AML fines continue: the conveyancing failings pattern

The SRA’s 2024–25 AML report confirms that the regulator conducted 935 proactive supervisory engagements in the year to April 2025, a 72% increase on the previous year.

Nearly a third of firms assessed were fully non-compliant; a further 54% were only partially compliant. Fines across 35 firms in 2025 alone exceeded £565,000, averaging at £16,000 per firm.

The scale of the supervisory programme is significant. The 935 engagements included 317 onsite inspections, 516 desk-based reviews, 71 thematic reviews, and 25 independent audits, during which 5,873 client files were examined in total. The number of cases referred to the Solicitors Disciplinary Tribunal rose sharply, from four in 2023/24 to 14 in 2024/25, with 13 of those resulting in a fine. Combined AML penalties across the year topped £953,000,  the highest total recorded to date.

The pattern of failures is consistent and well-documented: absent or template firm-wide risk assessments (FWRAs) not tailored to the firm’s specific risk profile; client and matter risk assessments (CMRAs) that are either missing entirely or mechanically completed without genuine analysis; and source of funds checks that collect documents but fail to verify or challenge the narrative behind them. Conveyancing remains the highest-risk area, given the large transaction values and the use of trusts and corporate structures to obscure beneficial ownership.

The SRA submitted 19 Suspicious Activity Reports (SARs) to the National Crime Agency during the year, involving suspected criminal funds totalling more than £148 million – double the figure from the previous year. Of those SARs, 73% related to property conveyancing. The SRA’s own thematic review on AML training, published in October 2024, found that staff training remains one of the most commonly deficient controls: many firms can produce a training log but cannot demonstrate that the training delivered actually resulted in fee earners understanding how to identify and respond to risk in practice.

The SRA’s warning

The SRA has been explicit: having a policy document on the shelf is not enough. Risk assessments must be risk-based, actively maintained, consistently applied across files, and evidenced in a way that withstands scrutiny. The SRA is also moving towards AI-driven supervisory targeting, meaning firms with data anomalies or gaps in their annual data returns can expect to receive proactive contact.

One particularly instructive enforcement case from the period saw a South-East London law firm – Amphlett Lissimore –  fined £114,000, calculated at 2% of annual turnover, for failing to maintain compliant policies, controls, and procedures and for having no client and matter risk assessment form or process in place across a period of several years. The SRA noted that the breaches had ‘persisted for longer than was reasonable’ and ‘had the potential to cause harm to the public interest’. The firm’s cooperation and remedial action mitigated the penalty – underlining that the starting point would have been higher still.

The transition to FCA supervision adds further urgency to this picture. The FCA’s supervisory approach is expected to be more data-driven and more unforgiving of superficial compliance than the SRA’s current model. Firms that reach the FCA transition period with incomplete risk assessments, untrained fee earners, or inadequate source-of-funds processes will face a more demanding regulator than the one that currently supervises them. The SRA’s own report notes that independent audits are now routinely requested during inspections, and that firms should treat them as an opportunity to identify and address weaknesses  – not as a box-ticking exercise.

Actions for you:

  • Check that your FWRA is genuinely firm-specific rather than a generic template. The SRA has consistently found that many FWRAs are templated documents that do not reflect the firm’s actual client base, practice areas, or geographic risk profile. A firm-wide risk assessment should be reviewed and updated at least annually, and whenever there is a material change in the firm’s work or client mix.

  • Audit a sample of recent CMRAs to ensure they include documented source-of-funds analysis, not just identity documents. Collecting a bank statement or proof of address is not, by itself, a source-of-funds check. The SRA expects firms to interrogate the narrative behind the funds: where did they originate, does that account for the full amount, and does the explanation make commercial sense? Fee earners should be trained to challenge, not simply record.

  • Ensure all AML training is logged and that MLCOs have active oversight and clear reporting lines. Training logs must record not just that training was completed but that it was understood and applied. The SRA’s thematic review on AML training found that management engagement is equally essential – staff take their cue from the tone set at the top of the firm, and AML should appear regularly on board and management agendas, not just in the compliance officer’s inbox.