SRA AML Audits: What Law Firms Need to Evidence

Originally published December 2025. Updated October 2026.

SRA AML audits and desk-based reviews examine whether a law firm’s anti-money laundering controls work in practice. Having a policy, a risk assessment and training certificates is only the starting point. The firm also needs evidence that its procedures are understood, applied and supervised.

For managing partners, MLROs and MLCOs, preparation should begin with a practical question: do the documents describe what the firm actually does, and do the files demonstrate it?

Would your AML arrangements withstand a file review?

An independent review can help identify gaps between your risk assessments, policies and day-to-day practice, with recommendations for improvement.

Explore Lexsure’s independent AML audits

What the SRA’s published figures show

The SRA’s 2024–25 AML annual report, published in October 2025, recorded 935 proactive AML engagements during the reporting period from 6 April 2024 to 5 April 2025.

Of the 833 firms assessed through proactive inspections or desk-based reviews, 112 were compliant, 451 partially compliant and 270 not compliant.

These are findings from firms examined through the SRA’s supervisory programme, not a compliance rate for the entire profession. They nevertheless demonstrate why firms should test their arrangements before receiving a regulatory enquiry.

What an SRA AML review may examine

The SRA’s report describes examination of firm-wide risk assessments, policies, controls and procedures, client and matter risk assessments and sampled files. Onsite work may also include interviews and examination of training records, independent audit reports and reporting records.

Preparation therefore needs to connect the firm’s written framework with its operational evidence. A well-presented policy cannot explain away a file on which required checks were not undertaken.

The SRA’s AML guidance and supporting resources should be read alongside the applicable regulations and current LSAG guidance.

Start with the firm-wide risk assessment

The firm-wide risk assessment should reflect the practice’s actual work, clients, delivery channels, geographical exposure and transaction patterns.

A generic document may omit important risks or describe services the firm does not provide. Review it when relevant circumstances change and record the reasoning behind the assessment.

The assessment should inform the controls adopted by the firm. Our article on the AML evidence chain linking the FWRA, policies and matter assessments explains why these documents need to tell a consistent story.

Policies must describe a workable process

AML policies, controls and procedures should explain who does what, when checks are required, how concerns are escalated and what evidence must be retained.

For example, a policy requiring source-of-funds enquiries should be supported by a process that staff can follow and supervisors can test. Buying a template or updating a paragraph does not establish that the procedure has been implemented.

Review whether your written arrangements address:

  • Client identification and beneficial ownership.
  • Client and matter risk assessment.
  • Source-of-funds enquiries and source-of-wealth enquiries where appropriate.
  • Enhanced due diligence and ongoing monitoring.
  • Internal reporting and escalation.
  • Record keeping, supervision and responsibility for updates.

Client and matter risk assessments should explain the decision

A risk rating is useful only if the file explains why it was selected and how it affects the work undertaken.

Assessments should address the particular client and transaction. They should also be reconsidered when new information changes the risk, rather than remaining a form completed at the start and never revisited.

The CDDmonitor client and matter risk assessment resources explain how structured assessments can support the process. The quality of the information and professional judgment remain essential.

Training should be relevant, regular and recorded

Regulation 24 requires regular AML training for relevant employees and relevant agents, together with written training records. It does not prescribe a universal annual course for every employee regardless of role.

Training should reflect responsibilities, exposure to risk and changes in the firm’s work or procedures. MLROs, MLCOs, supervisors and staff handling transactions may need different content.

The SRA’s thematic review of AML training provides examples of good and poor practice.

Keep evidence of what was covered, who attended and how gaps were addressed. Consider whether staff can apply the training to the situations they encounter.

An independent AML audit is different from an SRA inspection

An SRA review is regulatory supervision. An independent AML audit examines the firm’s arrangements as part of its own control framework.

Under Regulation 21, the requirement to establish an independent audit function applies where appropriate to the size and nature of the business. The assessment should not be reduced to a headcount threshold or an assumption that every practice has identical obligations.

The function includes evaluating the adequacy and effectiveness of AML policies, controls and procedures, recommending improvements and monitoring compliance with those recommendations.

Read more about the scope and preparation involved through CDDmonitor’s independent AML audit page and the practical resources at AML Audit Solutions.

Remediation needs evidence and follow-up

When weaknesses are identified, record the action required, the responsible person, the deadline and how completion will be verified.

Distinguish between updating a document, introducing a procedure and demonstrating that the procedure works. Those are separate stages.

For example, revising the source-of-funds policy may need to be followed by staff briefing, review of affected matters and sampling of new files. The audit report should become the starting point for improvement rather than a document filed away.

Do not overlook lender panel consequences

For conveyancing firms, a regulatory finding may also prompt separate enquiries from lenders or panel managers. The firm should check the applicable notification obligations and respond accurately with supporting evidence.

Our article on AML breaches and lender panel removal considers why remediation may need to address both regulatory and commercial concerns.

Prepare before the request arrives

Use the SRA AML audit preparation checklist as a starting point, then test the answers against your documents and sampled files.

The most useful preparation identifies discrepancies early: a policy that staff do not follow, an assessment unsupported by the evidence or an action plan that has never been completed.

Need an independent view of your firm’s AML controls?

Discuss a review of your risk assessments, policies, sampled files and implementation. Identify what needs improvement and how the firm will evidence the changes.

Discuss an independent AML audit