Immutis/Blog/CQS requirements for conveyancers: what the Conveyancing Quality Scheme asks of your firm
CQS & regulatory compliance

CQS requirements for conveyancers: what the Conveyancing Quality Scheme asks of your firm

CQS requirements for conveyancers: what the Law Society's Conveyancing Quality Scheme asks of your firm, from identity checks to fraud prevention controls.

Immutis Research··8 min read

The Conveyancing Quality Scheme, better known as CQS, is the Law Society's accreditation standard for residential conveyancing practices in England and Wales. It is how the market recognises a firm that runs conveyancing to a defined standard, and how many firms structure risk management across every matter.

This guide explains what CQS requirements ask of your firm, where fraud prevention and payment diversion controls fit inside the scheme, and what counts as evidence that you have a control in place. It is written for conveyancers and compliance officers, so the focus is practical throughout.

What is CQS, and who is it for?

CQS is the Law Society's accreditation scheme for residential conveyancing. Firms that hold the mark have been assessed against a defined set of requirements and have committed to maintaining them year after year. Law Society CQS accreditation is not a badge you buy once. It is a standing commitment that is reviewed and audited, so firms have to keep meeting the standard to keep the logo.

In practice, three groups of firms value it most:

  • Residential conveyancing practices of any size that want to signal quality to lenders and clients
  • Firms that take lender panel instructions, where holding CQS is often expected
  • Teams working towards a more structured, consistent way of running conveyancing work

The scheme is built on a CQS Code of Conduct and a set of mandatory requirements. Accredited firms commit to both, and the requirements cover the areas where conveyancing risk concentrates: client identity, money-laundering controls, staff competence and training, supervision of files, complaints handling, and risk assessment. The rest of this guide works through what each of those means on the ground.

What does CQS accreditation ask of your firm?

Nothing in the scheme is exotic. The requirements are the basics of well-run conveyancing, written down and applied consistently. The following is the shape of the obligations. Firms should rely on the current CQS materials from the Law Society for precise wording, because the detail changes over time.

Client identity verification

The firm must have a clear, documented process for verifying who its clients are. That means checking identity documents, confirming who sits behind the transaction, and keeping a record of what was checked and when. Identity verification is a cornerstone of the scheme because so much else depends on knowing who you are dealing with.

Anti-money-laundering controls

Firms must have controls in place that meet their obligations under UK money-laundering law. In practice: a written risk assessment, customer due diligence, source-of-funds checks, ongoing monitoring, and a nominated officer with a clear reporting route for suspicious activity. The controls have to be applied consistently, not improvised matter by matter, and the records have to survive an audit.

Staff competence and training

The firm must be able to show that fee earners are competent to run the work they handle and that training happens on a regular schedule. New starters, changes to the rules, and new risks all need to find their way into training records. A firm that cannot evidence its training cannot evidence its competence.

Supervision of files

Conveyancing files need active supervision, not occasional review. The expectation is that matters are checked at defined points in the transaction, that the checks are recorded, and that junior staff are not left to run completion work without oversight. A named supervisor and a recorded review point on each file is the standard shape.

Complaints handling

The firm needs a complaints process that clients can find and use, and that the firm follows. Records of complaints, responses, and outcomes should be kept. Regulators and auditors treat complaints as a signal of how the firm manages quality, so the trail matters as much as the process.

Risk assessment

The firm must maintain a risk assessment that covers the risks of its work and the controls it relies on. It should be reviewed regularly and updated when the risk profile changes. This is the document that ties the other requirements together, because it is where the firm names its exposure and its mitigations, including the fraud risks that sit over every completion.

Why do fraud prevention and payment diversion controls belong inside CQS?

The requirements exist because the risks they address are real, and none is more acute in modern conveyancing than fraud. Payment diversion is the clearest example. It works by changing bank details somewhere in the transaction chain, it is hard to spot from inside the matter, and it lands at completion, when the largest sums move.

CQS expects firms to have adequate systems and controls in place for the risks they face. That wording matters. It does not ask for a policy named "fraud prevention" gathering dust in a handbook. It asks for controls that are proportionate to the risk and that are applied. A firm that verifies the receiving account before completion funds move, records the check, and can evidence it has a control. A firm that "normally checks" but cannot show it does not.

The same logic runs through the SRA. Separate from CQS, the SRA requires firms to have adequate systems and controls in place to protect client money and to comply with the SRA Accounts Rules and the SRA Standards and Regulations. Protecting client money is not only about holding it in the right account. It includes making sure it goes to the right account. Verification of receiving details before money moves is precisely the kind of control the language of "systems and controls" points at.

