National Risk Assessment of Money Laundering and Terrorist Financing 2025

On 17 July 2025, HM Treasury published their National Risk Assessment of Money Laundering and Terrorist Financing 2025

This weighty document (163 pages to be exact) evaluates the UK’s exposure to money laundering and terrorist financing threats, helping regulated sectors understand and mitigate emerging risks. The overall findings are mixed but cautionary; while progress has been made in supervision and awareness, the threat level remains high due to increased use of complex structures, crypto-assets, and global instability, requiring continued vigilance and stronger controls across legal and financial services.

The report identified the threat of money laundering to law firms remains high. Here we’ve summarised the key findings, the report’s specificity legal firms, and the steps to take to embed the report’s recommendations.

Purpose and scope of the 2025 NRA

The 2025 NRA is the UK Government’s fourth comprehensive assessment (following 2015, 2017, 2020), jointly published by HM Treasury and the Home Office. It aims to identify, assess, understand, and mitigate the risks of money laundering (ML) and terrorist financing (TF) across the UK economy. It’s a foundational document for regulators, supervisors, law enforcement, and regulated entities that must embed these insights into risk-based controls.

The evolving threat landscape

The report highlights a marked increase in the sophistication of ML/TF threats, driven by advanced delivery methods involving crypto assets, AI and other digital platforms, and geopolitical shifts. Criminal networks are becoming increasingly adept at exploiting technology to facilitate illicit financial flows. This underscores the need for adaptive, agile regulatory responses.

Multi-sector risk assessment

The NRA pools insights from over 250 responses across regulated sectors, workshops, law enforcement, academia, and more. These collaborations frame four dimensions of risk: threat, vulnerability, control, and consequences – resulting in a detailed, risk-based evaluation approach.

UK Economic Crime Plan integration

Aligned with the Economic Crime Plan 2023–26, the NRA sets out “system prioritisation”, a mechanism to help the regulated community allocate resources in a risk-based, cost-neutral manner. This ensures businesses and public bodies target their efforts where they matter most.

Geopolitical and sanctions drivers

In light of conflicts like Russia–Ukraine and global sanctions regimes (latest update here) firms are also expected to screen against UK-designated persons, identify HRTC (High-Risk Third Countries per FATF), and strengthen controls against proliferation financing.

Key risk drivers and vulnerabilities

Highlighted issues include:

  • Money laundering by organised crime groups (drugs, fraud, corruption).
  • Misuse of legal persons and trusts to conceal beneficial ownership.
  • Financing of terrorism and proliferation through charities, trade systems.
  • Increasing use of novel payment systems and crypto assets.
  • Complex corporate structures—especially offshore UK-registered companies

Artificial Intelligence, but real risk

The risk assessment warns that artificial intelligence (AI) is being exploited by criminals to scale fraud and bypass financial controls in a number of ways:

  • Synthetic IDs & deepfakes
    AI creates realistic fake identities and documents to fool KYC/onboarding systems.
  • AI-driven phishing and scams
    Scammers are using AI to produce high-volume, convincing phishing emails and fraud schemes.
  • Beating detection tools
    Criminals use AI to test and refine laundering methods to evade transaction monitoring systems.
  • Money-mule recruitment
    AI-powered social engineering targets vulnerable people to move illicit funds.
  • Automated layering of funds
    AI bots move money across wallets, crypto exchanges, and online platforms to hide origins.


Clearly, this is all making criminal activity faster, more scalable, and even harder to detect.

Strengthening national defences

The report underscores improved collaboration between authorities, supervision enhancements via bodies like OPBAS, and legislative progress under SAMLA 2018. This includes more forceful provisions to tackle money laundering, terrorist financing, and sanctions compliance.

What the NRA 2025 specifically means for law firms

The 2025 National Risk Assessment reaffirms that the legal sector – particularly law firms involved in conveyancing, trust and company services (TCSPs), and the operation of client accounts – remains high risk for money laundering activity. (tip – navigate to page 118 for detailed reading).

Legal professionals are often targeted by criminals seeking to exploit the legitimacy of the sector and the large sums of money that can be moved through legal transactions. While overall compliance rates remain relatively strong, vulnerabilities persist, especially where firms adopt a “tick-box” approach to due diligence or lack proper AML training and awareness.

Firms offering a combination of legal services, such as full-service solicitors’ practices, are considered at greatest risk, especially where criminals use multiple firms to obscure source of funds and evade scrutiny. The misuse of client accounts, often seen as a veil of legitimacy, continues to be a major concern. While there is some optimism around the emergence of Third Party Managed Accounts (TPMAs) as a lower-risk alternative, regulators stress that more evidence is needed before their overall impact can be assessed.

The report also highlights an increase in enforcement, with a sharp rise in fines issued by Professional Body Supervisors (PBSs). However, supervision remains inconsistent, and HM Treasury has acknowledged the need for reform, especially around risk-based enforcement and information sharing.

For law firms, especially those dealing with high-value property, overseas clients, or complex corporate structures, this means ensuring AML compliance is not only robust but dynamic and risk-informed. Firms must review their policies, training, and monitoring systems, and be particularly cautious where client behaviour appears designed to complicate transactions or bypass due diligence checks.

Recommended actions for law firms

Firms must integrate the NRA’s outcomes into their internal risk assessments, tailoring their onboarding, customer due diligence (CDD), enhanced due diligence (EDD), and transaction monitoring according to sector-specific threats and emerging risks.

Firms should revisit and revise their CDD frameworks regularly, especially concerning high-risk technologies or cross-border flows associated with crypto or sanctions regimes. More specifically:

  1. Embed NRA findings into firm-wide risk assessments and control frameworks.
  2. Apply enhanced due diligence where required (e.g., complex trust structures, high-risk jurisdictions, crypto).
  3. Enhance sanctions screening using up-to-date lists of designated persons and high-risk third countries.
  4. Review client due diligence/monitoring periodically to account for new vulnerabilities.
  5. Engage in sector forums to stay aware of threats and supervisory expectations.
  6. Regular training for staff on evolving ML/TF typologies (crypto, trade-based finance, sanction risks).


Final summary

The 2025 NRA is a comprehensive, evidence-driven evaluation of UK-wide ML/TF risks. Firms must translate its findings into proactive, risk-based customer due diligence, enhanced monitoring, and stronger controls, particularly around crypto and sanctions.

This isn’t going away – the threat is ever increasing.  Embedding these recommendations now is critical to ensure compliance and resilience in an increasingly dynamic regulatory environment.