Skip to main content

Certification you can stand behind.

Legal Services

Certification audited without reading a privileged file

Information security, quality, continuity and wellbeing certification for firms, chambers and in-house teams, assessed from access logs, registers and redacted samples rather than the contents of a matter.

Quiet modern law library corridor with tall shelving and cool daylight

Explore the controls

The operational pressures the audit is read against

Your auditor works from the pressures your teams already carry, not from a blank template.

Client data of the highest sensitivity

Privilege and confidentiality obligations make information security existential.

Client security questionnaires

Corporate clients and panels increasingly require demonstrated security management.

Consistency across matters and teams

Quality varies with the individual unless process discipline supports them.

Continuity of service

Court deadlines and completions do not wait for incidents to resolve.

Field view

Walk the firm. Meet the evidence.

Scroll through a working practice, from the street to the quiet floor. Each stop is somewhere an auditor asks a firm to show its working without disclosing a client's.

Elegant law firm facade of stone and glass at blue hour

Stop 01 / 04

One firm, absolute discretion

A practice trades on judgment and confidentiality. An audit here has to reach the evidence without reaching the advice, and every stop on this walk is arranged that way.

Certification services for this sector

  • Certification to ISO 27001, 9001, 22301 and 45003

    Stage 1, Stage 2 and an independent certification decision covering the practice areas, offices and support functions inside your scope of certification.

  • Combined audits across the standards

    Security, quality, continuity and wellbeing examined by one audit team in a single visit, so shared requirements are assessed once rather than four times.

  • Multi-office sampling and transfer

    Sampling across offices where the system is genuinely common, and transfer of an active accredited certificate without restarting your cycle.

  • Pre-assessment, surveillance and training

    An optional pre-assessment that reports gaps without prescribing fixes, surveillance in Years 1 and 2, recertification in Year 3, and public training courses.

How the audit runs here

  1. Scope and duration set before the visit

    Effective headcount across fee earners, support staff and contracted services, the offices in scope and the risk category fix audit time by formula, not by negotiation.

  2. The auditor works around privilege, not through it

    Access is to systems, registers, access logs and redacted or dummy examples. Where a document itself has to be seen, it is viewed with your people present, under confidentiality terms agreed before the visit.

  3. Evidence sampled from intake to closure

    A matter is selected at random and followed through conflict check, engagement terms, supervision, file review and archiving. The auditor assesses the record, never the advice.

  4. Findings graded, decision separated

    Majors, minors and opportunities for improvement are reported in writing after the visit. Someone outside the audit team takes the certification decision.

Sector evidence

Legal sector examples will appear here only where a certified organization has approved publication in writing. CORE does not publish client names, matter details or audit findings without that consent.

How case studies work

Legal Services questions, answered straight

Ready to certify your legal services operation?

Tell us the standards, scope, headcount and sites. You will get a clear scope statement, an audit duration set by the accreditation body's formula, and a fixed quotation.