Five SRA AML Fines in One Month: What the December 2025 Decisions Reveal

Updated September 2026: This article examines five SRA AML enforcement decisions published during December 2025. The findings and financial penalties are presented as a dated regulatory snapshot, followed by the practical lessons that remain relevant to law firms.

Five AML enforcement decisions published in December 2025 resulted in combined fines of £47,933, together with investigation costs. The firms differed in size, location and circumstances, but the regulatory findings repeatedly returned to the same weaknesses.

Those weaknesses included inadequate firm-wide risk assessments, outdated AML policies, missing client and matter risk assessments and insufficient scrutiny of source of funds.

The decisions demonstrate that the SRA does not need to establish that a firm knowingly facilitated money laundering before taking enforcement action. A failure to establish, maintain or apply the controls required by the Money Laundering Regulations can itself result in a financial penalty.

Five decisions and £47,933 in fines

Location Published Fine Principal findings
Swinton, Manchester 10 December 2025 £19,013 Inadequate FWRA, policies not regularly updated and deficient CDD, ongoing monitoring and source of funds scrutiny on five files.
Stonehouse, Gloucestershire 11 December 2025 £8,426 Four of six reviewed files had no CMRA, and the firm’s CMRA document did not comply with Regulations 28(12) and 28(13).
Shaw, Oldham 11 December 2025 £11,271 The firm failed to establish and maintain fully compliant AML policies, controls and procedures between June 2017 and January 2025.
Reigate, Surrey 12 December 2025 £2,987 Historic policy failures, failure to review and update PCPs, and periods without an up-to-date written FWRA.
Mirfield, West Yorkshire 17 December 2025 £6,236 An inadequate FWRA and PCPs over a period exceeding seven years, with no recorded CMRA on four of six reviewed files.

Each firm was also required to pay £600 towards the SRA’s investigation costs.

The failings were not merely technical

It can be tempting to describe these outcomes as penalties for missing paperwork. That understates what the SRA decisions say.

The SRA’s position was that the missing or inadequate documentation represented weaknesses in the controls designed to prevent law firms from being used for money laundering or terrorist financing.

A missing risk assessment is not simply an empty box on a file opening checklist. It may mean that the firm cannot demonstrate:

  • which risks were identified;
  • why the client or matter received a particular rating;
  • whether enhanced due diligence was considered;
  • how source of funds concerns were addressed;
  • whether changing circumstances were monitored; or
  • why the firm concluded that it was safe to proceed.

This is why the SRA may impose a fine even where there is no evidence that money laundering occurred or that a client suffered a direct financial loss.

Lesson one: a firm-wide risk assessment must describe the actual practice

Regulation 18 requires a firm to identify and assess the money laundering and terrorist financing risks to which its business is subject.

A compliant firm-wide risk assessment should reflect the firm’s real work, clients, delivery methods, geographical exposure and transaction risks. It should not simply repeat headings taken from the Money Laundering Regulations or LSAG guidance.

The assessment should help the firm answer practical questions such as:

  • Which departments conduct work within the regulated sector?
  • What proportion of matters involve conveyancing or the movement of client money?
  • How frequently are third parties providing purchase funds?
  • Does the firm act for overseas clients, companies, trusts or politically exposed persons?
  • Which delivery channels increase impersonation or identity risk?
  • What risk level should normally apply to each category of work?

A generic FWRA can create a dangerous mismatch. The firm-wide document may describe one risk appetite while fee earners apply a completely different approach on client files.

Lesson two: an AML policy requires active change control

Regulation 19 requires firms to establish, maintain and regularly review policies, controls and procedures.

Several of the December decisions involved policies that were absent, deficient or not properly updated over extended periods. A document may have been appropriate when first created but become obsolete as legislation, guidance, sanctions risks, technology and the firm’s work change.

A credible review process should record:

  • when the policy was reviewed;
  • who conducted the review;
  • which legal, regulatory or operational changes were considered;
  • what amendments were made;
  • how the changes were communicated to staff; and
  • whether training, forms and workflow systems were updated.

Firms can review available AML policies and procedures, but acquiring a template is only the beginning. It must be adapted to the practice and implemented consistently.

Lesson three: every relevant file needs a meaningful CMRA

Two of the reviewed firms had no recorded client and matter risk assessment on four of six sampled files. In one case, the CMRA document itself was also found to be noncompliant.

