Originally published May 2024. Updated October 2026.
This AML audit case study concerns a practice whose regulatory review identified gaps in its firm-wide risk assessment, policies and training. The original account records a two-week deadline for corrective action.
The case illustrates the pressure created when basic AML arrangements need to be addressed after a regulator has identified weaknesses. It also raises a separate question: how does the firm demonstrate that the changes work in practice?
Would a review expose gaps in your AML arrangements?
An independent review can help identify weaknesses in risk assessments, policies, training and file-based controls before they become an urgent remediation exercise.
What the regulatory review identified
According to the original case account, the practice was assessed as non-compliant because of:
- An absent firm-wide risk assessment.
- AML policies and procedures that needed updating.
- Insufficient AML training for staff.
- A gap in the MLRO’s enhanced AML training.
The regulator gave written notice requiring the deficiencies to be addressed within two weeks. That deadline belongs to this particular account; firms should not assume that every regulatory review provides the same period or opportunity to remedy breaches.
What the practice submitted
The account records that the practice submitted an AML policy, a firm-wide risk assessment and evidence of training for the MLRO and relevant staff within the specified period.
It does not record the regulator’s final assessment, whether further evidence was requested or whether any subsequent action followed. Submission should therefore not be described as proof that the matter was closed.
The risk assessment should drive the controls
A firm-wide risk assessment should reflect the practice’s actual services, clients, transactions, delivery channels and geographical exposure.
The policies should explain how the firm manages those risks. Client and matter risk assessments then apply the framework to individual instructions.
Our article on the AML evidence chain linking the FWRA, policies and CMRAs explains why these documents need to support one another.
The CDDmonitor firm-wide risk assessment resources provide a starting point for reviewing the assessment process.
Training needs to reflect responsibilities
The original account distinguishes between staff training and the MLRO’s training needs. That distinction is useful: a person responsible for considering internal reports and making reporting decisions needs training suited to that role.
Training should also explain the firm’s own procedures, including when staff must escalate concerns and what information they should provide.
Keep records of the content, attendance and any follow-up required. A certificate establishes attendance; practical testing can help establish whether the training has been understood.
Submitting documents is one stage of remediation
After updating the written framework, the practice should establish whether staff apply it consistently.
A remediation plan can record:
- The weakness identified and the corrective action.
- The person responsible and completion deadline.
- How revised procedures were communicated.
- Whether existing matters need review.
- How implementation will be tested.
- Who will review the results and address remaining gaps.
Do not backdate documents or present a later review as evidence that an earlier assessment was completed. Keep the chronology of discovery, correction and testing accurate.
A regulatory review and an independent AML audit are different
This case describes regulatory supervision. An independent AML audit forms part of a firm’s own arrangements for evaluating its controls.
Where appropriate to the size and nature of the business, Regulation 21 requires an independent audit function. Its responsibilities include evaluating AML policies, controls and procedures, recommending improvements and monitoring compliance with those recommendations.
Learn more through CDDmonitor’s independent AML audit page and the resources at AML Audit Solutions.
Prepare before the deadline arrives
The practical lesson is to identify gaps while there is time to investigate them properly. A short regulatory deadline can make it difficult to update documents, train staff and demonstrate implementation together.
Use the SRA AML audit preparation checklist to organise a review, then test the answers against the evidence.
Our article on SRA AML audits and what law firms need to evidence provides further guidance on connecting the written framework with sampled files.
Need an independent assessment of your AML controls?
Discuss the scope, timing and evidence required for a review of your practice. If a regulatory deadline already applies, make that clear at the outset.
This anonymised case study is based on the account originally published in May 2024. It does not identify the regulator or establish a final regulatory outcome.