HM Treasury AML Supervision Report: Lessons for Law Firms

Originally published May 2024. Updated October 2026.

HM Treasury’s AML supervision report for 2022–23 highlights weaknesses in risk assessments, policies, customer due diligence and staff understanding. For law firms, the practical question is whether their written arrangements match the work undertaken on individual matters.

The report was published on 1 May 2024 and covers the period from 6 April 2022 to 5 April 2023. Its findings should be read as historical supervisory evidence, rather than a description of today’s compliance position.

Do your AML documents match your firm’s practice?

An independent review can help identify gaps between the firm-wide risk assessment, policies, staff understanding and sampled files.

Explore independent AML audits

What the AML supervision report identified

The HM Treasury supervision report for 2022–23 records common weaknesses reported by accountancy and legal professional body supervisors.

These included inadequate policies, customer due diligence, client risk assessment records and firm-wide risk assessments. Supervisors also linked some weaknesses in understanding to templates or third-party policies that had not been properly tailored.

The legal-sector case study

The report describes an unnamed high-risk law firm with 16 fee earners across two offices. It had relied on an AML policy last updated in 2016 until August 2022.

Inspectors found insufficient training records, uncertainty among fee earners about risk assessments and identification requirements, and weaknesses on six reviewed files. These included missing identity documents and source-of-funds or wealth information.

Following an investigation, the supervisor issued a compliance plan. The report described a financial penalty as likely, rather than recording a confirmed final sanction.

A current policy needs an implementation process

Updating a policy is useful only if the firm understands what has changed and how the revised procedure will operate.

For each material amendment, establish:

  • Which staff and matters are affected.
  • Who is responsible for applying the procedure.
  • What records must be retained.
  • When supervisory approval is required.
  • How implementation will be checked.

A policy template can support drafting, but the firm must adapt it to its services, risks and working arrangements. The completed document should describe a process that staff can actually follow.

Connect the firm-wide and matter-level assessments

The firm-wide risk assessment addresses the practice’s overall exposure. Client and matter risk assessments apply that framework to individual instructions.

Neither should be treated as an isolated form. The risks identified should inform the checks, monitoring and escalation undertaken.

Our article on the AML evidence chain linking the FWRA, policies and CMRAs explains how those records should support one another.

The CDDmonitor client and matter risk assessment resources provide further information about a structured assessment process.

Test understanding as well as attendance

The case study illustrates why training records and staff understanding need separate consideration.

A practical discussion with fee earners can establish whether they know when to assess risk, what evidence to obtain and when to refer a concern to the MLRO or supervisor.

Use examples drawn from the firm’s actual work. Ask staff to explain the action they would take and the records they would retain. Where uncertainty emerges, address it through targeted training and follow-up.

Our earlier AML audit case study on missing assessments, policies and training considers how these weaknesses can combine.

Review the substance of source-of-funds enquiries

Documents should support an explanation of the funds used in the transaction. Retaining a bank statement without considering what it shows may leave important questions unanswered.

Where money comes from overseas or a third party, identify the relevant parties, the explanation for the payment and the evidence needed in the circumstances. Record how inconsistencies or gaps were resolved.

The review should establish whether the work undertaken matches the risk assessment and the firm’s own procedures.

Use an independent audit to test the controls

Where appropriate to the size and nature of the business, Regulation 21 requires an independent audit function. Its responsibilities include evaluating AML controls, recommending improvements and monitoring compliance with those recommendations.

An independent audit is different from a supervisory inspection. It supports the firm’s own assessment of whether its arrangements are adequate and effective.

Further resources are available through CDDmonitor’s independent AML audit page, AML Audit Solutions and the SRA AML audit preparation checklist.

Turn findings into verified improvements

An action plan should identify the weakness, corrective action, responsible person, deadline and evidence needed to confirm completion.

Distinguish between revising a document, briefing staff and testing new files. Each stage answers a different question about implementation.

Our updated article on SRA AML audits and what firms need to evidence explains how to prepare a consistent record of the controls in operation.

Read historical findings alongside current guidance

This article concerns the 2022–23 reporting period. For current requirements, use the applicable regulations and guidance, including the SRA’s AML resources.

Later Treasury publications can be found in the official AML supervision report collection.

Could similar weaknesses exist in your firm?

Discuss an independent review of your AML framework and sampled files, with recommendations and follow-up on implementation.

Discuss an independent AML audit