Home » SRA AML Fines 2026: What law firms are getting wrong, and how to avoid it
SRA AML Fines 2026: What law firms are getting wrong, and how to avoid it
Anne Austin
Director
A recent analysis conducted by Legal Futures revealed that the SRA had fined 59 law firms a combined total of £600,000 for AML breaches in the past six months.
Key takeaways:
- Every firm fined either lacked a firm-wide risk assessment, had no AML policy, had inadequate controls, or had not completed client matter risk assessments, and in many cases, all of the above
- The failures are consistent and recurring – and they are not confined to poorly-run firms
A Regulation 21 AML audit is the most effective way to understand the real state of your firm’s compliance before the SRA does
Why are law firms being fined for AML breaches?
When the SRA publishes a round of AML enforcement decisions, it’s tempting to scan the firm names, confirm you don’t recognise any of them, and move on. I’d encourage you to look deeper.
Fifty-nine law firms have been fined a combined total of £600,000 for anti-money laundering breaches. The firms varied in size and practice area. But what strikes me most about this enforcement round isn’t the scale of the fines – it’s how consistent the failures are. Every single one of the 59 firms either did not have a firm-wide risk assessment or AML policy in place, had inadequate controls and procedures to manage money laundering and terrorist financing risks, or had failed to complete client matter risk assessments. In many cases, all three.
These are not obscure technical requirements and they are not new news. They are the foundations of any compliant AML framework. And yet, across 59 different firms, they were missing or inadequate.
What AML failures did the SRA find? Three cases that show the pattern
Three of the fined firms received the maximum individual penalty of £25,000. Their cases are worth examining closely, because the SRA’s language reveals something important about how these failures develop.
MG failed to keep up-to-date written records of its money laundering and terrorist financing risk assessments, failed to review and update its policies, controls and procedures, and failed to conduct client matter risk assessments. This is a firm that may well have had documents in place at some point – the failure was in never revisiting or maintaining them. Lesson to be learnt – stale documents are not compliant documents.
William Heath & Co was inspected across six client files. Not one file contained a client matter risk assessment. In four of the six, the firm also failed to scrutinise client transactions or the source of funds. The SRA recommended that fee-earners receive training on source of funds checks – a recommendation that tells us the problem wasn’t just missing paperwork, but a gap in understanding at the point of doing the work.
BRR had a massive eight-year failure to conduct client matter risk assessments. The SRA noted that this “translated to a poor understanding of the risks posed by clients and matters and resulted in insufficient scrutiny being applied.” Eight years. Across what will have been hundreds, perhaps thousands, of client matters.
What these firms have in common is not bad intent. There is no suggestion that any of them were facilitating money laundering knowingly. What there is, in each case, is a combination of inadequate systems, insufficient training, and critically, no meaningful mechanism for checking whether AML obligations were actually being met in practice.
The three most common AML compliance failures in law firms
Having carried out Regulation 21 audits across firms of all sizes, I see the same issues come up time and again. The SRA’s enforcement decisions reflect what I often find on the ground.
1. The AML framework exists on paper but hasn’t been maintained
A firm-wide risk assessment written three years ago and never reviewed is not a compliant FWRA – it is a weak safety harness that creates a false sense of security. Your client base evolves, your practice areas shift, new risk typologies emerge, the regulatory environment changes. None of that is reflected in a document that was written when the firm and the regulatory landscape looked different. Reviewing and updating your FWRA is an ongoing obligation, not a one-off task.
2. Client matter risk assessments are inconsistent or absent at file level
This is the gap between what the policy says and what actually happens when a fee-earner opens a new matter. In firm after firm, I find that the MLCO has put together a sound AML policy – but when you look at the files, the CMRAs are missing, incomplete, or filled in as a formality, tick-box style, with no real thought applied. The policy and the practice have diverged, and nobody has checked. This is precisely the failure the SRA identified at William Heath & Co, and it is far more widespread than that single firm.
3. AML training hasn’t kept pace with the firm’s obligations
Source of funds and source of wealth checks, in particular, continue to catch firms out. Fee-earners often understand the concept in theory but lack confidence in applying it in practice – what questions to ask, what documentation to request, what an adequate answer looks like, and when to escalate. One of the most common questions that arise during our AML training sessions is ‘how far do I need to go?’. This shows up in files, and increasingly it shows up in enforcement decisions. We wrote action point guidance for law firms last year here.
Does my law firm need a Regulation 21 AML Audit?
Under the Money Laundering Regulations, most law firms are required to have an independent audit of their AML controls – known as a Regulation 21 audit. In my experience, this requirement is significantly underused. Firms either aren’t aware of it, decide it doesn’t apply to them, or bury their head in the sand because they’re not sure what it will reveal.
