Legal Spend Audits | Custodia Advisory
The Question Most Institutions Aren't Asking
Is your institution paying for what it agreed to pay for — and nothing more?
It sounds like a simple question. In practice, it is almost never asked with the rigour it deserves. Legal invoices move through procurement under time pressure, approved against budget lines rather than against the specific terms of engagement letters and Outside Counsel Guidelines. The assumption — reasonable on its face, rarely verified in practice — is that what's on the invoice reflects what was agreed.
A legal spend audit is the exercise that tests that assumption. And in our experience, the gap between assumption and reality is consistently larger than institutions expect.
What a Legal Spend Audit Is
A legal spend audit is a structured, independent review of invoices, matters, and billing patterns over a defined period — conducted against the specific terms of your engagement letters, Outside Counsel Guidelines, and fee arrangements.
It is not a general review of whether your legal spend is too high. It is a specific, line-by-line assessment of whether what you have been billed reflects what you agreed to pay — and where it does not, what the basis for recovery or renegotiation is.
The output is a clear, evidence-based report: what was found, what it means, and what to do about it.
What We Look For
Every audit is scoped to your specific arrangements and billing history. Across engagements, the issues we identify most consistently include:
Rate non-compliance Rates billed above those agreed in the engagement letter or OCG — including incremental increases applied without the required notice or approval, and rates carried over from prior matters where a new arrangement was in place.
Staffing non-compliance Work performed and billed at seniority levels above what the OCG or engagement letter permits for that matter type — partner billing for routine work, senior associates billing where junior resource was specified.
Block billing Time entries that bundle multiple tasks into a single line, making it impossible to assess whether the individual components were reasonable, necessary, or guideline-compliant.
Non-compliant disbursements Third-party costs billed outside agreed categories, without required itemisation, above agreed caps, or for services not contemplated in the original engagement.
Out-of-scope work Additional work performed and billed without the prior approval the engagement letter or OCG requires — sometimes clearly identified as additional, sometimes absorbed quietly into existing matter billing.
Duplicate entries Two or more timekeepers billing for the same activity — a call, a document review, an internal discussion — where duplication is not justified by the nature of the work.
Matter misallocation Costs allocated to the wrong matter, fund, or entity — sometimes inadvertently, sometimes as a result of inadequate billing controls at the firm level.
Scope Options
Legal spend audits can be structured in several ways depending on your specific needs and exposure:
Single-firm audit A focused review of one panel firm's billing across a defined period — useful where a specific relationship has raised concerns, or as a pilot before a broader portfolio review.
Single-matter audit A deep review of billing on one specific transaction or matter — particularly useful for complex, high-value transactions where billing volume makes line-by-line review difficult to run internally.
Portfolio-wide audit A comprehensive review across all panel firms and jurisdictions over a defined period — the most complete picture of where spend is and isn't compliant across the institution's full legal cost base.
Historical audit A review of billing from prior periods — designed to identify recoverable overbilling from past engagements, which can in some cases extend several years back depending on the terms of the relevant engagement.
Ongoing periodic audit A standing audit cycle — quarterly or annual — that replaces one-off reactive review with a proactive, systematic check that prevents non-compliance from accumulating before it is caught.
What This Looks Like in Practice
An asset manager with legal spend distributed across five jurisdictions and eight panel firms has no consolidated view of what it is paying, to whom, and against what terms. Invoices are processed by a small procurement team against a payment run — coded to cost centres, matched to purchase orders, and passed for approval. No one is reviewing them against the relevant engagement letters or OCGs.
We run a portfolio-wide audit across two years of invoices. The findings include:
- Duplicate time entries across three firms on matters where multiple timekeepers attended the same calls
- Disbursements billed above the agreed cap by two firms, consistently and across multiple matters
- Two rate cards that have not been updated in the system since the original engagement three years earlier — meaning every invoice since has been checked against outdated figures, and incremental rate increases have been passing through unchallenged
- Out-of-scope regulatory work billed by one firm across four matters without the prior approval the OCG requires
- One matter where costs have been allocated to the wrong fund entity, creating a discrepancy that will complicate the fund's year-end accounting
The report gives the institution a clear basis to recover fees from three firms, renegotiate terms with two, retire one panel relationship, and correct the entity allocation before year-end. It also gives procurement a specific list of what to check on every future invoice — turning a reactive audit finding into a standing control.
Why Independent Audit Matters
Legal spend audits conducted by the institution's own procurement or finance team — however capable — face an inherent limitation: the people reviewing the invoices are the same people who approved them. An independent audit removes that conflict. It applies an objective, external lens to billing that has already passed through internal review — and it consistently finds things that internal review missed, not because internal teams aren't diligent, but because they are reviewing invoices as approvers, not as auditors.
For institutions with LP or investor reporting obligations around cost governance, an independent audit also provides something internal review cannot: a defensible, third-party validation of spend compliance that can be referenced in investor communications and due diligence responses.
How We Work
Every legal spend audit begins with a scoping conversation — what period to cover, which firms and matters to include, and what the institution already knows or suspects about its billing exposure. From there we work directly with your existing invoice data. No new systems, no platform onboarding, no disruption to existing workflows.
Findings are delivered in a clear written report with specific, prioritised recommendations — what to recover, what to renegotiate, what to change in the invoice review process going forward.
Related Reading
- Block Billing, Rate Creep & the Other Ways Law Firms Quietly Over-Bill
- The Last Mile Problem: Why OCGs Fail Where They Matter Most
- How to Build Outside Counsel Guidelines That Actually Work
Custodia Advisory — custodiaadvisory.com — advisory@custodiaadvisory.com