Compliance

CICC Compliance & Inspection Guide for Immigration Lawyers and RCICs

What inspectors look for, what records you need, and how to be audit-ready at all times — not just when the notice arrives.

The College of Immigration and Citizenship Consultants (CICC) has the authority to inspect any licensed RCIC's practice at any time. Immigration lawyers face similar oversight from their provincial law societies. These inspections are not hypothetical — they happen, and the consequences of non-compliance range from remedial orders to licence suspension.

This guide covers what inspectors look for, what records you need to produce, and how to structure your practice so compliance is built in — not bolted on.

What triggers an inspection?

CICC inspections can be triggered by:

  • Client complaints — the most common trigger. A dissatisfied client contacts the CICC directly.
  • Random audits — the CICC conducts routine compliance reviews of randomly selected licensees.
  • Referrals — from IRCC, law enforcement, or other regulatory bodies.
  • Renewal reviews — compliance checks during licence renewal.
  • Pattern detection — unusual application volumes, refusal rates, or complaint patterns.

What inspectors look for

Whether you are an RCIC or an immigration lawyer, inspectors assess the same core areas:

1. Client file completeness

Every client file must contain a complete record of the engagement: signed retainer agreement, all communications, documents submitted, IRCC correspondence, and case notes. Inspectors check whether files are organized, accessible, and complete — not scattered across email, spreadsheets, and shared drives.

2. Retainer agreements

The CICC requires signed retainer agreements before work begins. These must include specific sections: scope of services, fee structure, complaint process, and more. Inspectors verify that retainers exist for every client and contain all required elements.

3. Communication records

A chronological record of all client interactions — phone calls, emails, messages, meetings — with timestamps and content. The standard is not “you communicated” but “you can prove you communicated, when, and what was said.”

4. Financial records

Fee disclosure, invoices, payment records, and trust accounting (where applicable). Inspectors check that fees match what was agreed in the retainer and that billing is transparent.

5. Data protection

How do you store and protect client data? Inspectors increasingly ask about digital security: encryption, access controls, and data handling practices. PIPEDA compliance is not optional.

Common compliance issues

  • Missing retainer agreements — work started before the retainer was signed, or the retainer is missing required sections.
  • Incomplete communication logs — phone calls not documented, emails not saved to client files.
  • Disorganized files — documents scattered across personal email, Google Drive, and paper folders with no central system.
  • No audit trail — no way to prove who accessed what data, when, and what changes were made.
  • Inadequate data protection — client PII stored in unencrypted spreadsheets or shared inboxes.

How to be inspection-ready at all times

The firms that pass inspections easily are not the ones that scramble when the notice arrives. They are the ones whose daily workflow produces compliant records as a byproduct. Here is what that looks like:

  • Centralized case management — every client, case, document, and communication in one system. No data in personal inboxes or local drives.
  • Automatic audit trail — every action logged with timestamps and user attribution, immutable and exportable.
  • Template-based retainers — CICC-compliant templates that ensure every required section is included, every time.
  • Timeline-logged communications — calls, emails, and messages automatically recorded on the case timeline.
  • Role-based access — team members see only what they need. Audit-ready access controls.
  • Client-side encryption — sensitive identifiers protected at the application level, not just at rest.

Immigration lawyers vs. RCICs: different regulators, same principles

Immigration lawyers are regulated by their provincial law society, not the CICC. But the compliance principles are the same: complete records, proper agreements, documented communications, and data protection. The tools that keep an RCIC inspection-ready work equally well for a lawyer facing a law society audit.

Built for compliance from day one

Immicase produces audit-ready records as part of your daily workflow. CICC-compliant retainers, immutable audit trail, timeline-logged communications, and role-based access — all in one platform.

Compliance built into your workflow

Every action logged. Every document tracked. Every retainer template-based. Be inspection-ready every day — not just when the notice arrives.

No credit card required · Full access for 14 days · Cancel anytime