SRA Standards and Regulations 2019 at sra.org.uk/solicitors/standards-regulations/ replaced the SRA Handbook and set the current core rules — the SRA Code of Conduct for Firms and the SRA Code of Conduct for Solicitors govern professional obligations, including Rule 6.3 on client confidentiality and Rule 6.4 on disclosure. A WhatsApp thread that leaks matter details to a wrong contact, or a template broadcast that carries a client name to a broadcast list, is a live SRA issue with Legal Ombudsman and — for serious cases — SRA Disciplinary Tribunal exposure. The Money Laundering Regulations 2017 (SI 2017/692) at legislation.gov.uk/uksi/2017/692 apply to solicitors doing property transactions, trust and company services, tax advice, and other regulated activity. Client due diligence, PEP checks, and ongoing monitoring are required — a WhatsApp intake exchange that captures a prospective client's instructions before CDD is documented risks a first-transaction step happening on non-compliant identity evidence. The SRA has publicly warned about 'third-party interlopers' — scammers who impersonate a client or solicitor over email and WhatsApp to divert client-account money on completion. A WhatsApp instruction to change bank details for a completion payment should never be actioned without an independent verification call to a number on record — the loss on a diverted completion falls on the firm and its PII.
UK law firms meet five rulebooks the day they turn on WhatsApp: SRA Codes of Conduct, MLR 2017, Legal Services Act 2007, Legal Ombudsman, and UK GDPR.
The five rulebooks a UK law firm actually meets when it turns on WhatsApp
The day a UK solicitor's firm switches its client-intake, matter-communication, and marketing flow onto WhatsApp — via a Business Solution Provider, a practice management system integration, or an informal team WhatsApp — five separate rulebooks come into play. The SRA Standards and Regulations 2019 at sra.org.uk/solicitors/standards-regulations/ replaced the SRA Handbook and set the current professional-obligations framework, including the SRA Code of Conduct for Firms and the SRA Code of Conduct for Solicitors — Rule 6.3 confidentiality and Rule 6.4 disclosure are the two that touch every WhatsApp thread. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs, legislation.gov.uk/uksi/2017/692) apply to solicitors doing property, trust and company services, tax advice, and other regulated activity — SRA sectoral AML guidance at sra.org.uk/solicitors/guidance/aml-sectoral-guidance/ is the interpretation. The Legal Services Act 2007 (legislation.gov.uk/ukpga/2007/29) defines reserved legal activities and the regulatory architecture within which the SRA sits. The Legal Ombudsman at legalombudsman.org.uk handles consumer complaints about legal services and its guidance shapes the acceptable-service standard. And UK GDPR plus PECR, interpreted by the ICO at ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications, control client-data handling and any WhatsApp broadcast that constitutes marketing. Every section below picks one of these five threads.
Why 'HubSpot alternative' is the wrong lens for a UK law firm
HubSpot is a marketing-and-sales CRM built around lead-nurture, deal-pipeline, and email-marketing automation. Pricing scales per contact and per feature tier. For a Shopify seller, a consulting agency, or a SaaS company running lead-nurture, HubSpot is defensible.
A UK law firm does not have that shape of problem. A client is not a deal in a pipeline — they are a matter with a signed engagement letter, a documented lawful basis for processing, a due-diligence file, a client-account balance, and a fixed set of professional obligations wrapped around the retainer. The firm's day-to-day tools sit at the intersection of three categories:
A Legal Practice Management System (PMS) that holds the client, the matter, time recording, disbursements, billing, client account, and document management. UK-common: LEAP (leap.co.uk, Australian origin, huge UK footprint), Clio (clio.com, Canadian origin, strong UK), Actionstep (actionstep.com, NZ origin), PracticeEvolve (practiceevolve.com, UK), Osprey Approach (ospreyapproach.com, UK), Iken (iken.biz, UK), DPS Software (dpssoftware.co.uk, UK), Peppermint (pepperminttechnology.com, UK enterprise).
A document management system (DMS) that stores the matter file with version control, matter-based folder structure, security, and audit trail. Often the PMS's own DMS module; sometimes iManage or NetDocuments at larger firms.
A client-messaging rail that carries intake first-response, appointment scheduling, matter-status updates, and lawyer-client questions — connected to the PMS so every conversation lands on the matter file.
The realistic UK-market shortlist for the messaging rail:
PMS-native messaging where the platform includes an integrated client portal and messaging (LEAP, Clio, and others).
