info@lookup.com.au 1300 553 559 Remote Assist
    Lookup Logo
    Law Firm Business Outcome

    Improving Document and Matter Information Management in a Law Firm

    An executive guide for law firm partners, practice managers and directors on how to create a structured, searchable and governed information environment that supports matter management, collaboration, security and AI readiness.

    Abstract editorial illustration representing the transformation from document chaos to governed matter information in a law firm
    Executive Summary

    The two-minute answer

    Improving document and matter information management is not achieved by purchasing a single platform. It requires a deliberate combination of information architecture, access control, governance, workflow and technology that reflects how the firm actually works.

    The objective is to create an environment where matter information is authoritative, easy to find, appropriately protected, consistently structured, connected to business workflows and ready to support future automation and AI.

    The best document management approach depends on the firm's workflow, existing systems, security requirements, integration needs and information-governance model. Technology should support that structure — not force the practice into an arbitrary filing model.

    LOOKUP helps law firms approach this challenge using the LOOKUP Business Modernisation Framework™ — ensuring structure, governance and security are established before migration, automation or AI.

    The Problem

    Why legal information becomes difficult to manage

    As law firms grow, information accumulates across more clients, more matters, more staff and more systems. What worked for a small team often becomes difficult to manage at scale. Common causes include:

    Matter growth

    More matters, more documents and more staff creating information across expanding practice areas.

    Email

    Matter correspondence, attachments and advice stored in individual inboxes rather than governed systems.

    Shared drives

    Legacy network folders with inconsistent structure, broad permissions and limited searchability.

    Local storage

    Documents saved to desktops, laptops and personal devices outside any governed environment.

    Specialist applications

    Practice management, document management, billing and research systems that don't always share information well.

    Duplicate documents

    The same file saved in multiple locations with slight variations and no clear authoritative version.

    Version uncertainty

    Staff unsure which document is current, leading to errors and rework.

    Hybrid work

    Staff working from home, court, client sites and multiple offices needing consistent access to matter information.

    External collaboration

    Sharing documents with clients, counsel and third parties through inconsistent and sometimes insecure methods.

    Knowledge repositories

    Precedents, policies and internal knowledge scattered across systems with no single source of truth.

    Law Firm Information Ecosystem

    Matter information does not live in a single application. It spans multiple systems — and governance needs to operate across all of them.

    Matter Information
    Email
    DMS
    Practice Mgmt
    SharePoint
    Teams
    OneDrive
    Client Portals
    Local Files
    Common Symptoms

    The common signs of poor information management

    Poor information management rarely announces itself. It accumulates gradually until the cumulative effect becomes a visible business problem.

    Staff cannot find the right document

    Time is wasted searching across email, shared drives, practice management and local folders because information is not consistently stored or named.

    Multiple versions exist

    Emailed attachments, local copies and shared-drive versions create uncertainty over which document is authoritative, leading to errors and rework.

    Permissions are too broad

    Access inherited over time, former staff accounts still active and changed roles mean more people can see sensitive matter information than intended.

    Documents are stored in email

    Email frequently becomes an unofficial document-management repository, making matter information inaccessible to the rest of the firm and difficult to govern.

    External sharing is inconsistent

    Different staff share documents with clients and counsel through different methods — attachments, public links, portals — creating inconsistency and security risk.

    Different teams organise documents differently

    When each practice group or office develops its own structure, the firm cannot scale consistently and knowledge reuse becomes difficult.

    Business Outcomes

    What are law firms really trying to achieve?

    The objective is not simply to move files into a new system. The objective is to create an information environment that supports the firm's business goals:

    Find information faster

    Staff spend less time searching and more time on legal work.

    Reduce duplicate documents

    A single authoritative version of each document, reducing errors and confusion.

    Improve collaboration

    Teams working together on matter documents without version conflicts.

    Protect sensitive information

    Confidential matter information accessible only to those who need it.

    Improve client experience

    Faster response, secure document sharing and consistent service.

    Reduce administrative handling

    Less manual document routing, filing and follow-up.

    Create consistent workflows

    Documents flowing through structured matter processes.

    Improve leadership visibility

    Clearer insight into matter status, document activity and information access.

    Support hybrid work

    Staff accessing matter information securely from any location.

    Prepare for AI

    Governed, structured information that supports future AI adoption.

