Every immigration firm that considers delegating case support runs into the same professional-responsibility questions, usually in the same order. This page works through them with the rules they come from, and sets out what should be in place before the first matter is assigned.
Read this first
This is general information, not legal advice. The rules discussed are the ABA model position. Your state’s rules govern, several states depart from the model materially, and nothing here is a substitute for confirming the position in your own jurisdiction. If a provider — including us — hands you a document and calls it a compliance solution, treat that claim sceptically.
The short answer
Yes, immigration firms may delegate preparatory and administrative case work to non-lawyers, including non-lawyers located outside the United States, provided the firm supervises the work, remains responsible for the representation, protects client confidences, and makes whatever disclosure its jurisdiction requires.
The complications are not about whether it is permitted. They are about what “supervises” requires operationally, where the unauthorised-practice line falls, what disclosure your specific state demands, and how any of it is evidenced afterwards if questioned.
Which rules actually apply
Four model rules and one formal opinion do most of the work.
| Authority | What it governs | Practical effect |
|---|---|---|
| Model Rule 1.1 | Competence | You remain responsible for competent representation regardless of who performs the underlying task |
| Model Rule 1.6 | Confidentiality of client information | Triggers the disclosure and consent question when outside non-lawyers receive protected information |
| Model Rule 5.1 | Responsibility of partners and supervisory lawyers | Firm-level obligation to have measures giving reasonable assurance of conformity |
| Model Rule 5.3 | Responsibility regarding non-lawyer assistance | The core supervision duty over delegated work, including outside providers |
| Model Rule 5.5 | Unauthorised practice of law | Defines what must not be delegated at all |
| ABA Formal Op. 08-451 | Outsourcing legal and non-legal support services | The direct treatment: permits outsourcing subject to supervision, competence, confidentiality and consent |
| ABA Formal Op. 00-420 | Billing for contracted services | Constrains how outsourced cost may be passed to the client |
Rule 1.1: competence stays with you
The competence obligation is the one firms most often assume is transferable, and it is not. If work is delegated and the resulting filing is deficient, the deficiency is the firm’s. This is not a technicality — it shapes the whole operating model.
Two obligations follow. First, satisfy yourself about the competence of the people doing the work — not merely the provider’s marketing, but what training they have and how output is checked. Second, retain enough involvement to catch errors. A supervision arrangement where work is approved without being read is not supervision; it is a signature.
Rule 1.6: confidentiality and what triggers consent
Rule 1.6 protects information relating to the representation. When someone outside the firm will see that information, two questions follow: whether disclosure to the client is required, and whether consent is required.
ABA Formal Opinion 08-451 contemplates both where outside non-lawyers will receive Rule 1.6-protected information. The practical distinction commonly drawn is between substantive legal work and access to confidential material on one hand — where disclosure and consent are contemplated — and purely routine administrative tasks on the other, where it generally is not.
Do not lean on the routine-administrative exception
In immigration practice, almost nothing is purely administrative in the relevant sense. Someone organising evidence for an asylum claim is handling persecution accounts, medical records and family history. The exception exists, but a firm relying on it to avoid disclosure in this vertical is taking a position that is hard to defend.
Rules 5.1 and 5.3: what supervision means in practice
“Reasonable efforts to ensure conduct compatible with the professional obligations of the lawyer” is the standard. It is deliberately non-prescriptive, which leaves firms to work out what it means operationally. In practice, five things:
- A named supervising attorney per matter. Not a general arrangement — a specific person who is responsible. Where no supervising attorney is designated, no work should be performed.
- Written scope. Permitted and prohibited tasks set out explicitly, so the boundary does not depend on someone’s judgement in the moment.
- A review gate that cannot be bypassed. Draft work stored in a state that cannot be filed directly, and substantive attorney review before anything leaves the firm.
- An audit trail. Approval recorded with reviewer and timestamp. If supervision is ever questioned, this is the evidence, and it cannot be reconstructed retrospectively.
- Defined escalation criteria. What goes to the attorney immediately rather than into a queue, written down rather than assumed.
Rule 5.1 adds a firm-level dimension: partners and managerial lawyers must have measures in place giving reasonable assurance of conformity. That is an argument for a written protocol rather than per-attorney habit, because a habit is not a measure.
