You may recall an excitable period last summer where we were promised a “clearer and more proportionate anti-money laundering (AML) regime”, when the government recognised that AML checks were seen as a major burden to law firms? 

Well, those changes, following the government’s consultation last September, are about to come into force (expected by the end of June).  Sadly, they are not as ground-breaking as perhaps some may have hoped. Indeed, the more cynical amongst us may feel they have done the opposite of the stated aim of reducing “unnecessary regulatory burdens” and enhancing the “effectiveness of the UK’s AML framework”. However, we will leave that for you to decide 😉.

 

What are the main changes which will impact law firms?

High-risk third countries

Regulation 33 previously stated that Enhanced Due Diligence (EDD) must be carried out where clients are established in a ‘high-risk third country (HRTC)’, which was defined as a country on either of the FATF lists, known as the ‘black’ (or ‘Call for Action’) list and the ‘grey’ (or ‘jurisdictions under increased monitoring’) list.  The ‘high-risk third country’ definition is going, to be replaced by ‘FATF call for action country’.  What this means in practice is that the mandatory EDD requirements (Reg 33(3A)) will now only apply to ‘black’ list countries (currently North Korea, Iran and Myanmar). (For those firms with offices in the UK and mainland Europe, do remember that the EU lists and EDD requirements have not changed).

However, do not fall into the trap of thinking EDD is no longer required for ‘grey’ list countries (or indeed other high-risk countries not on either of the FATF lists). Regulation 33(6)(c) still requires consideration of geographical risk factors when considering whether there is a high risk of money laundering requiring EDD to be applied and being on the ‘grey’ list (or having a low score on the Transparency International Corruption Perceptions Index) will certainly be one of those risk factors.  What it may mean is that the level of EDD you carry out when dealing with ‘grey’ list countries, including source of wealth checks, may be able to go down a notch, but as always, document your thought process carefully.

Unusually complex and unusually large

There are various triggers in Regulation 33 for when EDD must be carried out, including in relation to transactions.  The former reference to ‘complex or unusually large’ transactions is replaced with ‘unusually complex or unusually large in each case given the nature of the transaction’. The difficulty with previously having to treat all ‘complex’ matters as high risk and therefore requiring EDD was that it rather missed the point that a risk-based approach should be taken.

This more nuanced approach, taking into account when a transaction is out of the ordinary, in terms of complexity and size, for a particular firm or legal professional, knowing what they know about the transaction and the parties involved, will hopefully result in more thought-through and therefore effective risk assessments, focusing on more ‘out of place’ transactions and avoiding automatic capturing of inherently complex transactions which are in fact routine for the service provider and parties involved.

However, with nuance and discretion comes the risk of fee earners possibly missing the red flags. Real thought must be given by firms (and documented in their Firm Wide Risk Assessments) as to what makes a transaction unusually complex or unusually large for them, with staff trained accordingly.  And, as ever, at matter level, it will be important for fee earners to document the reasoning for concluding whether a transaction is (or isn’t) unusually complex or unusually large.

Pooled Client Accounts (PCAs)

These amendments appear to be likely to increase the administrative burden for firms with client accounts, rather than relieving it.  The intention was to make it easier for banks to provide organisations with pooled client accounts, but the result is likely to be more scrutiny by those banks of the underlying beneficial owners of the funds in those accounts, namely your clients.

Whilst banks already had the ability to require firms to provide information on the identity of the underlying clients if required, because they were able to rely on simplified due diligence (SDD) when dealing with law firms, this has rarely been requested.  The amendments, which now explicitly require firms to provide information about underlying clients on request, mean that PCAs are no longer automatically seen as inherently low risk (although SDD has not been outlawed altogether) with an onus on banks to carry out and justify a risk assessment of law firms (and other pooled client account holders), making it more likely that banks will request such information to protect their own position.

Given the number of clients whose funds are held in law firm client accounts, the administrative burden of responding to bank requests could be significant, and there is presumably a risk of firms being ‘debanked’ if your bank does not like the information you provide.  This is likely to be particularly hard for firms with a client account but which do not carry out any (or much) in-scope work as they will be less used to carrying out the level of CDD on their clients as those in-scope firms. However, hopefully banks will see such firms as lower risk and be less likely to exercise their new powers, but that is just speculation.  Ultimately, firms can only provide what they have and there is no suggestion that CDD on out of scope clients must suddenly mirror that on in scope clients, but you may have to explain the distinction and reasoning for it to your bank.

