L
Obiter
AML Compliance 9 min read

AML Compliance for Solicitors: The Complete 2025 Guide

Everything UK solicitors need to know about AML compliance in 2025 — SRA requirements, CDD, record-keeping, and avoiding regulatory sanctions.

C

Obiter Editorial Team

Published 15 May 2025

Anti-money laundering compliance has become one of the most demanding regulatory obligations facing UK law firms. In 2023–24, the Solicitors Regulation Authority issued over £3.5 million in fines to firms for AML failings, and the pace of enforcement is accelerating. Whether you run a high-street practice handling conveyancing or a City firm advising on complex commercial transactions, understanding your AML obligations is no longer optional — it is foundational to staying in business.

This guide covers everything solicitors need to know about AML compliance in 2025: the legal framework, what the SRA expects, how to build a compliant practice, and the common pitfalls that lead to sanctions.

The Money Laundering Regulations 2017

The primary legislation governing AML compliance for solicitors is the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs), as amended. These Regulations implement the EU’s Fourth and Fifth Anti-Money Laundering Directives into UK law and were substantially updated by the Money Laundering and Terrorist Financing (Amendment) Regulations 2019.

The Proceeds of Crime Act 2002 (POCA) sits alongside the MLRs and creates criminal offences including:

  • Section 327 — concealing, disguising, converting, or transferring criminal property
  • Section 328 — entering into or becoming concerned in an arrangement facilitating the acquisition, use, or control of criminal property
  • Section 329 — acquiring, using, or possessing criminal property

Solicitors benefit from the “authorised disclosure” defence under POCA — if you file a Suspicious Activity Report (SAR) with the National Crime Agency (NCA) before proceeding with a transaction, you avoid criminal liability even if the funds turn out to be proceeds of crime. This is one reason timely SAR filing matters so much.

The SRA’s Role as Supervisory Authority

The SRA is the designated supervisory authority for solicitors under the MLRs. Its responsibilities include risk-assessing the legal sector, supervising individual firms’ compliance, and taking enforcement action. The SRA publishes an AML sectoral risk assessment that firms are required to take into account when conducting their own firm-wide risk assessments.

The Legal Sector Affinity Group (LSAG) — which includes the Law Society, Bar Council, CILEx, and other legal professional bodies — publishes guidance on complying with the MLRs that the SRA endorses. LSAG guidance is not legally binding, but courts and the SRA treat it as authoritative.

Does Your Firm Fall Within Scope?

Not every law firm is subject to the full AML regime. The MLRs apply to firms that act as “relevant persons,” which in the legal context means firms that carry out “relevant business.” This includes:

  • Conveyancing — buying or selling real property
  • Company and business work — formation, operation, or management of companies or other legal persons
  • Client account management — managing client money, securities, or other assets
  • Trust work — creating, operating, or managing trusts
  • Nominee services — acting as a nominee shareholder or director

If your firm does any of these activities, you are in scope. Purely contentious work (litigation) generally falls outside the MLRs, but many firms do a mix of contentious and non-contentious work — meaning the AML regime applies to the non-contentious elements.

Building Your AML Compliance Framework

Firm-Wide Risk Assessment

Every in-scope firm must conduct and document a firm-wide risk assessment (FWRA). This is a written analysis of the money laundering and terrorist financing risks your firm faces, taking into account:

  • Services offered — conveyancing carries higher inherent risk than, say, will-writing
  • Client types — clients who are PEPs, high-net-worth individuals, or based in high-risk jurisdictions increase risk
  • Geographic reach — cross-border transactions involving high-risk third countries require enhanced scrutiny
  • Delivery channels — how you take on clients (referrals, online, walk-in) affects verification approaches

The FWRA must be reviewed regularly — at minimum annually — and whenever there is a material change in your firm’s work, client base, or the risk environment. The SRA will ask to see your FWRA during any inspection, and a stale or superficial assessment is a common enforcement trigger.

Policies, Controls, and Procedures

Firms must have written AML policies, controls, and procedures (PCPs) that are proportionate to the nature and size of the practice. These must cover:

  • Customer due diligence (CDD) and enhanced due diligence (EDD)
  • Ongoing monitoring of client relationships
  • Suspicious activity reporting
  • Staff training
  • Record-keeping
  • Senior management responsibility

For firms with multiple offices or more than a handful of fee earners, a standalone AML policy document is best practice. Sole practitioners can incorporate AML procedures into a broader compliance manual, provided they are specific and up to date.

Appointing a Money Laundering Compliance Officer

Firms with more than one employee must appoint a Money Laundering Compliance Officer (MLCO) at senior management or partner level. The MLCO is responsible for ensuring the firm’s AML policies are implemented and effective. They must have sufficient authority, resources, and access to information to do the job properly — the SRA takes a dim view of MLCOs who are nominally appointed but functionally powerless.

Firms above a certain size (the MLRs specify firms with more than 25 employees in some contexts) must also appoint a Money Laundering Reporting Officer (MLRO) — the person who receives internal suspicious activity reports from staff and decides whether to make an external SAR to the NCA. In smaller firms, one person often holds both roles.

