The Financial Conduct Authority says it wants to work in partnership with solicitors when it assumes responsibility for anti money laundering supervision of the legal sector. That is an important and constructive message. It is not, however, an invitation for firms to relax.
The FCA has indicated that it expects to begin supervising approximately 60,000 legal and accountancy entities towards the end of 2028. Its stated intention is to be proportionate, risk based and intelligence led, with a focus on criminals and the minority of professional firms that enable financial crime.
As reported by the Law Gazette, the language is one of partnership. The FCA’s own speech to the Law Society Economic Crime Conference also stresses communication, trust and engagement with the profession.
For well run firms, that should be reassuring. It should not be confused with light touch supervision. A regulator promising to avoid unnecessary burden may still expect clear evidence that a firm’s controls are proportionate, understood and effective.
Partnership is not immunity from scrutiny
A productive relationship between regulator and profession should improve the quality of supervision. The FCA can learn more about how legal work is undertaken, while firms can obtain clearer expectations and more consistent engagement.
But partnership does not alter the underlying question that every supervised firm must be ready to answer: can it demonstrate that its AML framework works in practice?
The answer will not be found in a policy document alone. It will be found in the connection between the firm’s risk assessment, its procedures, the decisions recorded on individual files, the quality of supervision and the action taken when weaknesses are identified.
The regulator changes, but the rules do not disappear
The planned transfer of supervision does not replace the Money Laundering Regulations 2017. Firms must continue to comply with their existing obligations while the transition is prepared and after the supervisory responsibility changes.
Those obligations include a firm wide risk assessment that reflects the risks actually faced by the practice, policies and controls designed around those risks, proportionate client due diligence, ongoing monitoring and an independent audit function where appropriate to the size and nature of the business.
The practical significance of this continuity is examined in Mastering the FCA AML Audit: Is Your Law Firm Ready?. The regulator may change, but firms should not wait for a new supervisory handbook before testing whether their present arrangements are effective.
What intelligence led supervision may mean in practice
The FCA says it will use data, technology and intelligence to identify risk. It already processes very large volumes of information across the sectors it supervises, while recognising that technology does not replace human judgement.
For solicitors, the important point is not whether an automated system will decide that a breach has occurred. The more immediate issue is whether data or intelligence may prompt a focused inquiry. If it does, the firm may need to explain its risk decisions clearly and promptly.
A firm should therefore be able to show why a matter was classified at a particular risk level, what due diligence was undertaken, how source of funds and source of wealth concerns were resolved, who approved any departure from normal procedure and whether monitoring continued as the transaction developed.
Records that merely confirm that a box was ticked may be of limited value if they do not explain the professional judgement behind the decision.
Less unnecessary paperwork does not mean less evidence
The FCA has said that it does not want a one size fits all model or paperwork that adds burden without improving outcomes. That should encourage firms to remove duplication and design controls that reflect their genuine risks.
It does not mean that records are unimportant. Proportionate supervision still depends on evidence. A concise and meaningful assessment is likely to be more useful than a lengthy generic form, but the file must still show what was considered, what was decided and why.
This distinction matters in conveyancing, where transaction pressure can turn a risk assessment into a routine opening form. The client and matter risk assessment should remain live. It may need to change when new parties appear, funds arrive from an unexpected source, the transaction structure alters or information conflicts with the original instructions.
What partnership should look like inside the firm
A firm’s relationship with its regulator is only one part of the picture. Effective AML compliance also depends on an honest internal relationship between fee earners, the MLRO, compliance officers and senior management.
That means creating an environment in which concerns can be escalated without commercial pressure, management information is examined rather than merely circulated, and remedial actions are assigned to named individuals and followed through to completion.
Before the supervisory transfer, firms should be able to demonstrate:
- a current firm wide risk assessment tailored to the practice;
- policies, controls and procedures that correspond with the risks identified;
- client and matter risk assessments that record meaningful reasoning;
- consistent source of funds and source of wealth enquiries;
- effective sanctions, politically exposed person and adverse information checks;
- clear internal reporting and suspicious activity escalation routes;
- training that is relevant to each person’s work;
- senior management oversight supported by reliable information; and
- a documented process for correcting weaknesses and confirming that remediation has worked.
Independent audit tests whether the evidence holds together
Regulation 21 requires an independent audit function where this is appropriate having regard to the size and nature of the business. Independence does not necessarily mean that the work must always be outsourced. It does mean that the review must be sufficiently objective and must test the framework rather than simply endorse it.
A useful audit should examine whether policies are being followed on live and completed matters, whether risk assessments contain defensible reasoning, whether staff understand escalation procedures and whether earlier findings have been corrected.
The purpose is not to generate another badge or certificate. It is to identify the gap between the firm’s written framework and what happens in practice. Our guide to what solicitors need to know about preparing for an FCA AML audit explains the evidence that firms should start assembling and testing.
Use the period before 2028 properly
The transfer timetable gives firms an opportunity to improve before FCA supervision begins. It should not be treated as a reason to postpone action. Current regulatory duties continue to apply, and weaknesses identified now can already expose a firm to enforcement, reputational damage and commercial consequences.
Our earlier article, The FCA AML Audit: Are Conveyancing Firms Ready?, considers how an evidence led supervisory model may affect conveyancing practices. The latest FCA comments add an important dimension: the regulator wants engagement with the profession, but it also expects firms to take responsibility for the effectiveness of their own controls.
The sensible response is not to speculate about the precise form of a future FCA inspection. It is to ask whether the firm could defend its present arrangements today.
The question firms should ask now
Partnership can improve supervision, but it cannot substitute for preparation. A firm that understands its risks, tests its controls and records its reasoning should be better placed to engage constructively with any regulator.
The real question is therefore not whether the FCA intends to be cooperative. It is whether the firm can provide reliable proof that its AML system deserves the regulator’s confidence.
Test your AML framework before the regulator does
Lexsure provides support with AML policies and procedures, firm wide risk assessments, client and matter risk assessments, training and independent AML audits.
This article is for general information only and does not constitute legal or regulatory advice. Firms should consider their own circumstances and the current legislation, guidance and supervisory requirements.