Either way, now would be a good time for all firms to consider how such requests from your bank will be assessed, documented and responded to.  And don’t forget to check that your engagement terms refer to your obligation to provide CDD information about them to your bank on request.

Concerns about firms breaching confidentiality and privilege have been addressed with specific references in the regulations to providing such information not amounting to a confidentiality breach and an explicit provision that privileged information will not have to be provided.  (Whilst this is good news, assessing privilege and confidentiality issues is not always simple.)  Added to that, the updated regulations regarding PCAs will only apply to client accounts created after the changes come into force, so firms with an existing client account will not be impacted (unless you change your client account).

Trusts Registration Service (TRS)

The categories of trusts required to register beneficial ownership information with the TRS in Regulation 45ZA have been expanded to include non-UK trusts which acquired an interest in land in the UK before 6/10/20 and continue to hold that interest (whereas previously pre-2020 trusts were not captured), which is likely to impact long-standing offshore structures, and the categories of ‘relevant taxes’ that trigger trust registration has been amended to remove Stamp Duty Reserve Tax.

The category of excluded trusts (which do not have to be registered) in Schedule 3A has also been expanded to cover certain small, low risk trusts by way of a de minimis exemption, and the registration grace period for trusts arising on death has been extended, which will no doubt be welcomed by private client practitioners.

Firms advising on trust creation or administration should update their guidance to clients and alert those now brought into scope of the TRS (or indeed taken out of scope) and ensure deadlines for registration are complied with.  Firms acting on behalf of trust structures will need to consider, as part of their CDD, whether the trust should have been registered and remember to file discrepancy reports if the information the client provides about beneficial ownership differs from that recorded on the TRS.

‘Off the shelf’ firms

The definition of ‘trust or company service provider’ (TCSP) (which are brought into scope of the MLRs by way of Regulation 12) is amended to specifically include firms providing services in relation to the sale of ‘off the shelf’ companies.  Where a firm provides such services, the full Regulation 27 CDD requirements will now come into play (if you weren’t already doing so).

 

Other changes – lower impact for law firms but still important to be aware of

Sterling thresholds

The MLRs make various references to monetary thresholds, for example in relation to ‘occasional transactions’ in Regulation 27, but mainly in relation to other (non-law firm) ‘relevant persons’ covered by the MLRs. Given the general consensus that law firms do not often carry out ‘occasional transactions’ (as they ‘establish a business relationship’ with their clients), the change from these thresholds being quoted in euros to sterling is unlikely to have a major direct impact on law firms.

FCA authorised persons – reporting duties

Regulation 23 requires Financial Conduct Authority (FCA) authorised firms to notify them if they act as a money service business or a TCSP. Additional requirements to notify the FCA of any changes to the information originally provided have now been added.  This will become more relevant for law firms when the FCA take over AML supervision for the legal sector (mainly in relation to their TCSP work), about which you can read more here.

Cryptoasset exchange providers and custodian wallet providers

The crypto-sector is regulated by the FCA for MLR purposes and the changes brought in by these regulations will be unlikely to directly impact law firms. However, if you deal with clients in the crypto sector, it would be sensible to review the updated legislation, including the new EDD regime in Regulation 34A.

 

What should firms be doing now?

  • Review and update your AML Firm Wide Risk Assessment (FWRA) and AML Policies & Procedures (together with any associated workflow implications) to reflect the above changes:
    • High risk third country lists and the EDD requirements
    • What an ‘unusually complex’ and ‘unusually large’ transaction looks like to your firm
    • The expansion of CDD requirements to any TCSP services you provide relating to the sale of ‘off the shelf’ companies (if applicable)
  • Where you advise on trust creation or administration, or act for trust structures
    • review your client trust list and update your guidance to clients about when trusts must be registered with the TRS
    • review your CDD procedures to ensure you are looking for evidence of trust registration in the right places and know when to report discrepancies
  • Consider your client account procedures and how you will deal with bank requests for client information, with appropriate updates made to your engagement terms as necessary.
  • Train staff on these changes
  • And finally, with the SRA’s ongoing thematic review looking at whether firms are putting into practice what their policies and procedures say they do, firms should not only be updating them to reflect these latest AML changes, and refreshing staff training accordingly, but also auditing practices across the firm to ensure compliance. File reviews are the easiest way to do this, with an annual (or at least every 2 years) independent audit for a more holistic review of compliance.