SRA's updated Sectoral Risk Assessment: What's moved, what's new, and what it means for your firm
Home » SRA’s updated sectoral risk assessment: What’s moved, what’s new, and what it means for your firm
Anne Austin
Director
On 6 August 2026, the Solicitors Regulation Authority updated its sectoral risk assessment for anti-money laundering, terrorist financing, proliferation financing and sanctions.
It will come as little surprise to lawyers that conveyancing remains the sector’s highest inherent money laundering risk. High-value transactions, large sums moving through client account, time pressure, opaque ownership structures and the ability to turn criminal proceeds into legitimate-looking property all make it attractive to criminals. The SRA’s message is clear: source of funds and source of wealth checks remain one of the most important controls firms can use to manage that risk.
Transfer through a UK bank account does not by itself indicate that funds are legitimate." - SRA Sectoral Risk Assessment, updated 6 August 2026
SRA Guidance
That line, buried in the transaction risk section, is worth pinning to every conveyancing and finance team wall. It directly challenges one of the most common reasons we hear for missing or inadequate source of funds checks: treating a UK-regulated bank as a proxy for clean money -a point Victoria Marshall of Pearson Legal highlighted effectively last month.
What’s changed since last year
A few risks that were “emerging” in last year’s update have now been integrated into the established framework. Risks relating to client accounts, politically exposed persons (PEPs), and supply chains are no longer treated as “emerging” or thematic watch-items. They are now folded directly into the established baseline risk framework. If a firm’s FWRA still categorises these as future or emerging watch-items, it will be considered non-compliant.
One notable removal is the perceived risk of the decentralised nature of consultant-led law firms. The 2026 version drops that concern, alongside broader risks tied to firm business models, which the SRA says were removed as “not specific to the AML sphere”. Consultant-model firms should not read this as the risk disappearing, because robust central AML oversight remains good practice, but it is a useful signal of where the regulator’s current attention sits.
What’s new
The SRA identifies several current and emerging risk areas.
- Cash-intensive businesses and high street crime.
The SRA now flags cash-intensive businesses and nominee arrangements as a heightened risk, because beneficial ownership, control and source of funds can be hard to establish. This follows an NCA operation last October that saw police raid 2,734 high street premises – mini-marts, barbershops, vape shops, nail bars and car washes – arresting 924 people and seizing £10.7m in suspected criminal proceeds. The risk assessment specifically calls out so-called “ghost directors”: individuals who allow their names to appear on company documentation for a fee while having no real involvement in the business. The SRA also advises vigilance for businesses whose turnover, profitability or activities appear inconsistent with their size, age or apparent operations. Firms doing commercial property work for cash-intensive businesses, or company work involving nominee directors, should expect closer scrutiny of these matters.
- Passporting
The SRA warns against relying on due diligence carried out by another department, office, or jurisdiction on a prior matter without checking whether it remains appropriate for the current instruction. This is an issue we often see during Reg. 21 audits and is a useful prompt for multi-office or multi-department firms to review internal file-transfer protocols.
- Company registration integrity.
Following Companies House reform, 920 companies entered expedited strike-off in the past year for providing false information. The SRA’s practical warning is that: criminals using struck-off shell companies may still be holding onto old Companies House documentation and presenting it as current. So, if you don’t already do so, build a Companies House check into your standard AML process, rather than simply relying on a company’s own paperwork.
- AI/deepfakes and cyber fraud.
There is a sharper focus on AI-enabled fraud and deepfakes, reflecting FATF’s recent work on AI-enabled impersonation risk in remote client onboarding. We’ve written about the governance gap many firms still have around AI use, and this update confirms that an AI policy is no longer just an internal governance issue: it now has a direct AML dimension.
AI-enabled impersonation techniques, including deepfakes, may increase the risk of identity fraud and misrepresentation during client onboarding and throughout the life of a matter. The risk may be greater where firms rely on remote verification methods or digital onboarding processes. On the identity verification side, the direction remains the same as we set out earlier this year in our piece on digital ID and AML compliance. Digital identity is moving from a convenience to an expected part of a well-functioning compliance framework. Firms should check their provider appears on the government’s Digital Identity and Attributes Trust Framework (DVS) register, with a new version of the framework and the CertifID trust mark both expected later in 2026.
Cyber-enabled fraud, intersecting with other areas of organised crime, is also highlighted as a key money laundering risk. Referencing FATF’s paper, the SRA notes that cyber-enabled fraud, including mandate fraud or social engineering, can generate criminal proceeds, and firms may either be used as a conduit or be attacked directly.
- Global instability and uncertainty
This new section has encapsulated and revised the emerging risks of economic uncertainty and capital flight, and moved sanctions risk firmly into the spotlight.
