SRA AML Annual Report 2024–25: Key Takeaways for COLPs, Partners and MLROs

The Solicitors Regulation Authority (SRA) has published its Anti-Money Laundering (AML) Annual Report 2024–25, and the findings are essential reading for law firm compliance officers, partners, and MLROs.

Despite increased regulatory scrutiny, tougher supervision and record fines, one in three law firms inspected remains non-compliant with the Money Laundering Regulations 2017.

In the words of SRA outgoing Chief Executive, Paul Philip: ‘While most firms demonstrated a strong understanding of their obligations and a clear commitment to compliance, the identification of non-compliance in nearly a third of cases highlights the continued need for sector-wide improvement and sustained regulatory attention’ —just as AML oversight prepares to transfer to the Financial Conduct Authority (FCA).

Supervision and outcomes: key data

The SRA completed 935 proactive AML engagements in 2024-2025 —nearly double the number of the previous year (545).

Of the 935 firms the SRA engaged with, 833 had an on-site proactive inspection or a desk-based review. The remaining engagements were as part of a wider investigation, part of a thematic review, or a review of the firm’s own independent audit report.

Outcome

Number of Firms

Percentage

Compliant

112

13%

Partially compliant

451

54%

Non-compliant

270

32%

The top 5 failings identified in inspections and DBRs 

  • Missing or incomplete client/matter risk assessments
  • Failure to carry out or record source of funds checks
  • Lack of adequate/effective AML policies, controls, and procedures
  • Missing or outdated firm-wide risk assessments. While the proportion of compliant firm-wide risk assessments rose slightly to 47%, the SRA warned that many firms still treat AML frameworks as static paperwork rather than living, risk-responsive tools.
  • Failure to carry out client identification/verification or to record it non file

Enforcement: A clear warning for firm leadership

Enforcement activity intensified sharply in 2024–25:

  • 426 AML-related reports received (up from 227)
  • 58 Regulatory Settlement Agreements (£661,200 total fines)
  • 15 adjudicator fines (£292,133 total)
  • 14 SDT cases (£545,650 total fines)
  • Combined AML penalties topped £1.5 million—the highest yet. The SRA linked this to a shift toward data-led supervision and a greater focus on leadership accountability.

Risk hotspots and emerging challenges

  • Conveyancing continues to dominate AML risk, accounting for 73% of all suspicious activity reports (SARs).
  • Sanctions compliance received heightened attention: 47 targeted sanctions inspections and over 300 sanctions-controls checks.
  • Emerging issues include digital onboarding, deepfake ID fraud, and gaps in hybrid working controls.
  • The SRA expects the FCA to build on this with even stronger expectations around technology, governance, and data integrity.

What this means for COLPs, Partners and MLROs

The SRA’s latest report delivers a clear message: senior management accountability is central to effective anti-money laundering (AML) compliance. The regulator identified three recurring themes driving AML breaches across the profession, each pointing to weaknesses in leadership oversight and operational controls.

Theme One: weak leadership focus on AML controls

Many firms still underestimate the importance of maintaining robust, compliant AML frameworks. Failures often stem from inadequate firm-wide risk assessments or outdated policies, controls, and procedures (PCPs) that do not reflect the firm’s actual exposure to money laundering and terrorist financing risk.

Theme Two: insufficient training and supervision

The SRA found that fee earners frequently lack practical understanding of both the Money Laundering Regulations and their firm’s internal PCPs. Inconsistent or minimal AML training leaves staff ill-equipped to identify and respond to risk, exposing firms to regulatory breaches.

Theme Three: gaps in systems and processes

A number of firms rely too heavily on manual checks and professional judgment, without automated safeguards. The absence of system-driven “stops” – for example, preventing funds from being received before customer due diligence (CDD) is complete – means high-risk transactions can progress unchecked.

Together, these findings reinforce the SRA’s stance that AML compliance must be owned at the top. Senior leaders are expected to ensure their firms have the right culture, systems, and oversight in place to prevent financial crime – and to evidence that responsibility in practice.

Key actions for leadership teams

  1. Refresh firm-wide risk assessments at least annually and when exposure changes.
  2. Audit AML training to ensure it’s role-specific, interactive, and evidenced.
  3. Run regular file reviews checking the adequacy of ID verification, client/matter risk assessments and source-of-funds checks.
  4. Review sanctions screening processes for accuracy and record-keeping.
  5. Document decision-making—particularly where risk-based judgments are applied.
  6. Evidence partner/board-level engagement: ensure AML appears regularly on board agendas and minutes.

Looking ahead

  • The SRA’s final AML report underlines both progress and persistent shortcomings. The forthcoming FCA supervisory regime is expected to be more data-driven and unforgiving of superficial compliance.
  • For COLPs and MLROs, the message is unmistakable: AML systems must be living frameworks—actively managed, evidence-based, and owned by leadership and all staff must be trained on how to implement them.

In the SRA’s words: “Good practice must be evidenced, not assumed.” This echoes our regular refrain during AML training:

“If it isn’t written down, it didn’t happen!”