Lexcel Renewal IT Gaps

Most law firms treat Lexcel renewal as a case management and file-handling exercise. It often receives only a passing mention in policy documents that Lexcel has not been updated in two years.

That’s a mistake.

Lexcel v6.1 explicitly requires evidence of information security and risk management.

Assessors want to see it working, not just written down; our IT support for solicitors page covers this standard.

Here’s where firms most commonly fall short.

๐Ÿ”‘ 1. Access Control Reviews Exist on Paper, Not in Practice

Lexcel expects a documented process for reviewing who has access to what, and evidence that the review actually happens.

Having an access control policy is not the same as a log.

That log shows you checked it in the last 12 months.

What assessors want to see: a dated record of the last access review, who conducted it, and what changed as a result. This is exactly the kind of gap our managed security and network reliability services are built to close before it becomes a renewal problem.

๐Ÿ’พ 2. Backup Testing Is Assumed, Not Verified

Almost every firm has backups. Far fewer have proof that a restore actually works. “Backup completed successfully” in a system log is not the same as evidence of a tested, working restore process.

What assessors want to see: a record of an actual restore test, with a date and outcome.

๐Ÿšช 3. Leaver Access Isn’t Closed Down Fast Enough

This is the most common gap we see. It is the easiest to fix. Offboarding isn’t tied to a hard deadline, and a staff member’s system access can stay active for weeks. Lexcel guidance emphasises timely offboarding.

What assessors want to see: a leaver checklist with access revocation as a same-day or next-day step, not a “when we get to it” task.

โš ๏ธ Why This Matters Beyond the Audit

These aren’t just box-ticking issues. Each one is a real risk:

  • Stale access control means former employees or ex-staff retain routes into client data
  • Untested backups mean you find out they don’t work during an actual incident, not before
  • Delayed leaver offboarding is one of the most common causes of data breaches in professional services

None of these require expensive tooling. They require a documented process someone actually follows.

๐Ÿ”— The DSPT Parallel

This overlap isn’t a coincidence. Moreover, the Data Security and Protection Toolkit assesses care and health providers. Lexcel shows a similar expectation of security discipline, and we apply it across every regulated business we support.

If your practice can’t produce this evidence today, you’re not alone. It’s the single biggest reason Lexcel renewals turn stressful in the final weeks.

โœ… Get Ahead of It

We run a free 20-minute IT review for firms heading into Lexcel renewal. Additionally, you will walk away knowing exactly where your access control, backup, and offboarding processes stand against assessor expectations. Before renewal season, full details on what our free cybersecurity and network audit covers are on our homepage.

Book your free review


GuardIQ works with regulated businesses across NW London, including legal practices and care providers, on IT compliance and security aligned to sector-specific standards.