The SRA published its annual AML report last week. The report reveals that a record number of firms (864 – around one in six of all firms in the regulated sector – up from 545 the previous year and 273 the year before that) received an inspection, a desk-based review or an assessment of their independent audit. A further 71 firms were subject to thematic reviews. Only 13% (112) of the 833 firms that were given a rating were deemed to be fully compliant (22% last year), 54% (451) were partially compliant (i.e., they had deficiencies in one or more areas) and 32% (270) were not compliant (failing to meet core AML requirements). This is a significant increase from 2023/24 when 23% of firms inspected were found to be not compliant.
Main areas of non-compliance
- The most frequent breach was failure to carry out adequate client-and-matter risk assessments (CMRAs). For instance, among the files reviewed, 16 % had no or incomplete CMRA, and 39 % had a risk assessment that was ineffective (e.g., focusing on operational risk rather than AML risk).
- Only 47 % of firms had a compliant firm-wide AML risk assessment.
- 33 % lacked compliant AML policies/procedures
- 28 % failed to provide staff AML training
- Additional recurring issues:
- About 10 % of files did not contain source-of-fund checks.
- About 6 % of files lacked or failed to properly record client identification/verification checks.
- Failure to apply enhanced customer due diligence and enhanced ongoing monitoring
- Firms not recognising when their work placed them under the scope of AML regulations (i.e., that they needed to apply AML controls).
- Weak culture of AML compliance: lack of training for fee-earners, weak supervision, and systems that allowed matters to progress without mandatory AML checks.
While many firms had a process in place, this was often not being followed, “showing a disconnect between the policies, controls and procedures and what is happening at matter level”.
Enforcement
In the 2024/25 year, the SRA issued 64 letters of advice/warning and 73 fines totalling £953,333. Further, 14 matters were sent to the Solicitors Disciplinary Tribunal (SDT), which resulted in 13 fines amounting to £545,650.
AML Compliance Checklist
Firms must be able to evidence that they:
- Conduct firm-wide risk assessments (FWRA) reflecting services, clients, delivery channels and geography.
- Perform client and matter risk assessments (CMRA) and keep them on file.
- Maintain tailored AML policies, controls, and procedures (PCPs) — not generic templates.
- Apply due diligence (CDD & EDD) including verification of source of funds/wealth.
- Provide regular AML training to all relevant staff.
- Monitor and review AML controls regularly.
- Have procedures for reporting and escalation of suspicious activity (SARs).
- Integrate sanctions compliance into AML frameworks.
- Document decisions and rationale for risk-based approaches.
- Keep comprehensive AML records for inspection.
Click here for a summary of the SRA’s report and key findings.



