Legelp

Is it ethical to outsource immigration paralegal work? The complete compliance guide

August 5, 2026 · 22 min read

Outsourcing immigration paralegal work is permissible under the ABA model rules where the firm supervises the work and remains responsible for the representation. ABA Formal Opinion 08-451 contemplates client disclosure and consent where outside non-lawyers receive information protected by Model Rule 1.6. State rules vary, and yours govern.

Every immigration firm that considers delegating case support runs into the same professional-responsibility questions, usually in the same order. This page works through them with the rules they come from, and sets out what should be in place before the first matter is assigned.

Read this first

This is general information, not legal advice. The rules discussed are the ABA model position. Your state’s rules govern, several states depart from the model materially, and nothing here is a substitute for confirming the position in your own jurisdiction. If a provider — including us — hands you a document and calls it a compliance solution, treat that claim sceptically.

The short answer

Yes, immigration firms may delegate preparatory and administrative case work to non-lawyers, including non-lawyers located outside the United States, provided the firm supervises the work, remains responsible for the representation, protects client confidences, and makes whatever disclosure its jurisdiction requires.

The complications are not about whether it is permitted. They are about what “supervises” requires operationally, where the unauthorised-practice line falls, what disclosure your specific state demands, and how any of it is evidenced afterwards if questioned.

Which rules actually apply

Four model rules and one formal opinion do most of the work.

The governing framework
AuthorityWhat it governsPractical effect
Model Rule 1.1CompetenceYou remain responsible for competent representation regardless of who performs the underlying task
Model Rule 1.6Confidentiality of client informationTriggers the disclosure and consent question when outside non-lawyers receive protected information
Model Rule 5.1Responsibility of partners and supervisory lawyersFirm-level obligation to have measures giving reasonable assurance of conformity
Model Rule 5.3Responsibility regarding non-lawyer assistanceThe core supervision duty over delegated work, including outside providers
Model Rule 5.5Unauthorised practice of lawDefines what must not be delegated at all
ABA Formal Op. 08-451Outsourcing legal and non-legal support servicesThe direct treatment: permits outsourcing subject to supervision, competence, confidentiality and consent
ABA Formal Op. 00-420Billing for contracted servicesConstrains how outsourced cost may be passed to the client

Rule 1.1: competence stays with you

The competence obligation is the one firms most often assume is transferable, and it is not. If work is delegated and the resulting filing is deficient, the deficiency is the firm’s. This is not a technicality — it shapes the whole operating model.

Two obligations follow. First, satisfy yourself about the competence of the people doing the work — not merely the provider’s marketing, but what training they have and how output is checked. Second, retain enough involvement to catch errors. A supervision arrangement where work is approved without being read is not supervision; it is a signature.

Rule 1.6: confidentiality and what triggers consent

Rule 1.6 protects information relating to the representation. When someone outside the firm will see that information, two questions follow: whether disclosure to the client is required, and whether consent is required.

ABA Formal Opinion 08-451 contemplates both where outside non-lawyers will receive Rule 1.6-protected information. The practical distinction commonly drawn is between substantive legal work and access to confidential material on one hand — where disclosure and consent are contemplated — and purely routine administrative tasks on the other, where it generally is not.

Do not lean on the routine-administrative exception

In immigration practice, almost nothing is purely administrative in the relevant sense. Someone organising evidence for an asylum claim is handling persecution accounts, medical records and family history. The exception exists, but a firm relying on it to avoid disclosure in this vertical is taking a position that is hard to defend.

Rules 5.1 and 5.3: what supervision means in practice

“Reasonable efforts to ensure conduct compatible with the professional obligations of the lawyer” is the standard. It is deliberately non-prescriptive, which leaves firms to work out what it means operationally. In practice, five things:

  1. A named supervising attorney per matter. Not a general arrangement — a specific person who is responsible. Where no supervising attorney is designated, no work should be performed.
  2. Written scope. Permitted and prohibited tasks set out explicitly, so the boundary does not depend on someone’s judgement in the moment.
  3. A review gate that cannot be bypassed. Draft work stored in a state that cannot be filed directly, and substantive attorney review before anything leaves the firm.
  4. An audit trail. Approval recorded with reviewer and timestamp. If supervision is ever questioned, this is the evidence, and it cannot be reconstructed retrospectively.
  5. Defined escalation criteria. What goes to the attorney immediately rather than into a queue, written down rather than assumed.

