An SRA inspection tests whether supervision is real, not whether a firm has a policy that says it happens. Inspectors are trained to look past the document sitting in a compliance folder and ask a narrower question: on this file, on this date, who gave the instruction, who reviewed the output, and who signed off before it went anywhere near a client or the court. That is the practical test behind an SRA inspection: a firm that can answer it in thirty seconds, for any matter an inspector picks at random, is in a completely different position from one that has to reconstruct the answer after the fact.
What documentation actually demonstrates supervision?
An SRA inspection generally comes down to three things: the written instruction given for a specific task, a record of review and sign-off before the work left the firm, and a clear line showing which authorised individual held responsibility for that matter at the time, consistent with the SRA Code of Conduct for Firms. None of this needs to be elaborate. A dated instruction, a reviewed draft with tracked changes or comments, and a final sign-off recorded somewhere searchable is usually enough, provided it exists for every matter rather than a sample of them.
The detail that trips firms up is consistency. A beautifully documented file sitting next to three others with nothing recorded doesn’t read as diligence, it reads as evidence that the process is optional. Inspectors notice the gaps more than they notice the good examples, which is exactly backwards from how most firms prepare.
Why is a policy document alone not enough?
A policy describes intent. Task-level records of instruction and review demonstrate that the intent was actually carried out on real matters, the same standard set out in the COLP checklist article. Regulators have seen enough well-written policies attached to poorly supervised files to treat the policy itself as close to irrelevant during an inspection. What they want is the evidence trail underneath it.
This matters more, not less, once part of the work is delegated externally, since an SRA inspection will look at delegated files just as closely as anything handled in-house. The Court of Appeal’s ruling on delegated litigation tasks confirmed that an unauthorised person can carry out conduct-of-litigation work on behalf of an authorised individual who retains responsibility, but that protection only holds if the retained responsibility is demonstrable. A firm relying on outsourced capacity without a documented instruction-and-review trail is relying on an argument it cannot actually prove.
What should be built into a working process from day one?
A simple, consistent record of instructions given and work reviewed, so the evidence exists as a by-product of normal working rather than something reconstructed after the fact, exactly as structured on the How It Works page. The point of building it into the workflow itself, rather than treating it as a separate compliance step, is that it survives staff turnover, busy weeks, and the natural tendency to skip paperwork under deadline pressure.
Case management systems make most of this straightforward. A task assigned with a note, a document returned with the reviewer’s initials and date, and a status change to “approved” or “filed” creates a timestamped trail without anyone having to think about compliance while they work. The firms that struggle at inspection are usually the ones trying to layer this on afterwards rather than building it into the tools they already use.
What does an inspector actually look for when outsourced work is involved?
Largely the same things as with any delegated task, with one addition: proof that the firm, not the provider, directed and approved the work. That means the instruction should originate from the firm’s fee earner, not simply be a forwarded brief from the provider, and the sign-off should show a named individual at the firm reviewing the specific output before it was used.
An inspector who sees this structure holding up consistently across several outsourced matters generally treats it as a well-run arrangement rather than a risk area. The dedicated-team structure that avoids conflicts by design tends to reinforce this impression, since it shows the arrangement was set up with regulatory exposure in mind rather than bolted on.
How does this connect to the COLP’s personal accountability?
The COLP carries personal responsibility for the firm’s compliance arrangements, which means the documentation trail isn’t just useful during an inspection, it’s what the COLP would rely on if asked to account for a specific matter months later. A COLP who can point to a consistent instruction-and-review record across outsourced work is in a far stronger position than one relying on a general assurance that “the process works.”
This is also where the written engagement terms matter. A properly drafted arrangement sets out data handling, confidentiality, and the supervision structure clearly enough that the COLP can rely on it as part of the evidence base, rather than having to take it on trust from the provider.
What happens if the documentation trail has gaps?
Gaps don’t automatically mean a finding against the firm, but they shift the burden. Without a record, the firm is asking the inspector to accept that supervision happened on the strength of reputation rather than evidence, which is a weaker position than most firms realise until they’re in the room being asked the question directly.
The fix is rarely complicated. Most gaps come from informal instructions, an email exchange with no formal sign-off, or work reviewed verbally with nothing written down. Closing that gap is usually a matter of adjusting habits rather than adding new systems, particularly once the record-keeping is built into the workflow rather than treated as an extra step.
How does this fit alongside a firm’s existing file-management workflow?
Most firms already have the raw material for this trail sitting inside their case management system; the gap is usually that it isn’t being captured consistently for delegated work specifically. A firm using Clio, LEAP, Osprey, or Actionstep can typically build the instruction-and-review record directly into task assignment and document approval, so nothing extra is bolted on top of how the team already works.
Where firms get this right, the record-keeping becomes almost invisible day to day, and only becomes visible again the moment it’s actually needed, whether that’s an inspection, an internal query, or a complaint that needs tracing back to who did what and when. That’s the standard worth building toward from the outset, covered in more depth in the first 30 days of an outsourcing engagement, rather than retrofitted once an inspection date is already on the calendar.
What should a firm ask a provider about their own record-keeping?
The same discipline that satisfies an SRA inspection is worth asking of a provider directly: whether they maintain their own internal log of instructions received and work delivered, separate from whatever the firm records on its own systems. A provider that can produce this independently, matter by matter, gives the firm a second, corroborating source if the primary record ever has a gap. This is one of several questions worth working through before instructing any outsourced provider, alongside confidentiality terms and how conflicts are avoided structurally rather than by policy alone, addressed in the article on client confidentiality when work is delegated externally.
Firms that ask this question early tend to find out quickly whether a provider takes supervision seriously as a shared responsibility, or treats it as something the firm alone has to manage. That distinction is usually visible well before the first file moves, and it’s a reasonable basis for comparing options against the published packages and what each one actually includes.
Preparing for an SRA inspection or internal audit?
We’ll assign a dedicated paralegal to your matter for 7 days, no charge, so you can see exactly what our engagements document, and how, before deciding anything.
Confidential · No obligation · Typically a 20-minute call
Frequently Asked Questions
What records should a firm keep for every outsourced task?
The written instruction given, the reviewed output, and confirmation of who signed off before the work was relied on or sent externally.
Is a general outsourcing policy enough to satisfy an SRA inspection?
Not on its own. Task-level evidence of instruction and review is what demonstrates the policy was actually followed on real matters.
Who is responsible for maintaining these records, the firm or the provider?
Primarily the instructing firm, though a well-run provider’s own process should support and evidence the same trail.
Does this documentation requirement change if the outsourced provider is based outside the UK?
The core requirement doesn’t change. The firm’s own instruction-and-review trail is what matters for supervision; the international transfer mechanism is a separate, additional requirement covered under data processing terms.


