In a major regulatory shift, the Government announced on 20 October 2025 that the FCA is to take over AML/CTF supervision of law firms currently regulated by the SRA. The date of the transition is subject to legislation and funding and as yet unclear. The SRA will continue to regulate all other aspects of solicitor conduct, professional standards, the SRA Standards and Regulations, accounts rules etc.
Why the change?
The current AML/CTF regime—split across multiple professional body supervisors—has been criticised as fragmented and inconsistent. By appointing the FCA as the Single Professional Services Supervisor for all regulated legal service providers in England and Wales, the Government aims to create a unified, risk-based system aligned with financial services regulation. The goal is greater consistency, stronger oversight and reduced vulnerability to financial crime.
The impact on law firms
This development signals a significant shift in how AML compliance will be monitored and enforced within the legal sector. The FCA’s approach is notably more advanced – both data-driven and “effectiveness”-oriented – and may well mean a stricter approach to compliance.
What can law firms expect to see?
In the financial services sector, the FCA already expects firms to demonstrate that compliance measures function effectively—not merely that policies exist. Compliance controls must be active, tested and continuously maintained. Under the FCA’s model, proactive supervision, real-time risk tracking and robust assurance testing are the norm. Law firms should expect to transition toward this same standard. In summary, expect to see:
A stronger focus on effectiveness – not just existence – of controls – expect to have to prove that your policies work in practice.
Ongoing, consistent compliance monitoring – greater expectations around record-keeping, oversight by senior management, monitoring and regular audits.
Greater clarity and consistency around accountability and consequences – expectations are likely to be more clearly defined and enforcement more direct.
What should firms do now?
Firms should start preparing now for a more intensive and evidence-based regulatory environment. Key steps should include:
Review AML policies, procedures and governance, assessing whether your systems truly work in practice. Focus on strengthening data quality and record-keeping, risk assessments and due diligence processes and internal monitoring and reporting. Ensure there is clear ownership of AML risk as well as senior management accountability and that MLRO and MLCO roles are well-defined and resourced.
Ensure file reviews, supervision, ongoing monitoring and audits are performed consistently and proactively. Test your systems to assess their effectiveness. Strengthen evidence gathering now to be able to respond to more requests for data showing their effectiveness.
Train staff and foster a culture of demonstrable compliance and accountability emphasising and embedding risk awareness and a proactive approach.