Rule 5.1 adds a firm-level dimension: partners and managerial lawyers must have measures in place giving reasonable assurance of conformity. That is an argument for a written protocol rather than per-attorney habit, because a habit is not a measure.

Rule 5.5: the unauthorised practice boundary

The most-asked question, and the one with the clearest test once stated properly. The test is not whether a task is difficult, lengthy or specialised. It is whether performing it correctly requires legal judgement.

Indexing two hundred exhibits is laborious and requires none. Deciding which twelve of them answer the question actually being asked requires it entirely. Formatting a declaration requires none. Deciding what the declaration should say does.

Applying the judgement test
TaskDelegable?Why
Populating forms from a firm-supplied recordYesTranscription against a defined record
Choosing which form or category to file underNoA legal determination about eligibility and strategy
Collecting, labelling and indexing evidenceYesOrganisation, not evaluation
Deciding whether evidence is sufficientNoJudgement against a legal standard
Preparing draft response language for revisionYes, with carePreparatory only; the theory and the decision to argue it are the attorney’s
Advising the client what the response means for themNoLegal advice
Tracking deadlines and escalating themYesAdministrative, provided escalation criteria are pre-defined
Deciding how to respond to a missed deadlineNoStrategy and risk assessment
Sending scheduling and document-request updatesYesAdministrative communication using approved templates
Answering a client question about eligibilityNoLegal advice, regardless of how simple the question seems

Note the pattern in the right-hand column. The delegable items are all execution against a decision already made. The non-delegable ones are all the decision itself. That is the line, and it holds across every task type we deal with. The task-level treatment is in RFE response support and petition and form preparation support.

State variation, and why it decides the question

The ABA model rules are a model. Your state’s rules are the law that applies to you, and on outsourcing the divergence is real rather than cosmetic.

Florida Ethics Opinion 07-2 requires disclosure where legal work is outsourced overseas. California, New York and North Carolina have issued their own opinions applying differing thresholds for when disclosure and informed consent are required. Others apply the general informed-consent standard without an outsourcing-specific opinion.

The practical implication is uncomfortable for providers and important for firms: a single national consent form cannot be correct everywhere. Any provider handing you one is giving you a starting point that your counsel must adapt, and any provider describing it as a compliance solution is overstating what a template can do.

If your practice is multi-state — and immigration practices frequently are, since federal immigration practice is not limited by state licensure in the way most practice is — the analysis needs to account for every jurisdiction in which you are admitted and practising.

Where consent is required, four mechanics matter more than the wording.

Timing. Before access, not after. Consent obtained once work has started leaves a gap on matters already in flight that has no clean retrospective fix.

Specificity. Generic language about “third-party vendors” is weak. Name the provider, state that personnel are located outside the United States and where, describe what they will and will not do, and say plainly that a licensed attorney approves everything before filing.

Language. This is an immigration practice. If the client’s primary language is not English, consent obtained in English is worth very little — as a matter of informed consent and, frankly, as a matter of decency. Issue it in the client’s language.

A real option to decline. Consent that carries an implied penalty is not informed consent. State explicitly that declining will not affect the representation or the fee, and mean it — which means having a plan for staffing those matters in-house.

Privilege and work product

The general position is that attorney-client privilege and work-product protection are preserved where outside personnel act as agents of the firm for the purpose of delivering legal services. This is the same basis on which privilege extends to a firm’s own staff, to contract attorneys, and to experts retained to assist.

Three things strengthen the position: written confidentiality undertakings binding each individual; a data processing agreement including an obligation on the provider to assert privilege against third-party demands and to notify you before disclosing anything; and keeping work inside your systems, so the material never sits in a location outside your control.

Nobody can guarantee this

No provider can guarantee how a particular court or agency will rule on privilege in every circumstance, and one claiming otherwise is overselling something they do not control. What a provider can do is avoid weakening the position and contract to defend it.