WhatsApp Business API BSPs as a supplementary rail: WATI, Callbell, 360dialog, Twilio — Meta-approved gateway providers on business.whatsapp.com/partners.
Legal-specific comms tools (limited UK market): most firms use the PMS-native rail plus a WhatsApp BSP where the client base prefers WhatsApp.
HubSpot's defensible role in a UK law firm stack is narrow: pre-engagement marketing (converting web enquiries into booked consultations) sitting alongside the PMS. It does not model the matter, the client account, or the SRA-record trail.
🎯 For law firms
Weekly notes on what's actually working for law firms.
After-hours intake scripts, client-portal comparisons, retainer follow-ups — no fluff.
✓ Check your inbox for the first note.
SRA Codes of Conduct, Rule 6.3 confidentiality, and the WhatsApp thread that becomes disclosable
The SRA Code of Conduct for Firms (sra.org.uk/solicitors/standards-regulations/code-conduct-firms/) and the SRA Code of Conduct for Solicitors (sra.org.uk/solicitors/standards-regulations/code-conduct-solicitors/) set the professional obligations that apply to every WhatsApp message a firm sends or receives on client matter work.
Rule 6.3 (confidentiality): 'You keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents.' A WhatsApp thread that leaks a matter fact — the name of a party, the amount of a settlement, the fact of a divorce — to a wrong contact is a Rule 6.3 breach.
Rule 6.4 (disclosure): 'Where you are acting for a client on a matter, you make the client aware of all information material to the matter of which you have knowledge...' A WhatsApp reply that summarises without disclosing a material development is a Rule 6.4 issue.
Rule 8.1 (client complaints): firms must give clients information about how and to whom to complain, including the Legal Ombudsman. A WhatsApp intake that skips this creates a Legal Ombudsman-escalation gap later.
Where WhatsApp workflows create SRA exposure:
Shared staff WhatsApp where a matter mention leaks to team members who are not on the matter file — Chinese-wall breach.
Personal WhatsApp between fee-earner and client where matter facts sit on a personal device that can be lost, seized, or subject to disclosure order in a different context.
Group chats with multiple clients on adjacent matters (property chain, adjacent divorce parties) — every message becomes disclosable to every group member.
Auto-replies that reveal case identity ('sorry, I'm out of the office — for urgent matters on the Smith divorce, contact...').
WhatsApp Web on shared reception PCs — client conversations visible to anyone at the desk.
PMS-native client portal as the default client channel; WhatsApp used only where the client explicitly prefers it and the exchange is auto-archived to the matter file.
Firm-wide WhatsApp policy that names the confidentiality obligation and the personal-device prohibition.
Matter-specific communication log in the PMS that pulls in WhatsApp exchange summaries.
Disappearing messages disabled on any firm WhatsApp Business account.
Fee-earner phone lock and remote wipe capability across every device that carries client conversations.
Legal Ombudsman signposting in every client-facing intake message.
Money Laundering Regulations 2017: what a WhatsApp client-intake exchange must and must not capture
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs, SI 2017/692, legislation.gov.uk/uksi/2017/692) apply to solicitors' firms doing regulated activity — most commonly property transactions, trust and company services, tax advice, management of client money, and certain corporate work. The SRA's AML sectoral guidance at sra.org.uk/solicitors/guidance/aml-sectoral-guidance/ is the interpretive anchor.
Core MLR 2017 requirements that hit WhatsApp intake:
Firm-wide risk assessment (Regulation 18) — the firm has a documented AML risk assessment that names WhatsApp intake as a channel and how it is controlled.
Client due diligence (CDD, Regulation 27–29) — identity verification of the client, verification of the beneficial owner if the client is not an individual, purpose-and-nature of the business relationship. Must be done before a business relationship is established or a transaction is executed.
Enhanced due diligence (EDD, Regulation 33–35) — for higher-risk clients including Politically Exposed Persons (PEPs), non-face-to-face clients (which every WhatsApp intake starts as), and clients from high-risk third countries.
Ongoing monitoring (Regulation 28(11)) — the firm keeps the CDD current and monitors the business relationship on a risk-sensitive basis.
Record-keeping (Regulation 40) — CDD records kept for five years from the end of the business relationship.
Suspicious Activity Reports (SARs) — filed with the National Crime Agency under the Proceeds of Crime Act 2002 where suspicion arises.
Where WhatsApp intake creates MLR issues:
A first-instruction message via WhatsApp acted on before CDD is documented — the firm has entered into a business relationship without the required due diligence.
