CQS Information Management and Security Policy: What Should Firms Review?

A conveyancing firm’s information security procedures are tested in ordinary working moments: a fee earner receives revised bank details, someone sends documents to the wrong email address, or a member of staff uploads client information to an AI tool.

These are situations in which staff need clear instructions, an agreed verification process and someone to approach when something does not look right.

A CQS Information Management and Security Policy should help the firm manage those decisions. Its value depends on whether the document reflects the systems, responsibilities and safeguards actually used by the practice.

What should an information management and security policy cover?

The Lexsure CQS CPMS Information Management and Security Policy template addresses a range of subjects, including:

  • Data protection, confidentiality and the handling of personal information.
  • Information risk management and an information asset register.
  • Collection, distribution, storage, retention and disposal of information.
  • Backups, physical security, user accounts and malicious software.
  • Preventing the misdirection of emails and paper records.
  • Bank account security and the verification of payment details.
  • Staff training, data subject access requests and cybercrime prevention.

That breadth matters. Information security is not solely the responsibility of the firm’s IT provider. Partners, supervisors, accounts staff and fee earners make decisions that affect the security of client information and money.

A useful review therefore asks whether the policy gives each person a workable procedure for the decisions they are expected to make.

1. Checking bank details before sending money

Payment verification deserves particular attention in conveyancing, where a single transaction can involve substantial sums and several parties.

The policy should explain how staff establish that payment details are genuine, who authorises the transfer and what happens when details change or cannot be verified.

It should also distinguish between receiving an instruction and independently authenticating it. A familiar name, email signature or apparently credible message does not complete that process.

The individual policy paragraph on checking bank details of other conveyancers and third parties provides suggested wording on authentication procedures. Its public summary expressly identifies the need for adaptation to the arrangements adopted by each firm.

When reviewing this section, ask whether a new member of the accounts team could follow the procedure without relying on unwritten knowledge.

2. AI-enhanced phishing and voice cloning

Some older procedures place considerable confidence in a telephone conversation. Firms should now examine what their verification process actually establishes and whether a convincing voice or video call could cause staff to bypass other safeguards.

The paragraph on AI-enhanced phishing and voice-cloning defences addresses this issue specifically. The proposed wording introduces additional verification controls for changes to bank details.

Those controls are suggested policy provisions for firms to consider and adapt. They should not be presented as a universal CQS rule requiring every practice to use an identical authentication method.

The practical review question is whether your firm’s agreed procedure remains effective when the communication appears credible, the request is urgent and completion is approaching.

3. Generative AI and confidential client information

AI use creates another information management question: what may staff enter into a tool, and under what conditions?

A policy review should consider approved tools, the handling of confidential information, access permissions, supervision and the checks required before an output is used in client work.

It should also establish who can authorise a new tool. Staff need a clear route for seeking approval rather than making individual decisions about whether a service is suitable for client documents.

The Generative AI Governance policy update, dated July 2026, is an example of wording available for consideration within the Information Management and Security Policy.

Our earlier article on five September CQS policy updates firms should review also considers AI alongside other developments affecting the firm’s policy library.

4. Backups, recovery and business continuity

An information security policy should connect with the firm’s recovery arrangements. If staff cannot access the case management system or essential documents, the practice needs to know how it will continue handling urgent matters.

Useful questions include:

  • Who is responsible for maintaining and testing backups?
  • When was the firm’s ability to restore information last tested?
  • Who decides whether systems should be isolated following an incident?
  • How will staff contact clients and other parties if normal communications are unavailable?
  • How will urgent exchanges, completions and deadlines be managed?

Our earlier article, Ransomware: Lessons for Conveyancers, provides historical context for the importance of backups and recovery. Its age also illustrates why technical procedures require fresh review.

Read this alongside our guidance on the CQS Business Continuity Policy and Plan. The information security policy and continuity plan should describe compatible responsibilities and actions.

5. Evidence that staff have received the policy

Approving a revised document is only one stage of implementation. The people expected to apply it need to receive the changes and understand how their work is affected.

The staff acknowledgement policy provision offers suggested wording for recording that relevant staff have received, reviewed and understood the policy.

An acknowledgement can support the firm’s records. Practical training, supervision and checks on how procedures are followed give the policy owner further evidence of implementation.

For example, a short discussion of a suspicious payment request may reveal more about staff understanding than circulating a lengthy document without explanation.

Keep the policy aligned with the way your firm works

A template provides a starting structure. The firm still needs to identify its responsible people, systems, verification methods, escalation arrangements and review process.

Before approving an amendment, consider:

  • Responsibility: who owns the procedure and who provides cover?
  • Practicality: can staff follow it using the systems available?
  • Consistency: does it agree with the firm’s other policies and client communications?
  • Implementation: what training or operational changes are needed?
  • Evidence: how will the firm record approval, communication and subsequent review?

The same approach applies across the policy library, including the areas discussed in our earlier CQS Risk Management Policy guidance.

Support for reviewing and updating CQS policies

The POLICYmonitor CQS Policy Update Service supplies notifications about relevant suggested paragraphs for firms to consider including in their policies. The service describes a typical monthly notification identifying five new paragraphs drafted during the previous month.

This gives policy owners a regular opportunity to assess developments, decide whether amendments are appropriate and record the action taken.

The firm remains responsible for selecting and adapting wording, approving changes and ensuring that the resulting procedures are implemented.

Review your information security policy

Give your team clear procedures for handling information, checking payment details and using technology safely. Start with a structured policy template and adapt it to the way your firm works.

View the Information Security Policy →

Already have a policy? Explore the CQS Policy Update Service for suggested wording to support your ongoing reviews.

The linked policy paragraphs are suggested wording for consideration and adaptation. Their inclusion in a policy does not, by itself, establish compliance with CQS, data protection law or other professional obligations.