Automated AML Checks: How Technology Is Changing Compliance for Law Firms
How automated AML checks work for UK law firms — electronic identity verification, PEP screening, sanctions monitoring, and the compliance gains technology delivers.
Obiter Editorial Team
Published 15 May 2025
The way UK law firms conduct anti-money laundering checks is changing. Where compliance once meant photocopied passports and manual spreadsheet logs, technology now enables real-time identity verification, continuous PEP and sanctions screening, and automated audit trails — all integrated into the day-to-day instruction workflow. For firms that have made the transition, automated AML checks have reduced administrative overhead, improved compliance quality, and transformed the relationship between fee earners and regulatory requirements.
This guide explains how automated AML checks work in practice, what technology can and cannot replace in the compliance process, and what firms should consider when moving from manual to automated processes.
The Problem With Manual AML Compliance
Before examining what automation offers, it is worth understanding the limitations of the manual approach that most firms still rely on, at least partially.
Manual Processes Are Slow and Inconsistent
In a traditional manual AML process, the fee earner asks the new client to provide identity documents, chases up missing items by email, photocopies documents when received, files them, and records a note in the matter file. Each step depends on human action — and each step is therefore variable in timing and quality.
Research by the Law Society and sector bodies suggests that manual CDD processes take an average of 45 minutes of fee earner time per new client matter. Across a practice with any significant volume of in-scope work, this represents a substantial drag on billable time. More importantly, manual processes introduce inconsistency: one fee earner applies rigorous checks; another is less thorough. The firm’s compliance position depends on the vigilance of individuals rather than the reliability of systems.
Manual Records Are Vulnerable
Photocopies get lost. Files are misfiled. The scanned passport saved to a network drive disappears when the server is replaced. A fee earner leaves and takes their mental model of the client with them. Manual records are inherently fragile, and a firm cannot demonstrate to the SRA that it conducted adequate CDD if the records are not retrievable.
Manual Screening Is Practically Limited
Checking a client against PEP and sanctions lists manually — by searching government websites or commercial databases one entry at a time — is practical for a small volume of new clients. It is completely impractical at scale, and it provides no mechanism for ongoing monitoring: once a client passes the initial screen, they are never checked again unless someone specifically remembers to do so.
How Automated AML Checks Work
Electronic Identity Verification
Electronic identity verification (eIDV) is the most widely deployed element of automated AML compliance. An eIDV check works by:
-
Data input — the client’s name, date of birth, and address are submitted to the verification system (either entered by the fee earner or submitted by the client directly through a client portal)
-
Database matching — the system queries multiple independent data sources simultaneously. These typically include credit bureau records, electoral roll data, passport and driving licence validation databases, and Companies House data for company-related checks
-
Match scoring — the system scores the match between the submitted data and the records in each data source, producing a result that indicates whether the submitted identity is verified, partially verified, or unverified
-
Document verification (optional) — many systems now also offer document scanning: the client photographs their passport or driving licence on their phone, and AI-powered image analysis checks the document for authenticity markers and extracts the data
-
Result and record — the system produces a dated, referenced record of the check, showing what data sources were used, what the result was, and when the check was conducted. This record is stored automatically in the client file.
The whole process, for a straightforward UK-based individual client, can be completed in under two minutes. For comparison, the equivalent manual process — posting or receiving identity documents, copying them, filing them, noting the date — typically takes 15–30 minutes of fee earner time, plus whatever time the client takes to post documents.
What eIDV Can and Cannot Do
eIDV is not a complete replacement for all manual verification. Its strengths and limitations are:
Strengths:
- Fast and consistent — every check follows the same process
- Audit-ready — the result is automatically documented with a timestamp and reference
- Suitable for the majority of clients who appear in electronic databases
- Particularly effective for UK-resident adults with established credit and electoral roll histories
Limitations:
- Clients who are not well represented in electronic databases — elderly people who have never had credit, recently arrived overseas nationals, people who have moved frequently — may produce a low match score and require supplementary document-based verification
- eIDV checks the existence and consistency of an identity, not whether the person presenting that identity is genuinely who they say they are. A sophisticated fraudster with access to a real person’s details can potentially pass an eIDV check
- For higher-risk clients, eIDV is a useful supplement to document-based verification, not a replacement
LSAG guidance makes clear that eIDV can satisfy the identity verification requirement where the result meets the required standard (matching across two independent data sources with no material discrepancies). For enhanced due diligence scenarios, document-based verification alongside eIDV remains best practice.
Automated PEP and Sanctions Screening
Automated PEP and sanctions screening runs the client’s name and other identifying details against continuously updated databases of Politically Exposed Persons and individuals and entities subject to financial sanctions.
How screening works technically:
The submitted identity data — typically name, date of birth, and nationality or country of residence — is checked against a database compiled from official sanctions lists (UK OFSI, UN, EU, US OFAC, and others) and PEP registries (built from government websites, official gazettes, verified media sources, and other official data).
The system applies matching algorithms that identify potential matches, accounting for name variations, transliterations, and common aliases. The result is either:
- No match — the system finds no credible match against any listed individual
- Potential match — the system identifies one or more individuals in the database whose details are consistent with the submitted data
- Confirmed match — where sufficient identifying details overlap to constitute a strong match
Where a potential match is returned, a compliance officer or MLRO must review the match manually and determine whether it is a genuine match or a false positive. The system should provide sufficient detail about the matched individual to enable this determination.
