Firmwide risk assessments: turn the SRA framework into a document that reflects your firm

A firmwide risk assessment (FWRA) should explain how your firm could be exposed to money laundering and terrorist financing, and what you do about those risks. It is not a generic AML statement or a form to complete once and file away. It is the firm-level foundation for your policies, controls and procedures, and it should help fee-earners make better-informed client and matter risk assessments.

The Solicitors Regulation Authority’s firmwide risk assessment guidance sets out the legal framework and the areas firms should consider. Its template can help structure the work, but the assessment needs to reflect your firm’s actual clients, services, transactions and controls. The SRA updated its guidance on 19 June 2026, so use the current version when reviewing your document.

What the FWRA has to do

Regulation 18 of the Money Laundering Regulations 2017 requires an in-scope firm to identify and assess the money laundering and terrorist financing risks to which its business is subject. The written assessment should be appropriate to the size and nature of the firm, take account of the SRA’s sectoral risk assessment and address the relevant risk factors in the firm’s business.

The SRA identifies five core areas to consider:

  • your clients;
  • the countries or geographic areas in which you operate, or to which clients and matters are connected;
  • the products and services you provide;
  • your transactions; and
  • how your products and services are delivered.

Regulation 18A also requires firms to assess proliferation-financing risk. That can be covered in the FWRA or in a separate assessment. The right format depends on the firm; the risk itself still needs to be considered.

The assessment should set out the firm’s exposure and explain how the firm reached its conclusions. It should also identify how the risks will be mitigated. The SRA says the FWRA should be regularly reviewed, kept up to date and approved by senior management. A template can help structure the work, but the SRA warns firms against copying specimen text without tailoring it.

Start with your real practice, not the template

The SRA template begins with basic information about the firm, its MLCO and MLRO, number of fee-earners and the proportion of work that falls within the Money Laundering Regulations. Those details matter: they give context to the risk assessment and help the firm explain the scale and shape of its regulated work.

Before rating risks, gather information the firm can support. For example, review the types and locations of clients, matter volumes, services provided, transaction values and funding patterns, referral sources, office locations, remote working arrangements and relevant audit or file-review findings. Use current internal data where possible. If a figure is an estimate, say so and explain its basis.

A useful firm profile might describe the balance of individual and corporate clients, client turnover, referral channels and common funding sources. Use your own figures and evidence. Another firm’s client mix or risk ratings are not a substitute for assessing your own practice.

1. Assess the clients your firm actually serves

Describe the firm’s client profile and usual patterns of business. Consider the kinds of people and organisations that instruct you, how they come to the firm, whether they are repeat or new clients, and whether the firm often acts for clients with features that may increase risk.

The SRA guidance prompts firms to think about politically exposed persons, high-net-worth individuals, clients with cash-intensive businesses, complex or layered ownership, clients whose identity is difficult to verify, sanctioned persons and clients with links to higher-risk jurisdictions. The useful question is not simply whether any of these categories could appear. It is how likely they are in your practice, what the firm knows about them, and what staff should do when the risk arises.

Referral routes are part of the picture too. Record whether work comes from estate agents, other introducers, online enquiries, existing clients or walk-ins. A referral does not remove the need to understand who the client is, why they are instructing the firm or whether the matter fits the client’s normal activity.

2. Map geographic connections carefully

Geographic risk is broader than the location of the firm’s offices. Consider where the firm operates, where clients live or do business, where their income and assets are located, and where the property or other matter is connected. Include relevant international connections even if most of the firm’s work is local.

Consider corruption, sanctions, currency controls and high-risk countries, using reliable sources as well as the firm’s own experience. Make the analysis proportionate to the firm: a local residential conveyancing practice may have a different exposure from a firm handling international corporate or commercial property work. Avoid unsupported blanket statements such as “all clients are low risk” or “we do not act internationally” if the firm has not checked the evidence.

3. Describe each service and the risks it can create

List the services the firm actually provides and assess the risks associated with them. For a property practice, this may include residential and commercial work, purchases and sales, lease extensions and enfranchisement, and landlord and tenant matters. The point is to be precise: a broad label such as “property work” may hide materially different services and risk profiles.

