The SRA’s latest annual AML report was published on 30/10/25. It’s essential reading for all firms in scope of the Money Laundering Regulations (MLRs), particularly given the headline finding that almost a third of firms the SRA engaged with were not AML compliant, with another 54% being only partially compliant – and even those out of scope should read the sanctions sections.  

SRA proactive AML engagements (including onsite inspections, desk-based reviews and thematic reviews) rose to 935 this year (April 2024-April 2025), up from 545 last year, leading to more referrals to the Investigations Team and enforcement action. At the SRA Compliance Officers’ Conference in October, the message was clear: if you haven’t been reviewed yet, expect it soon. Now is the time to get your AML house in order.  Even if you slip through the SRA net this time, being prepared for the FCA takeover in the coming years is an absolute must!

Why AML matters

Aside from the obvious ramifications of a negative SRA inspection on firms and staff…

  • Over £100 billion is laundered annually through the UK or UK corporate structures
  • Approximately 4,500 organised crime groups (OCGs) operate in the UK
  • Statistically, some (or a lot) of that money must be flowing through law firms, albeit unknowingly (we hope!)
  • OCGs negatively impact our communities, services, children, vulnerable people etc.
  • Noone wants to be involved in inadvertently supporting these statistics. AML checks disrupt this.

Biggest risks to law firms

As we were reminded in the National Risk Assessment and the SRA’s Sectoral Risk Assessment in the summer (covered in our last compliance update):

  • conveyancing transactions are attractive to criminals due to the large sums that can be “laundered” at once
  • the setting up of trusts and companies can be used to obscure the ownership and control of assets
  • solicitors’ client accounts can be used to legitimise the appearance of dodgy funds.

Biggest AML weaknesses identified by SRA

1. Client and matter risk assessments (CMRAs)

Failure to perform/ properly document CMRAs is the biggest reason for referrals to the Investigation team. Of the 5,873 files reviewed during the reporting period, 16% didn’t contain a CMRA at all or they were incomplete, and 39% did not effectively assess AML risks (instead focussing on business risks).

Pro tips:

  • Ensure CMRAs are properly completed on every in-scope matter, with justification for the risk level and due diligence required clearly recorded.
  • Recirculate the SRA’s Warning Notice for staff to (re-)read, together with the firm’s FWRA to remind them of the firm-specific risks/ what the firm deems as high risk.

2. Source of funds/ Wealth checks

Failure to carry out source of funds/ wealth checks and then properly analyse/ document the findings.  Understanding the source of funds to be used in a transaction is a fundamental part of the risk-based approach. This includes being alert to the funding source described in your enquiries differing from the source that actually remits the money to your client account – this is a red flag!

Pro tips:

  • Do not simply obtain documents and file them – analyse them and consider whether what you have been told makes sense based on what you know about the client.
  • The higher the transaction/ client risk, the more you need to probe, and the more comprehensive documentation you will need.
  • Document your thought process – why are you satisfied that the funds are legitimate?
  • Check that funds arrive in your client account from where you expect them to.

3. Policies, controls & procedures (PCPs)

Inadequate/ ineffective PCPs, and even when the PCPs are good in theory, they are not being followed on the ground (such as CMRAs being completed). The key issues often missing from, or insufficiently dealt with in, PCPs are set out in the ‘Additional Findings’ section, including risks associated with new products and business practices (including technology), reporting discrepancies to Companies House (including in relation to overseas entities), Reliance, Simplified Due Diligence, products/ transactions favouring anonymity, high-risk jurisdictions and sanctions (in particular how to effectively screen for them).  With the SRA’s next thematic review on firms’ compliance with Regulation 19(3)(e) – monitoring and management of compliance – now is the time to check your PCPs.

Pro tips:

  • Check that your PCPs include everything they should (see above).
  • Include a list of (tailored) red flags to help staff spot things which are out of the ordinary.
  • Review your processes to ensure staff are complying with the PCPs. Think:
    • regular file reviews, including checking source of funds (the SRA notes that firms conducting regular file reviews are generally more compliant)
    • reports to senior management, with steps being taken to tackle non-compliance
    • file checklists (electronic or otherwise) to remind staff of the steps to follow
    • ongoing supervisor checks for open matters

4. Firm-wide risk assessment (FWRA)

Lack of/ inadequate FWRAs (although the SRA are continuing to see improvements) – the (living) bedrock of your AML compliance.  The key issues often missing from FWRAs are set out in the ‘Firm Controls’ section of the report, including lack of granular detail.