So the argument is straightforward. Fraud prevention controls are a recognised part of a compliant practice. They support CQS because they answer a named risk in the risk assessment, and they support SRA compliance because they protect client money. A firm that treats verification as a control, rather than a hope, has a stronger answer to both.

What counts as evidence of a control under CQS?

This is the question that separates a firm with a policy from a firm with a control. CQS accreditation is reviewed and audited, which means at some point someone will ask you to show the work. A policy document describes what you intend to do. Evidence shows what you did.

For a fraud prevention control, the evidence needs three properties:

  1. Documented. The record says what was checked, when, and how. Nobody has to rely on memory.
  2. Timestamped. The record proves the check happened at the relevant time, not reconstructed after the event.
  3. Independently verifiable. A lender, an insurer, or an auditor can confirm the record is genuine and unaltered, without taking the firm's word for it.

A control that meets these three tests is defensible at a CQS compliance review. A control that does not is difficult to evidence, and harder still to rely on when something goes wrong.

How does a signed verification report support audit and professional indemnity?

A signed verification report is a practical way to satisfy the evidence test for payment diversion and identity controls.

The report records exactly what was checked on a matter: the receiving account, the documents behind the money, the identity checks, and the confirmation itself. It is timestamped at the point the checks ran, and it carries a signature that lets anyone verify the report is genuine against a published signing key. Because verification runs against an independent record, anyone can check the report is authentic.

That has two consequences in practice.

First, audit. When the CQS review comes around, the firm can point to matter files that contain a verifiable artefact for every completion. The reviewer does not have to take the firm's word that the checks happened. The evidence is on the file, and it is independently checkable.

Second, professional indemnity. If a claim follows a transaction, the matter file becomes the record of what happened. A firm that can show a signed, timestamped, independently verifiable report of its checks is in a much stronger position than a firm that can only say "we normally check". The report does not claim nothing can go wrong. It records that the control was run. In a dispute, that distinction is decisive.

What should your conveyancing quality scheme checklist include?

The CQS requirements above reduce to a checklist that a compliance officer doing CQS compliance work for a conveyancing practice can run in an afternoon:

  • Do you have a written, current risk assessment that names fraud and payment diversion?
  • Is client identity verification documented and applied consistently across matters?
  • Are AML checks, source-of-funds checks, and ongoing monitoring recorded?
  • Are training records up to date for every fee earner who handles conveyancing?
  • Do files have recorded supervision at defined points?
  • Is your complaints process easy to find, followed in practice, and evidenced?
  • Do you have a named control for verifying the receiving account before completion funds move?
  • Does that control produce a documented, timestamped, independently verifiable record?
  • Can you show an auditor an example matter file that contains that record?

Work through the list and the firm has a coherent answer to what CQS asks of it. Leave the last three questions off and the firm has a policy, not a control.

What does the SRA require alongside CQS?

One more note, because for most conveyancing firms the SRA sits alongside CQS rather than in place of it. The SRA requires firms to have adequate systems and controls in place to protect client money and to comply with its accounts rules and the SRA Standards and Regulations. That is a standing requirement, not a new one.

The practical overlap is where fraud prevention lives. Protecting client money includes making sure it reaches the account it is meant to reach. Verification of receiving details, confirmation of any change, and a recorded trail are exactly the kind of control the SRA's systems and controls requirement is after. It is diligence, applied at the point where the money moves.

How do you meet CQS requirements without adding more manual work?

The honest problem with any compliance requirement is that it adds to an already busy matter flow. The answer is to make the control part of the workflow rather than an extra step for fee earners to remember.

The firms that evidence their controls best do not rely on memory. They build the control into the process so it runs for every matter, and they keep the artefact automatically. That is the difference between compliance on paper and compliance on the file.

Immutis runs the checks for you, produces one signed verification report per matter, and gives you a public verify link that anyone can check against the published signing key. Run it on a single matter or every matter, and the report sits on the file ready for your CQS review, your lender, and your insurer. To be clear about the limits: Immutis does not make your firm CQS compliant. Only the firm can do that. What Immutis does is document the fraud-prevention control, which is the part most firms struggle to evidence.

Read our guide to payment diversion fraud in conveyancing and how to stop it.

CQSconveyancing quality schemeLaw SocietySRA complianceanti-money-laundering