Rule 5.5: the unauthorised practice boundary
The most-asked question, and the one with the clearest test once stated properly. The test is not whether a task is difficult, lengthy or specialised. It is whether performing it correctly requires legal judgement.
Indexing two hundred exhibits is laborious and requires none. Deciding which twelve of them answer the question actually being asked requires it entirely. Formatting a declaration requires none. Deciding what the declaration should say does.
| Task | Delegable? | Why |
|---|---|---|
| Populating forms from a firm-supplied record | Yes | Transcription against a defined record |
| Choosing which form or category to file under | No | A legal determination about eligibility and strategy |
| Collecting, labelling and indexing evidence | Yes | Organisation, not evaluation |
| Deciding whether evidence is sufficient | No | Judgement against a legal standard |
| Preparing draft response language for revision | Yes, with care | Preparatory only; the theory and the decision to argue it are the attorney’s |
| Advising the client what the response means for them | No | Legal advice |
| Tracking deadlines and escalating them | Yes | Administrative, provided escalation criteria are pre-defined |
| Deciding how to respond to a missed deadline | No | Strategy and risk assessment |
| Sending scheduling and document-request updates | Yes | Administrative communication using approved templates |
| Answering a client question about eligibility | No | Legal advice, regardless of how simple the question seems |
Note the pattern in the right-hand column. The delegable items are all execution against a decision already made. The non-delegable ones are all the decision itself. That is the line, and it holds across every task type we deal with. The task-level treatment is in RFE response support and petition and form preparation support.
State variation, and why it decides the question
The ABA model rules are a model. Your state’s rules are the law that applies to you, and on outsourcing the divergence is real rather than cosmetic.
Florida Ethics Opinion 07-2 requires disclosure where legal work is outsourced overseas. California, New York and North Carolina have issued their own opinions applying differing thresholds for when disclosure and informed consent are required. Others apply the general informed-consent standard without an outsourcing-specific opinion.
The practical implication is uncomfortable for providers and important for firms: a single national consent form cannot be correct everywhere. Any provider handing you one is giving you a starting point that your counsel must adapt, and any provider describing it as a compliance solution is overstating what a template can do.
If your practice is multi-state — and immigration practices frequently are, since federal immigration practice is not limited by state licensure in the way most practice is — the analysis needs to account for every jurisdiction in which you are admitted and practising.
Getting consent: the mechanics
Where consent is required, four mechanics matter more than the wording.
Timing. Before access, not after. Consent obtained once work has started leaves a gap on matters already in flight that has no clean retrospective fix.
Specificity. Generic language about “third-party vendors” is weak. Name the provider, state that personnel are located outside the United States and where, describe what they will and will not do, and say plainly that a licensed attorney approves everything before filing.
Language. This is an immigration practice. If the client’s primary language is not English, consent obtained in English is worth very little — as a matter of informed consent and, frankly, as a matter of decency. Issue it in the client’s language.
A real option to decline. Consent that carries an implied penalty is not informed consent. State explicitly that declining will not affect the representation or the fee, and mean it — which means having a plan for staffing those matters in-house.
Privilege and work product
The general position is that attorney-client privilege and work-product protection are preserved where outside personnel act as agents of the firm for the purpose of delivering legal services. This is the same basis on which privilege extends to a firm’s own staff, to contract attorneys, and to experts retained to assist.
Three things strengthen the position: written confidentiality undertakings binding each individual; a data processing agreement including an obligation on the provider to assert privilege against third-party demands and to notify you before disclosing anything; and keeping work inside your systems, so the material never sits in a location outside your control.
Nobody can guarantee this
No provider can guarantee how a particular court or agency will rule on privilege in every circumstance, and one claiming otherwise is overselling something they do not control. What a provider can do is avoid weakening the position and contract to defend it.
Who owns an error
Your firm. Responsibility for the representation does not transfer to a vendor, and a contractual indemnity — while worth having — does not change your position with your client or with your bar. An indemnity allocates money after the fact. It does not allocate professional responsibility.
This is the practical reason the review gate matters, and why it should be substantive rather than formal. An attorney who approves work without reading it has created a record showing they approved it, which is worse than no record at all.
Billing treatment
Where firms most often get tripped up, because it feels commercial rather than ethical.
