The SRA Compliance Checklist Every Conveyancing Practice Manager Should Have for IT and Cybersecurity

Business Evolution Radar Chart

The SRA Compliance Checklist Every Conveyancing Practice Manager Should Have for IT and Cybersecurity

SRA compliance for law firms is not a one-off exercise. It sits in the background of every decision your practice makes — how you store client data, how you respond to an incident, whether your systems would survive a disruption. For smaller conveyancing practices without a dedicated IT function, that responsibility usually lands on the practice manager or a managing partner. This checklist is designed to make that responsibility a little more manageable.

What the SRA Actually Expects from Your IT and Security Arrangements

The SRA Standards and Regulations set out clear obligations around protecting client money, handling confidential information, and maintaining the kind of business continuity that allows you to keep serving clients even when things go wrong. These are not aspirational targets — they are minimum standards, and the SRA expects firms to demonstrate how they are being met.

For conveyancing practices specifically, the stakes are high. You are handling large financial transactions, sensitive personal data, and time-critical completion deadlines. If your systems fail or your data is compromised, the consequences extend well beyond an awkward conversation with a regulator.

The Checklist: IT and Cybersecurity Areas the SRA Will Look At

This is not exhaustive, and it is not a substitute for proper legal or compliance advice. But it covers the areas that consistently come up for conveyancing firms — and the areas where smaller practices are most likely to have gaps.

1. Data Protection and Client Confidentiality

  • Are client files and communications stored securely, with access restricted to the people who need it?
  • Is your email environment configured to prevent unauthorised access? (Microsoft 365, for example, requires specific security settings that are not switched on by default.)
  • Do you have a clear policy on how long client data is retained, and how it is deleted?
  • Are you registered with the ICO and compliant with your UK GDPR obligations?

Data protection and SRA compliance for law firms are closely linked. A breach that exposes client data is likely to trigger obligations under both regimes.

2. Cybersecurity Controls

  • Is multi-factor authentication (MFA) enabled on all staff accounts, including email?
  • Are software and operating systems kept up to date, including third-party conveyancing platforms such as Osprey, LEAP, or Videss?
  • Do you have endpoint protection in place on every device — including laptops used at home by fee earners?
  • Is there a process for revoking access when a member of staff leaves?

Conveyancing firms are a known target for email fraud and identity theft. Cybercriminals specifically look for gaps in firms handling property transactions. We have written about this in more detail in our piece on why conveyancing firms in Surrey and the Home Counties are being targeted by cyber criminals.

The National Cyber Security Centre publishes practical guidance for small organisations, including a Cyber Essentials framework that maps well onto SRA expectations around cybersecurity.

3. Business Continuity and Disaster Recovery

  • Do you have a documented business continuity plan that covers IT failure, ransomware, and loss of access to key systems?
  • Are your data backups tested regularly — not just taken, but actually restored and verified?
  • Could your team continue working if your office became inaccessible? Is remote access secure and reliable?
  • Do you know how long recovery would take, and does that timeframe meet your SRA obligations to clients?

This is an area where many smaller firms discover their arrangements are less robust than they assumed. A backup that has never been tested is not a backup — it is a hope.

4. Incident Response

  • Do you have a written procedure for responding to a cyber incident or data breach?
  • Do all staff know who to contact and what to do if they suspect a phishing attack or fraudulent instruction?
  • Is there a clear escalation path that includes notifying the ICO within 72 hours where required?
  • Have you run any form of staff awareness training in the last 12 months?

The SRA expects firms to act promptly when something goes wrong. Without a plan, the instinct is often to try and manage an incident quietly. That approach typically makes things worse.

5. Third-Party and Supplier Risk

  • Do you know which third parties have access to your systems or client data?
  • Have you reviewed the security practices of your key technology suppliers?
  • Are your conveyancing platform providers contractually obliged to notify you of a breach?

Third-party risk is an area that often catches firms off guard. Your SRA obligations do not pause because a supplier had a problem.

6. Policies, Documentation, and Staff Awareness

  • Do you have a written information security policy, even a simple one?
  • Is it reviewed at least annually?
  • Do new starters receive any IT security induction?
  • Is there a clear acceptable use policy covering email, devices, and remote working?

Documentation matters for two reasons. First, it shapes behaviour. Second, it demonstrates to the SRA — and to your insurer — that you take these obligations seriously. A firm that cannot produce a policy when asked is at a disadvantage, regardless of how well it actually operates.

Where Smaller Firms Typically Fall Short

Practice managers at smaller conveyancing firms tell us the same things consistently. They know something needs doing, but IT sits below a dozen other priorities until something breaks or a renewal lands on their desk. The result is a patchwork — some things handled well, others quietly ignored because no one has time to address them.

SRA compliance for law firms does not require a large in-house IT team. It requires the right processes, the right controls, and someone who keeps an eye on things systematically. That is where external managed IT support earns its place — not by doing things you cannot do, but by making sure they actually get done.

A Note on Microsoft 365 Security

Many conveyancing firms run their business on Microsoft 365, and it is genuinely a strong platform. But the default configuration is not a secure configuration. Licences that include advanced security features — conditional access policies, identity protection, email filtering — often go unused simply because no one has switched them on.

This matters for SRA compliance because email is the primary attack vector for conveyancing fraud. A single compromised account can be used to intercept completion instructions or redirect client funds. Correct Microsoft 365 configuration is not optional for a firm handling property transactions.

How to Use This Checklist

Go through it with a colleague — ideally someone outside the IT conversation, because a second perspective often surfaces assumptions the practice manager did not know they were making. Where you find gaps, prioritise by risk rather than convenience. A missing MFA policy is a higher priority than a slightly outdated data retention schedule.

If you find multiple gaps, that is not unusual for a firm your size. The point is to know where you stand so you can make informed decisions — not to feel bad about where you started.

Where Computer Care Fits In

We work with conveyancing firms across the Home Counties who want to stay SRA-compliant and operationally resilient without hiring an IT manager. Our approach starts with understanding where you are — reviewing your technology, identifying the gaps, and working with you to close them in a sensible order.

If this checklist has flagged something you are not sure how to address, we are happy to have a straightforward conversation about it. No pressure, no obligation — just a practical look at where you stand and what your options are.

If you would like to talk it through, get in touch with the Computer Care team and we can take it from there.