Who owns an error

Your firm. Responsibility for the representation does not transfer to a vendor, and a contractual indemnity — while worth having — does not change your position with your client or with your bar. An indemnity allocates money after the fact. It does not allocate professional responsibility.

This is the practical reason the review gate matters, and why it should be substantive rather than formal. An attorney who approves work without reading it has created a record showing they approved it, which is worse than no record at all.

Billing treatment

Where firms most often get tripped up, because it feels commercial rather than ethical.

ABA Formal Opinion 08-451, read with Formal Opinion 00-420, constrains how outsourced cost may be passed on. Charging the client more than the actual cost as a disbursement, without disclosure, is not permissible. Whether the cost is treated as a disbursement at cost, or absorbed into your fee, is a decision to take with your own counsel before the engagement rather than after the first invoice.

A related trap: if outsourced support reduces the hours your firm spends on a matter, and you bill hourly, the client’s bill should reflect the hours actually worked by the firm. Efficiency gains are not billable as if they had not occurred.

Client contact by non-lawyers

Permissible within limits, and worth setting out precisely because it is where arrangements most often drift.

Appropriate: scheduling, document requests, confirmation of receipt, administrative status updates — using firm-approved templates rather than free composition.

Not appropriate: anything touching eligibility, merits, strategy, likely outcomes, or the consequences of any action. These route to the supervising attorney unanswered. Not answered cautiously — unanswered.

Identification: where a client is told who they are dealing with, that person is identified as case support working under the firm’s supervision. Never as an attorney, never as a paralegal “of the firm” if they are not, and never as someone authorised to advise.

The failure mode here is gradual. A support person who has answered forty administrative questions correctly will eventually be asked a forty-first that sounds administrative and is not. The defence is training plus an explicit instruction that declining to answer is mandatory and will never be treated as a service failure.

Data security for immigration files

Immigration files are unusually sensitive, and the sensitivity is not incidental — it is the substance of the claim.

What an immigration file typically contains: Immigration and citizenship status; history of entry, detention or removal; country of origin and ethnicity; religious or political opinions; membership of persecuted groups; sexual orientation and gender identity; health and psychological records including trauma evaluations; criminal history; biometric identifiers; financial and tax records; and data concerning children.

That is special category data under the GDPR, sensitive personal information under the CPRA, and sensitive personal data under India’s DPDP Act. For a client with an asylum claim, disclosure of the file is not an inconvenience — it is potentially a safety issue for people still in the country of origin.

Minimum requirements to ask for:

  • A named contracting entity you can independently verify.
  • An independently certified information security programme.
  • Least-privilege access scoped to assigned matters, with revocation on offboarding within a defined window.
  • A data processing agreement covering sub-processors, breach notification timelines, and what happens to data on exit.
  • Confirmation of whether client data is copied out of your systems at all — and if so, where it goes.
  • An explicit position on whether any tooling submits client data to third-party services that retain or train on it.

That last one has become material. A provider marketing “AI-assisted” work should be able to say precisely what happens to data submitted to any model, in writing. Our own position is set out in our compliance posture and the contracting framework.

Diligence on the provider

Formal Opinion 08-451 expects you to satisfy yourself about the provider’s competence and safeguards. Concretely, that means asking:

  1. Who is the contracting entity, and can I verify its registration?
  2. Where are personnel located, physically?
  3. What background verification is performed before access?
  4. What confidentiality undertakings do individuals sign?
  5. How is access provisioned, reviewed and revoked?
  6. What certification does the security programme hold, and by whom?
  7. What happens to data if the relationship ends?
  8. Who else has access — sub-processors, subcontractors, affiliates?

Record the answers. Diligence you cannot evidence is diligence you may as well not have performed.

Pre-engagement checklist

Before the first matter is assigned, all of the following should exist:

What must be in place before assignment
ItemOwnerWhy it cannot wait
Client consent, in the form your jurisdiction requiresFirmConsent after access leaves a gap on matters already in flight with no clean fix
Written supervision protocol naming the supervising attorneyFirm, with provider inputRule 5.1 expects a measure, not a habit
Documented permitted and prohibited task listsJointThe UPL boundary cannot depend on in-the-moment judgement
Executed data processing agreementJointBreach and sub-processor terms are worthless agreed after an incident
Scoped system access under least privilegeFirmAccess broader than the assignment is the most common avoidable exposure
Defined escalation criteriaFirmWithout them, escalation depends on someone recognising an issue they were never told to look for
Recorded diligence on the providerFirmFormal Op. 08-451 expects it, and it cannot be reconstructed later

Training and competence of the provider's staff

Formal Opinion 08-451 expects you to satisfy yourself about the competence of the people performing delegated work. That obligation is easy to state and frequently discharged with a glance at a provider’s website, which is not the same thing.