A CMRA should translate the firm-wide risk assessment into a decision about the individual client and matter. It should be specific enough to explain why the work is considered low, standard or high risk.

The assessment should address relevant factors including:

  • the nature and purpose of the transaction;
  • the client’s circumstances and instructions;
  • the source and structure of the funding;
  • third party involvement;
  • geographical risk;
  • company, trust or beneficial ownership structures;
  • sanctions and PEP results;
  • remote instruction or identity risks; and
  • any unusual urgency, complexity or inconsistency.

The AML Client and Matter Risk Assessment framework provides a structured approach to recording those considerations.

The CMRA must also remain under review. New information arising during the matter may require a different risk rating, additional due diligence or escalation to the MLRO.

Lesson four: source of funds involves scrutiny, not collection

The highest fine in the group included findings concerning customer due diligence, ongoing monitoring and source of funds across five files.

Obtaining a bank statement is not the same as scrutinising source of funds. The fee earner must consider whether the evidence explains the origin of the transaction money and whether it is consistent with what is known about the client.

Relevant questions may include:

  • How was the money accumulated?
  • Why is it being transferred from this account?
  • Does the account belong to the client or a third party?
  • Are recent credits explained?
  • Is the level of savings consistent with the client’s occupation and circumstances?
  • Is the arrangement consistent with the lender’s instructions?

Our article Paperwork Is Not a Shield examines a separate December 2025 decision in which the firm had foundational AML documents but failed to apply its controls consistently at matter level.

Lesson five: remediation helps, but does not erase the breach

The decisions show that cooperation, admissions and prompt remediation can affect the financial penalty. They do not normally remove responsibility for the historic failure.

Several firms received credit for bringing their AML arrangements into compliance, cooperating with the investigation or admitting breaches at an early stage. The SRA still imposed financial penalties because the firms had operated without adequate controls for significant periods.

This means a firm should not postpone remediation simply because earlier noncompliance cannot be undone. Corrective action may:

  • reduce the likelihood of repetition;
  • limit the period of continuing breach;
  • protect current clients and matters;
  • demonstrate cooperation and responsible management; and
  • provide mitigation if the SRA subsequently investigates.

What should an MLRO or managing partner do now?

A proportionate internal review should begin with evidence rather than reassurance. The firm should test whether its documents and systems operate in practice.

Priority checks include:

  1. Review the FWRA. Confirm that it reflects the firm’s current work, clients, delivery methods and geographic exposure.
  2. Review the AML policy. Check that it reflects current law, guidance and the firm’s actual procedures.
  3. Sample live and closed files. Select files across fee earners, offices, departments and risk levels.
  4. Examine CMRAs. Check that the ratings are supported by matter-specific reasoning and remain under review.
  5. Test source of funds. Look for scrutiny and documented conclusions rather than the mere presence of statements.
  6. Check escalation. Confirm that higher-risk matters and unusual circumstances are referred appropriately.
  7. Record remediation. Assign responsibility, deadlines and evidence of completion for each identified weakness.

Why independent AML audit findings matter

An independent AML audit under Regulation 21 should examine both the design and implementation of the firm’s policies, controls and procedures.

A document-only exercise may confirm that an FWRA and AML policy exist while missing the same matter-level failures identified in the December decisions. The audit should include a representative file sample and test whether fee earners are following the stated procedures.

Our guide to how often a firm should conduct an independent AML audit explains why audit frequency should be risk-based rather than determined by a fixed calendar interval alone.

The work should not end when the report is issued. Our later article on what happens after a Regulation 21 independent AML audit addresses remediation, ownership and follow-up testing.

Would your AML controls survive a six-file sample?

An independent AML audit can compare the firm’s FWRA and policies with what is actually recorded on individual client files.

Find out more about independent AML audits

The continuing message from the December decisions

These decisions should not be read as evidence that producing more paperwork is the solution. The recurring issue was the failure to connect firm-wide documents with everyday decisions on client files.

A defensible AML framework requires three aligned levels:

  • a firm-wide risk assessment describing the risks faced by the practice;
  • policies, controls and procedures explaining how those risks will be managed; and
  • client and matter risk assessments evidencing how the framework was applied to individual instructions.

If those levels contradict one another, or if one is missing, the firm may be unable to demonstrate compliance when the SRA selects its sample.

This article provides general information and does not constitute legal or regulatory advice. It summarises five SRA decisions published in December 2025. Firms should review the complete decisions, current legislation, LSAG guidance and applicable SRA requirements.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *