Skip to main content

December 2025: The SRA’s AML Audit Crackdown Has Arrived

The Solicitors Regulation Authority (SRA) isn't sending Christmas cards this year. They're sending in the AML auditors.

Despite the upcoming shift where the FCA will assume wider AML regulatory oversight, the Solicitors Regulation Authority (SRA) is turning up the heat one last time. Forget a gentle warning—welcome to the AML Blitz of December 2025.


Let’s cut to the chase. SRA Chief Executive Paul Philip is clearly done with excuses. His public message is unambiguous: "We are still finding fairly basic deficiencies in AML arrangements within firms."

Translation for the Partners: You might effortlessly navigate a complex, multi-million-pound merger, but somehow, you still haven't nailed your fundamental firm-wide risk assessment. The era of the gentle wrist-slap is officially over. The SRA has made it clear that fines are "continually going up." AML Compliance is no longer a 'nice-to-have'—it’s an expensive, enforced reality.

The Downpour, Not the Drizzle

Remember that target of 700 SRA AML audits for 2025 period? They aren't waiting for the calendar to tick over. Between November and February alone, the SRA was already overshooting their target by 128%. This isn't a regulatory drizzle; it’s a full-blown, year-end downpour.

To help them prioritise which firms get the "VIP Audit Treatment," the SRA recently ran an intensive, six-week data-gathering exercise. It was a targeted effort designed to effectively sniff out firms for immediate inspection. If you submitted poor data, you've already put yourself on the priority list.


The Three Flavours of SRA AML Audit Pain

When the SRA AML audit team knocks on your door, you don't get a simple pass/fail. You get one of three escalating outcomes:

  • The Gold Star: You are fully compliant. They smile, they leave. (Given the current climate, this is highly ironic and very rare).
  • The Hand-Holding: You have "some corrective actions" needed. They offer guidance and require remediation. Crucially, no formal action is taken. This is often called "Outcome 2, where you panic-fix everything right after they leave."
  • The Slap: You have serious issues. You're given a stern compliance plan, but here's the kicker: your firm gets immediately referred to the AML investigation team for further action. Congratulations, your firm is now in the naughty corner, complete with official paperwork and a much bigger fine looming.

Your Last-Minute, Common-Sense Compliance Checklist

If reading this just gave you a sudden chill—and it has nothing to do with the winter weather—here is your simple, yet crucial, five-point checklist to shore up your defences right now.

  1. The Magic Documents: Do you have your current Policies, Controls, and Procedures (PCPs) documented, approved, and easily accessible? If the answer is "It's somewhere on the shared drive," you are already losing.
  2. Risk Assessment: Have you completed and signed off your Regulation 18 firm-wide risk assessment? This is the bedrock of your entire AML framework. A firm-wide risk assessment sets the framework, but client and matter risk assessments are where AML compliance actually lives or dies.
  3. The Training Fairy: Every single member of staff needs annual AML training. Not just the partners. Not just the fee earners. Everyone.
  4. MLRO/MLCO VIP Treatment: These individuals are your heroes (and those taking the bullet). They require special, tailored, one-to-one training that goes beyond the standard firm module. Equip them with the right armour.
  5. Damage Control: Run an idependent AML Audit now. Identify any immediate potholes (e.g., outdated PCPs, missing training logs), write down a clear plan for how you will fill them, and get the MLRO and Partners to sign it off. This is your immediate mitigation plan. You can’t fix the past, but you can certainly stop the breach today.

The SRA is coming and soon it will be the FCA. Get ready.


Comments

Popular posts from this blog

FCA AML Audit: Financial Regulator Takes Over Legal Oversight!

The UK government has dropped a regulatory bombshell that will fundamentally reshape your life, and yes, we are talking about the dreaded FCA AML audit. For years, you’ve been supervised by your legal peers, the SRA, but those days of relative comfort are drawing to a close. The big news? Responsibility for Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) supervision for the legal and accountancy sectors is being handed over to the Financial Conduct Authority (FCA. That's right, the same folks who put the fear of God into the big banks are now coming for your conveyancing files. Cue the dramatic music. What does the FCA take-over actually mean? Forget the gentle nudge; prepare for the financial services full-body search. An FCA AML audit is likely to look a lot more like a detailed financial inspection and a lot less like a polite chat with the SRA. Think maximum emphasison: Ironclad AML documentation (no more "it's in my head" polici...

FCA AML Audit: Why Solicitors Time to Rethink AML Compliance

If you’re a partner or a compliance officer at a law firm, I want you to take a quick second and think about your last AML review. Was it a check the box exercise to keep the SRA happy? If the answer is yes, we need to have a serious chat. The regulatory landscape for solicitors is shifting fast . The Financial Conduct Authority (FCA) is stepping onto the field with a much more active role, and they play a much tougher game than we've seen in the past. Today, we’re breaking down why the FCA AML Audit is the new essential safeguard—and why "good enough" policies just won't cut it anymore. Why the "Old Way" of AML is Riskier Than Ever Historically, many of us approached AML compliance through a traditional SRA lens. But let’s be real: that approach is becoming a major liability. The FCA’s style is risk-based, evidence-focused, and—most importantly outcome-driven. They don’t just want to see your manual; they want to see your proof. ...