Three questions get to something real:

  1. What does onboarding actually consist of? Specifically: are personnel trained on your checklists, templates and conventions, or on a generic house methodology? The first is what you want, because your procedures are the specification against which the work will be judged.
  2. How is output checked before it reaches you? A provider with no internal quality step is passing an unfiltered stream to your supervising attorney, which converts your review gate from a safety net into the only control.
  3. How are the scope boundaries reinforced? Not whether they exist on paper, but how often they are re-confirmed and what happens when someone declines to answer a question. If declining is treated as a service failure inside the provider’s own performance culture, the boundary will erode regardless of what the contract says.

A practical test for the trial period: ask a question that sits just across the line — something that sounds administrative but is really a request for advice — and see what happens. A correct refusal, escalated promptly, tells you more about the arrangement than any amount of documentation.

Note also that competence is not static. Forms change editions, procedures change, and a person competent last year on a filing type may not be current. Ask how the provider keeps up, and how you would find out if they had not.

Documenting supervision so it survives scrutiny

Compliance that cannot be evidenced is, from the perspective of anyone asking about it later, indistinguishable from no compliance. This is the part firms most consistently under-build, because it produces no immediate benefit and only matters on the day it matters a great deal.

Five records worth maintaining:

  1. Signed consents, filed per matter. Not in a general folder — in the matter file, retrievable when someone asks about that specific client.
  2. The supervision protocol, with version history. If scope changed over time, you want to be able to show what applied when.
  3. Approval records with reviewer and timestamp. Produced automatically by your case management system if it is configured to; worth confirming that it is, because most firms assume it and few check.
  4. Access grants and revocations. Who had access to what, and when it ended. Revocation records matter more than grants.
  5. Diligence file on the provider. Answers to the questions above, dated, plus copies of certifications relied on.

None of this is onerous once established. All of it is close to impossible to reconstruct retrospectively, which is why it belongs in the setup phase rather than on a list of things to tidy up later.

Multi-state practice

Immigration practice complicates the jurisdictional analysis in a way most practice areas do not. Federal immigration practice is not confined by state licensure in the ordinary way, so a firm may routinely serve clients located in states where no attorney at the firm is admitted.

That raises a question the model rules do not answer cleanly: whose disclosure standard applies — the state where the attorney is admitted, the state where the client is located, or both? The conservative approach is to apply the most demanding standard among the jurisdictions plausibly engaged, which in practice usually means following the Florida-style position of disclosing overseas outsourcing outright regardless of where the client sits.

That is a defensible default rather than a legal conclusion. It is exactly the sort of question to put to counsel once, decide firm-wide, and then apply consistently — rather than re-deciding matter by matter, which is how inconsistency creeps in.

If something goes wrong

Worth thinking about before it happens, because the instinct in the moment is usually wrong.

A filing error surfaces. The error is the firm’s regardless of who prepared the document. Correct it on its merits first; the question of how it happened is a separate exercise, conducted afterwards, and the answer is usually a gap in instructions rather than a gap in diligence.

Scope was exceeded. Someone answered a question they should have escalated. Establish what was said, assess whether the client was prejudiced, correct the position with the client directly and promptly, and tighten the instruction. Treating it as a disciplinary matter for the individual usually produces concealment of the next one.

A data incident. This is why the data processing agreement specifies a notification window. Your obligations to clients, courts and regulators are yours to discharge — the provider’s role is to give you the facts fast enough that you can. A provider who notifies you late has failed at the single most important thing they contracted to do.

The arrangement ends abruptly. This is what the exit terms are for: data returned or deleted, matters in flight documented, access revoked on a defined timeline. Firms that negotiated only a notice period, without a handover specification, discover the difference at exactly the wrong moment.

