How a FirmGuard check maps to the Legal Sector Affinity Group guidance (April 2025)
The LSAG guidance is the document your AML policy answers to. Its own compliance principles ask you to document any electronic ID&V tool you use — its role, its data sources, and when you use it (Technology PCPs; §7).
This page is that documentation for FirmGuard: what each check does, section by section — and, just as importantly, what remains your firm's own judgement.
| LSAG (Part 1) | What a FirmGuard check gives you | What stays with your firm |
|---|---|---|
| §6.12–6.14 Identification & verification; methods |
Verification "on the basis of documents or information … from a reliable source, independent of the client" (§6.14): the client's identity document, captured and checked from their own phone, bound to them by a biometric face match. On iPhone the passport's NFC chip is read directly — the issuing state's own cryptographic signature, the strongest independent source available for the document itself. | The risk-based judgement (§6.13) on the level of verification each client and matter requires. |
| §6.14.3 Electronic verification (EID&V) |
The guidance's test for an EID&V tool: secure from fraud and misuse, appropriate assurance that the person claiming an identity is that person. Chip signature + biometric binding answers both limbs, and every check records how it verified — evidence of the tool's role and data sources, as the Technology PCPs (§7) expect. | Documenting in your PCPs the circumstances in which you use the tool — this page is built to be filed for exactly that. |
| §6.15–6.16 Beneficial owners |
For company clients: the ownership chain traversed from the Companies House register, each natural-person owner identified and individually screened, recorded per person. Discrepancies surface for your reporting judgement. | §6.14.1 is clear the CH register cannot be solely relied on to verify a beneficial owner (reg 28(9)) — verifying each BO to the standard your risk assessment requires remains your call; a FirmGuard check can be sent to any BO to do it. |
| §6.18–6.19 Enhanced due diligence & PEPs |
Every check screens against PEP data; a match forces a named decision — your MLRO records proceed or decline, with reasons, dated and attributed. The system never decides for you; it makes your decision inspectable. | The EDD measures themselves, senior-management approval, and the §6.19 judgement on what a client's PEP status means for this matter. |
| §6.25 Sanctions |
Screening at check time against OFSI/UN/OFAC/FCDO data refreshed daily; the result — and the date of the lists it ran against — recorded in the audit pack. | Freezing and reporting obligations if a true match arises. |
| §6.21 Ongoing monitoring |
Completed clients are re-screened as the lists update; changes alert your MLRO by email — monitoring that actually runs, not a policy sentence. | Re-applying CDD on new instructions or changed risk (your PCPs' trigger list). |
| §6.22, §10 Records & data protection |
Every check produces a dated audit pack — what was checked, how, the evidence, the verdict, who decided what — retained five years in tamper-evident storage, GDPR-compliant. When your supervisor asks for the client file, it exists. | Your matter files, and your record-keeping PCPs. |
What we don't claim: FirmGuard is not your practice-wide risk assessment, your PCPs, or your MLRO — the guidance places those with you (§§3–5). FirmGuard is the evidence layer underneath them. Where your firm's own policy specifies additional data sources beyond document-and-biometric verification, your policy governs — §6.14 lists several acceptable routes, and yours is the judgement on which to use. FirmGuard is independent: not affiliated with, or endorsed by, LSAG, the SRA or the Law Society.
Hold your own audit pack in five minutes.
The fastest way to judge a check is to run one on yourself — the driving licence in your wallet is enough. First month free, 50 checks, no card.
Start free — 50 checks on us