International Fraud Awareness Week: Why law firms must strengthen fraud defences

Whilst AML controls and compliance are at the forefront of most COLPs’ and MLROs’ minds, fraud continues to be one of the most disruptive and costly risks facing UK law firms. And while fraud often overlaps with money laundering, fraud risks should be assessed separately.

As criminal tactics evolve, firms need systems that are robust, agile, and ready for emerging threats. International Fraud Awareness Week, founded by the Association of Certified Fraud Examiners (ACFE) is an ideal moment for firms to review their controls, training, and governance.

Why law firms are attractive targets for fraud

Law firms handle large sums of client money, operate under significant time pressure, and rely heavily on client trust – all factors that create opportunities for internal and external fraudsters. Weak internal controls – limited segregation of duties, lack of supervision, or no independent audit function – can leave smaller firms exposed.

Internal and external fraud risks affecting law firms include:

  • Employee dishonesty i.e. fictitious or inflated expenses claims; misuse of the office credit card for personal purchases; theft from client or office account, including diversion of client money or fees to a personal account

  • Cyber-fraud including social engineering (tricking staff into revealing sensitive information, granting access to the firm’s systems, or performing actions that compromise security) and Friday afternoon fraud (fraudsters impersonating a homebuyer or their solicitor by hacking into their emails and sending a fake email with altered bank details for the funds transfer)

  • Property and mortgage fraud – including clients making false representations of their earnings or the value of property; vendor fraud (impersonating the property owner to sell the property without the owner’s knowledge)

Essential measures for preventing fraud in law firms 

The Economic Crime and Corporate Transparency Act which passed into law in September 2025 introduced the failure to prevent fraud offence. Only large law firms are affected by this, but the Home Office guidance on fraud prevention procedures is equally applicable to firms of all sizes. This states that organisations should develop a fraud prevention framework , based on the following six principles:

  • Top-level commitment – the board of directors, partners and senior management should be committed to prevent fraud, and operate in an open culture of transparency where staff feel able to raise any ethical concerns and fraud is never acceptable. Provide confidential, trusted channels for reporting concerns.

  • Fraud risk assessment – assessing the nature and extent of the firm’s exposure to the risk of employees, agents, clients and other associated persons committing fraud. Consider ‘the fraud triangle’ of opportunity, motive and rationalisation. The risk assessment should be dynamic, documented and kept under regular review.

 

Figure 1: The 'Fraud Triangle'
  • Fraud prevention policies and procedures – these should be proportionate and risk based.

    – Review the firm’s existing regulatory compliance framework, financial reporting controls and fraud prevention measures and consider whether they are adequate to prevent the fraud risks identified in the firm’s risk assessment.

    – Consider the adequacy of the firm’s supervision structure. Weak or insufficiently independent oversight remains a common factor cited in regulatory interventions

    – Where weaknesses are identified, develop new written systems and controls to prevent fraud. Policies must be consistently applied across the firm and actively tested.

  • Due diligence – law firms are required to verify the identity of clients and to screen employees under the Money Laundering Regulations 2017 and the overlapping professional requirement to ‘Know Your Client’. Ensure the firm’s Outsourcing Policy includes appropriate due diligence procedures for outsourced suppliers, e.g. electronic screening, checking trading history or professional or regulated status, and that contracts contain termination clauses for compliance breaches.

  • Communication and training – train all staff to ensure that anti-fraud policies and procedures are embedded and understood throughout the firm, ensuring that everyone is familiar with the whistleblowing policy. Provide role-specific training to those in the highest risk areas, such as residential conveyancing to help staff recognise and respond to social engineering, impersonation, invoice manipulation, and other common fraud techniques.

  • Monitoring and review –Monitor the effectiveness of the firm’s fraud prevention measures annually, or when triggered by changes in the risks (internally or externally) and/or actual fraud incidents. Consider evolving threats, including deepfake-enabled impersonation, authorised push payment (APP) fraud, and digital payment risks.


How Enderley Consulting can support your firm

Counter-fraud specialist Gavin Ball leads the Enderley team in helping law firms implement practical measures that align with UK best practice and guidance from the Fraud Advisory Panel (FAP), City of London Police, and FCA.

We can help your firm by:

  • Delivering practical anti-fraud training
  • Carrying out a firm wide risk review
  • Drafting or strengthening anti-fraud policies and procedures
  • Devising effective reporting mechanisms

If your firm is CQS-accredited, then it must have a property and mortgage fraud prevention policy and a documented practice wide fraud risk assessment.

Fraud prevention should not be a tick-box compliance exercise! It’s essential to protecting your clients, your people, your firm’s finances and reputation and ultimately, its success.