SRA AML Supervision: What to Expect and How to Prepare
How the SRA supervises law firms for AML compliance, what an inspection involves, common findings, and how to prepare your firm before the SRA comes knocking.
Obiter Editorial Team
Published 15 May 2025
SRA AML supervision has intensified markedly over the past three years. The regulator has expanded its dedicated AML team, invested in data analytics to identify higher-risk firms, and increased both the number of inspections and the severity of enforcement outcomes. In 2023–24, the SRA opened over 700 AML investigations and issued fines totalling millions of pounds — a significant escalation from earlier years.
Understanding how SRA supervision works, what inspectors look for, and how to prepare your firm is now a practical necessity for any practice engaged in in-scope work. This guide explains the process from start to finish.
How the SRA Selects Firms for Inspection
Risk-Based Supervision
The SRA uses a risk-based approach to supervision, concentrating inspections on firms assessed as presenting the highest risk of AML failures. The factors that increase the probability of inspection include:
Practice area profile. Firms with significant conveyancing, company and commercial, or trust work are in higher-risk categories by virtue of their work. The SRA’s sectoral risk assessment consistently identifies residential conveyancing and company service provider activities as the highest-risk activities in the legal sector.
Client account volume. Firms handling large volumes of client money — particularly in conveyancing — are inherently higher risk and attract closer scrutiny.
Previous SRA interactions. Firms that have previously been the subject of regulatory concern (prior warnings, conditions, or investigations) are more likely to receive an AML inspection.
Intelligence and referrals. The SRA receives intelligence from the National Crime Agency, HMRC, Action Fraud, and other agencies. A referral relating to a specific firm will typically trigger an inspection.
Sectoral data analysis. The SRA uses data from the Annual Firm Return (which all firms must submit) and from other sources to identify firms whose profile differs from peers in ways that suggest AML risk.
Random or thematic selection. Not all inspections are risk-triggered. The SRA conducts thematic reviews across sectors and may select firms for inspection as part of a broader exercise.
How You Will Be Notified
In most cases, the SRA will notify a firm in writing (usually by email to the firm’s registered address) that it has been selected for an AML inspection. The notification will typically:
- Explain the purpose of the inspection
- Identify the specific regulations being reviewed
- Request that the firm make available specified documents and records
- Set a date for the inspection (either a desk-based review or an on-site visit)
In some cases — particularly where the SRA has received intelligence of imminent harm — it may conduct an unannounced inspection. This is relatively rare but does occur.
What the SRA Will Ask For
The SRA’s standard AML inspection typically requests a substantial volume of documentation. A typical request will cover some or all of the following:
Firm-Level Compliance Documents
- Firm-wide risk assessment (FWRA) — the current version and any previous versions from the preceding three years
- AML policies, controls, and procedures — the current written PCP document, signed off by senior management
- MLCO and MLRO appointment evidence — letters of appointment, job descriptions, CVs demonstrating suitability
- Training records — evidence of AML training for all relevant staff, including dates, content, and attendance records
- SAR log — the MLRO’s record of internal SAR reports received, external SARs filed, and decisions not to file
Client-Level CDD Records
The SRA will request CDD files for a sample of client matters. The sample typically focuses on in-scope work in higher-risk categories and may include:
- A specified number of conveyancing matters from a recent period
- Corporate matters involving company formations or acquisitions
- Matters with third-party payers
- Any matters where the SRA has specific intelligence
For each sampled matter, inspectors will look for:
- Evidence of identity verification (documents or electronic verification records)
- Evidence of beneficial owner identification and verification (for corporate clients)
- Evidence of source of funds checks (particularly for higher-value transactions)
- Evidence of the risk assessment applied to the client and the matter
- Evidence of EDD where required
- Senior management sign-off for EDD clients
Systems and Process Evidence
The SRA may also ask about:
- How new clients are onboarded (the practical process)
- How the firm conducts PEP and sanctions screening
- How ongoing monitoring is conducted
- How the firm’s AML procedures have been communicated to staff
- How the firm has updated its procedures in response to regulatory changes
What Inspectors Actually Look For
Experienced inspectors are not looking for technical perfection — they are assessing whether the firm has a genuine AML compliance culture and effective controls in practice. The main things they assess are:
Adequacy of the FWRA
Is the firm-wide risk assessment a substantive analysis of the firm’s actual risks, or a generic template? Inspectors look for:
- Specific analysis of the firm’s practice areas and client base
- Evidence that the assessment has been reviewed and updated
- A link between the risk assessment and the firm’s PCPs (i.e., the policies respond to the identified risks)
A FWRA that could apply to any law firm in the country — with no firm-specific detail — is a red flag.
Completeness of CDD
For the sampled client files, inspectors check that CDD is:
- Present (the documents or EV results are actually in the file)
- Complete (not just identity but also beneficial ownership and source of funds where appropriate)
- Current (refreshed where the relationship has developed or the client’s circumstances have changed)
- Proportionate (EDD applied where the risk warrants it)
The most common CDD failure is an absence of source of funds evidence for higher-value conveyancing transactions. Inspectors will look at every property transaction in the sample and ask: is there SOF evidence? If not, why not?
