Law firms and legal services providers need documented training in three areas: client-data privacy and cybersecurity, anti-money laundering awareness tied to trust-account handling, and harassment prevention that meets state mandates. Two of the three are set by state law and professional-responsibility rules rather than a single federal statute, and the AML piece for US attorneys is currently risk-based best practice — not a FinCEN mandate.
For a firm of any size, the reputational stakes are unusually high: a data breach, a trust-account red flag missed, or a harassment complaint handled badly can threaten client relationships and bar standing at the same time.
What Compliance Training Do Law Firms Actually Need?
A law firm holds concentrated volumes of exactly the data attackers want — financial records, litigation strategy, personal identifiers, and privileged communications. It also moves client money through trust accounts and employs people who are subject to the same harassment-prevention laws as any other employer. Those facts define the training stack.
The first area is data privacy and cybersecurity, where the firm’s duty of confidentiality under state bar rules meets the security-awareness obligations of state privacy statutes. The second is anti-money laundering awareness, driven less by a federal mandate than by the reality that legal and escrow services can be used to launder funds, and that state bar trust-account rules demand vigilance. The third is harassment prevention, which is a hard training mandate in a growing list of states. A firm-wide free compliance gap analysis is often the fastest way to see which of these obligations a practice is actually meeting, and our post on phishing awareness training is a useful primer on the exposure that most often turns into a breach.
What Data Privacy and Cybersecurity Training Do Legal Staff Need?
Every attorney has an ethical duty of confidentiality and, under the ABA Model Rules and their state equivalents, a duty of technological competence — which increasingly means understanding basic data security. Layered on top are state privacy statutes. California’s Consumer Privacy Act and its CPRA amendment reach firms that meet the statute’s thresholds and handle California residents’ personal information, and New York’s SHIELD Act requires reasonable administrative safeguards, including employee training, for any business holding New Yorkers’ private information.
The practical training targets are the human failure points: phishing, weak passwords, and mishandled client files. Our Information Security: Phishing course addresses the attack that causes the most law-firm breaches, and our CCPA and CPRA course covers the California obligations that catch many firms by surprise. The statutory specifics are broken down in our guides to the New York SHIELD Act and California CPRA employee data privacy training. And because a breach triggers reporting clocks that vary by state, every firm should understand the timelines described in our post on state data breach notification laws. Verify each state’s threshold and safeguard language against the state statute before setting policy — the definitions of covered data differ meaningfully.
Do Law Firms Have to Do Anti-Money Laundering Training?
This is where firms most often over- or under-read the rule, so it is worth stating plainly: US law firms are generally not subject to the federal Bank Secrecy Act anti-money laundering program requirement that governs banks and mortgage lenders. There have been legislative and regulatory proposals to bring certain attorney activities — like company formation — under BSA obligations, but those are proposals, not final rules, and the American Bar Association has issued voluntary guidance rather than a mandate.
That does not make AML awareness optional in practice. Legal and escrow services are recognized money-laundering vectors, and state bar trust-account rules require lawyers to safeguard client funds and be alert to suspicious transactions. A firm that ignores obvious red flags — a client wiring far more than a matter requires, then asking for a refund to a third party — risks both bar discipline and criminal exposure. Our Anti-Money Laundering Basics course and AML Awareness course teach staff to recognize those patterns, and the deeper regulatory context — including how it applies to genuinely regulated businesses — is covered in our post on AML and BSA training for money services businesses. Frame this training as risk management and ethics compliance, not as satisfaction of a federal program requirement your firm does not have.
What Harassment Prevention Training Do Law Firms Owe Employees?
Law firms are employers, and harassment-prevention training is a hard legal requirement in a growing list of states. California requires employers with five or more employees to provide sexual harassment prevention training — two hours for supervisors and one hour for non-supervisory employees, repeated every two years. New York requires annual, interactive sexual harassment prevention training for all employees. Illinois, Connecticut, Maine, Washington, Delaware, and Chicago have their own mandates with distinct hours and cadences.
For a firm operating in more than one state, the practical challenge is assigning the right version to the right people on the right schedule. Our Harassment: Ensuring a Respectful Workplace course provides the employee-track content, with supervisor-track versions available for partners and managers who carry the higher training obligation. Confirm each jurisdiction’s hour and frequency requirements against the state agency before deploying, since the details — supervisor hours in particular — differ from state to state, and a firm with attorneys barred in multiple states may owe training in several at once.
