Any business planning for the future needs clear objectives and an understanding of the obstacles that may prevent those objectives being achieved. Rarely do those threats, or risks, stand still. Even though they may have been identified when the objectives were agreed, and even entered in a risk register, it is important to keep risks under review.
An annual risk management review is an essential part of any risk management strategy but it is often overlooked or is paid only lip service. Done well, it enables you to assess your firm’s risk profile and to benchmark whether your performance is improving or deteriorating. Identifying whether those changes are in one particular team, department or office is particularly valuable. The effectiveness of your review is dependent on performance data.
The review makes sound business sense but it is worth reflecting on the regulatory context. The SRA does not impose any specific requirements but Principle 8 requires you to run your business in accordance with sound financial and risk management principles. Drilling down into its Handbook, the guidance note to Rule 8.2 of the Authorisation Rules, says that it would expect firms to have “a system for monitoring, reviewing and managing risks.” Lexcel, the Law Society’s practice management standard, is more prescriptive, with your obligations set out in the risk management section.
Section 5.16 of Lexcel, version 6, lists 8 types of data that must be included in the review which is quite helpful as some firms struggle to see beyond claims and complaints when it comes to reviewing risk. The matters listed do, of course, include claims and complaints, plus file review data, all compliance breaches, conflict of interest data and steps taken to address all risks identified in these areas, although there is no reason why other data should not be included.
Your complaints data can provide really useful intelligence. These clients are telling you where they think you could do better. If there have been shortcomings in communication, as is often the case in relation to costs or alleged delay, this should prompt a review of how you can improve. Even if you think the complaint is misplaced, it is worth putting yourself in the client’s shoes to see whether you could do things differently in future to enhance the client experience.
If you receive complaints from clients you knew were going to be trouble from the outset, this should prompt you to tighten your client acceptance procedures. If most complaints concern your costs, but are unjustified, improve how you communicate costs information so that wriggle room is minimised.
Apart from the nature of the complaint, your data could helpfully include the cost of resolving each complaint. This will obviously be far more than any compensation paid or costs written off. Record the total time incurred in investigating and resolving complaints, not forgetting to multiply the time spent on each complaint at partners’ meetings by the number of people present.
If your time recording procedures don’t make this easy, consider a paper exercise, perhaps on a trial basis initially. If the true cost of complaints comes as a surprise, use this to help drive improved client care across the firm. Resist the temptation to see complaints as purely negative. If you can improve your service as a result, that is positive.
The same goes for claims data. Lightning will strike more than once in the same place if there are shortcomings in your procedures. Include circumstances as well as claims as, in risk management terms, the near misses that don’t turn into claims can generate information as important as the full-blown claim. They can highlight where your procedures could be improved before you receive that claim.
File review data may not be an obvious source of risk data. Whether it is will depend on the quality of your file reviews. Which office procedures are ignored or misunderstood? Is a new policy required? Is there a training need in one practice area or across the whole firm? For many firms, the process has become very mechanical. Yet your files are at the heart of your service delivery. If your file reviews are not flagging up potential risk areas, then perhaps it is time to review your procedures. Rather like tests of your business continuity plan that run like clockwork every time, there is a good chance that your question set needs refreshing to target topical risks. Insurers can be quite sanguine about firms that boast about their file reviews unless they can point to procedures that have been improved as a result.
Another item for review is your compliance data. Any area where a firm is not meeting its compliance obligations poses the risk of reputational damage. Serious non-compliance could see the firm facing a referral to the Solicitors Disciplinary Tribunal or worse, forced closure.
One unusual requirement in Lexcel is the need to review any matters notified to the COLP and COFA even if they don’t involve compliance breaches. Obviously, firms should encourage the open communication of potential compliance issues to their compliance officers, even though many of these might subsequently turn out not to involve a compliance issue. One option may be to differentiate ‘informal’ communications with COLP or COFA from the more formal ‘notifications’ which require some form of remedial action even if they fall short of a compliance failure.
Looking beyond the strict requirements in Lexcel, particularly now that the more rigorous Money Laundering Regulations 2017 are in force, firms may see considerable benefit in reviewing its anti-money laundering performance. This could be internally, in the number of suspicious notifications to the Money Laundering Reporting Officer or externally to the National Crime Agency. The SRA has real concerns that law firms are out of step with other regulated entities in the number of Suspicious Activity Reports that they make.
Another area of risk data worth exploring is the number of high risk matters handled by the firm. Many firms ask fee earners to assess a matter’s risk score as part of the client acceptance process but few track all high-risk matters being handled by the firm at any one time. Lexcel requires additional procedures for the management of high risk matters but is silent on the holistic approach required by the firm. Obviously, the more such matters a firm handles, the higher its risk profile. Accordingly, it makes sense to review this, perhaps quarterly.
Having undertaken a review, your conclusions need to be pulled together so that improvements can be made for the year ahead. With firms coming under ever increasing pressure, this can really help your firm to improve the service it provides to its clients, year on year. If you think that it is smart to save time by copying and pasting the risk data from one year to the next, in the hope of fooling a Lexcel assessor, think carefully who is fooling whom. Any corners cut in this important area put your firm at a competitive disadvantage with other more conscientious firms.
If you are clear about the risks to your objectives and take active steps to manage those risks, then achieving them becomes more realistic. In today’s ever more competitive environment, the firms that make the effort to review the risks they face will keep themselves ahead of the competition. What sort of firm are you?
For more information on this article, please contact:
Marco D’Ovidio, Associate Director, Aon UK Limited
On 0117 9485116
Whilst care has been taken in the production of this article and the information contained within it has been obtained from sources that Aon UK Limited believes to be reliable, Aon UK Limited does not warrant, represent or guarantee the accuracy, adequacy, completeness or fitness for any purpose of the article or any part of it and can accept no liability for any loss incurred in any way whatsoever by any person who may rely on it. In any case any recipient shall be entirely responsible for the use to which it puts this article.
This article has been compiled using information available to us up to 19 October 2017.