Functioning SAR Procedures
The SAR log tells inspectors whether the firm’s internal reporting process is functioning. An MLRO who has received zero internal reports over three years in a busy conveyancing practice is implausible — it suggests either that the internal reporting culture is broken or that staff are not recognising suspicious activity.
Inspectors also assess whether the MLRO’s decisions not to file external SARs are documented with reasoning. A log that simply records “no suspicious activity” without any analysis of the cases considered is inadequate.
Genuinely Effective Training
Inspectors look beyond whether training has been conducted to whether it appears to have been effective. Red flags include:
- Generic online training not tailored to the firm’s specific work
- Training conducted once at induction and never refreshed
- Fee earners who cannot explain the basic CDD process for their practice area
- Training records that are incomplete or suggest box-ticking
Common SRA Inspection Findings
The SRA publishes thematic findings from its AML supervisory work. The most consistently reported issues are:
No FWRA or a superficial one. First on almost every inspection report. Firms that have never prepared a substantive firm-wide risk assessment are in immediate breach of Regulation 18.
CDD not completed before work begins. Conveyancing files where substantive work began before CDD was obtained — often because of completion deadline pressure.
Inadequate beneficial owner verification. Corporate clients verified at company level without identifying or verifying the individuals with significant control.
No source of funds evidence. Higher-value property transactions with no documentation of where the purchase funds came from.
PEP and sanctions checks not conducted. Firms that rely on client self-declaration or have no process for screening clients against PEP and sanctions lists.
Inadequate ongoing monitoring. Clients with longstanding relationships and unchanged CDD from many years earlier.
Training gaps. Support staff and newer fee earners who have received no AML training.
Preparing for an SRA Inspection
Before You Receive a Request
The best preparation for an SRA inspection is a well-maintained AML compliance programme that is current and documented. Specific actions to take now:
Review and update your FWRA. If it has not been reviewed in the past 12 months, update it now. Ensure it reflects your current practice areas and client base.
Audit a sample of your own CDD files. Pick 10–20 conveyancing or corporate files at random and check whether they contain complete, current CDD including source of funds evidence. Any gaps need to be addressed (for live files) or documented (for closed files).
Check your SAR log. Does it record all internal reports received, the MLRO’s decision, and the reasoning? Are there adequate numbers of reports given your volume of in-scope work?
Verify training records. Do you have records for all relevant staff for the past three years? Are there gaps for new starters or staff who missed refreshers?
Confirm MLCO/MLRO appointment documentation. Are the appointments in writing? Do the appointees have adequate authority and resources?
When You Receive an Inspection Request
- Acknowledge the request promptly and cooperate fully
- Identify who will be the firm’s point of contact for the inspection
- Begin gathering the requested documents systematically
- Do not destroy or alter any records in advance of the inspection (this would be a serious additional offence)
- Seek advice from the Law Society or a compliance consultant if you have concerns about the inspection process or the firm’s position
During the Inspection
- Be honest and transparent with inspectors
- If the firm has failings, acknowledge them and explain what steps are being taken to address them
- Have your MLCO available to discuss the firm’s AML approach
- Provide documents promptly when requested
Inspectors are experienced and will quickly identify evasion or minimisation. Firms that acknowledge failings candidly and demonstrate remedial action consistently receive more proportionate outcomes than those that seek to downplay problems.
Outcomes and Enforcement
The range of possible outcomes from an SRA AML inspection includes:
No action — where the inspection finds no significant failings.
Requirement letter — where modest failings are identified, the SRA may issue a requirement letter specifying improvements to be made within a set timeframe.
Regulatory settlement agreement — where more serious failings are identified, the SRA may offer to resolve the matter by agreement, typically involving a fine, undertakings to improve, and monitoring.
Referral to the Solicitors Disciplinary Tribunal — for the most serious cases, the SRA refers the matter to the SDT for a formal disciplinary hearing. SDT sanctions include fines, conditions on practising certificates, suspension, and striking off.
Criminal prosecution — in the most serious cases involving deliberate or reckless breaches, criminal prosecution under Regulation 86 is possible.
The clear direction of travel is toward larger fines and more formal enforcement. The SRA’s expanded fining powers (unlimited since 2022 for the most serious cases) mean that significant financial penalties are now a realistic prospect for firms with systemic AML failures.
Obiter was designed to help fee earners and MLCOs maintain comprehensive, inspection-ready AML records without making compliance burdensome. From firm-wide risk assessment templates to audit-trailed CDD records and automated PEP screening, the tools your firm needs to satisfy an SRA inspection are built into the platform.
Topics:
Ready to reclaim 12+ hours a week?
See how Obiter handles your legal admin so you can focus on advising clients.