vendor risk
When Infrastructure Fails Lawyers: What the NextGen Bar Collapse Tells In-House Teams About Vendor Risk

A Failure of the Gatekeepers
In July 2026, Washington State scrapped its entire NextGen bar examination administration after a convention centre hardware failure left roughly 645 applicants locked out of the system. The NCBE, the organisation responsible for the NextGen exam, had positioned itself as the authoritative solution to a supposedly broken patchwork of state-run alternatives. California's attempt to build its own bar examination had been widely ridiculed. Yet when the test came, the centralised expert infrastructure failed in a way that a distributed, state-level system might have contained.
Affected candidates were offered a tentative September makeup date, a transfer to February 2027, or a refund. For individuals whose employment offers are contingent on licensure, none of those options is anything close to adequate.
This is not primarily a story about legal education. It is a story about what happens when organisations place unqualified trust in a single critical vendor, assume that institutional credibility equals operational resilience, and fail to contractually protect themselves when things go wrong.
The Vendor Credibility Trap
In-house legal teams and law firm operations managers make the same category of mistake routinely. A vendor arrives with impressive credentials, a roster of blue-chip clients, and a persuasive demonstration. The procurement conversation then focuses almost entirely on capability and price. Questions about failover architecture, data recovery time objectives, and contractual liability for service failures are deferred, softened, or omitted entirely.
The NCBE's reputational authority did not prevent a hardware failure from cascading into a state-wide examination collapse. Institutional credibility is not a substitute for contractual accountability or tested contingency planning.
For legal technology specifically, the stakes of this kind of failure are asymmetric. A contract management system that is unavailable during a negotiation deadline, a deal close, or a regulatory filing window does not simply cause inconvenience. It can produce missed deadlines, lapsed rights, or breached obligations that carry real financial and legal consequences.
What Your Vendor Contracts Should Actually Say
The Washington bar examination debacle is a useful prompt to audit your own vendor agreements across legal technology platforms. Several provisions deserve particular scrutiny.
Service level agreements should define not just uptime percentages but what happens when those levels are breached. A 99.5% uptime commitment sounds reassuring until you calculate that it permits roughly 44 hours of downtime per year, with no guarantee about when those hours fall.
Force majeure clauses require careful reading. Many technology vendors have drafted these broadly enough to encompass hardware failures at third-party facilities, which is precisely the category of failure that affected Washington. A well-negotiated clause should distinguish between genuinely unforeseeable external events and operational failures within the vendor's reasonable control.
Remedy provisions matter as much as liability caps. Service credits that amount to a fraction of a monthly fee are not meaningful remedies when a system outage derails a transaction or triggers a contractual default elsewhere in your portfolio.
Business continuity and disaster recovery obligations should be explicit, tested, and verifiable. The right to audit or request evidence of DR testing is worth negotiating at the outset.
Jurisdiction and Governing Law Are Not Formalities
One detail the Washington story surfaces is how quickly a technology failure acquires a jurisdictional dimension. The makeup arrangements, the transfer options, and the refund mechanics all operate within a specific regulatory and legal framework. The candidates' options depend on what Washington State's bar admission rules actually permit, not just on what the NCBE is willing to offer.
The same principle applies to commercial contracts. A governing law clause determines which remedies are available, how damages are calculated, and what notice periods are enforceable. An AI contract management system that operates without genuine knowledge of the applicable jurisdiction's law is managing documents rather than managing legal risk. Reading a contract from your counterparty's side while being unaware of what the law in that jurisdiction implies or requires is a meaningful gap in protection.
Resilience Is a Contracting Problem
The instinct after a failure like Washington's is to look for a better vendor. That instinct is not wrong, but it is incomplete. Vendor selection matters less than vendor governance, and vendor governance lives in the contract.
In-house teams that invest in AI-assisted contract management should expect their tooling to surface vendor risk obligations proactively, flag renewal dates before they lapse, and flag non-standard liability limitations before they are signed rather than after they become relevant. That requires a system that understands the legal significance of what it is reading, not merely one that can retrieve or summarise text.
The 645 candidates waiting for a September makeup date did not create the infrastructure risk that stranded them. But the contracting framework around the NCBE's administration did not protect them either. For legal teams, that is the most transferable lesson of all.
See how Adira drafts in your voice and reads contracts from your side.
Explore the showroom