Where firms most often go wrong

Six failure patterns, in rough order of frequency:

  1. Starting work before the paperwork. The single most common, and the hardest to fix retrospectively.
  2. Treating a provider’s template as sufficient. It is a starting point for your counsel, not a compliance solution.
  3. Formal rather than substantive review. Approving without reading creates a record that is worse than none.
  4. Scope drift in client communication. Gradual, and usually invisible until something goes wrong.
  5. Access broader than the assignment. Granting system-wide access because it is simpler than scoping it.
  6. No audit trail. Everything done correctly and none of it evidenced. If supervision is questioned, unevidenced compliance is indistinguishable from none.

Related reading

Frequently asked questions

Is it permissible to outsource immigration paralegal work outside the US?+

Yes, under the ABA model rules, provided the outsourcing lawyer remains responsible for competent representation under Model Rule 1.1 and supervises the work under Rules 5.1 and 5.3. ABA Formal Opinion 08-451 addresses this directly and permits outsourcing of both legal and non-legal support services, subject to disclosure, consent and supervision obligations. Permissibility is not the same as unconditional: the obligations attach to you, not to the provider.

What does ABA Formal Opinion 08-451 actually require?+

Three things in practice. First, you remain ultimately responsible for the quality of the work and the representation. Second, you must make reasonable efforts to ensure the conduct of those you outsource to is compatible with your own professional obligations, which is a supervision duty under Rules 5.1 and 5.3. Third, where the outsourced personnel will receive information protected by Rule 1.6, appropriate disclosure to the client and client consent are contemplated. The opinion also expects you to satisfy yourself about the provider’s competence and its confidentiality safeguards.

Do the rules differ from state to state?+

Materially, yes. Florida Ethics Opinion 07-2 requires disclosure where legal work is outsourced overseas. California, New York and North Carolina have issued their own opinions applying differing thresholds for when disclosure and informed consent are required. Because the applicable rule is your jurisdiction’s and not the ABA model, a provider offering a single national consent form is offering you a starting point, not a compliance solution.

What can immigration firms delegate, and what can they not?+

Delegable work is preparatory and administrative: drafting petitions and applications from firm-supplied information, assembling and indexing evidence, formatting declarations, compiling country-conditions material, tracking deadlines and case status, and sending administrative updates. Not delegable: giving legal advice, deciding case strategy or the relief sought, assessing merits, signing or submitting filings, appearing before any court or agency, quoting fees or accepting engagements, and any exercise of independent professional judgment reserved to a lawyer.

What is the test for whether a task can be delegated?+

Not difficulty, length or specialisation — whether performing it correctly requires legal judgement. Indexing two hundred exhibits is laborious and requires none; deciding which twelve answer the question being asked requires it entirely. Formatting a declaration requires none; deciding what it should say does. The pattern is that delegable tasks are execution against a decision already made, and non-delegable ones are the decision itself.

Who is responsible if outsourced work contains an error?+

Your firm. Responsibility for the representation does not transfer to a vendor, and a contractual indemnity does not change your position with your client or your bar — it allocates money after the fact, not professional responsibility. This is the practical reason the attorney review gate matters and why it must be substantive: an attorney who approves work without reading it has created a record showing they approved it, which is worse than no record.

Does outsourcing waive attorney-client privilege?+

The general position is that privilege is preserved where the outside personnel act as agents of the firm for the purpose of delivering legal services — the same basis on which privilege extends to a firm’s own staff and to retained experts. Written confidentiality undertakings, a data processing agreement obliging the provider to assert privilege against third-party demands, and keeping work inside your own systems all strengthen the position. No provider can guarantee how a particular court will rule, and one claiming otherwise is overselling.

When do we need client consent, and what should it say?+

Where outside non-lawyers will receive Rule 1.6-protected information, and wherever your jurisdiction requires it regardless. Four mechanics matter: obtain it before access rather than after; name the provider and state that personnel are located outside the United States; describe what they will and will not do and that an attorney approves everything before filing; and make declining genuinely costless, which means having a plan to staff those matters in-house. In immigration practice, issue it in the client’s own language.

