• A CQS risk management policy should help a conveyancing firm explain how it identifies risks, assigns responsibility and checks that its controls work. Its practical value depends on whether staff understand the procedures and apply them to their files.

    For firms drafting or reviewing their documentation, Lexsure’s CQS CPMS Risk Management Policy template provides a starting point covering operational responsibilities, strategic and regulatory risks, work type risk factors and an operational risk assessment guide.

    The next step is to adapt that framework to the practice: its people, conveyancing work, supervision arrangements and approach to escalating problems.

    Start with the risks your conveyancing firm actually faces

    A useful review begins with the work the firm undertakes. Different transactions can raise different risks, and those risks may change as new information emerges.

    Consider, for example, how the firm handles an unfamiliar lender instruction, an unresolved lease defect, an unusual source of funds or pressure to complete before necessary enquiries have been answered.

    For each significant risk, ask:

    • How will staff recognise it?
    • Who decides what action is needed?
    • When should the matter be escalated?
    • What evidence should the file retain?
    • How will management check that the agreed action happened?

    Our earlier article on CQS risk management policy guidance provides background to the policy framework. This review turns that framework into practical questions for the firm.

    Make risk management responsibilities clear

    A policy needs to identify who does what. Staff should know where to take a concern, who can authorise a decision and what happens when the usual supervisor is unavailable.

    Lexsure’s individual paragraph page on risk roles and responsibilities offers wording to consider when reviewing this part of the policy.

    Check that the document reflects the firm’s actual arrangements. Where one person holds several roles, distinguish the responsibilities attached to each role and explain how concerns will be addressed in practice.

    Review undertakings and the wording staff use

    Undertakings deserve specific attention in a conveyancing risk review. Consider who may give them, how they are recorded, who monitors outstanding obligations and how staff distinguish an estimate from a commitment.

    The paragraph page on undertakings policy wording addresses time estimates and the risk of accidentally giving an undertaking.

    Review standard correspondence alongside the policy. Staff training, email wording and the system for tracking undertakings should support the same approach.

    Include cyber risk in everyday procedures

    A conveyancing cyber risk review should consider how staff verify unusual instructions, handle requests to change payment details and report a suspected incident.

    Lexsure’s cyber risk policy paragraph page covers matters including training, access controls, incident response and secure handling of information.

    Use it as a prompt to examine the firm’s arrangements. Who receives an urgent report? What should staff do if an email appears to come from a trusted contact but asks them to bypass the normal procedure? Can the team explain the process without first searching for the policy?

    Address AI and technology partners

    If the firm uses AI or automated data extraction, its risk review should consider how outputs are checked before they inform legal advice.

    The paragraph page on AI and technology partners discusses the relevance of competence, due diligence, communication and supervision to technology use.

    Practical questions include who reviews an extracted provision, how an omission is identified and when the original document must be checked. The firm should also consider confidentiality, access to information and its arrangements with the provider.

    Check whether files demonstrate the policy in action

    A policy review becomes more useful when it is tested against actual files. Select matters involving different conveyancers, transaction types and levels of complexity, then examine whether the records support the decisions taken.

    Our article on what Van Halen can teach lawyers about conveyancing compliance explains why a small omission can prompt a wider investigation. A successful spot check, however, does not establish that every requirement has been satisfied.

    Likewise, our article on premature certificates of title illustrates the importance of ensuring that an assurance to a lender reflects the work actually completed.

    Where a review identifies a gap, record the response, assign responsibility and check whether the change has addressed the problem.

    Keep the CQS risk management policy connected to practice

    Review the policy when the firm’s work, staffing, systems or risk profile changes. Complaints, near misses and file reviews can also reveal where an existing procedure needs attention.

    Keep a record of revisions and explain relevant changes to staff. If a revised procedure affects live matters, identify those files and allocate the necessary follow-up.

    Our historical article on conveyancing risk management and the 2014 PII renewal season explores the relationship between documented controls, file evidence and explaining a firm’s approach to insurers.

    Drafting or reviewing your CQS risk management policy?

    Explore Lexsure’s CQS CPMS Risk Management Policy template as a starting point for documenting responsibilities, assessing conveyancing risks and organising the firm’s controls.

    Adapt the wording to your practice and check that staff procedures and file records support the policy you adopt.

    View the CQS Risk Management Policy Template