    Improve business continuity

    Information recoverable and accessible even during disruption.

    Scale operations

    Information architecture that supports growth without accumulating disorder.

    Information Architecture

    Design the information architecture before choosing the technology

    Before migrating files or selecting a platform, the firm should define how information is organised. Matter-centric information architecture typically considers:

    Matter
    Client
    Practice Area
    Document Type
    Status
    Owner
    Sensitivity
    Retention

    The precise structure should reflect how the firm actually works. No two practices are identical, and the information architecture should support the firm's practice areas, matter types, client relationships and governance requirements.

    Do not prescribe one universal legal folder structure. The objective is to create a model that staff can understand, follow and trust — not a rigid hierarchy that conflicts with how work is actually done.

    LOOKUP Perspective: Good information architecture mirrors the business. Technology should support that structure rather than force the practice into an arbitrary filing model.

    Platform Strategy

    SharePoint, Microsoft 365 and specialist legal systems

    Many law firms use a combination of specialist legal systems and Microsoft 365 for different purposes. Understanding the complementary roles of each platform helps firms avoid unnecessary duplication and integration gaps.

    Specialist legal document management systems (DMS) such as iManage, NetDocuments, LEAP and Actionstep are designed for legal workflows — matter-centric filing, version control, ethical walls, search and integration with practice management. They serve an important role in many firms.

    SharePoint and Microsoft 365 provide a governed collaboration and communication layer — Teams for matter-based collaboration, SharePoint for knowledge sharing, OneDrive for personal files and Microsoft Purview for information protection. These complement specialist systems rather than replacing them.

    The best approach depends on the firm's workflow, existing systems, security requirements, integration needs and information-governance model. LOOKUP does not argue that SharePoint should universally replace specialist legal platforms.

    Before purchasing another document platform, understand whether your existing Microsoft 365 environment can appropriately support the requirement. Many firms already own capabilities they are not fully using.

    Version control and authoritative information

    One of the most common information problems in law firms is uncertainty over which document is current. Emailed attachments, local copies and shared-drive versions create duplicate documents that diverge over time.

    Modern document platforms address this through co-authoring, version history and controlled review workflows. Instead of emailing copies, staff link to a single authoritative document. Instead of tracking changes manually, the platform maintains a complete version history.

    The business objective is not to eliminate human error — it is to reduce uncertainty over which document is current and make collaboration easier without creating multiple conflicting copies.

    Co-authoring

    Multiple staff working on the same document simultaneously without creating conflicting copies.

    Version history

    A complete record of changes, who made them and the ability to restore previous versions.

    Authoritative records

    A single source of truth for each document, reducing errors and rework.

    Permissions and confidential matters

    Permissions are one of the most important — and most neglected — aspects of legal document management. Access should reflect actual responsibility, not historical accumulation. Protecting client information depends on getting this right. For a broader view of cyber resilience including incident response and recovery, see our guide to strengthening cyber security and recovery in a law firm.

    Role-based access

    Permissions based on role and matter team rather than individual ad-hoc grants.

    Sensitive matters

    Matters requiring heightened confidentiality — such as ethical walls or information barriers — managed through deliberate access controls.

    External sharing

    Client and counsel access through controlled guest accounts, expiring links and governed portals.

    Lifecycle management

    Joiners, movers and leavers processed so access reflects current responsibilities — not past roles.

    Email should not become the unofficial matter repository

    Email is one of the most common causes of poor document management in law firms. Matter correspondence, advice, attachments and negotiations accumulate in individual inboxes — invisible to the rest of the firm, inaccessible to matter teams and difficult to govern.

    When email becomes the unofficial matter repository, information is lost when staff leave, difficult to search, impossible to govern and exposed to risks that matter-level controls are designed to prevent.

    Structured collaboration platforms — Teams, SharePoint, client portals — provide a governed alternative where matter communication and documents are stored in context, accessible to the right people and protected by appropriate controls.

    The objective is not to eliminate email — it remains an important communication tool. The objective is to ensure matter information lives in governed systems rather than scattered across inboxes.

    Secure client collaboration

    Sharing documents with clients, counsel and third parties is a daily activity in most law firms. When sharing is inconsistent — attachments, public links, different portals — it creates security risk and poor client experience.