I’d encourage a different way of thinking about it. A Regulation 21 audit, done properly, is the single most effective way of understanding the real state of your firm’s AML compliance – not just the state of your policies, but the state of your practice. It will tell you whether your FWRA actually reflects your firm’s current risk profile, whether your CMRAs are being completed consistently and thoughtfully at file level, whether your staff understand your procedures well enough to apply them, and where the gaps are – before the SRA finds them.
It is also, increasingly, the best evidence you can have that your firm takes its AML obligations seriously, should the SRA come looking.
When we carry out a Regulation 21 audit at Enderley, we often find the same thing: a firm whose senior management genuinely believe their AML framework is in good shape, and a different picture at file level. The MLCO knows the policy inside out. The fee-earners, under time pressure, are cutting corners on CMRAs or skipping source of funds documentation because they are unaware that it matters. The gap between the two is what enforcement decisions are made of.
At Enderley, our Regulation 21 audits cover your firm-wide risk assessment, AML policy, client matter risk assessments, and training records. We audit a sample of the firm’s files and interview staff across different roles to test their practical understanding – not just what the policy says, but what they actually do. Our findings are presented in a detailed written report with a traffic light summary of mandatory actions, recommendations, and advisories. And we don’t hand over the report and disappear. We work alongside your MLCO and MLRO to help action the findings – whether that means updating documents, improving file processes, or training the team.
How can law firms improve AML compliance without a full audit?
Not every firm needs to start with a full Regulation 21 audit, though most should. If you want to understand your firm’s position quickly, there are other starting points.
AML spot checks on files – we can carry out targeted spot checks on a sample of your firm’s files and give you a clear, honest picture of how consistently your team is applying your procedures in practice. This is a fast and proportionate way to identify whether there is a gap between your policy and your files before it shows up in an SRA inspection.
AML framework review – if your firm-wide risk assessment, AML policy, or client matter risk assessment templates haven’t been reviewed recently, we can assess them against current requirements and help you update them. This is often the quickest win: getting the documents right and then making sure the team is using them.
What AML training do law firms need?
If the gap is at the level of individual fee-earners and support staff – which it often is – training is where the most immediate improvement can be made.
We offer two routes. For firms that want training tailored specifically to their practice area, risk profile, and procedures, we deliver bespoke sessions, either in person or via Teams, focusing on the areas that matter most: how to complete a client matter risk assessment properly, how to investigate and evidence source of funds and source of wealth, how to recognise and handle PEPs, how to apply sanctions screening in practice.
For firms that need broader coverage across their teams, the Enderley Infohub offers a full suite of role-specific AML and financial crime webinars, starting at £950 plus VAT for five licences. Courses include money laundering compliance for different staff levels, source of funds and source of wealth, dealing with PEPs, navigating UK sanctions, and financial crime topics including bribery and tax evasion. All course completions (with a test at the end) are fed into a training record – important both for your own records and for demonstrating compliance to the SRA.
Frequently Asked Questions
What is a firm-wide risk assessment and do I need one?
A firm-wide risk assessment (FWRA) is a document that identifies and assesses the money laundering and terrorist financing risks your firm faces, based on your client base, practice areas, geographic exposure, and delivery channels. If your firm carries out work in scope of the Money Laundering Regulations, you are required to have one under Regulation 18 – and to keep it up to date.
How often should a law firm update its AML policy?
Your AML policies, controls and procedures should be reviewed whenever there is a material change to your firm’s risk profile or a regulatory change, and at least annually as a matter of good practice. Letting them become stale is one of the most common AML failures the SRA identifies.
What is a client matter risk assessment (CMRA) and who is responsible for completing it?
A client matter risk assessment is a documented assessment of the money laundering and terrorist financing risk posed by a specific client and matter. It should be completed at the start of every matter in scope of the MLR 2017, by the fee-earner handling the matter, and reviewed if circumstances change. It should document the fee earner’s thought and decision making process, their rationale for allocating the particular risk assessment rating and due diligence level, and a note of key supporting evidence.
What happens if the SRA finds AML failures at my firm?
The SRA has a range of enforcement powers including fines, conditions on a firm’s authorisation, and in serious cases referral to the Solicitors Disciplinary Tribunal. As this enforcement round shows, fines of up to £25,000 per firm are being applied for failures that are not confined to the most egregious cases.
How do I find out if my firm needs a Regulation 21 AML audit?
Under Regulation 21 of the Money Laundering Regulations 2017, firms carrying out work in scope of the MLR must take appropriate steps to ensure their AML policies, controls and procedures are being applied effectively – which includes independent audit. If you are unsure whether and how this applies to your firm, we are happy to advise.
If you are not confident in your firm’s AML framework, the consistency with which your team applies it, or your ability to produce complete training records for all staff, the time to act is now — before the SRA acts first.
If you’d like to talk through what good AML compliance looks like for a firm like yours, please get in touch.