For a conveyancing firm, consider the nature of the transactions you handle, the client types involved, the use of companies or trusts, third-party funding, unusual ownership structures, and whether the firm controls client money. Also identify work that falls outside the Money Laundering Regulations where relevant; the assessment should accurately describe the firm’s activities rather than assume every service is treated the same way.

4. Explain what is typical and what would be unusual

The transaction section should describe the kinds of transactions the firm handles, their typical size and frequency, and the features that could make a matter unusual. Consider complex or unusually large transactions and those that may facilitate anonymity. Include non-monetary transactions where relevant.

Put transaction values in context. A figure that is ordinary for one client group or local market may be unusual for another. Explain how the firm decides whether a transaction is consistent with what it knows about the client, the client’s wealth and the purpose of the matter. Where the firm identifies a higher-risk feature, the FWRA should lead to practical steps in its policies and client or matter assessment process.

5. Include the way work reaches and is delivered to clients

Consider delivery channels, including in-person contact, email, telephone, video calls and online portals. Explain which channels the firm uses and how they affect its ability to identify clients, understand instructions, communicate securely and notice unusual behaviour.

Remote onboarding, online messaging and introducer relationships should be assessed in the context of the firm’s controls. Simply listing a channel is not enough: show how the firm manages the risks that come with using it.

Show your method and connect the risks to controls

Make the methodology easy to identify; name the sources and approach used to assess risk; state the risks clearly; explain the risks rather than relying on labels; keep the assessment current; retain previous versions; use simple risk-rating terms; and distinguish inherent risk from risk after mitigation.

That last distinction is important. Inherent risk is the exposure before the firm’s controls are applied. Residual risk is what remains after those controls. A low residual rating should not obscure a high inherent risk: the document should show what controls reduce the exposure and how the firm knows they operate.

For example, if the firm identifies higher exposure from overseas funding, its assessment should connect that risk to the firm’s source-of-funds and source-of-wealth processes, escalation routes and staff guidance. If referral arrangements are relevant, explain how the firm manages conflicts, client choice, due diligence and the possibility that a referral source may not provide a complete picture of the client. The control should answer the risk identified, rather than sit in the document as a generic promise.

The FWRA and client or matter risk assessments do different jobs. The firm-wide document assesses the business as a whole; the client or matter assessment addresses the specific relationship or transaction. They should correspond: staff should be able to use the themes in the FWRA when assessing individual files, and lessons from file reviews should inform the next review of the FWRA.

Review it when the firm or its risk environment changes

A calendar review is useful, but a material change may call for an earlier review. Examples include adding or closing an office, starting a new service, changing the client base, taking on a new introducer, expanding international work, changing onboarding or payment methods, or finding recurring weaknesses through audits and file reviews. Record what was reviewed, what changed, who approved the assessment and why any section remains unchanged.

Keep earlier versions. They help the firm show how its understanding developed and make it easier to explain why a risk rating or control changed. A current date on the front page is not, by itself, evidence that the content has been reconsidered.

Using a template or getting tailored support

The SRA’s template is a useful framework, but it is not a finished assessment for your firm. Tailor it to your own clients, locations, work types, transaction patterns, delivery channels and controls. The SRA’s current FWRA guidance and sectoral risk assessment should be part of that review.

For firms looking for AML FWRA information and ongoing support, CDDmonitor’s AML firm-wide risk assessment page explains its AML Audit Help Desk and related support. This is a resource for firms considering how to prepare and maintain their assessment.

For firms seeking a bespoke drafting engagement, Policy Templates’ FWRA assessment service describes a consultative process to develop an assessment around a firm’s particular practice. That is a different route: the focus is on producing a tailored assessment through a dedicated engagement.

Neither a template nor external drafting support transfers responsibility away from the firm. Senior management must understand and approve the assessment, and the firm must make sure its policies, controls, procedures and file-level assessments reflect the risks it has identified.

Further reading

This article is general information for conveyancing firms and is not legal advice. Check the current legislation and SRA guidance when reviewing your firm’s arrangements.