SRA AML Audit Results in £23k fine

Originally published March 2024. Updated October 2026.

An SRA AML fine of £23,035.50 illustrates the consequences of failing to undertake client and matter risk assessments. The case concerned a sustained gap in the firm’s AML arrangements, despite the absence of material harm.

For conveyancing firms, the practical question is whether sampled files demonstrate that risk was assessed and that the assessment informed the checks, monitoring and supervision undertaken.

Would your files demonstrate effective AML risk assessment?

An independent review can help identify gaps between your written procedures and the evidence retained on client files.

Explore independent AML audits

What the SRA’s desk-based review found

In March 2023, the SRA’s AML Proactive Team conducted a desk-based review. Five sampled files had no client and matter risk assessments.

During the subsequent investigation, the firm accepted that it had not completed such assessments on its files before March 2023. The SRA found breaches of Regulations 28(12) and 28(13) of the Money Laundering Regulations 2017 and associated professional obligations.

The firm was fined £23,035.50 and ordered to pay £1,350 in costs.

Why the absence of harm did not prevent a fine

The SRA treated the duration and pattern of non-compliance as serious. It also considered the potential effect on the public interest and confidence in the profession.

Mitigation included the absence of material harm, admissions, cooperation and remedial action. These factors influenced the sanction but did not remove the underlying breach.

The wider lesson is that firms should test preventive controls before a loss or suspicious transaction exposes a weakness.

A client and matter risk assessment should guide the work

A CMRA should explain the risks associated with the particular client and transaction. A rating without supporting reasons gives a supervisor little basis for checking whether the level of due diligence is appropriate.

For a conveyancing matter, relevant considerations may include:

  • The client’s identity, ownership and control arrangements.
  • The purpose and structure of the transaction.
  • The origin and movement of purchase funds.
  • Third-party contributions or payments.
  • Relevant geographical exposure.
  • Unusual instructions, urgency or changes during the matter.

The assessment should lead to proportionate action. Where further enquiries, enhanced due diligence or additional approval are needed, the file should record what was done and the outcome.

The CDDmonitor client and matter risk assessment resources explain how a structured process can support this work. The quality of the information and professional judgment remain essential.

A firmwide risk assessment does not replace a CMRA

The firmwide risk assessment addresses the practice’s overall exposure. Client and matter assessments apply that framework to individual instructions.

The documents should be consistent, but they serve different purposes. A firm-wide assessment cannot establish that a particular transaction was considered appropriately.

Our article on the AML evidence chain linking the FWRA, policies and CMRAs explains why the written framework and file evidence need to support each other.

Policies and accreditation need evidence of implementation

A policy can describe an effective process without demonstrating that staff follow it. Accreditation, training attendance and standard forms also need to be supported by evidence of application.

Ask whether the firm can show:

  • When the assessment was undertaken.
  • Who completed and reviewed it.
  • The information supporting the risk rating.
  • The controls applied in response.
  • Whether new information prompted reassessment.

An AML policy template may support drafting, but it must be adapted to the practice, communicated and implemented.

Review the process before the regulator samples the files

A useful internal review compares the policy requirements with a selection of actual matters. It should identify missing assessments, unsupported ratings and failures to follow the controls prescribed by the firm.

Where appropriate to the size and nature of the business, Regulation 21 requires an independent audit function. Its role includes evaluating AML controls, recommending improvements and monitoring compliance with those recommendations.

An independent AML audit is different from an SRA desk-based review. It forms part of the firm’s own arrangements for testing its controls.

Further preparation resources are available through CDDmonitor’s independent AML audit page, AML Audit Solutions and the SRA AML audit preparation checklist.

Remediation must be recorded accurately

If assessments are missing, identify the extent of the problem and decide what current action is required. Do not backdate documents or present a later review as evidence that an assessment was completed earlier.

Record when the weakness was discovered, which matters were reviewed, what changes were introduced and how implementation was tested.

Our updated article on SRA AML audits and what law firms need to evidence explains how preparation should connect documents, training and file-based controls.

Are your AML procedures reflected in the files?

Discuss an independent review of your risk assessments, policies and sampled matters, with recommendations and follow-up on implementation.

Discuss an independent AML audit