How Often Should Your Firm Conduct an Independent AML Audit?

There is no universal rule requiring every law firm to conduct an independent AML audit every one or two years. The correct frequency must be determined by risk, recorded by the firm and reconsidered when its business or exposure changes.

That does not mean frequency is optional. Regulation 21 of the Money Laundering Regulations 2017 requires an independent AML audit function where appropriate to the size and nature of the business. The current Legal Sector Affinity Group guidance says that firms should take a risk based approach to frequency and that regular audits, including annual audits, may be appropriate.

The practical question is therefore not simply, “When was our last audit?” It is, “Does our audit programme provide sufficiently current assurance for the risks our firm is carrying today?”

What does Regulation 21 require?

Where Regulation 21 applies, the independent audit function must examine and evaluate the adequacy and effectiveness of the firm’s anti money laundering policies, controls and procedures. It must also make recommendations and monitor the firm’s implementation of those recommendations.

This is different from routine compliance monitoring. File reviews conducted by the MLRO or compliance team remain valuable, but they do not automatically amount to an independent audit of the function those individuals operate.

The starting point is the firm’s firm wide risk assessment. Relevant considerations include:

  • The nature, complexity, volume and value of the firm’s work
  • The number of partners, employees, offices and management layers
  • The client base and the jurisdictions connected with clients and transactions
  • The amount of conveyancing, corporate, trust and other higher risk work undertaken
  • The firm’s delivery methods, including remote instructions and digital verification
  • The visibility senior management has over operational files
  • Previous audit findings, regulatory contact, breaches and recurring file failures

Is an annual independent AML audit necessary?

For many conveyancing firms, an annual cycle will be a sensible and readily defensible starting point. Conveyancing combines substantial transfers of money, time pressure, fraud exposure, third party contributions and frequent source of funds questions. A control weakness can therefore affect a significant number of matters before the next review identifies it.

An annual audit should be considered particularly seriously where the firm:

  • Undertakes a substantial volume of conveyancing or other higher risk regulated work
  • Operates from several offices or through separate departments
  • Has experienced rapid growth or significant staff turnover
  • Regularly acts for companies, trusts, overseas clients or politically exposed persons
  • Accepts complex funding arrangements or significant third party contributions
  • Has previously received an SRA compliance plan, warning or adverse audit finding
  • Has identified repeated weaknesses in client and matter risk assessments, source of funds work, sanctions screening or ongoing monitoring

Annual does not mean that every audit must have identical scope. The firm may conduct a broad review of the complete AML framework and supplement it with targeted reviews of the areas presenting the greatest risk.

Can a lower risk firm audit less frequently?

A smaller firm with a simple structure and genuinely lower risk regulated work may conclude that a full independent audit is not required every year. However, it should not adopt an automatic two year or three year cycle without analysis.

The decision should be based on a written assessment that explains:

  • Why the proposed interval is appropriate for the firm’s size and risk profile
  • What internal monitoring will take place between independent audits
  • Which events will bring the next audit forward
  • Whether any higher risk department or work type requires more frequent targeted testing
  • Who approved the decision and when it will be reviewed

A firm should revisit that assessment at least annually even if it does not conduct a full audit annually. A timetable that was reasonable when approved can become unsuitable after a change in work type, personnel, systems or risk exposure.

Our earlier overview of AML compliance risks facing law firms identified recurring weaknesses in risk assessments, policies, training and source of funds work. Although that article reflects the position in 2025, those weaknesses remain useful indicators when deciding whether the interval between independent audits is still defensible.

Events that should bring an audit forward

A calendar should never prevent an earlier review. The following events should prompt the firm to reconsider whether an immediate full or targeted audit is needed.

A merger, acquisition or new office

A merger can bring together different policies, systems, risk appetites and working cultures. The LSAG guidance specifically identifies a takeover or merger as a reason to consider whether another audit is required.

A new technology or verification process

Introducing electronic identity verification, automated risk scoring, sanctions screening or a new case management workflow changes the control environment. An audit should test whether the system is configured correctly, reflects the practice wide risk assessment and is being used as intended.

A material change in services or clients

Opening a corporate department, accepting more international work or moving into a higher value property market may materially change the firm’s exposure. The audit schedule should change with it.