Pro tips:

  • Your FWRA MUST be tailored to your firm and its specific risks
  • Explain/ risk assess the different work-types in each department, the types of clients you act for, and the geographical reach of your work
  • Define what higher risk things look like to your firm, such as large or unusually complex transactions

5. Client due diligence (CDD)

Inadequate CDD, including identification and verification (of beneficial owners as well as clients), and over-reliance on electronic verification – the ‘green tick’ phenomenon!  The SRA highlights some examples of successful CDD in firms:

  • setting expectations with clients early on about what you will need
  • system controls preventing staff from progressing matters until CDD has been completed, together with file checklists
  • regular file reviews (to reduce the risk of ID checks being skipped!)
  • use of adverse media searches (trusty Google!).

Pro tips:

  • When using EID&V, read the whole report – don’t accept the ‘green tick’ at face value – what other risks does it uncover (PEPs, Sanctions, adverse media)?
  • The EID&V report DOES NOT replace your CMRA!
  • Beware complacency around clients known to you personally – CDD still applies
  • Watch out for ‘passporting’ clients from out-of-scope to in-scope teams if different approaches are taken to CDD
  • Re-do CDD if anything changes

6. Enhanced Due Diligence (EDD)

Failing to apply EDD and enhanced ongoing monitoring where the level of risk dictates it. Think connections with high-risk countries, PEPs, unusually complex or large transactions etc. Staff need to be able to identify when EDD must be applied.

Pro tips:

  • Include high risk issues on your CMRA forms as a reminder to staff
  • Refer staff to your FWRA to understand the specific high risks for your firm

Essential Compliance Controls and Regulatory Focus

Training and Management Buy-In

Staff are the first line of defence. AML training is seen as one of the most effective controls to prevent inadvertent involvement in money laundering (remember the Thematic Review last October?).  This is closely followed by senior management buy-in – people follow those at the top…so make sure those at the top value AML compliance and take action when people don’t comply.

Independent audits

These are a vital control and are now requested during SRA inspections. Firms must rectify issues raised by the auditor rather than simply ticking the box to confirm an audit was conducted. And always ensure your audits include file reviews.

Suspicious Activity Reports (SARs)

There is increasing focus on the quality of SARs submitted to the National Crime Agency (NCA) (which the SRA will review during inspections), with the SRA encouraging firms to refer to the NCA guidance and to read their (updated) Warning Notice. (The NCA also has some mini videos worth watching).  Be aware that during the current reporting period, the SRA submitted 19 of its own SARs based on firm inspections, 73% of which related to conveyancing transactions, including completed and abandoned transactions.  Some also related to out-of-scope work, such as litigation.

Pro tips:

  • No matter what stage in the transaction process, if you have suspicions, you should consider a report to the NCA.
  • If you decide not to report, document your reasons in case the SRA reach a different conclusion later on.
  • Firms out of scope of the MLRs still have certain reporting obligations under the Proceeds of Crime Act (POCA). The SRA’s POCA guidance provides helpful information.

Sanctions compliance

This applies to all law firms, regardless of whether they are in scope of the MLRs. The SRA emphasises the importance of firms assessing their sanctions exposure and knowing their clients (including beneficial owners) in order to screen effectively and avoid being used to evade sanctions. The SRA has various resources to help you get on the right track, or we can help with our template documents.

Pro tips:

  • Put in place a documented sanctions risk assessment and a policy for staff to follow regarding screening clients/ beneficial owners (and preferably counterparties) and knowing what to do if a sanctioned person or entity is flagged
  • Remember that the sanctions regime is strict liability
  • If you act for sanctioned individuals or entities, ensure you have the necessary expertise and understanding of OFSI licences. The biggest reason for SRA action in this space is failing to comply with licence reporting requirements and reporting frozen funds held.

Resources

The Further information/ useful links section does what it says on the tin…and it’s easier than searching the SRA’s website!

Conclusion

The message remains that the SRA are still very much on the case with AML issues (in spite of the future FCA take over), focussing on taking a risk-based approach to inspections and desk-based reviews, informed by their annual data-gathering exercises, but also using AI technology to monitor firms’ self-declared AML status, checking what services are offered to the public and comparing them to the records they hold. There is nowhere to hide!