Most law firms keep written policies on client intake and conflicts, engagement and fees, client money and trust accounting, file management and retention, confidentiality and data protection, information security, anti-money laundering, complaints, supervision, conduct and harassment, leave and expenses, and remote working. Procedures explain the steps for each policy, such as how a conflict check is run or who signs a trust reconciliation.
A policy only helps if people can find the current version and the firm can show who has read it. That means each policy has an owner, a version number, an effective date, and a record of acknowledgement by every member it applies to.
Regulators and insurers often ask for specific policies, and the list differs by jurisdiction and practice area. This guide is general information and not legal advice. Check your regulator's current rules and your insurer's requirements for the policies you must hold.
- Client intake, identity checks and conflict of interest procedure.
- Engagement letters, fee agreements and billing terms.
- Client money, trust accounting and reconciliation procedure.
- Anti-money laundering and sanctions screening, where your rules require it.
- File opening, document management, retention and destruction.
- Confidentiality, data protection and handling of personal data.
- Information security: passwords, two-factor authentication, devices and incident reporting.
- Deadlines and docket control, including second checks on calculated dates.
- Supervision of junior lawyers and non-lawyer staff.
- Complaints handling and how clients are told about it.
- Conduct, equality, anti-harassment and whistleblowing.
- Leave, expenses, remote working and use of firm equipment.
- Continuing legal education and training records.
- Name one owner.
- Each policy needs a person who keeps it current and answers questions about it. Without an owner, policies drift out of date.
- Keep it short and specific.
- State the rule, who it applies to, and the steps. Link procedures from the policy rather than repeating them.
- Version every change.
- Give each published version a number and effective date, and keep earlier versions so you can show what applied at any past date.
- Collect acknowledgement.
- Ask every member to confirm they have read the current version, and chase the people who have not. Re-collect when a material change is published.
- Review on a schedule.
- Review each policy at least yearly and after an incident, a rule change or a regulator's guidance update.
The most common mistake is a single long document that nobody reads, edited in place with no record of what changed. When a regulator or insurer asks which version applied on a given date, the firm cannot answer.
The second is collecting acknowledgement once at onboarding and never again. A policy that changed after someone joined has not been acknowledged by them. Tie acknowledgement to the version, not to the person's start date.
Draft the policy.
Create the policy in the Policies module. Keep procedures as related knowledge base pages where they need more detail.
See the modulePublish a version.
Publish the policy. Each published version is kept, and an earlier version can be restored if a change needs to be reversed.
See the moduleAsk for acknowledgement.
Switch on acknowledgement for the policy and watch the counts of who has and has not acknowledged it.
See the moduleAnnounce the change.
Post a notice to the whole firm or one department on the notice board, with comments, reactions and read tracking.
See the moduleKeep procedures findable.
Store step-by-step procedures in the knowledge base, with revision history and related pages, and refer to them from the policy text.
See the module
Stated plainly, so you can decide before you sign up rather than after.
- LawAOS does not ship pre-written policy templates; the firm writes its own policies.
- Acknowledgement is optional per policy and is recorded in the app; there is no e-signature step built into policy acknowledgement.
- LawAOS does not check your policies against any regulator's requirements; that review remains the firm's responsibility.
Anything the list leaves open, our team answers directly.