    Controlled sharing

    Documents shared through governed links with appropriate expiry and access controls.

    Guest access

    Clients and counsel given appropriate guest access to collaborate within the firm's environment.

    Identity verification

    External users verified through identity controls before accessing sensitive information.

    Sensitive information

    Confidential documents protected through additional controls based on sensitivity.

    No single collaboration method is appropriate for every client. The firm's risk profile, client requirements and systems should determine the model.

    Document lifecycle and retention

    Documents have a lifecycle — they are created, reviewed, shared, stored, retained and eventually archived or disposed. Managing this lifecycle deliberately improves searchability, reduces clutter and supports governance.

    Retention requirements vary by jurisdiction, matter type, document type and professional obligation. This page does not prescribe legal retention periods — firms should confirm applicable requirements with their professional bodies and legal advisers.

    From a technology perspective, the objective is to ensure the firm's systems can apply retention policies consistently, automate archival where appropriate and dispose of information safely when it is no longer required.

    01
    Create
    02
    Review
    03
    Share
    04
    Store
    05
    Retain
    06
    Archive
    07
    Dispose
    AI Readiness

    Information management is an AI-readiness issue

    AI tools such as Microsoft Copilot work within a user's existing Microsoft 365 permissions. If SharePoint, Teams or OneDrive permissions are broader than intended, Copilot may make information that a user already has permission to access easier to discover.

    This means poor permissions, inconsistent structure, duplicate documents and weak governance do not just create operational friction — they directly affect how useful and safe AI will be when introduced.

    AI makes information easier to discover. That makes good information governance more important, not less. Firms that improve document and matter information management today are significantly better positioned to adopt AI tomorrow.

    Permissions

    Clean, role-based access so AI operates within appropriate boundaries.

    Information quality

    Consistent naming, structure and metadata so AI can find the right information.

    Matter structure

    Matter-centric organisation so AI understands context and relationships.

    Governance

    Policies and controls that define how AI should interact with matter information.

    Workflow and document automation

    Document management and workflow are connected. When documents are structured and governed, automation becomes safer and more valuable. Reducing administrative overhead through automation depends on having the right information foundations in place first.

    Potential workflow opportunities include automated document requests, reminder sequences, document routing, approval workflows, task creation and matter status notifications — all of which work better when information is structured and governed.

    Automated requests

    Structured document requests sent to clients with clear instructions.

    Document routing

    Automatic routing of received documents to the correct matter folder.

    Approval workflows

    Generated documents routed for professional review before use.

    The Framework

    How this maps to the LOOKUP Business Modernisation Framework™

    Improving document and matter information management follows the same structured eight-stage framework. This ensures information architecture is designed before migration, governance is established before AI, and business workflow is understood before technology is selected.

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    Discover

    Map where matter documents currently live across all systems.

    Secure

    Review permissions, sensitive matter information and access controls.

    Modernise

    Move away from legacy shared drives and local storage where appropriate.

    Standardise

    Create agreed information structures, naming practices and metadata.

    Optimise

    Reduce duplicate handling, improve search and streamline workflows.

    Prepare

    Establish governance for automation and AI before deployment.

    Implement

    Migrate and deploy deliberately, with training and validation.

    Improve

    Review usage, searchability, permissions and workflows continuously.

    Business Outcomes

    What success looks like

    When document and matter information management is addressed systematically, the benefits extend beyond filing. Staff find information faster, collaboration improves, security strengthens and the firm builds better foundations for AI.

    Easier search

    Staff finding the right document quickly because information is structured, named consistently and stored in the right place.

    SearchabilityProductivity
    Clearer matter information

    Matter context preserved across all documents.

    Structure
    Controlled access

    Permissions reflecting actual responsibility.

    Security
    Less duplication

    Authoritative versions reducing errors.

    Quality
    Better collaboration

    Teams working together without version conflicts.

    Collaboration
    Improved knowledge reuse

    Precedents and policies findable and reusable.

    Knowledge
    Better AI foundations

    Governed information ready for AI adoption.

    AI Ready
    Migration

    Migration without creating a bigger mess

    Migration is an opportunity to improve information management, not merely relocate existing disorder. Copying shared-drive folders into SharePoint without redesign simply moves the same problems to a new platform.

    A proper migration should include:

    Discovery

    Understand what information exists, where it lives and who uses it.

