AML Firm-Wide Risk Assessment: The Foundation of Your AML Controls

An AML firm-wide risk assessment (FWRA) is the starting point for a law firm’s approach to preventing money laundering and terrorist financing. It should describe the risks that arise from the firm’s actual clients, services, transactions and ways of working, and explain how the firm manages them.

A completed template is not automatically a completed assessment. The document needs to show that the firm has considered its own risk profile, reached reasoned conclusions and connected those conclusions to its policies, controls and procedures.

This guide explains what an FWRA should do, the areas it needs to cover and how to keep it useful. The Solicitors Regulation Authority’s current firm-wide risk assessment guidance was updated on 19 June 2026. Firms should check that guidance and the SRA’s current sectoral risk assessment when preparing or reviewing their own document.

What is a firm-wide risk assessment?

A firm-wide risk assessment is the firm-level assessment required by Regulation 18 of the Money Laundering Regulations 2017. An in-scope firm must identify and assess the money laundering and terrorist financing risks to which its business is subject. The assessment must be in writing, appropriate to the size and nature of the business, kept up to date and available to the regulator on request.

The SRA’s sectoral risk assessment helps firms understand risks across the legal sector. It is an input to a firm’s own assessment, not a substitute for it. The FWRA must explain how the risks apply to the individual firm.

Regulation 18A also requires an in-scope firm to assess proliferation-financing risk. This can be addressed within the FWRA or in a separate assessment. Either way, the firm needs to consider and record its exposure.

Why the FWRA is the foundation of AML compliance

The FWRA should inform the firm’s anti-money laundering policies, controls and procedures. It should also help fee-earners assess risk at client and matter level. These documents have different purposes:

  • The FWRA assesses the risks faced by the firm as a whole.
  • The client or matter risk assessment considers the risks linked to a particular client or transaction.
  • The firm’s policies, controls and procedures explain what the firm does to manage the risks it has identified.

The documents should connect. For example, if the FWRA identifies a risk associated with complex ownership structures, the firm’s procedures should explain what information fee-earners must obtain, when they should escalate concerns and how the client or matter assessment should record the risk.

The SRA’s client and matter risk assessment guidance explains the related file-level requirement. An FWRA cannot replace a client or matter assessment, and a file-level form cannot make up for a missing or inadequate firm-level assessment.

The five risk areas to assess

Regulation 18 requires firms to consider relevant risks across five areas. The assessment should address each one, even if the firm concludes that a particular exposure is limited.

1. Clients

Describe the types of clients who instruct the firm and their usual patterns of business. Consider whether the firm acts for individuals, companies, trusts, property investors, overseas clients, politically exposed persons or clients with complex ownership arrangements. Include how clients find and instruct the firm, such as referrals, repeat instructions, online enquiries or walk-ins.

Consider what may make a client higher risk in the context of your practice: for example, a client whose identity is difficult to verify, a politically exposed person, a sanctioned person or a client whose profile or behaviour does not fit the expected pattern. Explain how staff are expected to identify and escalate these issues.

2. Geographic connections

Consider where the firm operates and where its clients, transactions, assets and sources of income are connected. Geographic risk is not limited to the address of the firm’s offices. A firm may have international exposure through its clients or transactions even when all its staff work in England and Wales.

Use current, reliable sources when considering sanctions, higher-risk jurisdictions and other relevant country risks. Explain which connections are relevant to the firm and why. Avoid unsupported statements that the firm has no geographic risk unless the firm has considered the location of clients, assets, funds and transactions.

3. Products and services

List the services the firm actually provides and assess the risks associated with them. For conveyancing practices, this may include residential and commercial purchases and sales, lease extensions, enfranchisement, landlord and tenant work, new-build transactions or acting in matters involving companies or trusts.

Specificity matters. A general reference to “property work” may fail to explain the different services, client types and transaction structures the firm handles. Identify which activities fall within the Money Laundering Regulations and consider whether client accounts, complex ownership, third-party funding or other features change the firm’s exposure.

4. Transactions

Describe the transactions the firm handles, their typical size and frequency, and the factors that may make a transaction unusual. Consider whether a transaction is unusually large or complex for the client, whether the funding arrangements are difficult to explain, and whether the structure could obscure who owns or controls the assets.

Put transaction values in context. A value that is ordinary for one client group or market may be unusual for another. The FWRA should help staff understand what is typical for the firm’s work and what should prompt further enquiries or escalation. Include non-monetary transactions where they are relevant to the firm’s practice.

5. Delivery channels

Explain how the firm provides its services and how clients interact with it. Consider face-to-face meetings, telephone, email, video calls, online portals, remote onboarding and the use of introducers. Assess how those channels affect the firm’s ability to verify identity, understand instructions, communicate securely and recognise unusual behaviour.

Listing a delivery channel is not enough. The assessment should explain how the firm manages the risks associated with using it.

Make the assessment specific, reasoned and usable

A useful FWRA explains the firm’s methodology: what information and sources were considered, how risks were assessed and how the firm reached its conclusions. Relevant information may include the firm’s client and matter data, services, transaction patterns, office locations, referral arrangements, audit findings and current regulatory risk assessments.

Distinguish between inherent risk and residual risk. Inherent risk is the exposure before controls are applied. Residual risk is what remains after the firm’s controls are taken into account. If the firm assigns a low residual rating to an area with significant inherent risk, explain which controls reduce the risk and how the firm checks that they work.

Use clear language and risk ratings that staff can understand. Avoid relying on a score alone: record the reasons for the rating and the controls that follow from it. The document should help staff make decisions, not simply demonstrate that a form exists.

Templates must be tailored to your firm

The SRA provides a template to help firms structure an FWRA. It can be a useful starting point, but it does not supply the firm’s own risk analysis. The SRA cautions against copying generic or specimen wording without adapting it to the firm’s circumstances.

Before approving a template-based assessment, check that it accurately describes your firm’s clients, services, locations, transaction types, delivery channels and controls. Remove text that does not apply, add material risks that the template does not capture, and explain the firm’s reasons for its ratings and conclusions.

Keep the FWRA under review

An FWRA should be reviewed regularly and when a material change affects the firm’s risk profile. Examples include starting a new service, changing the firm’s client base, opening or closing an office, changing onboarding or payment processes, taking on a new introducer, expanding international work, or identifying recurring issues through audits or file reviews.

Record the review date, the information considered, any changes made and the senior-management approval. Retain previous versions so the firm can explain how its assessment developed over time. Updating the date alone does not show that the firm has reviewed the substance of the document.

Getting help with your FWRA

For firms looking for AML FWRA information and support, CDDmonitor’s AML firm-wide risk assessment page explains its AML Audit Help Desk and related resources.

For firms seeking a tailored drafting engagement, Policy Templates’ FWRA assessment service describes a consultative process for developing an assessment around a firm’s particular practice.

External support can help a firm prepare or review its assessment, but responsibility remains with the firm. Senior management should understand and approve the FWRA, and the firm’s controls and client or matter assessments should reflect the risks it identifies.

Further reading

This article is general information for conveyancing firms and is not legal advice. Check the current legislation and SRA guidance when reviewing your firm’s arrangements.