Identity documents (passport photo, utility bill) sent via WhatsApp and left in the fee-earner's phone gallery rather than uploaded to the PMS AML file — a record-keeping and security failure.
WhatsApp exchanges that reveal PEP status, unusual source of funds, or third-party instruction that should have triggered EDD or a SAR but did not.
Non-face-to-face client onboarding via WhatsApp where the firm did not apply the additional EDD measures required under Regulation 33(1)(a).
Deletion of WhatsApp threads with AML-relevant content before the five-year record-keeping window expires.
Safe patterns:
WhatsApp intake as first-response only — the substantive engagement, CDD, and matter opening happen in the PMS with proper document upload and identity verification (electronic ID&V providers such as SmartSearch, Thirdfort, Credas, Amiqus are the UK-common tools).
Templated intake reply that names the CDD requirement and links to the firm's onboarding process.
PMS-integrated AML file that captures the CDD documents and the risk assessment for each matter.
Firm MLR risk assessment explicitly addresses WhatsApp intake as a non-face-to-face channel and names the compensating EDD controls.
Sole-practitioner and small-firm SRA AML thematic review findings (published at sra.org.uk) are worth reading annually for enforcement direction.
Client Account rules, third-party interlopers, and the WhatsApp payment instruction every UK firm should not act on
The SRA Accounts Rules at sra.org.uk/solicitors/standards-regulations/accounts-rules/ govern how a firm holds and handles client money. Rules on segregation, prompt banking, and prohibitions on using client money as a banking service are the framework's core.
Third-party interloper scams — the SRA has publicly warned firms about a specific fraud pattern: scammers monitor solicitor–client email or WhatsApp threads, wait for a completion or settlement moment, then impersonate the client (or the other side's solicitor) to send a last-minute bank-detail change so the completion money lands in the scammer's account instead. The loss on a diverted completion is typically borne by the firm and its Professional Indemnity Insurance.
Where WhatsApp workflows create Accounts Rules and interloper exposure:
Bank-detail changes accepted over WhatsApp without independent verification. This is the single most-warned-about pattern. The firm should have a written policy that ANY change to bank details for a client-account payment requires an independent call to a number on record (not a number in the incoming email or WhatsApp), and that the incoming instruction is treated as suspicious until verified.
Completion instructions received via WhatsApp — even from a familiar client's known number — should be verified out-of-band if they materially deviate from prior instructions.
Client-account details shared via WhatsApp for onward transmission — an interloper who intercepts these can build a plausible impersonation of the firm.
Compromised fee-earner mobile device with WhatsApp Web open on a colleague's shared PC — session hijack is a known vector.
Multi-party matters (property chain, corporate transaction) where WhatsApp instructions from one solicitor to another are treated as authenticated by the number alone — no independent verification.
Safe patterns:
Written firm policy on payment-instruction verification: every payment instruction on client account, regardless of channel, requires independent verification. WhatsApp is not treated as authenticated.
Two-person authorisation on outgoing client-account transfers above a threshold.
Client-facing warning at engagement: the firm's engagement letter explicitly warns clients that the firm will never change its bank details by email or WhatsApp, and that clients should independently verify any such instruction.
Cyber-security incident-response plan that treats any suspected interloper contact as a reportable event (SRA notification, cyber-insurance activation, potential SAR).
WhatsApp Business Platform rather than personal WhatsApp Business App — the API deployment allows better audit trail and account-security controls than a personal number does.
Professional Indemnity Insurance, the SRA Minimum Terms, and the WhatsApp advice a partner gives outside a retainer
SRA-regulated firms must hold Professional Indemnity Insurance (PII) that complies with the SRA Minimum Terms and Conditions of PII. The core requirements: sum insured of not less than £2 million any one claim for firms formed as unincorporated partnerships or sole practices, £3 million any one claim for firms with limited-liability structures; cover from a Participating Insurer; run-off cover for firms that cease to practise. Detail at sra.org.uk/solicitors/guidance/participating-insurers/.
Where WhatsApp exposes the firm's PII position:
Informal 'quick advice' via WhatsApp to a familiar contact who is not a formally-engaged client — creates a duty of care without a retainer, and PII cover on such informal advice is contested by insurers on claim.
Fee-earner advice in a personal WhatsApp thread on a matter that is not open on the firm's PMS — no matter file, no time recording, no engagement letter, no CDD; and yet the fee-earner has arguably given legal advice.
