Client intake is where a firm first receives sensitive information: names, addresses, financial details, medical facts and the story behind the matter. It is also where speed matters most, because prospects often contact several firms and hire the first one that responds well. A good intake workflow is both quick and careful. A poor one relies on email attachments, sticky notes and memory.
This post describes how to design a workflow that improves the client experience and protects data from the first contact.
Map the current process
Start by writing down every step from first inquiry to opened matter. Typical stages include the first call or web form, screening, a conflicts check, a consultation, the engagement letter, payment of a retainer and creation of the matter. Note where information is stored at each stage and who touches it. Most firms find that the same details get retyped three times, and that some sit in personal inboxes.
Step 1: Capture inquiries in one place
Route web forms, phone messages and email inquiries into a single system, typically your practice-management platform's intake tool or a CRM. Avoid collecting detailed facts through a general contact form that emails to a shared inbox. If your web form collects sensitive details, make sure the site uses HTTPS, that submissions are stored in a protected system, and that your privacy notice explains what happens to the information.
Consider limiting the first form to basic contact details and a short description, then moving sensitive facts to a secure channel after screening.
Step 2: Run conflicts checks early
Before you invite substantial confidential information, check for conflicts using the data already in your system. Model Rule 1.18 addresses duties to prospective clients, and receiving information from someone who is not hired can create conflict problems. Record what you collect and limit who can see it until the check clears.
Step 3: Use secure client communication
For documents and detailed information, use a client portal or encrypted file transfer rather than regular email attachments. ABA Formal Opinion 477R describes a risk-based approach to securing communications and notes that some situations call for stronger protection than ordinary email. Explain to clients, in plain language, how to use the portal and why you prefer it.
Step 4: Streamline engagement and e-signature
Send the engagement letter electronically with a signature tool that creates an audit trail. Include the firm's communication practices, such as how you handle payment instructions and why clients should call to verify any change. Confirm the signer's identity appropriately for the matter type.
Step 5: Handle payments safely
Use a payment processor integrated with your billing system, and keep trust and operating funds properly separated according to your state's rules. Never ask clients to email credit card or bank details. When accepting retainers or settlement funds, apply a written verification procedure for any bank instructions.
Step 6: Automate the handoff
Once a matter is opened, the system should create the folder structure, assign tasks, add the right team to the matter and set up calendar deadlines automatically from templates. Automation reduces both errors and the temptation to improvise.
Step 7: Limit access and retention
- Give intake staff access to intake data, not every matter file.
- Apply role-based permissions and ethical walls where required.
- For prospects who do not become clients, set a retention rule and a process for sending a non-engagement letter and later deleting or archiving their data per your records policy.
Metrics worth tracking
- Time from inquiry to first response
- Percentage of inquiries that become matters
- Number of steps requiring manual re-entry
- Number of documents received by unsecured email
Use these numbers to improve the process over time. A faster first response often matters more than a perfect website.
Common mistakes
- Collecting sensitive documents through personal or text-message channels
- Skipping conflicts checks to move faster
- Leaving prospect data in shared inboxes indefinitely
- Giving everyone access to the intake database
- Not telling clients how the firm will and will not communicate about money
Training and review
Train front-desk and intake staff on phishing, impersonation attempts and how to handle sensitive information. Review the workflow annually, and whenever you change software.
Counsel Cyber helps firms configure practice-management and e-signature tools, secure client portals and Microsoft 365 for a smoother intake process. If you are rethinking intake, we can help you map and secure it.