- Legal Futures - https://www.legalfutures.co.uk -

SRA desk-based reviews and AML inspections

By Georgia Tuckley [1], junior compliance officer at Legal Futures Associate DG Legal [2]

The Solicitors Regulation Authority (SRA) has strengthened its approach to anti-money laundering (AML) supervision in recent years. Regulatory engagement has become more proactive, structured and routine, reflecting the increasing importance placed on ensuring that law firms have effective AML systems and controls in place.

As intervention from the SRA is becoming more frequent, firms may encounter regulatory engagement through a number of routes including:

The SRA uses a risk-based approach when determining the frequency and intensity of its supervision. There is therefore no single factor that determines whether a firm will be selected for regulatory engagement.

Importantly, firm size alone is not a determining factor. Smaller practices remain firmly within the scope of AML supervision and should not assume that regulatory scrutiny is reserved for larger organisations. The SRA supervises firms across different risk categories, although higher-risk firms may be subject to more frequent or intensive supervision.

The reality for firms is that SRA AML supervision has become a normal part of the regulatory landscape. Preparation should therefore be viewed as an ongoing compliance function rather than a reactive exercise.

Desk-based reviews

Desk-based reviews (DBRs) are generally narrower in scope and conducted remotely. The SRA describes DBRs as part of an ongoing, rolling programme of risk-based supervision, with several firms selected each month. Firms are notified in advance and receive an AML questionnaire.

Once notified, firms have 10 calendar days to provide the initial information requested by the SRA. This includes:

The SRA then typically requests a sample of files for review. Its latest AML annual report confirms that it generally reviews between 10 and 12 files per firm, depending on the size and nature of the practice. Larger firms or firms undertaking a high volume of regulated work are more likely to have 12 files reviewed.

The desk-based reviews typically examine the framework in place and review whether this is consistent, effective and representative of the firm’s risk profile. The SRA specifically examines the FWRA, PCPs, CMRAs and a sample of files to assess compliance with the firm’s PCPs and the MLRs.

At this stage, we can usually expect the following issues to be raised: generic documentation, inconsistent policies that do not reflect the practice, and gaps in client due diligence records.

The SRA’s latest supervisory work also identifies failures in client and matter risk assessments, source of funds checks, source of wealth checks, PCPs, firm-wide risk assessments and enhanced due diligence and ongoing monitoring as recurring areas of concern.

The SRA’s 2024-25 figures demonstrate the level of scrutiny involved. Of the 833 firms that received an AML proactive inspection or DBR and were given a compliance rating, 112 were assessed as compliant, 451 as partially compliant and 270 as not compliant. This meant that 32% were assessed as not compliant.

AML inspections

AML inspections represent a more detailed level of regulatory scrutiny. The SRA’s published material refers to onsite AML inspections and explains that these involve document reviews and typically interviews with the firm’s money laundering reporting officer (MLRO) and money laundering compliance officer (MLCO). In some cases, the SRA also speaks with fee-earners.

If a firm is selected for an AML inspection, it can expect the review to include:

The objective is to determine whether AML policies are genuinely embedded and test implementation as much as documentation. During an AML inspection, the SRA is looking for evidence that staff understand and follow the firm’s procedures rather than simply confirming that written policies exist.

The SRA’s recent supervisory work demonstrates that the distinction between having a procedure and evidencing its implementation is particularly important.

For example, its 2025 thematic review of source of funds and source of wealth found that firms sometimes collected supporting documentation without adequately scrutinising it, and that files did not always contain an adequate audit trail or rationale for decisions.

Responding effectively

An effective and engaging response to the SRA will help the process run smoothly and have a positive impact on the overall outcome.

Adopt a structured approach. When notified of a review or inspection, firms should remain calm and organised. It is important that the scope of the request from the SRA is reviewed carefully and deadlines are identified.

