Legal Services
Certification audited without reading a privileged file
Information security, quality, continuity and wellbeing certification for firms, chambers and in-house teams, assessed from access logs, registers and redacted samples rather than the contents of a matter.

Explore the controls
The operational pressures the audit is read against
Your auditor works from the pressures your teams already carry, not from a blank template.
Client data of the highest sensitivity
Privilege and confidentiality obligations make information security existential.
Client security questionnaires
Corporate clients and panels increasingly require demonstrated security management.
Consistency across matters and teams
Quality varies with the individual unless process discipline supports them.
Continuity of service
Court deadlines and completions do not wait for incidents to resolve.
Field view
Walk the firm. Meet the evidence.
Scroll through a working practice, from the street to the quiet floor. Each stop is somewhere an auditor asks a firm to show its working without disclosing a client's.

Stop 01 / 04
One firm, absolute discretion
A practice trades on judgment and confidentiality. An audit here has to reach the evidence without reaching the advice, and every stop on this walk is arranged that way.
Standards that matter in legal services
Recommended by relevance to the sector's risk profile and customer requirements.
Certification services for this sector
Certification to ISO 27001, 9001, 22301 and 45003
Stage 1, Stage 2 and an independent certification decision covering the practice areas, offices and support functions inside your scope of certification.
Combined audits across the standards
Security, quality, continuity and wellbeing examined by one audit team in a single visit, so shared requirements are assessed once rather than four times.
Multi-office sampling and transfer
Sampling across offices where the system is genuinely common, and transfer of an active accredited certificate without restarting your cycle.
Pre-assessment, surveillance and training
An optional pre-assessment that reports gaps without prescribing fixes, surveillance in Years 1 and 2, recertification in Year 3, and public training courses.
How the audit runs here
Scope and duration set before the visit
Effective headcount across fee earners, support staff and contracted services, the offices in scope and the risk category fix audit time by formula, not by negotiation.
The auditor works around privilege, not through it
Access is to systems, registers, access logs and redacted or dummy examples. Where a document itself has to be seen, it is viewed with your people present, under confidentiality terms agreed before the visit.
Evidence sampled from intake to closure
A matter is selected at random and followed through conflict check, engagement terms, supervision, file review and archiving. The auditor assesses the record, never the advice.
Findings graded, decision separated
Majors, minors and opportunities for improvement are reported in writing after the visit. Someone outside the audit team takes the certification decision.
Sector evidence
Legal sector examples will appear here only where a certified organization has approved publication in writing. CORE does not publish client names, matter details or audit findings without that consent.
Legal Services questions, answered straight
Ready to certify your legal services operation?
Tell us the standards, scope, headcount and sites. You will get a clear scope statement, an audit duration set by the accreditation body's formula, and a fixed quotation.