    Data clean-up

    Remove duplicate, obsolete and trivial information before migration.

    Duplicate review

    Identify and consolidate duplicate documents.

    Access review

    Review permissions before migrating so access reflects current needs.

    Information architecture

    Design the target structure before moving any files.

    Naming

    Agree consistent naming conventions before migration.

    Ownership

    Assign clear ownership for each information area.

    Pilot and training

    Pilot with a small group, validate, then communicate and train.

    LOOKUP Perspective: A migration is an opportunity to improve information management, not merely relocate existing disorder. The strongest outcomes come from combining discovery, clean-up, architecture and governance before a single file is moved.

    Research & Insights

    Research and professional guidance

    Several recognised organisations provide guidance relevant to law firms seeking to improve document and matter information management:

    Law Society of New South Wales

    The Law Society of NSW provides guidance on technology in legal practice, including considerations around confidentiality, information governance and the management of matter information.

    View source: Artificial Intelligence Guidance
    Law Council of Australia

    The Law Council maintains policy guidance addressing professional responsibility, client confidentiality and the appropriate management of information when adopting new technologies.

    View source: Artificial Intelligence and the Legal Profession
    Microsoft Learn

    Official Microsoft documentation explaining how Copilot uses Microsoft Graph to access user data within existing permission boundaries — directly relevant to information governance before AI adoption.

    View source: Microsoft 365 Copilot Architecture
    Australian Cyber Security Centre (ACSC)

    Baseline security guidance relevant to protecting matter information across document management systems, Microsoft 365 and email.

    View source: Essential Eight Mitigation Strategies
    Office of the Australian Information Commissioner (OAIC)

    Statutory guidance relevant to firms handling personal and confidential information in document management systems and cloud platforms.

    View source: Notifiable Data Breaches Scheme

    These organisations do not prescribe a single approach to document management. However, their guidance consistently points to the same conclusion: information governance, security and structure should be established before technology adoption — not added afterwards.

    Illustrative Scenario — Not a Client Case Study

    Illustrative business outcome

    This is an illustrative scenario, not a LOOKUP client case study. It reflects common challenges law firms may encounter and demonstrates how a structured technology approach could be applied.

    Business Challenge

    A growing law practice has matter information scattered across a specialist DMS, email, a shared drive, SharePoint and local folders. Different teams organise documents differently, permissions have accumulated over years, and there is growing interest in Microsoft Copilot but no clear plan for preparing the information environment.

    LOOKUP Approach

    • Discovered where matter information currently lives across all systems
    • Designed a matter-centric information architecture reflecting the firm's practice areas
    • Reviewed and cleaned up permissions before migration
    • Standardised naming conventions and metadata across the practice
    • Migrated documents deliberately — clean-up first, structure second, technology third
    • Established governance for external sharing, retention and sensitive matters
    • Prepared the Microsoft 365 environment for future AI adoption

    Potential Business Outcomes

    • More consistent document handling across all practice groups
    • Better searchability — staff finding the right document faster
    • Reduced unnecessary access to sensitive matter information
    • Improved collaboration through governed Teams and SharePoint
    • Less duplicate filing and version confusion
    • Better foundations for automation and AI adoption
    Executive Questions

    Frequently asked questions

    What is legal document management?

    Legal document management is the structured storage, organisation, access control and governance of matter documents and legal information across the systems a law firm uses — including specialist DMS, practice management, Microsoft 365, email and archives.

    What is matter-centric document management?

    Matter-centric document management organises documents around the matter they relate to — so all correspondence, evidence, pleadings and advice for a specific matter are stored together, accessible to the matter team and governed by appropriate access controls.

    What is the best document management system for law firms?

    The best approach depends on the firm's workflow, existing systems, security requirements, integration needs and information-governance model. Many firms use a combination of specialist legal DMS and Microsoft 365 for different purposes. No single platform is universally best for every firm.

    Can law firms use SharePoint?

    Yes. SharePoint can provide a governed collaboration and document layer for matters, knowledge sharing and internal communication. It complements specialist legal systems rather than replacing them for all purposes.

    Can SharePoint replace a legal DMS?

    Not universally. Specialist legal DMS platforms are designed for legal workflows — matter-centric filing, ethical walls, legal search and integration with practice management. SharePoint provides collaboration and governance but is not a like-for-like replacement for all DMS capabilities.