Can outsourced personnel communicate with our clients?+

Within limits. Scheduling, document requests and administrative status updates are generally appropriate using firm-approved templates. Anything touching eligibility, merits, strategy, likely outcomes or consequences routes to the supervising attorney unanswered — not answered cautiously, unanswered. Where a client is told who they are dealing with, that person is identified as case support working under the firm’s supervision, never as an attorney or as someone authorised to advise.

Can we bill clients for outsourced work?+

This requires care. ABA Formal Opinion 08-451, read with Formal Opinion 00-420, constrains how outsourced cost may be passed on: charging the client more than the actual cost as a disbursement, without disclosure, is not permissible. Whether the cost is treated as a disbursement at cost or absorbed into your fee is a decision to take with your own counsel before the engagement. A related trap for hourly firms: efficiency gains from outsourced support are not billable as if they had not occurred.

What should we require on data security?+

A named contracting entity you can verify; an independently certified information security programme; least-privilege access scoped to assigned matters with revocation on offboarding; a data processing agreement covering sub-processors, breach notification timelines and data handling on exit; confirmation of whether client data is copied out of your systems at all; and an explicit written position on whether any tooling submits client data to third-party services that retain or train on it. Immigration files carry persecution grounds, health and trauma records, criminal history and data about children.

What diligence should we do on a provider?+

Formal Opinion 08-451 expects you to satisfy yourself about competence and safeguards. Ask who the contracting entity is and whether you can verify its registration; where personnel are physically located; what background verification precedes access; what confidentiality undertakings individuals sign; how access is provisioned, reviewed and revoked; what certification the security programme holds and from whom; what happens to data if the relationship ends; and who else has access, including sub-processors. Record the answers — diligence you cannot evidence is diligence you may as well not have done.

What should be in place before the first matter is assigned?+

Client consent in the form your jurisdiction requires; a written supervision protocol naming the supervising attorney; documented permitted and prohibited task lists; an executed data processing agreement; scoped system access under least privilege; defined escalation criteria; and recorded diligence on the provider. Assembling these after work has started leaves a disclosure gap on matters already in flight, which has no clean retrospective fix.

How do we satisfy ourselves about the competence of a provider’s staff?+

Ask three things. What onboarding actually consists of — specifically whether personnel are trained on your checklists and conventions or a generic house methodology, since your procedures are the specification the work will be judged against. How output is checked internally before it reaches you, because a provider with no quality step converts your review gate from a safety net into the only control. And how scope boundaries are reinforced, including what happens culturally when someone declines to answer a question. A practical trial-period test is to ask something that sits just across the line and see whether it is correctly refused and escalated.

How does multi-state practice affect the disclosure analysis?+

It complicates it, because federal immigration practice is not confined by state licensure in the ordinary way, so a firm may routinely serve clients in states where none of its attorneys are admitted. That raises a question the model rules do not answer cleanly: whose disclosure standard applies — the state of admission, the state where the client sits, or both. The conservative approach is to apply the most demanding standard among the jurisdictions plausibly engaged, which usually means disclosing overseas outsourcing outright regardless of client location. Decide it once firm-wide with counsel and apply it consistently, rather than re-deciding matter by matter.

What should we do if outsourced work causes a problem?+

Depends on the problem. A filing error is the firm’s regardless of who prepared it — correct it on its merits first, then investigate separately, and expect the cause to be a gap in instructions rather than a gap in diligence. If scope was exceeded, establish what was said, assess client prejudice, correct the position with the client promptly, and tighten the instruction; treating it as a disciplinary matter usually produces concealment of the next one. A data incident is what the notification window in the data processing agreement exists for — your obligations to clients and regulators are yours to discharge, and the provider’s job is to give you the facts fast enough to do it.

What are the most common compliance mistakes firms make?+

Six, in rough order of frequency: starting work before the paperwork exists; treating a provider’s template as a compliance solution rather than a starting point for their own counsel; formal rather than substantive attorney review; gradual scope drift in what non-lawyers answer for clients; granting system-wide access because scoping it is more effort; and doing everything correctly while evidencing none of it, since unevidenced compliance is indistinguishable from none if it is ever questioned.

Legelp provides dedicated remote paralegals to US immigration firms, working inside your case management system under your supervision.

Book a free case audit →