source, arrives at procurement stage, and varies between clients in ways the firm cannot control. A firm that has established its position per matter type answers in a day. A firm that has not spends three weeks and occasionally loses the engagement.
It also means the answer has to be evidenced rather than asserted. 'Our data is held in the EU' is a claim; a documented control mapping showing which service holds what, in which region, enforced by which policy, is an answer.
Per matter type rather than firm-wide. Litigation for a domestic client, cross-border corporate work, and matters involving regulated sectors carry different obligations and should carry different technical positions.
The architectural consequence is that region restriction has to be enforceable at a granularity below the tenant. Azure policy applied at management group scope, with matter environments landing in the group matching their requirement, achieves this without maintaining separate tenants.
The alternative — a single restrictive position applied firm-wide — is simpler and rules out services the firm could legitimately use for the majority of its work.
Client security questionnaires have become the point at which professional services engagements stall, and the questions that cause delay are rarely the technically difficult ones.
Where is client data stored, in which country, and can that be evidenced. How is access granted, reviewed and revoked. What happens to client data at the end of an engagement. Do you use subcontractors and are they bound by the same terms. Have you tested your incident response plan, and when.
Each is answerable in a day by a firm that maintains a standing answer set, and in three weeks by one that reconstructs it per engagement. Firms that can return a complete, evidenced questionnaire in two days close faster and occasionally win on that basis.
Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.
Five steps. The first is a legal exercise rather than a technical one.
Establish residency obligations per matter type, with the reasoning written down.
Region restriction by policy at management group scope, not by convention.
Private endpoints and private DNS so no service carries a public surface.
Diagnostic settings by policy, retention matched to the longest obligation you carry.
A standing questionnaire response set, reviewed quarterly, owned by one person.
The same argument lands differently across an executive team. These are the three versions worth separating.
Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.
On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.
Send us a questionnaire you have recently been asked to complete and we will map which answers your current environment can already evidence, and what the remainder would take.
Most firms have a conflicts policy and a matter site structure. Very few have tested whether the wall exists anywhere other than in the site.
A control that depends on partners behaving differently from how they demonstrably behave is not a control — and in a negligence context it is worse than none.
Describe the situation in your own words.