A regulatory finding or significant breach

An SRA visit, inaccurate regulatory declaration, compliance plan or serious internal failure should normally lead to independent testing. The purpose is not merely to confirm that a document has been rewritten. The auditor should establish whether the cause has been identified, affected files have been considered and the revised control operates effectively.

An earlier review of the Government’s AML supervision report recorded problems including outdated policies, inadequate due diligence, missing risk assessments, poor training records and weaknesses in MLCO knowledge. These are precisely the types of connected failures that can justify bringing an independent audit forward.

Repeated file review failures

A pattern of missing client and matter risk assessments, weak source of funds evidence, incomplete sanctions checks or absent ongoing monitoring suggests a systemic issue. A targeted audit should not be postponed until the next scheduled full review.

What does independence mean?

The auditor does not have to be external, but must be independent of the function being reviewed. The current LSAG guidance says that the person should not be the MLRO, MLCO, a member of the compliance team or part of the team that performed the original work.

The auditor must also have suitable AML and audit knowledge, authority to examine the relevant records and direct access to senior management. Where a firm uses an external consultant, it should satisfy itself that the individual or organisation has the necessary specialist knowledge and experience.

Our article explaining why an independent AML audit should be your first move examines the value of obtaining external scrutiny before a weakness becomes a regulatory or commercial crisis.

What should the audit cover?

The scope should follow the risks identified in the practice wide risk assessment. It should test both the design of the firm’s arrangements and what happens on actual files. Depending on the practice, this may include:

  • The practice wide risk assessment
  • AML policies, controls and procedures
  • Client and matter risk assessments
  • Customer due diligence and beneficial ownership
  • Source of funds and source of wealth enquiries
  • Enhanced due diligence and politically exposed person controls
  • Sanctions and proliferation financing controls
  • Ongoing monitoring
  • Suspicious activity reporting arrangements
  • Training, supervision and staff screening
  • Governance, record keeping and remediation of earlier findings

File sampling must also be risk based and sufficiently broad to provide meaningful assurance across the firm’s locations, work types and client base. Sampling only straightforward or recently completed files is unlikely to reveal the weaknesses that matter most.

Keep evidence of the decision and the audit

The LSAG guidance says that firms should retain records of their audits and make them available to their supervisor when requested. The record should include the scope and sampling basis, the material examined, the findings, the recommendations and senior management’s consideration of the results.

The firm should also record how each recommendation was addressed. An audit report left in a folder is not evidence that controls have improved. Our guide to what happens after a Reg 21 independent AML audit explains how findings should be converted into tracked and evidenced remedial action.

What about possible future FCA supervision?

Firms should continue to follow their present legal and supervisory obligations. They should not describe a proposed change in AML supervision as though it has already altered the regulator responsible for solicitors. However, firms monitoring the developing position may also wish to understand how an FCA AML audit could differ if the proposed supervisory arrangements are implemented. Any future planning should remain clearly distinguished from the requirements that apply today.

A practical frequency framework

There is no statutory table that assigns every firm a fixed interval. The following framework can nevertheless assist senior management:

  • Higher risk or rapidly changing firms: consider a full annual audit with more frequent targeted testing where necessary.
  • Firms with significant conveyancing exposure: annual independent assurance is likely to be a sensible starting point, supported by continuing internal file monitoring.
  • Smaller and demonstrably lower risk firms: determine the interval through a written risk assessment, review the decision annually and specify the events that will bring the audit forward.
  • Firms with a serious finding or material change: do not wait for the normal cycle. Commission a focused or full audit according to the issue identified.

The absence of a fixed statutory deadline should not be treated as permission to postpone independent scrutiny. The firm must be able to explain why its chosen frequency is appropriate and show that its audit function is capable of identifying whether AML controls actually work.

A firm that is not yet ready to commission its next audit should at least review its present arrangements against a structured AML audit checklist for law firms. A checklist is not a substitute for independent testing, but it may help senior management identify obvious gaps and decide whether the audit timetable should be brought forward.

Is your firm due for an independent AML audit?

If your previous review is no longer consistent with the firm’s present risk profile, or if significant changes have occurred since it was completed, now is the time to reassess the audit timetable.

Find out more about an independent AML audit for your firm.

This article provides general information and does not constitute legal advice. Firms should assess their obligations by reference to the Money Laundering Regulations 2017, current LSAG guidance, their supervisory requirements and their own risk profile.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *