NEWS

News and information from the world of
regulatory compliance and risk management

Back

Court of Appeal Clarifies: When Does a Breach of SRA Rules Become Misconduct?
29 April 2026

The Court of Appeal has delivered an important judgment in the Dentons anti-money laundering case, providing long-awaited clarity on when a breach of the SRA rules will amount to professional misconduct.

For compliance professionals, COLPs, COFAs and law firm leaders, the decision is significant: it confirms that not every regulatory breach will automatically trigger disciplinary liability.

Background: The Dentons Case

The case concerned Dentons, one of the world’s largest law firms and its compliance with the Money Laundering Regulations 2007.

The SDT initially found that Dentons had breached AML obligations, particularly around verifying the source of wealth of a politically exposed person. However, it concluded that the breach was inadvertent and not sufficiently serious to amount to professional misconduct.

The SRA appealed, arguing that a breach of regulatory obligations—particularly under Principle 7 (“comply with legal and regulatory obligations”)—should automatically constitute misconduct.

The High Court: A Strict Liability Approach

In 2025, the High Court (Lang J) sided with the SRA and adopted what many saw as a strict liability approach.

The court held that, for certain rules (including AML requirements), no additional element of seriousness or culpability was required—a breach alone was enough.

This interpretation caused concern across the profession. If correct, it would mean that even minor or technical breaches—however inadvertent—could expose firms and individuals to disciplinary findings.

The Court of Appeal: Restoring the “Seriousness” Threshold

The Court of Appeal has now rejected that approach.

In a key ruling, it confirmed that a breach of SRA rules will only amount to misconduct if it is “sufficiently serious”.

The court gave several reasons:

  • A strict liability interpretation would represent a “substantial departure” from the common law understanding of misconduct.
  • It would lead to absurd or disproportionate outcomes, potentially capturing trivial regulatory failings.
  • It would be inconsistent with the SRA’s own enforcement strategy and procedural rules, which already incorporate a seriousness threshold.

Importantly, the Court of Appeal confirmed that seriousness is an “inherent requirement” when determining whether conduct breaches the SRA Principles in a disciplinary sense.

However, the case has been remitted to a freshly constituted SDT to determine whether the Dentons breach meets that threshold and, if so, what sanction (if any) is appropriate.

What Does “Sufficiently Serious” Mean?

While the Court of Appeal did not provide a rigid test, the judgment reinforces that context matters. Factors likely to be relevant include:

  • The nature and impact of the breach
  • Whether the breach was systemic or isolated
  • The degree of culpability or fault
  • The firm’s systems, controls and compliance culture
  • Any harm (actual or potential) to clients, the public or the rule of law

This aligns with long-standing SDT jurisprudence: misconduct requires conduct that is serious, reprehensible, or culpable, not merely technical non-compliance.

Practical Implications for Law Firms

1. Not All Breaches Are Equal

The decision confirms that technical breaches do not automatically equal misconduct. This is a welcome clarification for firms operating in complex regulatory environments such as AML.

2. But Compliance Still Matters

Firms should not interpret this as lowering the bar. A breach may still:

  • Trigger regulatory investigation
  • Require self-reporting
  • Lead to sanctions if sufficiently serious

The distinction is between breach and disciplinary misconduct—not between breach and no consequences.

3. Evidence of Compliance Culture Is Critical

The Dentons case highlights the importance of demonstrating:

  • Robust policies and procedures
  • Effective training and supervision
  • Clear audit trails and decision-making records

The SDT originally noted that Dentons had strong AML systems overall, which influenced its finding that the breach was not misconduct.

4. Risk-Based Compliance Is Reinforced

The ruling aligns with a risk-based approach to regulation, particularly in AML. Regulators and tribunals must assess:

  • The seriousness of the failing
  • The firm’s broader compliance framework
  • Whether the issue reflects systemic weakness or isolated error

A Shift Back to Proportionality

Ultimately, the Court of Appeal’s decision restores proportionality to SRA enforcement.

It confirms that:

Professional discipline is not intended to punish every regulatory misstep, but to address conduct that is truly serious.

For compliance professionals, this provides both reassurance and a clear message:

  • Good systems and culture matter
  • Context will be scrutinised
  • Seriousness remains the key threshold

Conclusion

The Dentons case marks a pivotal development in legal regulation. By rejecting strict liability and reaffirming the need for “sufficient seriousness”, the Court of Appeal has clarified the boundary between regulatory breach and professional misconduct.

For law firms, the takeaway is clear: focus not just on avoiding breaches, but on building a defensible, well-evidenced compliance framework capable of withstanding regulatory scrutiny.

read more articles