ABA Formal Opinion 08-451, read with Formal Opinion 00-420, constrains how outsourced cost may be passed on. Charging the client more than the actual cost as a disbursement, without disclosure, is not permissible. Whether the cost is treated as a disbursement at cost, or absorbed into your fee, is a decision to take with your own counsel before the engagement rather than after the first invoice.
A related trap: if outsourced support reduces the hours your firm spends on a matter, and you bill hourly, the client’s bill should reflect the hours actually worked by the firm. Efficiency gains are not billable as if they had not occurred.
Client contact by non-lawyers
Permissible within limits, and worth setting out precisely because it is where arrangements most often drift.
Appropriate: scheduling, document requests, confirmation of receipt, administrative status updates — using firm-approved templates rather than free composition.
Not appropriate: anything touching eligibility, merits, strategy, likely outcomes, or the consequences of any action. These route to the supervising attorney unanswered. Not answered cautiously — unanswered.
Identification: where a client is told who they are dealing with, that person is identified as case support working under the firm’s supervision. Never as an attorney, never as a paralegal “of the firm” if they are not, and never as someone authorised to advise.
The failure mode here is gradual. A support person who has answered forty administrative questions correctly will eventually be asked a forty-first that sounds administrative and is not. The defence is training plus an explicit instruction that declining to answer is mandatory and will never be treated as a service failure.
Data security for immigration files
Immigration files are unusually sensitive, and the sensitivity is not incidental — it is the substance of the claim.
What an immigration file typically contains: Immigration and citizenship status; history of entry, detention or removal; country of origin and ethnicity; religious or political opinions; membership of persecuted groups; sexual orientation and gender identity; health and psychological records including trauma evaluations; criminal history; biometric identifiers; financial and tax records; and data concerning children.
That is special category data under the GDPR, sensitive personal information under the CPRA, and sensitive personal data under India’s DPDP Act. For a client with an asylum claim, disclosure of the file is not an inconvenience — it is potentially a safety issue for people still in the country of origin.
Minimum requirements to ask for:
- A named contracting entity you can independently verify.
- An independently certified information security programme.
- Least-privilege access scoped to assigned matters, with revocation on offboarding within a defined window.
- A data processing agreement covering sub-processors, breach notification timelines, and what happens to data on exit.
- Confirmation of whether client data is copied out of your systems at all — and if so, where it goes.
- An explicit position on whether any tooling submits client data to third-party services that retain or train on it.
That last one has become material. A provider marketing “AI-assisted” work should be able to say precisely what happens to data submitted to any model, in writing. Our own position is set out in our compliance posture and the contracting framework.
Diligence on the provider
Formal Opinion 08-451 expects you to satisfy yourself about the provider’s competence and safeguards. Concretely, that means asking:
- Who is the contracting entity, and can I verify its registration?
- Where are personnel located, physically?
- What background verification is performed before access?
- What confidentiality undertakings do individuals sign?
- How is access provisioned, reviewed and revoked?
- What certification does the security programme hold, and by whom?
- What happens to data if the relationship ends?
- Who else has access — sub-processors, subcontractors, affiliates?
Record the answers. Diligence you cannot evidence is diligence you may as well not have performed.
Pre-engagement checklist
Before the first matter is assigned, all of the following should exist:
| Item | Owner | Why it cannot wait |
|---|---|---|
| Client consent, in the form your jurisdiction requires | Firm | Consent after access leaves a gap on matters already in flight with no clean fix |
| Written supervision protocol naming the supervising attorney | Firm, with provider input | Rule 5.1 expects a measure, not a habit |
| Documented permitted and prohibited task lists | Joint | The UPL boundary cannot depend on in-the-moment judgement |
| Executed data processing agreement | Joint | Breach and sub-processor terms are worthless agreed after an incident |
| Scoped system access under least privilege | Firm | Access broader than the assignment is the most common avoidable exposure |
| Defined escalation criteria | Firm | Without them, escalation depends on someone recognising an issue they were never told to look for |
| Recorded diligence on the provider | Firm | Formal Op. 08-451 expects it, and it cannot be reconstructed later |
Training and competence of the provider's staff
Formal Opinion 08-451 expects you to satisfy yourself about the competence of the people performing delegated work. That obligation is easy to state and frequently discharged with a glance at a provider’s website, which is not the same thing.
