Law firms

How Should a Law Firm Collect a Client's ID and Documents?

Not by email or WhatsApp. A client's ID is confidential from the first exchange, and for regulated due diligence an unverified emailed photo doesn't meet the standard. Collect onboarding documents through a secure, encrypted link, isolated per matter, then run your identity verification and keep the records you're required to keep.

Not by email or a messaging app. For a law firm, a client's ID and onboarding documents are confidential from the first exchange, and for regulated client due diligence an unverified emailed photo doesn't meet the standard and leaves a copy in your inbox you're then responsible for. Collect onboarding documents through a secure, encrypted link, kept separate for each matter, then run whatever identity verification your rules require and keep the records you're obliged to keep. Collecting the document and verifying the person are two different steps.

One note before the how-to: the documents a matter actually requires, and how long you keep them, depend on your jurisdiction's anti-money-laundering rules and your professional regulator. Build the list from the official, current source. This guide is about how to collect and organize, not which documents any particular matter legally requires.

Why an emailed passport is the wrong start

Asking a client to photograph their passport and email it fails on two counts. It's insecure: a government ID now sits in the client's sent folder, your inbox, and both providers' backups, with no expiry and no record of who opened it. And for regulated due diligence it doesn't count. A photo a client sends in, with nothing to independently confirm it, isn't remote identification, so onboarding that starts in an inbox creates a compliance gap you'll have to close later anyway (JAM Virtual Support, ACCA client due diligence factsheet).

The wider risk is what stored copies become. In September 2026, a KYC vendor was found to have leaked scans of more than 153 million driver's licenses it had collected over years (KrebsOnSecurity). A firm's inbox full of client passports is a smaller version of the same target. The fix is to collect through a channel built for it, and to hold only what you're required to hold.

Collecting is not verifying

This is the distinction that keeps onboarding both compliant and honest. Three separate jobs sit inside "get the client's ID," and it helps to name them:

StepWhat it isWhere a secure link fits
CollectGet the ID and onboarding documents from the client, privatelyThis is the part a secure, encrypted intake link solves
VerifyConfirm the person is who the document says (certified copy, video, or an ID-verification service)Separate step. You run your own check on the clean file
RetainKeep the due diligence record for the period your rules requireSeparate step. Store the record per your AML duty

A tool that collects the document securely is not doing your verification, and it shouldn't claim to. What it does is get you a clean, legible file to run that check against, instead of a photo buried in an email thread.

How to collect onboarding documents securely

  1. Start from your own due diligence list. Build the document list from your regulator's current requirements, not from a blog. For an individual that's usually a current government photo ID and proof of address; for a company, the register check and IDs for directors and beneficial owners.
  2. Stop the emailed or messaged photo. Don't let onboarding begin in an inbox or a chat. It's insecure, and for regulated due diligence an unverified photo doesn't count as identification.
  3. Send one secure intake link per client or matter. A branded page, no account for the client to create, collecting exactly the documents on your list, isolated from every other matter.
  4. Verify separately. Run your certified-copy, video, or electronic ID check on the documents you received. Collection got them to you safely; verification confirms the person.
  5. Retain what you're required to keep. Store the due diligence record for the required period. Apply expiry or deletion only to what you're not obliged to keep, like the collection link itself.
  6. Keep the audit trail. Log what was collected, when, and from whom, so you can show how onboarding was handled if a regulator or the client ever asks.

How long to keep it

Due diligence records, including a client's ID, are generally kept for at least five years from the end of the business relationship (anti-money-laundering.eu). This is where a firm's instincts and a privacy tool can pull in opposite directions: you can't simply auto-delete a record you're legally required to retain. So keep the statutory record deliberately, and reserve expiry for the transient intake link and for anything you collected but aren't required to hold.

Regional note: the UK, EU (AMLD), and US (BSA) all land near a five-year retention period, and some jurisdictions require longer. Confirm the current rule and your regulator's requirements yourself rather than relying on this page.

Where doconvoy fits

For the collection step, doconvoy replaces "email me a photo of your passport" with a secure request. The client opens a branded link, the documents are encrypted in their browser so the provider only ever holds ciphertext it can't read, each matter stays isolated, and the exchange is logged. Because the intake tool can't read the files, it respects the confidentiality and privilege duty you owe from the first exchange. What doconvoy is not: an identity-verification engine, or your record-keeping system. You still run your own verification and retain the record for the required period. Think of it as the encrypted front door to your onboarding, not the checks behind it.

Send clients an encrypted intake link for their ID and onboarding documents, isolated per matter, instead of email.

Collect client documents securely

Related: Collect identity documents securely · Collecting a client's passport and ID · How encryption works · Is it safe to send your passport over email or WhatsApp? · How to collect documents from clients without email attachments

Common questions

Is emailing a passport copy enough for client due diligence?

No. An unverified photo a client emails in isn't remote identification, and most guidance treats it as a compliance gap rather than acceptable due diligence. It also leaves a copy of a government ID sitting in your inbox and sent folder. Collect the document securely, then verify identity as a separate step.

Does a secure upload link satisfy KYC or AML verification?

No, and it's important to be clear about this. A secure link fixes the collection step, so the ID reaches you privately instead of by email. It does not verify that the person is who the document says. Verification is a separate step: certified copies, a video ID check, or an electronic ID-verification service. Collect securely, then verify.

How long should a law firm keep a client's ID?

Client due diligence records, including ID, are usually kept for at least five years from the end of the business relationship, and many firms keep them longer to cover negligence-claim limitation periods. The exact period depends on your jurisdiction, so confirm it against your regulator's current rules. Keep the record you're required to keep; only the transient collection link should expire.

What's the safest way to ask a client for their ID?

Send one secure, encrypted intake link per client or matter, collecting exactly the onboarding documents on your list, isolated from every other client. Then run your verification on the clean files and retain the record for the required period. No inbox, no messaging app, no shared folder.