Group WhatsApp chats where a fee-earner comments on a matter that is not theirs — potential Chinese-wall breach and confidentiality issue, either of which can drive a Legal Ombudsman or SRA complaint that in turn touches PII cover.
WhatsApp response times that undermine the standard of care — a matter that requires urgent attention, dealt with on a chat thread the fee-earner has muted, can support a negligence claim.
Deleted WhatsApp threads on a matter that later becomes a claim — the firm cannot produce the record that supports its defence.
Safe patterns:
Written firm policy prohibiting substantive legal advice outside a formal retainer, and prohibiting fee-earner personal-WhatsApp use with clients.
PII insurer notified of the firm's use of WhatsApp and the compensating controls (auto-archive to PMS, no substantive advice outside retainer).
Retainer template that names the client-communication channels the firm uses and out-of-hours position.
Fee-earner conduct training at induction and annually covering WhatsApp risk, including the confidentiality and duty-of-care implications of informal contact.
The UK-market Legal Practice Management Systems that actually cover the client, matter, and billing surface
Realistic UK-market shortlist for a UK solicitors' firm (pricing to be verified on each vendor's live pricing page):
LEAP (leap.co.uk) — Australian origin, huge UK footprint particularly at high-street and mid-market firms. Client and matter management, time recording, billing, client account, document management, integrated case types (conveyancing, wills and probate, family, civil litigation) with UK-specific forms and workflows. Popular default for small-to-mid firms.
Clio (clio.com) — Canadian origin, strong UK adoption. Client and matter management, time and billing, document management, client portal with messaging. Cloud-first.
Actionstep (actionstep.com) — NZ origin, UK adoption at forward-thinking firms. Highly customisable workflow-driven PMS.
PracticeEvolve (practiceevolve.com) — UK origin. Full PMS with UK conveyancing depth, popular at mid-market firms.
Osprey Approach (ospreyapproach.com) — UK origin, cloud PMS with strong SME adoption. Includes AML, matter management, time and billing, and client account.
Iken (iken.biz) — UK origin. PMS with in-house legal team adoption alongside private practice.
DPS Software (dpssoftware.co.uk) — UK origin, long-established. Firms across conveyancing, family, and mixed practice.
Peppermint Technology (pepperminttechnology.com) — UK origin, enterprise scale. Common at larger UK firms.
Enterprise / larger-firm tier:
Aderant (aderant.com), Elite (Thomson Reuters) (elite.com), 3E — enterprise financial and matter management at magic-circle and larger commercial firms.
Document management — often bolted on separately at larger firms:
iManage (imanage.com), NetDocuments (netdocuments.com) — enterprise-grade DMS common at commercial firms.
AML electronic ID&V providers (integrated with most UK PMS):
SmartSearch (smartsearch.com), Thirdfort (thirdfort.com), Credas (credas.com), Amiqus (amiqus.co) — UK-market electronic ID and AML-verification providers.
AML integration — electronic ID&V providers integrated natively.
Client portal and messaging — matter-linked client communication with audit trail.
UK-specific matter types — conveyancing forms (TA6, TA10, HMLR forms), probate forms, family court forms.
PII data-security position — encryption, access controls, incident-response support.
UK data residency — UK GDPR position on client-file hosting.
Where a WhatsApp BSP fits at a UK law firm — and where it can't replace the PMS
A WhatsApp Business API deployment via a Business Solution Provider is a supplementary client-messaging rail. It does not replace the PMS or the DMS. Where it earns its place at a UK law firm:
Client-preferred channel: some clients will always prefer WhatsApp over a client portal or email. A WhatsApp Business API number lets the firm meet the client on their preferred channel without exposing a fee-earner's personal number.
Appointment reminders: consultation confirmations, hearing-date reminders, document-signing reminders — transactional messaging that hits WhatsApp read rates well above email.
Matter-status short updates: 'exchange confirmed', 'court date received', 'document uploaded to your portal' — pointer messages that route the client to the PMS.
AML CDD chase: 'please upload your ID via [link]' with a link into the firm's e-ID&V provider.
Fee-collection reminder: light reminder before due date, with a link into the firm's payment portal.
Legal Ombudsman signposting: intake message includes the firm's complaint route and the Legal Ombudsman contact — a Code of Conduct Rule 8.1 requirement.
BSP options with UK relevance:
WATI (wati.io), Callbell (callbell.eu), 360dialog (360dialog.com), Twilio (twilio.com), Infobip (infobip.com). Meta's official BSP directory at business.whatsapp.com/partners is the source of truth for approved providers.
