Crypto and Money Laundering: Due diligence implications for firms

The use of cryptocurrency in money laundering is increasingly appearing in SRA supervisory findings and national risk assessments.

Both the SRA’s 2025 AML report and the UK National Risk Assessment classify cryptoasset exposure as high risk, citing speed, pseudo-anonymity, and cross-border functionality as the primary concerns. The profession’s exposure arises not only from direct crypto transactions but from indirect routes: client funds that have passed through crypto exchanges, clients involved in the crypto industry, and the use of crypto to layer proceeds before they arrive in a matter.

This is not a niche risk confined to firms with a specialist crypto practice. The National Crime Agency estimates that more than £100 billion is laundered through the UK or UK-linked structures every year, and cryptoassets are an increasingly common tool in that process. OFSI has separately confirmed the creation of a Crypto Cash Fusion Cell – an interagency taskforce comprising the NCA, Metropolitan Police, FCA, City of London Police, and OFSI, specifically targeting criminal abuse of cryptoassets by sanctions enablers.

Significant regulatory change is also underway in the crypto sector itself. From autumn 2027, the FCA’s new cryptoasset regulatory framework under FSMA 2000 (as amended by FSMA 2023) will require firms engaged in cryptoasset activities to seek full FCA authorisation. Amendments to the Money Laundering Regulations in September 2025 require crypto firms to conduct customer due diligence on all users, monitor pooled accounts, and report suspicious activity on the same basis as banks. Trust registration obligations for crypto assets held in trust structures have also been tightened.

Additional requirements for law firms with cryptoasset business clients

The FCA already supervises UK cryptoasset businesses for AML and CTF purposes under the Money Laundering Regulations, requiring registration and compliance with the MLRs. The new authorisation regime, expected to come into force on 25 October 2027, goes further: firms wishing to carry out any of the newly regulated cryptoasset activities under FSMA will require full FCA authorisation, not just registration. Firms with clients who are cryptoasset businesses should be aware that their clients’ own regulatory status and compliance obligations are changing — and this may affect the risk profile of the matter.

For law firms, this raises the bar for source-of-funds checks where a client has any cryptoasset background. Simply accepting funds into client account without understanding their provenance – including whether they passed through crypto – will not be sufficient. The SRA’s 2024–25 AML report found repeated issues with the quality of source-of-funds and source-of-wealth checks across the profession: documents were often collected but not analysed, and in some cases explanations provided by clients did not match the actual origin of funds received into client account. Where funds have a crypto origin or have passed through a crypto exchange, this risk is heightened  – because the transaction trail, while technically visible on the blockchain, is more complex to interpret than a conventional bank transfer and may require specialist tools or advice to verify properly.

When applying enhanced due diligence in crypto-related matters, firms should consider: obtaining a detailed account of the client’s history with cryptoassets, including when assets were acquired and from which exchange or wallet; reviewing blockchain transaction records or requesting a third-party blockchain analytics report where the value of the transaction warrants it; checking whether the exchange used by the client is registered with the FCA for AML purposes; and documenting the rationale for the risk rating applied and the due diligence steps taken. A standard source-of-funds questionnaire designed for conventional bank transactions is unlikely to be adequate for matters with a crypto origin.

Actions for you:

  • Update your firm-wide risk assessment to address cryptoasset exposure explicitly. The SRA expects firm-wide risk assessments to reflect the actual risk profile of the firm’s client base and practice areas. If your firm has acted for – or is likely to act for – clients in the crypto sector, or has received funds with a crypto origin, this should be addressed in your FWRA with appropriate controls identified. Generic templates that do not address crypto exposure are unlikely to satisfy a supervisory inspection.

  • Train fee earners to identify when funds may have a crypto origin. Red flags include: clients who are involved in crypto trading, mining, or NFT activity; transactions involving funds from a wallet or exchange rather than a conventional bank account; clients reluctant to explain the source or history of their assets; and transaction values that do not correspond to the client’s known financial profile. Fee earners do not need to be crypto specialists — but they do need to know when to pause and escalate.

  • When clients are involved in the crypto industry or present crypto-derived funds, apply enhanced due diligence and document your reasoning. Enhanced due diligence in this context means going beyond standard identity and source-of-funds checks. It means understanding the provenance of the assets, verifying the client’s explanation, and documenting why you were satisfied or why you were not and what you did about it. The SRA’s enforcement record shows clearly that documenting a decision, even an imperfect one, is significantly better than not documenting at all.

  • Consider whether your standard source-of-funds questionnaire is adequate for this risk. If it was designed for conventional transactions and does not ask about crypto wallets, exchanges, or prior conversion of digital assets, it needs to be updated. A short additional section covering crypto origins or a separate supplementary questionnaire for matters where crypto exposure is identified  is a straightforward and proportionate control.