Three questions get to something real:
- What does onboarding actually consist of? Specifically: are personnel trained on your checklists, templates and conventions, or on a generic house methodology? The first is what you want, because your procedures are the specification against which the work will be judged.
- How is output checked before it reaches you? A provider with no internal quality step is passing an unfiltered stream to your supervising attorney, which converts your review gate from a safety net into the only control.
- How are the scope boundaries reinforced? Not whether they exist on paper, but how often they are re-confirmed and what happens when someone declines to answer a question. If declining is treated as a service failure inside the provider’s own performance culture, the boundary will erode regardless of what the contract says.
A practical test for the trial period: ask a question that sits just across the line — something that sounds administrative but is really a request for advice — and see what happens. A correct refusal, escalated promptly, tells you more about the arrangement than any amount of documentation.
Note also that competence is not static. Forms change editions, procedures change, and a person competent last year on a filing type may not be current. Ask how the provider keeps up, and how you would find out if they had not.
Documenting supervision so it survives scrutiny
Compliance that cannot be evidenced is, from the perspective of anyone asking about it later, indistinguishable from no compliance. This is the part firms most consistently under-build, because it produces no immediate benefit and only matters on the day it matters a great deal.
Five records worth maintaining:
- Signed consents, filed per matter. Not in a general folder — in the matter file, retrievable when someone asks about that specific client.
- The supervision protocol, with version history. If scope changed over time, you want to be able to show what applied when.
- Approval records with reviewer and timestamp. Produced automatically by your case management system if it is configured to; worth confirming that it is, because most firms assume it and few check.
- Access grants and revocations. Who had access to what, and when it ended. Revocation records matter more than grants.
- Diligence file on the provider. Answers to the questions above, dated, plus copies of certifications relied on.
None of this is onerous once established. All of it is close to impossible to reconstruct retrospectively, which is why it belongs in the setup phase rather than on a list of things to tidy up later.
Multi-state practice
Immigration practice complicates the jurisdictional analysis in a way most practice areas do not. Federal immigration practice is not confined by state licensure in the ordinary way, so a firm may routinely serve clients located in states where no attorney at the firm is admitted.
That raises a question the model rules do not answer cleanly: whose disclosure standard applies — the state where the attorney is admitted, the state where the client is located, or both? The conservative approach is to apply the most demanding standard among the jurisdictions plausibly engaged, which in practice usually means following the Florida-style position of disclosing overseas outsourcing outright regardless of where the client sits.
That is a defensible default rather than a legal conclusion. It is exactly the sort of question to put to counsel once, decide firm-wide, and then apply consistently — rather than re-deciding matter by matter, which is how inconsistency creeps in.
If something goes wrong
Worth thinking about before it happens, because the instinct in the moment is usually wrong.
A filing error surfaces. The error is the firm’s regardless of who prepared the document. Correct it on its merits first; the question of how it happened is a separate exercise, conducted afterwards, and the answer is usually a gap in instructions rather than a gap in diligence.
Scope was exceeded. Someone answered a question they should have escalated. Establish what was said, assess whether the client was prejudiced, correct the position with the client directly and promptly, and tighten the instruction. Treating it as a disciplinary matter for the individual usually produces concealment of the next one.
A data incident. This is why the data processing agreement specifies a notification window. Your obligations to clients, courts and regulators are yours to discharge — the provider’s role is to give you the facts fast enough that you can. A provider who notifies you late has failed at the single most important thing they contracted to do.
The arrangement ends abruptly. This is what the exit terms are for: data returned or deleted, matters in flight documented, access revoked on a defined timeline. Firms that negotiated only a notice period, without a handover specification, discover the difference at exactly the wrong moment.
Where firms most often go wrong
Six failure patterns, in rough order of frequency:
- Starting work before the paperwork. The single most common, and the hardest to fix retrospectively.
- Treating a provider’s template as sufficient. It is a starting point for your counsel, not a compliance solution.
- Formal rather than substantive review. Approving without reading creates a record that is worse than none.
- Scope drift in client communication. Gradual, and usually invisible until something goes wrong.
- Access broader than the assignment. Granting system-wide access because it is simpler than scoping it.
- No audit trail. Everything done correctly and none of it evidenced. If supervision is questioned, unevidenced compliance is indistinguishable from none.