Ongoing monitoring:
A significant advantage of automated screening over manual processes is the ability to run ongoing monitoring. The client’s details remain in the screening system, which re-checks them automatically whenever the underlying PEP or sanctions databases are updated — typically daily. If a client who was clean at onboarding subsequently becomes sanctioned or is appointed to a PEP-qualifying role, the system alerts the firm automatically.
Without automated ongoing monitoring, a firm has no practical mechanism for detecting these changes. A client whose uncle was appointed a government minister two years after onboarding would continue to be treated as a standard client unless someone specifically re-checked them.
Source of Funds Automation
Source of funds verification is harder to automate than identity checks because it involves assessing the substantive plausibility of documentary evidence — a task that requires judgment rather than just data matching.
However, technology is beginning to make inroads here:
Client portals and automated document requests — systems can automatically request SOF documentation from clients at the appropriate point in the transaction workflow, track which documents have been received, and alert the fee earner to outstanding items. This does not automate the assessment of SOF but significantly reduces the administrative burden of chasing documents.
Bank statement analysis — some newer platforms use AI to analyse uploaded bank statements, identifying salary credits, significant cash deposits, and transfers that may require further explanation. This assists the fee earner in spotting red flags without reading every line of a multi-month bank statement.
Integration with open banking — where clients consent, open banking connections can provide verified, up-to-date account data directly from the client’s bank, eliminating the risk of document manipulation. This is an emerging capability rather than standard practice in most UK law firms, but it is developing rapidly.
Beneficial Owner Verification
Automated tools for beneficial owner verification are increasingly sophisticated:
Companies House integration — systems can automatically retrieve PSC (Persons with Significant Control) data from Companies House for UK-registered companies, prepopulating the CDD record with the registered beneficial owners
Corporate registry lookups — for overseas companies, some systems have connections to international corporate registries, enabling automated retrieval of ownership information for companies in major jurisdictions
UBO questionnaires — automated systems can send UBO declaration questionnaires directly to corporate clients, collecting signed declarations of the beneficial ownership structure and flagging discrepancies with official registry data
The Compliance Gains From Automation
Firms that have implemented automated AML checks consistently report significant improvements across three dimensions:
Completeness
When CDD checks are integrated into the matter workflow — so that a matter cannot be progressed without completed CDD — the compliance failure rate drops dramatically. The system ensures that every client receives every required check, regardless of how busy the fee earner is or how pressured the transaction timeline becomes. SRA inspection findings show that the most common CDD failures are matters where checks were simply not conducted, rather than matters where checks were conducted inadequately.
Speed
Automated eIDV typically returns a result within 30–60 seconds, compared to a manual process that can take days waiting for documents by post. Faster compliance means faster matter progression — a genuine commercial benefit as well as a compliance improvement.
Quality of Records
Automated systems produce consistently formatted, timestamped, audit-trailed records that are immediately retrievable by matter or client. The contrast with manual records — which may be in various formats across different files, or may simply be missing — is significant when the SRA asks for CDD documentation.
What Technology Cannot Replace
Professional Judgment
Automated checks can identify data matches, flag PEP connections, and alert to missing documents. They cannot exercise the professional judgment that AML compliance ultimately requires: Is this transaction suspicious? Does this explanation make sense? Does this client’s stated wealth seem plausible?
The fee earner and MLRO remain responsible for the quality of compliance decisions. Automation assists that judgment; it does not substitute for it.
Human Intelligence
Fee earners in client meetings observe things that no database can: a client who seems nervous discussing the source of funds, instructions that do not add up, a story about business activities in a jurisdiction that does not ring true. These qualitative observations feed into the SAR decision in ways that automated systems cannot replicate.
The SAR Decision
Filing a Suspicious Activity Report requires a human decision by the MLRO. Automated systems can flag elevated risk and provide the information needed to make the decision, but the decision itself is always a human one.
Implementing Automated AML Checks
Integration First
The greatest compliance and efficiency gains come from automating checks within the existing workflow, not as a separate system that requires fee earners to log in to a different platform. Integration between AML software and your practice management system should be the primary implementation criterion.
Calibrate Thresholds Appropriately
Automated screening systems can be configured for sensitivity. Too-sensitive settings generate excessive false positive matches, creating more manual review work. Too-relaxed settings risk missing genuine matches. Work with your vendor to calibrate thresholds against your actual client population.
Staff Training Is Essential
Technology changes the nature of AML compliance work but does not reduce the need for trained, engaged staff. Fee earners need to understand what the automated checks are doing, how to interpret results, and what to do when a check returns a potential match or an incomplete result.
Document Your Approach
Automation changes your AML procedures. Update your PCPs to describe the automated processes you have implemented, so that your documented procedures accurately reflect how CDD is actually conducted.
Obiter is built around automated AML compliance — identity verification, PEP and sanctions screening, ongoing monitoring, and CDD record management are all embedded in the client onboarding workflow. Fee earners take instructions; Obiter handles the compliance checks in the background. Starting from £49 per month per fee earner, you can begin your free trial at obiteros.com.
Topics:
Ready to reclaim 12+ hours a week?
See how Obiter handles your legal admin so you can focus on advising clients.