The Scenario
Your firm is a consultancy, accountancy, surveying practice, or specialist services business that sends a steady stream of documents to clients. Reports, valuations, accounts, statements, certificates. Today, the vast majority go out the same way: as PDF attachments to an email, sometimes with a Mimecast secure-send wrapper, sometimes not. Your account managers do it dozens of times a week. Senior staff do it less often, but for higher-value documents.
You have a vague firm-wide policy that anything containing personal or financial data should go through secure send. In practice, what happens is whatever the sender remembers to do at the moment of sending. This is one of several recurring friction points we cover across our client management use cases.
The Problem
The specific frustration is the document you sent six months ago that the client cannot find now. They forwarded it to their solicitor, then archived their inbox, then changed laptops. They email asking for a copy. Your account manager has to find the original thread, confirm it is the latest version, and re-send it, sometimes alongside two later revisions the client did not realise existed. Version confusion is endemic. The “final” document, the “final final” document, and the “really final” document all live in the same inbox.
The risk is sharper. You do not actually know who has access to each document after it has been sent. A PDF attached to an email can be forwarded, downloaded, printed, screenshotted, and stored anywhere. If a client’s email is compromised, every document you have ever sent them is exposed. Under the UK GDPR your firm is the controller, and “we emailed it” is not a satisfying answer to a data subject access request asking where their personal data has been transmitted.
The Approach
A controlled document delivery system replaces the attachment-and-hope pattern. Documents are uploaded to a secure delivery layer, which can be part of the client portal system or a standalone delivery interface, and the client is notified with a link rather than an attachment. The client authenticates, downloads the current version, and the access is logged with timestamp, IP, and user.
Every document carries metadata: client, matter or job, document type, date issued, version. When a newer version is published, the older one is marked superseded but retained for audit. Sensitive documents can require additional verification, such as a one-time code to the client’s phone, without anyone having to remember to “use secure send.” Access can be expired, revoked, or extended. The document is delivered, but it never leaves your control. The same controlled flow is what underpins our digital contract signing workflow, where the document needs to come back as well as go out.
The delivery layer integrates with your document production tools through an API integration, so the workflow your team already follows of generating the report and exporting the PDF pushes the document into the delivery system automatically rather than landing as an attachment in an outgoing email.
The Outcome
The “can you resend the report” emails drop sharply, because the client has a permanent, authenticated place to find every document you have ever sent them. Version confusion disappears, because there is one current version with an audit trail of what came before it. Your account managers stop being human document repositories.
The risk picture improves more than the operational one. When the next data subject access request comes in, you can answer it in minutes: here is every document, here is who accessed each one and when, here is the current status of each. That logged access trail is what our audit trail and compliance systems are built to capture. When a client’s email is compromised, the documents you have sent them are not exposed, because they were never delivered as attachments. The policy that used to depend on every sender remembering to use secure send becomes the default behaviour of the system.
Who This Applies To
Professional services firms, including accountants, solicitors, surveyors, financial advisers, consultants, and healthcare providers, that send sensitive documents to clients on an ongoing basis. It is most acute for firms regulated by the SRA, FCA, ICAEW, RICS, or operating under specific GDPR sensitivity in health, finance, or legal work. Typical firm sizes are five to two hundred staff. Firms that need to grant client-side colleagues their own logins should also look at delegate access for client teams.
Take the Next Step
If your sensitive documents are travelling as email attachments, the gap between your policy and your practice is wider than it should be. We build controlled document delivery layers that fit on top of your existing document production workflow. Let us show you what one looks like in your firm’s context.