Client Due Diligence: The Practical Requirements

Standard CDD

For every new client in scope, you must verify identity before establishing the business relationship (or in limited circumstances, during it). Standard CDD requires you to:

  1. Identify the client — obtain their full name, date of birth, and address
  2. Verify the identity — check it against reliable, independent source documents (passport, driving licence, utility bill, etc.)
  3. Understand the business relationship — know why the client is instructing you and the nature of the transaction

For corporate clients, verification extends to the company itself (certificate of incorporation, registered address, directors) and to the beneficial owners — those who ultimately own or control more than 25% of the company.

Enhanced Due Diligence

Standard CDD is insufficient in higher-risk situations. Enhanced due diligence (EDD) is required when:

  • The client is a Politically Exposed Person (PEP) or a family member/close associate of a PEP
  • The transaction involves a high-risk third country (designated by FATF or the UK Government)
  • The business relationship presents a higher risk by its nature

EDD means doing more: obtaining additional information about the client, the source of funds, and the source of wealth; getting senior management sign-off before proceeding; and monitoring the relationship more closely.

Ongoing Monitoring

CDD is not a one-off exercise. Firms must monitor ongoing client relationships to ensure that transactions are consistent with the firm’s knowledge of the client and their risk profile. In practice, this means:

  • Refreshing CDD when client circumstances change (new beneficial owner, change of jurisdiction, new type of transaction)
  • Being alert to transactions that do not fit the client’s known business or financial profile
  • Updating risk assessments as the relationship develops

Suspicious Activity Reporting

When a solicitor knows or suspects that a client is engaged in money laundering or terrorist financing, they must file a SAR with the NCA via the UKFIU’s SAR Online system. Failure to report is itself a criminal offence under s.330 POCA.

The “consent SAR” mechanism is particularly important in property transactions: if you file a SAR and request a “defence against money laundering,” the NCA has seven working days to grant or refuse consent. You must not proceed with the transaction until consent is granted (or the period expires without refusal). Proceeding before consent is a POCA offence.

Firms must maintain internal SAR procedures: staff must know how and to whom to escalate concerns internally, and the MLRO must keep records of all internal reports and decisions.

Record-Keeping Requirements

The MLRs require firms to keep CDD records for at least five years from the end of the business relationship, and records of transactions for at least five years from the date of the transaction. Records must be kept in a form that can be readily retrieved and provided to the SRA or law enforcement on request.

Poor record-keeping is a major source of SRA enforcement action. Firms that cannot produce CDD records for a client from three years ago cannot demonstrate that they complied with the Regulations at the time — and the SRA may well infer they did not.

Staff Training

All relevant staff must receive AML training. “Relevant staff” means anyone involved in relevant business — fee earners, legal secretaries, cashiers, and compliance personnel. Training must cover:

  • How money laundering works and why the legal sector is a target
  • The firm’s obligations under the MLRs and POCA
  • How to recognise suspicious activity
  • How to make an internal report
  • The consequences of failing to comply

Training must be proportionate to the person’s role and must be refreshed regularly. New starters should be trained before they begin working on in-scope matters. Records of training must be kept.

Common AML Failures and How to Avoid Them

The SRA’s enforcement data repeatedly highlights the same failures:

No firm-wide risk assessment, or an outdated one. Firms treat the FWRA as a box-ticking exercise rather than a live document. Review it annually as a minimum.

Deficient CDD. Relying on a scanned passport without verifying the source of funds, or failing to identify beneficial owners of corporate clients, are the most common CDD failures. Electronic verification can supplement but generally should not replace document-based verification.

No ongoing monitoring. Completing CDD at onboarding and never revisiting it is not compliance. Set calendar reminders to refresh CDD for long-running matters.

Inadequate SAR procedures. Staff do not know the internal escalation route, or the MLRO fails to file external SARs when warranted.

Poor record-keeping. Files cannot be retrieved, documents are missing, or retention periods have not been applied consistently.

The SRA’s Enforcement Approach

The SRA uses a risk-based supervisory approach, focusing resources on firms that present the highest AML risk — typically those in conveyancing, company and trust work, and client money-heavy practices. Enforcement outcomes range from requirements to improve policies through to fines, conditions on practising certificates, and (for the most serious failings) referrals to the Solicitors Disciplinary Tribunal.

Fines can be substantial: the SRA’s new unlimited fining power (in force since 2022) means there is no ceiling on financial penalties for the most serious cases. Firms that self-report and cooperate fully tend to receive more favourable outcomes than those where the SRA discovers failings through inspection.

Looking Ahead: Key Changes in 2025

The Economic Crime and Corporate Transparency Act 2023 introduced new Companies House verification requirements that affect how firms verify corporate clients. Firms should ensure their CDD procedures are updated to use verified Companies House data where available.

The UK’s updated FATF mutual evaluation is expected in 2025, and the outcome will likely prompt further regulatory activity. Firms should monitor LSAG and SRA communications for updated guidance.


Obiter automates the administrative side of AML compliance — running electronic identity checks, flagging PEP and sanctions hits, and generating audit-ready CDD records — so your fee earners spend their time on legal work rather than chasing documents. Firms using Obiter report that their MLRO can sign off CDD files in a fraction of the time previously required.

Topics:

aml compliance solicitors sra

Ready to reclaim 12+ hours a week?

See how Obiter handles your legal admin so you can focus on advising clients.