Client Intake Automation for Accounting and Law Firms
How small accounting, bookkeeping and law firms in the US and UK can automate client intake and onboarding: intake forms, conflict checks, engagement letters and e-signature, UK AML identity checks, secure document collection, practice-management integration and data protection.

Client intake automation for an accounting or law firm connects the steps between a prospect's first enquiry and the start of billable work: an intake form, a conflict check for law firms, identity and anti-money laundering checks where required, an engagement letter signed electronically, secure document collection, and a new client record in the practice-management system. Done well, it removes re-keying and chasing without removing the professional judgement each step needs. Done badly, it collects too much data, skips checks the firm is legally required to make, and scatters confidential documents across email and shared drives.
This guide is for small and mid-size firms in the United States and the United Kingdom. It walks through each stage, shows an example workflow, and ends with a requirements checklist you can use to brief a developer or evaluate software.
*This is general information, not legal or compliance advice. Your regulator's rules and your professional indemnity insurer's requirements take priority.*
What intake automation should and should not do
A professional-services intake is not the same as a sales lead form. The firm must decide whether it *can* act (conflicts, competence, capacity), whether it *may* act (identity and AML checks, sanctions), and on what terms (scope, fees, engagement letter). Automation helps by:
- Capturing consistent information once, in a structured format.
- Routing the matter to the right person with the facts already assembled.
- Triggering checks, documents and reminders in the correct order.
- Keeping an audit trail of who approved what and when.
Automation should not make the acceptance decision itself. A conflict search can surface possible matches, and an identity service can return a pass or refer result, but a fee earner or compliance lead should review and record the decision. Design every workflow with an explicit human approval step before the engagement letter goes out.
Intake forms: collect less, structure more
The intake form is where data protection starts. Under the UK GDPR and the EU GDPR, the data minimisation principle means collecting only what you need for a stated purpose. For a first enquiry that usually means:
- Contact details and preferred contact method.
- The type of matter or service (for example, bookkeeping, year-end accounts, tax return, employment dispute, property purchase).
- Names of other parties involved, which law firms need for conflict checks.
- Key dates, such as filing deadlines or limitation dates the prospect is aware of.
- How they heard about the firm.
Leave identity documents, bank statements and detailed case facts out of the public website form. Those belong in the secure onboarding stage after the firm has decided it can act. Warn prospects on the form not to send confidential details until the firm confirms it can help; for law firms, this also reduces the risk of receiving information from an opposing party.
Practical form choices:
- Use conditional logic so a tax prospect never sees litigation questions.
- Split party names into structured fields (individual or organisation, name, any former names) so conflict searches work.
- Record consent to marketing separately from the privacy notice acknowledgement, and never pre-tick it.
- Send submissions directly into your CRM or practice-management system rather than to a shared inbox.
The WordPress forms to HubSpot and Zoho guide shows how to connect Contact Form 7 or Elementor forms to a CRM through its API, with validation and error handling.
Conflict checks and acceptance (law firms)
Law firms must not act where there is a conflict of interest. In England and Wales, paragraph 6.2 of the SRA Code of Conduct for Solicitors prohibits acting where there is a conflict, or significant risk of one, between two or more current clients unless narrow exceptions apply with clients' informed consent given or evidenced in writing. In the US, state rules modelled on ABA Model Rule 1.7 govern conflicts with current clients, alongside rules on former clients and imputed conflicts across the firm.
An automated conflict step typically:
- 1Takes the prospect's name and every related party from the intake record.
- 2Searches current and former clients, opposing parties and related entities in the practice-management system, including fuzzy matching for spelling variations.
- 3Creates a conflict report and assigns it to the responsible fee earner.
- 4Blocks the engagement letter step until someone records "cleared", "cleared with consent" or "declined".
Accounting firms also have independence and conflict obligations under their professional bodies' ethical codes, particularly for audit and assurance work, so a simpler version of the same step is worth building for them.
Identity, KYC and AML checks for UK firms
In the UK, the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 apply to external accountants, tax advisers and insolvency practitioners, and to independent legal professionals when they participate in financial or real property transactions such as buying and selling property or businesses, managing client money, or forming and managing companies and trusts. Many solicitors' matters, especially conveyancing and corporate work, fall in scope; others, such as some litigation, may not.