What a WhatsApp BSP cannot do for a UK law firm:
Hold the matter file.
Model time recording, disbursements, or billing.
Handle client account transactions or three-way reconciliation.
Store AML CDD documents with the required security and retention.
Substantive legal advice (which needs to sit on the matter file with time recording and retainer basis).
In principle yes, but with discipline. Rule 6.3 confidentiality and Rule 6.4 disclosure of the SRA Code of Conduct for Solicitors apply to every channel including WhatsApp. Practical safeguards: use the firm's WhatsApp Business API number rather than a fee-earner's personal WhatsApp; auto-archive the exchange to the matter file in the practice management system; do not accept payment-instruction changes via WhatsApp without independent verification; disable WhatsApp's disappearing-messages feature on any firm account; and treat the WhatsApp thread as disclosable evidence in any subsequent complaint, disciplinary review, or litigation. Substantive advice sits on the matter file with time recording and a retainer basis — not on chat.
Yes — where the firm's regulated activity is engaged. For solicitors' firms doing property, trust and company services, tax advice, and other regulated activity under Regulation 12, client due diligence (Regulation 27–29) must be completed before a business relationship is established. A WhatsApp intake message is a channel of first contact — CDD (identity verification of the client and any beneficial owner, purpose and nature of the business relationship, PEP screening) must be documented before the firm acts on any instruction. Non-face-to-face onboarding (which every WhatsApp intake starts as) requires the additional EDD measures under Regulation 33(1)(a). SRA sectoral AML guidance at sra.org.uk/solicitors/guidance/aml-sectoral-guidance/ is the interpretive anchor.
A specific fraud pattern where scammers monitor solicitor–client email or WhatsApp threads, wait for a completion or settlement moment, then impersonate the client (or the other side's solicitor) to send a last-minute bank-detail change so the completion money lands in the scammer's account. The loss on a diverted completion is typically borne by the firm and its Professional Indemnity Insurance. Defence: written firm policy that ANY change to bank details for a client-account payment requires an independent call to a number on record (not a number in the incoming email or WhatsApp), and the incoming instruction is treated as suspicious until verified. The firm's engagement letter should explicitly warn clients that the firm will never change its bank details by email or WhatsApp.
Yes. The Privacy and Electronic Communications Regulations 2003 (PECR) govern electronic marketing in the UK and the ICO treats WhatsApp as electronic mail for these purposes. A broadcast to past clients promoting a new service requires either explicit prior consent or the narrow 'soft opt-in' exception — contact obtained during a similar-service engagement, marketing for the firm's own similar services, and easy opt-out at both collection and every subsequent message. A wills-only past client cannot be marketed for commercial-property work under the soft-opt-in exception without fresh consent. Maximum PECR fine: £500,000; UK GDPR-adjacent breaches can trigger the higher £17.5m or 4%-of-turnover ceiling.
The most commonly-used UK PMS platforms — LEAP, Clio, Actionstep, PracticeEvolve, Osprey Approach, Iken, DPS Software, Peppermint — support WhatsApp integration through a mix of native partnerships and third-party connectors. Underneath any of them the WhatsApp channel runs through Meta and a Business Solution Provider on Meta's official directory at business.whatsapp.com/partners — WATI, Callbell, 360dialog, Twilio, Infobip. Firms should confirm the integration auto-archives client conversations to the matter file (for SRA record-keeping), that AML electronic ID&V providers (SmartSearch, Thirdfort, Credas, Amiqus) can be triggered from the WhatsApp flow, and that UK data-residency is met.
⚖️
BossBot product
BossBot for Law Firms & Solicitors
Product page with honest feature list, "not for you if" filter, and live demo for this vertical.
Hi, I need advice on a contract dispute with a supplier. They haven't paid an invoice for 3 months
Hi! We handle commercial contract disputes regularly — this sounds like something we can help with. Would you like to book a free 15-minute initial call?
Yes please. Do you work on a no-win-no-fee basis?
For debt recovery cases we do offer conditional fee arrangements. Book a call and our solicitor will assess your case. What day suits you?
Tuesday or Wednesday morning would work
Tuesday 10am is available ✅ I'll confirm your slot — can I take your name and a brief summary of the contract value?
Set up in under an hour. 7-day free trial, no credit card required. Automate client-intake first-response, appointment reminders, and CDD chase alongside your practice management system.