The SRA published its latest Anti-money laundering, terrorist financing, proliferation financing and sanctions Sectoral Risk Assessment on 6/8/26 (as it is required to do at regular intervals  by the Money Laundering Regulations (MLRs)).

Regulation 18 requires firms to take the SRA’s sectoral risk assessment into account when drafting and maintaining their own firm-wide risk assessment (FWRA).  Accordingly, firms will be expected to review the SRA’s document and update their FWRA (including any separate sanctions firm wide risk assessment) to take into account the identified risks over the next few months.

Having compared the latest risk assessment to last year’s version, there are not as many substantive additional risks as might appear at first glance. Many of the risks referred to in the “Emerging and current risks” section are risks law firms have been aware of for some time and will (or should 😉) already be addressed in their FWRAs. The document has however, been substantially revised and streamlined, with some sub-sections now including less information, seemingly at the expense of (what I saw as) the useful tips for firms on how to mitigate the risks identified by the SRA, and some sections disappearing altogether, or being subsumed into other sections, (such as ‘Client account issues’, ‘Poor CDD scrutiny’, ‘Weak controls’, ‘Proliferation financing’, ‘Stringent currency controls’).  Without any explanation for the disappearance of whole sections (other than the ‘Changing firm business models’ and ‘External support’ sections removed for not being ‘specific to the AML sphere’), it can be difficult to understand the SRA’s intentions here. My view is that we should not conclude that these risks are no longer a concern and that the SRA’s 2025 Risk Assessment remains a useful resource. I would certainly warn against removing any of the previously addressed risks from your FWRA.  The focus now is for firms (in particular, COLPs, MLROs and MLCOs) to familiarise themselves with the SRA’s updated risk assessment, in particular the additional and expanded identified risks.

What hasn’t changed?

The legal sector remains high risk for money laundering, with conveyancing, trust or company services, and misuse and exploitation of client accounts remaining the services most at risk. It remains low risk for terrorist financing, but trust and company services remain medium risk, so firms doing TCSP work mustn’t become complacent.

What has changed?

We set out below the new risks which have been added since last year, or substantively amended (which in our view should be reflected/ updated in law firm FWRAs), together with some suggested actions to mitigate the identified risks.

AML Emerging risks

Technology: This section has been updated to focus on recent AI risks, including:

  • AI-enabled fraud using Deepfakes to commit identity fraud – mentioned last year but at that time there was no evidence it had been used to impersonate legitimate clients – that appears to have now changed.

    Actions: Review your onboarding procedures – be wary about relying solely on remote onboarding processes; check whether your electronic ID&V provider is registered on the Government’s DVS Register (which should mean that they are able to detect deepfakes and verify the authenticity of ID documents).

  • Cyber-enabled fraud has been made easier by the rapid adoption of digital technological innovations. For example, faster funds movement and increasingly sophisticated social engineering schemes has led to enhanced use of phishing emails, fake websites, social media advertising, and messaging applications to perpetrate scams remotely and at mass scale (according to the FATF paper published in February this year).

    Actions: Review the FATF paper on Cyber-enabled fraud and the Five Eyes Cyber Security Agencies Statement:The AI shift in cyber risk: why leaders must act now’ for insight into how to protect your firm.  Also read the SRA’s hot-off-the-press latest Warning Notice: Misuse of AI.

Passporting and reliance on existing due diligence: ‘Passporting’ clients between out-of-scope and in-scope teams, and full CDD obligations falling between two stools, has been a risk for some time, so whilst this is not really an ‘emerging risk’, this is a new section for the SRA.

Actions: Review your firm’s exposure to these risks. Do not rely on CDD undertaken by another office/ department. If your work is in-scope of the Regulations, it is your responsibility to ensure full/ updated CDD is carried out.  And/ or consider having a ‘whole firm’ policy on CDD so nothing ‘slips’ through.

Cash-intensive businesses and high street crime: The difficulties in relation to establishing beneficial ownership, control and source of funds associated with such businesses, making them attractive to criminals, are not new risks, but the SRA has gone into more detail, including listing the legal services mostly likely to be impacted and specific reference to ‘ghost directors’ – nominees unrelated to the company but willing, for a fee, for their name to be used to disguise the true ownership/ control.