    What is the difference between SharePoint and OneDrive?

    SharePoint is designed for team and matter-level document storage with shared access, permissions and governance. OneDrive is designed for personal file storage and controlled sharing. Both are part of Microsoft 365 and work together.

    How should law firms organise matter documents?

    Matter documents should be organised around matter, client, practice area, document type, status, owner, sensitivity and retention. The precise structure should reflect how the firm actually works — there is no single universal legal folder structure.

    Should law firms store matter files in email?

    No. Email should not become the unofficial matter repository. Matter information should live in governed systems where it is accessible to the matter team, searchable, protected and retained according to the firm's policies.

    How should law firms manage document versions?

    Modern document platforms provide co-authoring, version history and controlled review workflows. Instead of emailing copies, staff link to a single authoritative document. The objective is to reduce uncertainty over which document is current.

    Can law firms share documents through Microsoft 365?

    Yes. Microsoft 365 provides controlled external sharing through guest access, expiring links and governed portals. The firm's risk profile, client requirements and systems should determine the sharing model.

    How should sensitive matter permissions work?

    Permissions should reflect actual responsibility through role-based access, matter team membership and deliberate controls for sensitive matters — including ethical walls or information barriers where relevant. Access should be reviewed regularly.

    How does document management affect cyber security?

    Poor document management creates security risk — broad permissions, unmanaged external sharing, information in email and duplicate copies. Good document management strengthens security by ensuring information is stored in governed systems with appropriate access controls.

    How does document management affect AI?

    AI tools like Microsoft Copilot work within existing Microsoft 365 permissions. Poor permissions, inconsistent structure and weak governance reduce the usefulness of AI and increase oversharing risk. Good document management is a prerequisite for safe AI adoption.

    Should law firms clean up documents before migration?

    Yes. Migration is an opportunity to improve information management. Clean up duplicates, review access, design the target structure and agree naming conventions before moving any files.

    Where should a law firm start?

    Book a Technology Strategy Session. LOOKUP will help you map where matter information currently lives, design an appropriate information architecture, review permissions and build a practical roadmap for improvement. For a broader strategic view, see our guide on building a technology roadmap for a law firm.

    Verifiable Evidence

    Sources & Further Reading

    The following primary and authoritative sources support the research, professional guidance and regulatory context discussed on this page:

    Law Society of New South Wales
    Artificial Intelligence Guidance
    2024

    Professional guidance on technology in legal practice, including confidentiality, information governance and matter management considerations.

    View Source
    Law Council of Australia
    Artificial Intelligence and the Legal Profession
    2024–2025

    National guidance addressing professional responsibility, client confidentiality and information management when adopting new technologies.

    View Source
    Microsoft Learn
    Microsoft 365 Copilot Architecture and How It Works
    2024

    Official Microsoft documentation explaining how Copilot uses Microsoft Graph to access user data within existing permission boundaries.

    View Source
    Australian Cyber Security Centre (ACSC)
    Essential Eight Mitigation Strategies
    2024

    Baseline security guidance relevant to protecting matter information across document management systems and Microsoft 365.

    View Source
    Office of the Australian Information Commissioner
    About the Notifiable Data Breaches Scheme
    2024

    Official guidance on the NDB scheme relevant to firms handling personal and confidential information in document management systems.

    View Source

    Evidence Standard

    LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.

    This page provides business technology and governance information and is not legal, privacy or regulatory advice. Law firms should obtain appropriate professional advice regarding their specific obligations.

    Turn matter information into a business asset

    LOOKUP helps law firms improve document and matter information management, strengthen Microsoft 365, reduce administrative friction and build better foundations for secure automation and AI.

    About the Author

    Peter Kantarelis

    Founder, LOOKUP — Business Technology Strategist

    Peter Kantarelis is the Founder of LOOKUP and a business technology strategist helping Australian organisations modernise technology, strengthen cyber security and prepare for practical AI adoption.

    He regularly works with business owners and leadership teams to improve productivity, reduce operational risk and implement technology that delivers measurable business outcomes. The LOOKUP Business Modernisation Framework™ reflects more than 25 years of helping Australian businesses make better technology decisions.

    Avatar
    Hi there! Have a question? Chat with us here.