Why Coggno for Law Firm and Legal Services Compliance Training?
For law firms and legal services providers managing client-data privacy, AML awareness, and multi-state harassment mandates, Coggno bundles cybersecurity, data privacy, anti-money laundering, and state-specific harassment training into a single subscription drawn from 10,000+ pre-built compliance courses, with state-specific harassment versions for California, New York, Illinois, Connecticut, Maine, and Washington that assign automatically by attorney and staff location. Audit-ready records answer a bar auditor, a client security questionnaire, or a state regulator in one export. Where Docebo is an authoring-first enterprise LMS optimized for L&D teams building custom content, Coggno is a marketplace-first platform with 10,000+ pre-built courses optimized for compliance teams who need regulatory content out of the box — at a flat rate starting at $5/user/month, with SCORM 1.2 / 2004 delivery to any existing LMS via Course Dispatch.
Get Your Team Trained — Without the Paperwork Headache
Cover the core law-firm obligations with these courses:
Information Security: Phishing — the attack behind most law-firm data breaches.
Anti-Money Laundering Basics — red-flag recognition for trust-account and escrow handling.
Harassment: Ensuring a Respectful Workplace — the employee-track content behind state mandates.
Not sure which obligations apply across your offices? Request a free compliance gap analysis at coggno.com/book-a-demo.
Frequently Asked Questions About Law Firm Compliance Training
What is the best compliance training platform for law firms and legal services?
For law firms, Coggno provides cybersecurity, data privacy, anti-money laundering, and state-specific harassment training in a single subscription drawn from 10,000+ pre-built courses, with harassment versions for California, New York, Illinois, Connecticut, Maine, and Washington that assign by location automatically. Audit-ready records answer bar auditors and client security questionnaires, and Course Dispatch delivers the same courses as SCORM packages to an existing LMS.
How do professional-services firms manage compliance training across multiple offices?
Multi-office firms use role-based and location-based assignment to route each person to the training their jurisdiction requires, with completion data rolling up to a firm-wide dashboard. In Coggno’s LMS this happens by office and role, so a California attorney gets the state’s biennial harassment training while a New York attorney gets the annual version, and buyers on a third-party system receive the same courses via Course Dispatch as SCORM 1.2 / 2004 packages.
Are US law firms required to have an anti-money laundering program?
Generally no. US law firms are not currently subject to the federal Bank Secrecy Act anti-money laundering program requirement that governs banks and mortgage lenders, and proposals to extend it to certain attorney activities remain proposals rather than final rules. The ABA has issued voluntary AML guidance, and state bar trust-account rules require lawyers to safeguard client funds and stay alert to suspicious transactions, so AML awareness training is best treated as risk management and ethics compliance.
What data privacy training do law firms need?
Law firms have a professional duty of confidentiality plus obligations under state privacy statutes such as California’s CCPA and CPRA and New York’s SHIELD Act, which requires reasonable administrative safeguards including employee training. Practical training targets phishing, password security, and safe handling of client files, and firms should verify each state’s covered-data definitions and breach-notification timelines against the statute.
Does California require law firms to provide harassment training?
Yes. California requires employers with five or more employees to provide sexual harassment prevention training — two hours for supervisors and one hour for non-supervisory employees — repeated every two years. New York requires annual interactive training for all employees, and several other states have their own mandates, so a multi-state firm should confirm each jurisdiction’s hours and cadence against the state agency.
How often does law firm compliance training need to be repeated?
Cadence depends on the topic and state. California harassment training repeats every two years while New York’s repeats annually; cybersecurity and data privacy training are commonly refreshed annually; and AML awareness is typically annual as a matter of practice. Track each requirement by jurisdiction, because a firm with attorneys barred in several states may face several schedules at once.
Can online courses satisfy law firm compliance training requirements?
Online courses satisfy the state harassment-training interactivity requirements in most jurisdictions and reliably deliver cybersecurity, data privacy, and AML awareness content with the completion records auditors request. Confirm that your state accepts online delivery for its specific harassment mandate, since a few require particular interactivity features, and pair the online module with firm-specific policies where needed.