Posted by Yazad Bajina, chief commercial officer at Legal Futures Associate Kord [1]

Baijina: Firms need to link information with the structure for assessing risk
It’s been a busy time for the legal regulators.
On 3 September, the Solicitors Regulation Authority (SRA) published an independent review [2] into its handling of the run-up to PM Law’s collapse. This came alongside the latest review of its progress [3] against the Legal Services Board’s (LSB) post-Axiom Ince directions, which aim to improve its performance.
Most of the coverage has pointed the finger squarely at the regulators. It’s a view shared by the LSB itself, which is stepping up its enforcement action against the SRA.
Is it really fair to make this all about the SRA?
The review’s real findings perhaps point to a failure mode applying to any organisation sitting on scattered risk information. And that isn’t exclusive to firms under the SRA’s watch.
What the review found
These are the facts. There were two forensic investigations, an anti-money laundering (AML) inspection and a thematic review, along with multiple reports about PM Law Group firms, all held by different parts of the organisation.
Nothing was held in one source of truth, and, in the words of the report itself, the SRA ultimately “held more information about the PM Law Group than was ever drawn together into a single, coherent risk picture”.
Worse still, an investigator tasked with actually working out what was going on wasn’t assigned until 30 January 2026, days before the collapse of an 11-entity, 600 job organisation.
The SRA has operated with some level of candour here. It published the review itself, and the chair accepted the findings. It has been willing to bear some of the responsibility.
Structural limitations
None of these failings are deemed to have been the product of individual errors – though errors were certainly made. Instead, it’s the result of a “structural limitation in the SRA’s operational architecture”.
This is exactly what an organisation’s own compliance processes are meant to guard against. Firms hold client due diligence, transaction data, source of funds checks, AML records, and client money across different systems, teams and matter files. They’re expected to draw the links between each data point, spotting patterns and risk where they emerge.
What the SRA’s review ultimately shows is that possessing this information is only half the battle. It’s not the same as actually being able to act on it. Systems and structures need to be in place to do both.
Scale isn’t the solution
It’s tempting to assume more controls, more systems, and more oversight is the remedy.
But the PM Law review argues the opposite: it was a structural limitation, not a capacity one.
All too often there’s a missing link between the system holding the information and the structure for assessing risk. Many firms make that link manually, and that opens the door to errors, missed opportunities, and risks slipping in through the side door.
Organisations need to actively put systems and processes in place to build those connections. They can’t assume the risks will surface on their own – they will, but too late.
Would it be different next time?
Law firms are probably asking whether they would have handled the PM Law collapse differently. Perhaps they would, but it’s not necessarily the most useful question to ask.
Instead, firms should think about what their data looks like today. Is it disconnected, spread across different teams and systems and linked together laborious by hand, or are their structures in place that draw those links automatically?
The lesson from all this is that holding data isn’t enough. Having the structures in place to get a holistic view of what’s going on under your watch is how you surface issues before they become fatal.