Actions: Ensure staff know which businesses to look out for (e.g. take-aways; car washes; nail salons; barber shops etc) and which legal services are more likely to encounter them (e.g.  commercial property; company matters involving nominee or otherwise unconnected directors; transactions funded by businesses whose finances appear inconsistent with their size, age or apparent operations). Carry out adequate CDD on directors/ beneficial owners and source of funds/ wealth enquiries. Use Companies House data to check for signs of ‘ghost’/ nominee arrangements.

Global instability and uncertainty: Geopolitical instability (including conflict/ war and significant governance change) may increase corruption, sanctions evasion and illicit movement of assets. This section is the revised and expanded version of topics introduced last year (‘Economic Uncertainty’ and ‘Capital Flight’), going into more detail and setting out relevant risk factors to look out for, such as connections to PEPs, inconsistent or difficult to verify/ opaque source of funds/ wealth, complex ownership structures/ use of offshore companies, links to higher risk jurisdictions etc.

Actions: Research countries with which your clients/ involved parties are connected so that you are alive to these risks.  Screen clients/ beneficial owners (and possibly third parties) for sanctions and PEPs status. Carry out adequate CDD on directors/ beneficial owners and source of funds/ wealth enquiries.

Company registration: This is a new risk not previously mentioned by the SRA following the implementation of the Economic Crime and Corporate Transparency Act 2023 (ECCTA) and Companies House’s program of purging its register of misleading information and improper company listings.  The concern here is that criminals may still seek to use their existing misleading information for CDD purposes.

Actions: Use ‘live’ Companies House data to complete CDD checks rather than relying on old/ potentially illegitimate documents provided by clients.

Sanctions emerging risks

Sanctions remain an ongoing risk for firms, and not just those in scope of the Regulations. This section has been significantly expanded and updated to include common sanctions vulnerabilities, such as weaknesses in sanctions screening processes (including over-reliance on automated screening tools); inadequate understanding of client ownership and control arrangements (particularly given the incentives for designated persons to conceal their ownership of funds/ assets) – increased focus on this is vital in order to be able to screen clients effectively; and insufficient prioritisation by firms of sanctions-related risks.  Although there is a new sub-heading entitled ‘Emerging risks’, it addresses risks connected with the sanctions licensing regime which were raised last year. The new risks addressed are:

  • Russian sanctions regime – circumvention and procuring goods to support the war effort: This is a new section expressing concerns that the use of techniques for circumventing sanctions is on the rise, with certain third-country involvement likely to increase the risk (see the OFSI/ OTSI guidance, ‘Countering Russian sanctions evasion – guidance for businesses’ for details of the likely countries) and the increasing attempts by Russia to procure non-military (at least in appearance) goods from UK companies (often via the same third countries referred to above). Such goods (known as ‘dual-use goods’) include things like printing inks, oil lubricants, paints, varnishes, enamels, and lacquers, and industrial heat exchange units.
  • Other sanctions regimes: This is a new sub-heading emphasising that sanctions do not only apply to Russia, or the more ‘obvious’ countries like Iran and North Korea (or indeed countries at all, e.g. sanctions regimes relating to cyber-activity, terrorism, human rights abuses, corruption and threats to national security).

Actions: Take sanctions risks seriously…because the SRA and OFSI/ OTSI do and the regime is one of strict liability! Ensure you understand ownership and control structures, and the bigger picture into which the instruction fits; have a comprehensive screening process; train staff in the use of screening tools and when/ to whom to escalate concerns. In terms of the Russian sanctions regime in particular, be aware of the red-flag countries and the red-flag (dual use) goods, but also be alive to the fact that the sanctions regimes reach far beyond Russia.

(As an aside, rather oddly, the SRA has (without explanation) removed reference to their own guidance on Complying with the UK Sanctions Regime. We would still recommend referring to it!)

What now?

  • Review the SRA’s updated Sectoral Risk Assessment.
  • Update your FWRA to reflect the changes as soon as possible (remembering to keep a copy of the old version for SRA reference). (For clients we will be updating our template documents to assist you with this as part of our next round of updates).
  • Review your client and matter risk assessment and source of funds processes and ensure staff are following them/ documenting their thought processes, to show that identified risks are being assessed and mitigated.
  • Ensure staff are aware of the changes/ risks to look out for.