🇺🇸 Certified Legal Manager (CLM) · flashcards

Certified Legal Manager (CLM) Technology Management Flashcards

60 question-and-answer cards covering Technology Management as it is examined in Certified Legal Manager (CLM). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

60Cards in deck
24Free preview
9Syllabus topics
~211Chars per answer
FreePrice

24 sample cards from the Technology Management deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What does GDPR stand for, and to whom does it apply?

    General Data Protection Regulation (EU). It applies to any organization processing the personal data of individuals in the EU/EEA, regardless of where the organization is located.

  2. What does the CCPA/CPRA give California consumers, and who must comply?

    The California Consumer Privacy Act (as amended by CPRA) grants rights to know, delete, correct, and opt out of the sale/sharing of personal information. It applies to for-profit businesses meeting revenue/data-volume thresholds doing business in California.

  3. What is the difference between PII and PHI?

    PII (Personally Identifiable Information) is any data that can identify an individual (name, SSN, etc.); PHI (Protected Health Information) is health-related PII regulated under HIPAA.

  4. What is HIPAA, and when must a law firm comply with it?

    HIPAA (Health Insurance Portability and Accountability Act) protects health information. A firm must comply when it acts as a 'business associate'—handling PHI on behalf of a covered entity client—typically under a Business Associate Agreement (BAA).

  5. What is the difference between a data controller and a data processor under privacy law?

    A data controller determines the purposes and means of processing personal data; a data processor processes data on behalf of, and under the instructions of, the controller.

  6. What is a data breach notification requirement, and why is it critical for firms?

    It is a legal obligation to notify affected individuals (and often regulators) within a defined timeframe after a breach of personal data. Firms must comply to avoid penalties and meet ethical/contractual duties; e.g., GDPR requires regulator notice within 72 hours.

  7. What is data minimization as a privacy principle?

    Collecting and retaining only the personal data that is adequate, relevant, and necessary for the stated purpose, and disposing of it when no longer needed.

  8. What is the difference between a RFI, RFP, and RFQ in technology procurement?

    RFI (Request for Information) gathers general vendor/market information; RFP (Request for Proposal) solicits detailed solution proposals and pricing for a defined need; RFQ (Request for Quote) seeks specific price quotes for clearly specified products/services.

  9. What is a Service Level Agreement (SLA), and name two metrics it commonly defines.

    An SLA is a contract clause defining the service standards a vendor must meet. Common metrics: uptime/availability percentage (e.g., 99.9%) and response/resolution time for support requests.

  10. What is Total Cost of Ownership (TCO) in technology procurement?

    TCO is the complete cost of an asset over its lifecycle—not just purchase price, but implementation, training, maintenance, support, upgrades, and disposal—used to compare options realistically.

  11. What is the difference between perpetual licensing and SaaS subscription licensing?

    A perpetual license is a one-time purchase granting indefinite use of a specific software version (a capital expense); SaaS subscription licensing is a recurring fee for ongoing access to cloud-hosted software with updates included (an operating expense).

  12. What is vendor due diligence, and why is it important when procuring cloud/legal technology?

    It is the evaluation of a vendor's security, financial stability, compliance, data-handling, and reliability before contracting. It is important to protect client confidentiality, ensure data security, and meet the firm's ethical and regulatory duties.

  13. What is the ROI formula used to justify a technology investment?

    ROI = (Net Benefit / Cost of Investment) x 100, where Net Benefit = total gains (savings/revenue) minus the investment cost. A positive ROI indicates the gains exceed the cost.

  14. In change management, what does the ADKAR model stand for?

    Awareness (of the need to change), Desire (to support the change), Knowledge (of how to change), Ability (to implement it), and Reinforcement (to sustain it).

  15. What is the difference between a phased rollout, a pilot, and a 'big bang' implementation?

    A pilot deploys to a small test group first; a phased rollout introduces the system in stages (by group/module/location); a big bang switches all users to the new system at once on a single cutover date.

  16. What is User Acceptance Testing (UAT) and at what stage of implementation does it occur?

    UAT is testing by end users to verify the system meets business requirements and works in real-world scenarios. It occurs near the end of implementation, before go-live/production deployment.

  17. What is the role of a change advisory board (CAB) in IT change management?

    The CAB reviews, assesses risk of, prioritizes, and approves or rejects proposed changes to IT systems to minimize disruption and ensure changes are properly evaluated before implementation.

  18. Why is end-user training considered critical to a successful technology implementation?

    Even well-chosen technology fails to deliver value if users can't or won't use it. Training drives adoption, reduces resistance and errors, maximizes ROI, and improves productivity and data quality.

  19. What is data migration in a software implementation, and name one key risk.

    Data migration is transferring existing data from a legacy system into the new system. A key risk is data loss or corruption/mapping errors, which is why validation and testing of migrated data are essential.

  20. What is artificial intelligence (AI), and how is generative AI distinct from traditional AI in legal tech?

    AI is technology enabling machines to perform tasks requiring human-like intelligence. Generative AI creates new content (text, summaries, drafts) from learned patterns, whereas traditional/predictive AI mainly classifies, predicts, or analyzes existing data.

  21. What is blockchain, and name one potential legal-industry application.

    Blockchain is a decentralized, distributed, tamper-evident digital ledger. Legal applications include smart contracts, chain-of-title/property records, and verifiable document/transaction authentication.

  22. What is a smart contract?

    A self-executing program stored on a blockchain that automatically enforces and executes the terms of an agreement when predefined conditions are met, without intermediaries.

  23. What is the primary ethical/security concern when a law firm uses public generative AI tools?

    Confidentiality risk: client/confidential data entered into a public AI tool may be stored, used to train models, or exposed, potentially breaching the duty of confidentiality. Firms should use closed/enterprise tools and verify outputs (which can be inaccurate or 'hallucinated').

  24. What is Robotic Process Automation (RPA) and how is it used in legal operations?

    RPA uses software 'bots' to automate repetitive, rule-based digital tasks (data entry, intake, document assembly, conflict checks), increasing speed and accuracy and freeing staff for higher-value work.

What this deck covers

The Technology Management deck follows the Certified Legal Manager (CLM) Technology Management syllabus — 3 chapters and 9 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 20.0 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 211 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Technology Management flashcards FAQ

How many Technology Management flashcards are in this Certified Legal Manager (CLM) deck?

60 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Certified Legal Manager (CLM) flashcards free?

Yes. The preview here is free to read with no signup, and the full 60-card deck is free inside the Examius app.

What do the Technology Management cards cover?

They follow the Certified Legal Manager (CLM) Technology Management syllabus — 3 chapters and 9 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.