Choosing a Marketing Supplier When You Are a Regulated Firm
A due diligence checklist for solicitors, accountants and advisers appointing a website or marketing supplier — covering data processing, professional indemnity, approval workflow and IP ownership.
A regulated firm appointing a marketing supplier is doing something more consequential than buying a website. It is granting a third party the ability to publish statements in the firm's name, and usually handing over personal data at the same time.
The firm remains accountable for both. The supplier's contract does not transfer regulatory responsibility, and regulators do not accept "our agency wrote it" as an answer.
Most professional firms run less due diligence on a marketing supplier than on a stationery contract. Below is what the process should cover.
We have written separately on why generalist agencies struggle with regulated clients. This article is the practical counterpart: the questions to ask before signing.
1. Data protection
This is the area with the clearest legal requirements and the weakest supplier compliance.
Any supplier handling personal data on the firm's behalf — website enquiry forms, email marketing lists, CRM data, analytics identifying individuals, call recordings — is a processor under UK GDPR. Article 28 requires a written contract with specified terms.
Ask for:
- A data processing agreement meeting Article 28. Not a paragraph in the terms of business; a proper DPA covering subject matter, duration, nature and purpose, categories of data and data subjects, and the controller's instructions.
- A sub-processor list. Every supplier uses others — hosting, email platforms, analytics, form handlers, AI tools. You are entitled to know who they are and to be told of changes.
- International transfer arrangements. Most marketing stacks involve US-based processors. The transfer mechanism should be identified.
- ICO registration. Verifiable on the ICO's public register in under a minute.
- Security measures, described specifically. Access control, encryption, retention periods, and what happens to your data at the end of the contract.
- Breach notification terms. Article 33 requires the controller to notify the ICO within 72 hours where the threshold is met. That is impossible if the processor takes a fortnight to tell you. The DPA should require notification without undue delay, and should specify a period.
A supplier that cannot produce a DPA on request has not been asked for one before. That tells you what kind of clients they have.
2. Professional indemnity and liability
Two questions.
Does the supplier carry professional indemnity insurance, and at what level? A supplier whose error causes a regulatory breach, a data incident, or a defamation claim should have cover proportionate to the harm they can cause. For a firm relying on the supplier for compliance-adjacent content, "web design" cover at a low limit is not proportionate.
What does the liability cap say? Most agency contracts cap liability at fees paid, often over a limited period. A £6,000 annual contract capped at fees paid means £6,000 of recourse against an incident that could cost the firm considerably more. This may be commercially unavoidable with smaller suppliers, but the firm should know the position rather than discover it.
3. Content approval workflow
This is the control that matters most and the one most often absent.
The question is simple: can the supplier publish content in the firm's name without the firm seeing it first?
For a regulated firm the answer must be no. Where suppliers have autonomous publishing access — blog posts, social media, paid ad copy, Google Business Profile updates, review responses — material goes out that no qualified person has reviewed.
The workflow should specify:
- Who at the firm reviews content, by role
- What must be reviewed (in practice: anything making a claim about the firm, its services, its results, or the law)
- How approval is recorded — this becomes the audit trail
- Turnaround expectations in both directions
- What the supplier may publish without review, if anything, defined narrowly
Ask specifically about AI-generated content. Suppliers using generative tools for drafting should say so, and the approval workflow should account for it. AI-drafted content about regulated subject matter is a specific risk: it is fluent, plausible, and confidently wrong about rule detail in ways a non-specialist reviewer will not catch.
4. Sector understanding
Some questions that separate suppliers who understand the environment from suppliers who will learn on your account:
- What restrictions does our regulator place on how we advertise?
- Give an example of something a client asked for that you advised against on compliance grounds.
- How do you handle testimonials given our confidentiality obligations?
- What is your process for reviewing claims before publication?
You are not testing regulatory expertise — that is your responsibility, not theirs. You are testing whether they know the constraint exists. A supplier who has never encountered it will produce work that is perfectly competent by ordinary standards and wrong for you.
The specific failure to watch for: a supplier who responds to a compliance constraint by treating it as an obstacle to be worked around rather than a parameter to design within.
5. Ownership and exit
Firms discover the ownership problem at the point of leaving, which is the worst time.
Establish before signing:
- Who owns the website code and design? Bespoke work should transfer on payment. If the supplier retains ownership or licenses a proprietary platform, you are renting.
- Who owns the domain? It should be registered to the firm. Domains registered to agencies are a recurring and entirely avoidable source of disputes.
- Who controls hosting, DNS, analytics, and the Google Business Profile? The firm should hold at least owner-level access to all of them.
- What happens on termination? Content export, data return or deletion, transition assistance, and how long access persists.
- Content ownership. Articles written for the firm should belong to the firm.
The test: if the relationship ended tomorrow, what would the firm still have? If the answer is "a login we do not control", fix it before signing.
6. Substantiation of the supplier's own claims
A supplier making unevidenced claims in their own marketing will make them in yours.
Ask for the evidence behind the numbers on their website. Ask to speak to a client in your sector — not a reference the supplier selected, a client you can ask your own questions. Ask what they cannot do.
Suppliers who guarantee rankings, guarantee AI citation, or guarantee lead volumes are describing outcomes they do not control. In a sector where you are personally accountable for the accuracy of claims made in your name, this is a relevant character reference.
A proportionate checklist
For a firm appointing a supplier, the minimum viable process:
- ICO registration verified
- DPA reviewed and signed before any data is shared
- Sub-processor list obtained
- PI insurance confirmed with the limit noted
- Liability cap read and understood
- Approval workflow agreed in writing, with a named reviewer
- Domain, hosting, analytics and Business Profile registered to or controlled by the firm
- IP ownership confirmed in the contract
- Exit terms specified
- One unmanaged reference taken in your sector
Two hours of work. Materially less than the cost of any one of these going wrong.
Common questions
Is this proportionate for a small firm?
Yes, and arguably more so. A small firm has less internal capacity to catch supplier errors and less resilience if something goes wrong.
What if the supplier will not sign a DPA?
Do not engage them. It is a legal requirement where they process personal data on your behalf, and refusal indicates they are not equipped for regulated clients.
Can we rely on the supplier for compliance advice?
No. Suppliers can build compliance requirements into their process — most should — but accountability sits with the firm and its compliance function. Any supplier who suggests otherwise is describing something they cannot deliver.
Should we use a specialist or a generalist?
Either can work. What matters is whether the supplier's process accounts for the constraints you operate under. A generalist with a genuine approval workflow and a proper DPA is a better position than a self-described specialist with neither.
TIKF Group works with SRA, ICAEW and IAA-regulated firms, with data processing terms, approval workflow and compliance review built into the engagement. See our services or request an audit.
This article describes general procurement considerations and is not legal advice.
End of article
Related articles
- AI Visibility
SEO Is Not Enough Anymore. Here's What Changed.
AI search engines now answer your clients' questions before they ever reach your website. If your firm isn't visible to ChatGPT, Perplexity, and Google AI Overviews, you're already losing enquiries to competitors who are.
- Financial services
Financial Promotions Online: What FCA-Authorised Firms Need on Their Website
Websites and social posts are financial promotions. What FG24/1 expects, what standalone compliance means for a web page, and the record-keeping most firms handle badly.
- AI Visibility
Your Competitors Are Being Recommended by ChatGPT. Are You?
When a potential client asks ChatGPT or Perplexity for the best solicitor, accountant, or adviser in their area, a handful of firms get named. Most don't. Here's why — and what determines who makes the shortlist.