Firms in scope must carry out customer due diligence (CDD): identifying and verifying the client, identifying beneficial owners of corporate clients, understanding the purpose of the relationship, and applying enhanced checks for higher-risk clients such as politically exposed persons. Supervision sits with the relevant professional body (for example, the SRA for solicitors and ICAEW for its member firms), and HMRC supervises accountancy service providers not covered by a professional body. ICAEW's anti-money laundering guidance and HMRC's registration guidance are useful starting points.
Automation fits well here:
- Send the client a secure link to an electronic identity verification service that checks a photo ID document against a live selfie and runs address, sanctions and PEP screening.
- For company clients, pull officer and persons-with-significant-control data from Companies House into the file.
- Route "refer" results and higher-risk indicators to the compliance lead for manual review and enhanced due diligence.
- Store the evidence and the risk assessment against the client record.
Retention matters. Regulation 40 requires CDD records to be kept for five years from when the firm knows, or has reasonable grounds to believe, the transaction is complete or the business relationship has ended, and then personal data obtained for those purposes must be deleted unless an exception applies. Build that deletion step into the workflow rather than relying on memory.
US firms do not have a direct equivalent of the UK regulations for most accounting and legal work, but many still verify identity to prevent fraud, and they face their own security obligations, covered below.
Engagement letters and e-signature
Once a matter is cleared and checks are complete, the system can generate the engagement letter from a template, merging client name, scope, fee basis, responsible person and terms. For solicitors, the SRA Code requires clients to receive the best possible information about how their matter will be priced and the likely overall cost; for accountants, professional bodies publish engagement letter guidance and templates.
E-signature is widely accepted for engagement letters. In the US, the federal ESIGN Act and state laws based on the Uniform Electronic Transactions Act give electronic signatures legal effect for most commercial documents. In England and Wales, electronic signatures are generally capable of being valid for documents like engagement letters. Some documents, such as certain deeds or filings, have specific execution requirements, so confirm the rules for anything beyond a standard engagement.
Useful automation around this step:
- Generate the letter only after the conflict and AML steps are marked complete.
- Send it through an e-signature platform that records an audit trail (IP address, timestamps, signer email).
- On signature, automatically file the signed PDF to the client record and move the matter to "active".
- Chase unsigned letters on a schedule, then alert a person after a set number of reminders.
The automated proposal, contract and invoice workflow guide covers the document generation and signature mechanics in more depth.
Secure document collection and practice-management integration
Email attachments are the weakest link in most firms' onboarding. A client portal or secure upload link gives clients one place to upload identity documents, prior returns, bank statements or case documents, with encryption in transit and at rest, access control and an audit log. The legal client portal guide covers portal architecture, case tracking and secure signatures for legal practices.
Tool categories to connect:
| Category | Role in intake | Examples (descriptive only) |
|---|---|---|
| Website forms | Capture enquiries | Gravity Forms, Contact Form 7, HubSpot forms |
| CRM | Track prospects and follow-up | HubSpot, Zoho CRM |
| Practice management | Clients, matters, conflicts, time and billing | Clio or PracticePanther for law; Karbon, TaxDome or Canopy for accounting |
| Identity verification | ID, sanctions and PEP checks | Electronic ID verification services approved by your supervisor or insurer |
| E-signature | Engagement letters | DocuSign, Adobe Acrobat Sign, or built-in practice-management signing |
| Document collection | Secure uploads | Practice-management client portals or a custom portal |
| Automation layer | Glue between systems | Native integrations, Zapier or Make, or custom API code |
Prefer native integrations where they exist, and use an automation platform or custom code only for gaps. Each extra system is another place client data lives, another processor agreement, and another account to secure.