Sanctions obligations apply more broadly than the Money Laundering Regulations , covering any matter involving a designated person or sanctioned jurisdiction regardless of whether it falls within AML scope, and payments through a firm’s client or office account, including fees.
The standout addition is Russian sanctions circumvention techniques, four years on from the invasion of Ukraine. The risk assessment points firms to government guidance on goods being routed through third countries to support Russia’s war effort, including items that appear innocuous on paper: printing inks, oil lubricants, paints, varnishes and industrial heat exchange units among them. For firms advising on trade, export or corporate matters with any cross-border dimension, that’s a reminder that sanctions risk will not always announce itself through an obviously high-risk client or jurisdiction.
The risk assessment also sets out common weaknesses in firms’ sanctions screening: over-reliance on automated tools, weak understanding of ownership and control arrangements, and insufficient senior oversight. Firms should also note the new emerging risk around licensing breaches – including missing reporting deadlines, exceeding costs caps under the legal services general licence, and continuing to act after a licence has y expired. These process failures are entirely preventable with proper key dates systems and are exactly the sort of gap an independent audit tends to catch before the regulator does.
Wider risks
The SRA’s emerging-risks section is a reminder that risks rarely sit in neat boxes. It links global instability to increased corruption, sanctions evasion, illicit asset movement and proliferation financing risk, particularly where clients, funding or structures involve PEPs, opaque ownership, offshore arrangements, hard-to-verify wealth, or higher-risk jurisdictions and sectors.
AI-enabled impersonation, cyber-enabled fraud, cash-intensive businesses, nominee arrangements, offshore structures, PEP connections and global instability can all overlap in a single matter.
For firms, the practical question is not simply whether a client falls into one named risk category, but whether the overall picture — ownership, control, funding, geography, transaction value and urgency — makes sense.
How the profession is responding
It would be misleading to present this update as landing on a sector that’s calm and settled. The SRA’s AML Annual Report for 2024–25 recorded 935 proactive AML engagements – almost double the 545 of the previous period – with 833 firms subject to an onsite inspection or desk-based review, and sanctions-specific inspections running at 47 for the year. Fines have become more frequent and more severe, including against firms holding CQS and Lexcel accreditation, which the SRA has said should not be treated as a substitute for a firm’s own AML controls.
That intensity hasn’t gone unnoticed. Discussion among solicitors – and feedback from our own clients – shows real frustration with the mounting compliance burden, alongside scepticism about the regulator’s own effectiveness following its censure by the Legal Services Board over its handling of warning signs ahead of the SSB Group collapse. The tension is understandable: firms are being asked to shoulder increasingly detailed AML and sanctions obligations while confidence in the supervisor’s own judgement has taken a public knock.
Why this matters against the wider backdrop
Whatever view practitioners take of the SRA’s record, the practical reality is unchanged: the compliance bar keeps rising, and the FCA transition is likely to bring closer, more data led scrutiny. Firms assessed as higher risk under the National Risk Assessment should expect more intensive scrutiny once that transition happens. Getting the fundamentals right now – a compliant FWRA and AML policy, controls and procedures, fully investigated and recorded source of funds checks, and thoughtfully completed client and matter- risk assessments- isn’t just about satisfying the SRA. It’s about building a compliance system that will hold up under a regulator with sharper, more data-driven scrutiny.
What firms should do now
- Update your FWRA to reflect the 2026 SRA sectoral risk assessment. The SRA will ask for your FWRA if you’re selected for a proactive inspection or desk-based review and you should be able to demonstrate that you’ve considered and documented the latest risks
- Review CDD and EDD procedures for cash-intensive business clients and any matters involving nominee or unconnected directors. Are they sufficiently robust?
- Check your protocols for relying on due diligence carried out by another team or office on a prior instruction, particularly across multi-office or multi-department firms, or where clients frequently passport between departments. Amend your AML PCPs accordingly.
- Build a Companies House search into your onboarding process for company clients, regardless of whether they provide you with documentary evidence
- Review whether your digital identity verification provider is listed on the government’s DVS register
- Check that your sanctions screening isn’t over-reliant on automated tools alone, and that ownership and control analysis goes beyond a name-match
- Diarise sanctions licence deadlines and cost caps so nothing lapses or is exceeded by accident (if relevant)
- If you haven’t had an independent AML audit in the past 12 months, now is a sensible time.
Anne Austin is Founder of Enderley Consulting, providing compliance advice and support to SRA- regulated law firms, including Reg. 21 AML audits, FWRA and AML PCP drafting, AML training, compliance gap analysis, and manual drafting, COLP and COFA support retainers, CQS and Lexcel consultancy.