What the IAA expects to find in a client file
The Code of Standards 2024 is a specification for the client file: care letters, attendance notes, written progress, six-year retention. A checklist.
Most practices treat the client file as an archive: the place work goes once it is finished. The IAA treats it as evidence. That difference is the whole gap between an audit that takes an afternoon and one that eats a fortnight.
The Code of Standards 2024 sets out nine Principles, each supported by specific Codes. Three of those Principles are effectively a specification for what a client file must contain. Below is that specification, in the order the work actually happens.
Before the work starts
Two Codes land before any advice is given.
Code 5.3 requires that all prospective clients get an effective client care letter. Code 5.4 goes further: you must keep a record of the client's agreement to it, either as a signed and dated copy or as evidence of their electronic agreement. The record, not just the letter.
Code 5.2 covers conflicts. Where there is a real or potential conflict of interest, you explain it fully and clearly in writing, and written consent must be obtained before you act.
There is a useful detail in the Code's own introduction about how this is judged. It gives Code 5.4 as its example of a Code that can be missed without the Principle being breached: where a client is in detention and agreement cannot be obtained, the Commissioner may accept, on evidence, that the client knew what was being done on their behalf and that it was in their interest to proceed. The lesson is not that the requirement is soft. It is that evidence carries the argument when the paperwork could not.
While the case runs
Code 8.5 is the one that most files fail. You must keep a complete record of all your dealings with and on behalf of your clients, in the form of attendance notes. Every call, every meeting, every material decision.
Code 5.5 requires that each client is kept regularly informed, in writing, of the progress of their case. Note that both halves are testable: regularly, and in writing. An adviser who updates clients diligently by phone satisfies the client and fails the Code.
Code 5.6 asks for something practices rarely write down at all. You must have arrangements in place so that if you are temporarily unable to work, the client's case can still be progressed. In file terms that means the case has to be legible to a colleague who has never opened it, which is a higher bar than legible to the person who built it.
Money
Principle 9 applies to organisations that charge fees. Code 9.1 requires a fee scale and a fee that reasonably relates to the work done. Code 9.2 requires an invoice when payment is required, plus proof of payment of the sum taken. Where a client has pre-authorised card payments, Code 9.3 allows fees to be taken only seven days after the invoice was provided.
Code 9.4 is the one that divides the market: client money must be held in a distinct client account, separate from your business account, wherever you take money in advance or hold money for a client. Codes 9.5 to 9.7 govern returning what is left over and any refunds, promptly.
Worth being direct here, since we make software: ACTRA raises invoices, records payments received and keeps the client balance straight. It does not hold or reconcile client money, and we do not claim to. A practice operating a client account needs an accounting system built for that.
When the matter ends
Four Codes cover the exit, which is when disorganised files become expensive.
- Code 5.7: return all documents relating to the case when requested, without delay
- Code 5.8: provide a closure letter or statement when the case concludes, when the client withdraws instructions, or when you withdraw
- Code 5.9: transfer the file and all documents on request as soon as possible, without prejudice to the client, and irrespective of whether payment is outstanding
- Code 8.7: where you keep a client's original documents, the client must have a copy, and the originals go back as soon as they have served their purpose
Code 5.9 deserves a second read. A file cannot be held hostage over an unpaid invoice. If your only complete copy of a matter lives in a personal email account, that transfer is not something you can do quickly.
Six years, then destruction
Code 5.10 sets the retention period: keep all client files and records for at least six years, then securely destroy them.
Both halves are obligations. Six years of retention is a storage question. Secure destruction afterwards is a data protection question, and it is the half that gets forgotten, because nothing prompts it. A practice that has never deleted anything is not compliant by excess of caution; it is holding personal data with no basis for holding it.
Available on request
Code 8.6 states where the file has to be reachable from: store client records securely, ensure they are accessible to the client at any time, and available to the Commissioner upon request.
Code 8.4 says the same thing structurally. You must implement and maintain an effective file management system. Not a folder somewhere. A system.
Read alongside Code 8.3, which requires complete, clear and accurate financial records, and Code 3.5, which requires an effective written complaints procedure, the shape of an audit becomes clear. The Commissioner does not ask whether you are diligent. They ask you to produce things.
What this means for how you file
Turning the above into a file structure is mostly mechanical:
- One record per client, holding identity documents and the current picture rather than a chain of attachments
- A folder per matter, created when the matter opens so nothing is filed by improvisation
- The client care letter and its signed agreement together, not in separate systems
- Attendance notes against the matter, written as the work happens
- Outbound correspondence archived automatically, so "kept informed in writing" is provable without a search
- Invoices and recorded payments attached to the matter
- A retention clock per file, because six years counts from somewhere
Each line is a thing our own product does, and we built them in that order because the practice using it was audited on them. If you want the detail: documents and folder trees, contracts and their signing evidence, business email that files itself, and the audit trail underneath.
You do not need software to satisfy the Code. Plenty of small practices satisfy it with discipline and a good naming convention. What you cannot do is satisfy it retrospectively, which is the argument for putting the structure in before the caseload grows past the point where discipline scales.
This article summarises published requirements as general information, not legal or compliance advice. The Code of Standards itself is the authority, and it is shorter than you expect.