Paperwork Is Not a Shield: Why AML Compliance Must Be Evidenced on Every File

Updated September 2026: This article examines an SRA regulatory settlement published in December 2025 and the continuing importance of applying AML policies consistently at client and matter level.

A firm-wide risk assessment and a comprehensive AML policy may demonstrate that a law firm understands its obligations. They do not establish that those obligations are being followed on individual files.

That distinction sits at the heart of an SRA regulatory settlement involving a Staffordshire law firm. The firm had foundational AML documentation, but a desk-based review identified inconsistent client and matter risk assessments and inadequate scrutiny of source of funds.

The outcome is an important reminder that AML compliance is judged through evidence of what the firm actually did, not simply through the documents it had available.

What did the SRA find?

The SRA’s AML Proactive Supervision Team conducted a desk-based review involving six client files.

According to the published regulatory settlement:

  • three of the six files did not contain a client and matter risk assessment;
  • the firm failed to assess client and matter risk consistently;
  • one property transaction did not contain adequate source of funds scrutiny;
  • the firm’s approach did not provide a consistent audit trail explaining its risk decisions; and
  • the failures involved requirements under Regulation 28 of the Money Laundering Regulations 2017.

The firm was fined £2,584 and ordered to pay investigation costs of £600.

The firm had policies, but the controls were not consistently applied

This was not a case in which the firm had no understanding of AML compliance.

The SRA recorded that the firm had adequate policies, controls and procedures together with a firm-wide risk assessment proportionate to the size and nature of the business, subject to some minor guidance. Three of the six reviewed files also contained a documented client and matter risk assessment.

That evidence mitigated the potential impact, but it did not remove the regulatory breach. The problem was inconsistency. A procedure written into an AML policy is of limited value if fee earners do not apply it to every relevant matter.

The regulatory question is not merely:

Does the firm have an AML policy?

It is also:

Can the firm demonstrate that its policy was followed on this client, on this matter and at the relevant stages of the transaction?

Why the missing CMRAs mattered

Regulations 28(12) and 28(13) require a relevant person to conduct ongoing monitoring and apply customer due diligence measures on a risk-sensitive basis. A properly completed client and matter risk assessment helps the firm identify the risks presented by the client, the transaction, the source of funds, the delivery method and any other relevant factor.

A CMRA should not be a generic form completed only to satisfy a file opening checklist. It should show:

  • which risks were identified;
  • why the matter received its particular risk rating;
  • whether enhanced due diligence was required;
  • what information or evidence was obtained;
  • how unusual circumstances were resolved; and
  • whether the assessment changed during the matter.

The SRA referred to the importance of keeping risk assessment documentation current and creating a clear audit trail of the firm’s decision-making process.

A standard statement that the client is “low risk” will not achieve that if the file contains no reasoning or if the surrounding facts point towards a different conclusion.

Firms seeking a more structured approach can review the AML Client and Matter Risk Assessment framework.

Third party funding required further scrutiny

The source of funds failure arose on a property purchase for £89,500. The transaction was funded entirely by the client’s partner, with more than £90,000 received from that person.

The file contained savings account statements showing substantial available funds. However, the SRA found that the evidence did not explain how the partner had accumulated the money. There was no documented scrutiny or rationale demonstrating that the source of the wealth behind the funds had been considered.

This illustrates an important distinction. A bank statement may show where money was held immediately before it was transferred. It does not necessarily explain how the money was acquired.

Where a third party is providing the purchase money, the firm may need to understand:

  • the third party’s identity;
  • the relationship between the third party and the client;
  • why the third party is funding the transaction;
  • how the third party accumulated the money;
  • whether the payment is a gift, loan or beneficial investment;
  • whether any repayment or ownership interest is expected; and
  • whether the arrangement is consistent with the mortgage lender’s instructions.

A source of funds checklist can support consistency, but it does not replace professional judgement or the need to follow up unexplained information.

A CMRA must remain under review

A client and matter risk assessment is not complete merely because it was prepared when the file was opened.

Information obtained later may change the risk assessment. Examples include:

  • a previously undisclosed third party contribution;
  • a change in the proposed method of funding;
  • money arriving from an unexpected account;
  • a change in ownership or transaction structure;
  • new information concerning the client’s occupation or wealth;
  • an unexpected urgency or change in instructions; or
  • a new sanctions, PEP or adverse media result.

The assessment should be revisited when material information changes and again when the matter closes. The file should show what was reconsidered, what conclusion was reached and why.

The desk-based review tests the gap between policy and practice

An SRA AML desk-based review may begin with requests for documents such as the firm-wide risk assessment, AML policies, training records and details of the firm’s work.

Those documents allow the regulator to understand the framework the firm says it operates. File reviews then test whether that framework exists in practice.

That is where apparently well-prepared firms can encounter difficulty. A polished policy may describe mandatory CMRAs, ongoing monitoring and source of funds enquiries, while the sampled files show that those controls were used sporadically or not at all.

Our article on what happens after a Regulation 21 independent AML audit explains why remediation and follow-up are as important as producing the initial audit report.

What should firms check now?

Compliance officers should test actual files rather than relying exclusively on policy documents or verbal assurances from fee earners.

A practical review should examine whether:

  • every in-scope matter has a documented CMRA;
  • the risk rating is supported by matter-specific reasoning;
  • the CMRA reflects the firm-wide risk assessment;
  • source of funds and source of wealth have been distinguished correctly;
  • third party funders have been identified and assessed;
  • unusual transactions have been escalated and resolved;
  • ongoing monitoring is visible on the file;
  • the assessment was updated when circumstances changed; and
  • the closing review records any final AML considerations.

The exercise should include a representative sample across fee earners, departments, offices and risk levels. Reviewing only the files selected by the people responsible for them can produce a misleadingly positive picture.

Why an independent AML audit matters

An independent audit under Regulation 21 is intended to test the adequacy and effectiveness of the firm’s AML policies, controls and procedures. That requires more than confirming that the correct documents exist.

The audit should examine whether controls are understood, consistently implemented and evidenced on client files. It should identify the difference between the firm’s written procedure and day-to-day practice before that difference is exposed through regulatory scrutiny.

Our earlier article explains why an independent AML audit should be an early compliance step rather than a response reserved for when the SRA makes contact.

Do your files support what your AML policy says?

An independent AML audit can test the firm-wide framework against the evidence recorded on individual client files and identify inconsistencies before a regulatory review.

Find out more about independent AML audits

The lesson is implementation, not paperwork

The outcome does not suggest that AML policies and firm-wide risk assessments are unimportant. They are essential components of the compliance framework.

The lesson is that documentation at firm level must be converted into consistent action at matter level. Every risk assessment, source of funds enquiry and monitoring decision should be capable of explanation from the file.

When the SRA selects a sample, the firm may not have an opportunity to choose its best matters or reconstruct missing reasoning afterwards. The file itself must demonstrate what was considered, what was done and why.

This article provides general information and does not constitute legal or regulatory advice. Firms should consider their own risk profile, the Money Laundering Regulations, current LSAG guidance and applicable SRA requirements.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *