FrostKey FAQs

Practical answers about AI governance.

Questions about establishing a program, approving AI capabilities and configurations, educating employees, responding to client questionnaires, maintaining oversight, and producing organized evidence.

The framework behind the answers

Good governance follows a lifecycle.

These FAQs follow the same practical lifecycle described in The Law Firm Guide to AI Governance: understand AI Exposure, establish policy, approve capabilities and configurations, educate people, monitor change, maintain evidence, and improve the program over time.

01 Establish

Policy, objectives, responsibilities, and review ownership.

02 Evaluate & Approve

Tools, capabilities, configurations, risks, and safeguards.

03 Educate & Participate

FrostKey Academy, acknowledgements, attestations, and escalation.

04 Monitor & Demonstrate

Reviews, client questionnaires, evidence, and Governance Packages.

01

Starting the program

Questions firms ask when building the foundation.

What if our firm does not have an AI policy yet?

That is a common starting point. A practical first program should define the firm's expectations for AI use, confidentiality, approved and prohibited activities, responsibilities, escalation, education, and review.

FrostKey can help organize that foundation and provide practical starting language, but the firm remains responsible for reviewing and approving its policy.

What if we already have an AI policy?

An existing policy can become the foundation of the program. The next step is connecting it to approved capabilities and configurations, employee education, participation records, monitoring, review history, and evidence.

Is an AI policy enough?

No. A policy establishes expectations, but an operating program must also maintain decisions, communicate those expectations, review change, and preserve evidence over time.

Who should own the program?

Most firms designate a managing partner, administrator, operations leader, or other responsible owner. The program should have clear responsibility without requiring every attorney to become an administrator.

02

Capabilities and governance decisions

What firms should evaluate before enabling responsible use.

What should a firm approve: tools or specific AI uses?

Firms should look beyond product names. The meaningful decision may involve a tool, model, capability, configuration, integration, workflow, or material use case.

Once a capability is approved with clear safeguards, employees should be able to use it within those boundaries without seeking repetitive approval for every routine interaction.

Why do configurations matter?

Privacy settings, retention, training controls, integrations, data access, model selection, and administrative settings can materially change the risk profile of the same product.

Does FrostKey replace legal AI products or practice-management software?

No. Those systems help attorneys perform work or help the firm operate. FrostKey helps the organization govern how AI capabilities are evaluated, approved, communicated, maintained, and demonstrated.

Why not simply use AI to generate a policy?

Drafting a policy is only the beginning. The firm still must make its own decisions, approve the policy, educate employees, maintain records, review change, and show how the program operates.

03

Education and participation

How to help attorneys and staff use AI responsibly.

Why is employee education part of governance?

Policies are more effective when people understand the reasons behind them, the risks involved, the approved path forward, and when to escalate questions.

FrostKey Academy provides a built-in course experience with assignments, knowledge checks, completion records, and preserved participation evidence. Firms may also supplement Academy content with their own policies, guidance, and training.

What is FrostKey Academy?

FrostKey Academy is the platform’s built-in education program for responsible AI use. Firms can assign training, track completion, preserve knowledge-check results, and maintain participation evidence alongside the rest of the governance program.

What are policy acknowledgements?

Acknowledgements record that attorneys and staff received and understood the current policy or a material update. They are generally appropriate during onboarding and after meaningful policy changes.

What are attorney attestations?

Attestations are periodic confirmations that attorneys understand and are following the firm's AI requirements. They provide proportionate participation without documenting every AI interaction.

Do employees need to record every prompt or AI use?

Generally, no. Requiring records for every interaction creates unnecessary work and may discourage responsible adoption. Governance should focus on meaningful organizational decisions, clear rules, education, escalation, and periodic confirmation.

04

Maintenance and monitoring

How the program stays current as AI and expectations change.

What does ongoing monitoring include?

Monitoring may include relevant court decisions, bar guidance, insurer expectations, client requirements, vendor changes, product capabilities, and internal developments that could require a policy or governance response.

How often should records be reviewed?

The right cadence depends on the record. Policies commonly receive an annual review or review after a material change. Approved capabilities are reviewed as needed, acknowledgements follow onboarding or material updates, and attestations may be collected quarterly.

Does governance need to respond to every AI update?

No. The program should focus on developments that materially change risk, approved use, configuration, confidentiality, client obligations, or firm responsibilities.

How much ongoing work should the program create?

As little as reasonably possible. Good governance should reuse existing decisions, surface meaningful changes, coordinate required participation, and maintain evidence as part of the operating process.

05

Evidence and outside requests

What firms may need to show when someone asks about AI.

What records may a client or insurer ask for?

Requests may involve the firm’s policy, approved capabilities and configurations, confidentiality safeguards, Academy participation, acknowledgements, attestations, monitoring, review history, governance responsibilities, and completed client questionnaire responses.

What does audit-ready mean?

It means the firm can locate and produce a clear, organized record of how the program operates. It does not mean FrostKey certifies legal compliance or guarantees a particular outcome.

How does FrostKey help with client AI questionnaires?

FrostKey lets a firm maintain reusable firm-level answers, create client-specific response records, track draft and final status, preserve follow-up items, and connect completed responses to the broader governance record.

What is a Governance Package?

A Governance Package is an organized export of the records relevant to a request. It can bring together the current policy, approved capabilities and configurations, Academy and participation evidence, monitoring history, client questionnaire responses, and a governance summary.

Does FrostKey certify that a firm is compliant?

No. FrostKey helps firms organize and maintain their program and supporting evidence. The firm remains responsible for its legal, ethical, security, and compliance decisions.

06

Using FrostKey

How the platform fits into the firm's operating process.

What does FrostKey do?

FrostKey is an AI compliance management platform for law firms. It helps firms manage AI Exposure, policy, approved capabilities and configurations, FrostKey Academy, acknowledgements, attestations, monitoring, client questionnaire responses, and Governance Package evidence in one organized system.

Is FrostKey software or consulting?

FrostKey is software supported by educational resources and practical guidance. It is not a law firm and does not replace the firm's attorneys, advisors, or internal decision-makers.

Can firms of different sizes use FrostKey?

Yes. FrostKey is designed for solo attorneys, small and mid-sized firms, and larger firms that need a practical operating system for responsible AI governance.

What plans are available?

FrostKey offers Solo at $29 per month for one lawyer, Small Firm at $99 per month for 2–10 lawyers, and Growing Firm at $199 per month for 11–50 lawyers. Firms with more than 50 lawyers can contact FrostKey about larger-firm needs.

The core governance platform is available across the plans. The larger plans add the capacity, shared administration, onboarding support, and resources needed for larger teams.

Is our information secure?

FrostKey uses cloud infrastructure and access controls to protect firm records. Firms remain responsible for deciding what they upload, who has access, and how their internal security requirements are applied.

Does FrostKey provide legal advice?

No. FrostKey provides software, education, workflow support, and record organization. It does not provide legal opinions, regulatory determinations, compliance certification, or legal advice.

The Law Firm Guide to AI Governance
Want the full framework?

The FAQs answer individual questions. The book connects the entire program.

The Law Firm Guide to AI Governance explains how AI Exposure, policy, approved capabilities and configurations, education, monitoring, evidence, and improvement fit together.

It is designed as a practical starting point for firms at any stage—even before they use FrostKey.

The book explains the framework. FrostKey helps firms operate it.
Still have a question?

Tell us where your firm is today.

We can help point you toward the right resource, setup path, or FrostKey plan.