A coordinator should be appointed to respond to the request, typically the MLRO or MLCO. Relevant senior management should also be appropriately involved. A measured and intentional response reduces the risk of including contradictory information or over-disclosure that can raise further questions in the initial submission.

It will often benefit the firm more to engage early and agree an extension, if necessary, instead of submitting incomplete or inconsistent information.

Ensure document readiness. The SRA expects documentation to be current and in line with the most recent regulatory updates, controlled, consistent and reflective of actual practices.

Version control was identified as an often-overlooked issue. Firms should be able to demonstrate clearly which documents are current and approved.

Conduct an internal review. Before submitting any documentation, firms should critically assess whether documents align with each other and the processes reflect actual practice.

Addressing issues at this stage can prevent them developing into formal regulatory concerns and should be rectified as soon as possible prior to being sent.

Prepare staff for engagement. Everyone involved in discussions with the SRA should understand the firm’s AML framework, their individual responsibilities and expectations and the escalation procedures.

The goal should not be to provide technically perfect answers but rather responses that are clear, accurate, credible and consistent. Staff should be able to explain how the firm’s procedures operate and how they apply those procedures in practice.

Enforcement risk and regulatory consequences

Not every review results in enforcement action. In many cases, firms receive:

The SRA’s formal supervisory outcomes include guidance, a letter of engagement, a compliance plan or referral for investigation, depending on the level and extent of non-compliance. A compliance plan sets out actions that the firm must take and requires evidence that those actions have been completed.

However, serious breaches and issues can lead to more significant consequences. Potential outcomes include:

Firms should be aware that the consequences are not always purely regulatory. If the firm receives penalties and disciplinary action, it may also be affected in other ways, including reputational damage, disruption to business operations, and increased scrutiny from insurers, lenders and clients.

Best practice approach

We recommend that firms follow a best practice approach to ensure that any future engagement with the SRA results in a more straightforward experience and the best possible outcome.

Documentation should be reflective of the firm’s actual risk exposure and appetite, be reviewed regularly, kept up-to-date and align with the operational practices. To ensure that it does align with those practices, it is important to provide training to staff and promote a culture of compliance, so that reasonable decision making is used in line with the policies and procedures in place.

Strengthening audit trails will help support the documentation by evidencing that the procedure is effectively followed. File history should provide a full picture of the compliance measures taken, by recording:

Consistency should follow across all departments, especially where the firm provides services in both regulated transactional work and lower-risk work outside the scope of the MLR s.

Staff should be able to identify which measures apply to each matter and apply them consistently. Some firms opt to use different risk assessment templates for work in and out of scope, but it may be worth considering implementing one CMRA template and providing an explanation when certain sections may not be applicable for matters out of scope.

This approach would also mitigate the risk of a non-compliant risk assessment template being used for matters that have unexpectedly been brought within scope, where instructions may have been changed.

Where a firm uses different processes across departments, it should ensure that the differences are intentional, documented and supported by the firm’s risk assessment and PCPs.

Conclusion

The overarching takeaway should be that interaction from the regulator is no longer uncommon and could take place at any moment. The scale of the SRA’s recent supervisory activity demonstrates that AML engagement is now a routine part of the regulatory environment rather than an exceptional event.

Firms should make sure they are prepared in advance with compliant documentation, clear staff understanding and implementation, recording and evidencing decisions, rationale, and due diligence checks on file, and undertaking continuous reviews and ongoing monitoring internally to proactively flag potential concerns and address them early on before the SRA does.

Ultimately, firms should be able to demonstrate a clear and consistent link between their FWRA, PCPs, staff training, CMRAs and the evidence contained within individual files.

The objective should not simply be to have compliant documentation available when the SRA asks for it, but to demonstrate that the firm’s AML controls are understood, implemented and effective in practice.

Regulatory readiness should therefore be an ongoing process of reviewing and updating documentation, testing implementation, monitoring compliance, maintaining clear audit trails and addressing weaknesses promptly.