Example workflow
| Step | Trigger | Automated action | Human step | Output |
|---|---|---|---|---|
| 1. Enquiry | Website form submitted | Create prospect in CRM; send acknowledgement | None | Prospect record |
| 2. Triage | New prospect | Assign by service type; create task | Fee earner reviews fit | Accept or decline |
| 3. Conflict check (law) | Triage accepted | Search parties; create report | Record decision | Conflict cleared |
| 4. Identity and AML (UK in scope) | Conflict cleared | Send ID verification link; pull Companies House data | Review refers and risk | CDD file complete |
| 5. Engagement | CDD complete | Generate letter; send for e-signature; chase | Approve letter terms | Signed engagement |
| 6. Onboarding | Letter signed | Create client and matter; open portal; request documents | None | Active matter |
| 7. Retention | Matter closed | Schedule review and deletion dates | Approve deletion | Records disposed of |
Data protection, confidentiality and retention
UK and EU. Firms are controllers under the UK GDPR or EU GDPR. You need a lawful basis for each processing purpose, a clear privacy notice at the point of collection, processor agreements with every software vendor that handles client data, and appropriate security. The ICO's UK GDPR guidance and its guidance on storage limitation explain how long personal data can be kept. Identity documents and criminal-record or sanctions information need particular care.
United States. Tax return preparers are covered by the FTC's Safeguards Rule, which requires a written information security program; the FTC's guide to the Safeguards Rule explains the elements, and IRS Publication 5708 provides a template written information security plan for tax and accounting practices. Lawyers have a professional duty of confidentiality and, under rules modelled on ABA Model Rule 1.6, a duty to make reasonable efforts to prevent unauthorised disclosure of client information. State comprehensive privacy laws such as California's CCPA/CPRA apply only to businesses meeting their thresholds, so check whether they reach your firm; state data breach notification laws apply more broadly.
Confidentiality in the stack. Choose vendors that support multi-factor authentication, role-based access and audit logs, and where client data is stored matters for both UK/EU transfer rules and client expectations. Avoid pasting client details into consumer AI tools that may retain inputs.
Retention. Set a written retention schedule by record type: AML records (five years after the relationship ends under the UK regulations), engagement letters and matter files (often based on limitation periods and insurer requirements), and unsuccessful enquiries (short, since there is no ongoing purpose). Automate reminders and deletion, and keep a log of what was destroyed.
Requirements checklist
- [ ] Intake form collects only first-stage data, with conditional logic and structured party fields.
- [ ] Privacy notice linked at collection; marketing consent separate and unticked.
- [ ] Submissions go straight into the CRM or practice-management system over an authenticated API.
- [ ] Conflict search covers clients, former clients, opposing and related parties, with recorded decisions (law firms).
- [ ] UK in-scope matters trigger identity verification, beneficial ownership checks, sanctions and PEP screening, and a risk assessment.
- [ ] Engagement letters generate only after conflict and CDD steps are complete.
- [ ] E-signature audit trail saved with the signed document.
- [ ] Documents collected through a secure portal, not email attachments.
- [ ] Processor agreements in place for every vendor; data locations documented.
- [ ] Multi-factor authentication and role-based access on every system.
- [ ] Written information security program in place (US tax preparers) and confidentiality controls documented.
- [ ] Retention schedule defined and deletion automated with human approval.
- [ ] Each stage logs who did what and when.
A well-built intake workflow saves fee earners time, improves the client's first impression and makes compliance evidence easy to produce. If you want to design or build an intake system around your forms, CRM and practice-management software, see our business consulting services or contact us to talk through your firm's process.
Related posts

Google Consent Mode v2 and Cookie Consent: A Setup Guide for Business Sites
How to set up Google Consent Mode v2 alongside a compliant cookie banner: ePrivacy and PECR consent rules, the GDPR consent standard, the four consent parameters, basic versus advanced mode, CMP requirements, WordPress and Shopify implementation, Tag Assistant testing and common mistakes.
Read article →

US State Privacy Laws for Small Business Websites: What Applies and What to Do
A practical 2026 guide to US state privacy laws for small business websites: CCPA/CPRA thresholds, the other comprehensive state laws, Texas and Nebraska small-business rules, privacy notices, opt-out of sale and sharing, Global Privacy Control, pixels, forms, vendor contracts and CAN-SPAM.
Read article →

Landing Page vs Website Guide for Small Businesses
A practical guide to choosing between a focused landing page and a full business website.
Read article →
Author
Anushka Dahanayake
Anushka Dahanayake builds SEO-focused websites, e-commerce platforms, dashboards, and automation systems for businesses worldwide.
