Journey

AML compliance for legal services

Learning path for law firms implementing anti-money laundering compliance: firm-wide risk assessment, client due diligence, source of funds verification, legal professional privilege boundaries, suspicious activity reporting, and preparing for SRA supervisory visits.

Professional & Financial Services Running a Business Updated 3 September 2026
references 3 guides

Understand AML obligations for legal services

Law firms are among the highest-risk sectors for money laundering in the UK. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017) place specific obligations on firms providing legal services. The Solicitors Regulation Authority supervises law firms for AML compliance and has become increasingly active in enforcement, issuing fines and imposing conditions on firms that fall short.

This journey takes you through each element of an effective AML programme, from understanding which services are in scope through to preparing for SRA supervisory visits.

Anti-money laundering compliance for law firms

Overview of AML obligations under MLR 2017, the SRA's supervisory role, and what your firm must have in place

Determine which of your services are in scope

Not all legal work falls within the MLR 2017. The regulations apply to firms providing services in connection with financial or real property transactions, company and trust formation, and the management of client money or assets. Property, corporate, tax advisory, and private client work are almost always in scope. Litigation and employment law may not be, depending on whether transactions are involved. Getting this assessment right determines the scope of your compliance programme and avoids either under-compliance or unnecessary burden on fee-earners.

Complete your firm-wide risk assessment

Every firm in scope of the MLR 2017 must carry out a documented firm-wide risk assessment. This is the foundation of your AML programme. The SRA expects your risk assessment to identify the money laundering risks specific to your practice areas, client base, geographic exposure, and delivery channels. It must be proportionate to your size and complexity, reviewed regularly, and approved by senior management. The SRA's thematic reviews consistently find that weak or generic risk assessments are the most common compliance failing.

Apply client due diligence and verify source of funds

Customer due diligence (CDD) in legal services goes beyond identity verification. You must understand the purpose and intended nature of the business relationship, assess whether enhanced due diligence applies, and verify the source of funds and source of wealth where appropriate. Property transactions require particular attention: the SRA expects firms to verify where purchase funds originate, not simply accept client declarations. Ongoing monitoring means CDD is not a one-off exercise at onboarding but continues throughout the retainer.

Navigate legal privilege and suspicious activity reporting

The interaction between AML reporting duties and legal professional privilege (LPP) is one of the most complex areas for law firms. Privileged information obtained in the course of giving legal advice is exempt from the duty to report under the Proceeds of Crime Act 2002 (POCA), but the exemption is narrow. It does not apply where the lawyer is being used to facilitate crime, nor does it cover information obtained outside the privileged relationship. When the exemption does not apply, you must submit a suspicious activity report (SAR) to the National Crime Agency and, in many cases, seek a defence against money laundering (DAML) — formerly 'consent' — before proceeding with the transaction. Failing to report is a criminal offence; tipping off the client that a report has been made is also an offence.

Legal privilege and AML reporting obligations

When legal professional privilege applies to AML reporting, the limits of the exemption, SAR procedures, and how to avoid tipping off

Prepare for SRA supervision and maintain compliance

The SRA conducts both desk-based and on-site AML supervisory visits. Visits may be triggered by risk indicators, thematic reviews of particular practice areas, or random selection. The SRA expects to see your firm-wide risk assessment, CDD policies and completed files, training records, and evidence that the nominated officer (MLRO) is discharging their responsibilities. Keeping your AML framework current is an ongoing obligation: risk assessments must be reviewed when circumstances change, staff training must be refreshed annually, and policies must reflect regulatory updates.

Comply with SRA Standards and Regulations

The SRA's supervisory expectations, compliance officer duties, reporting obligations, and how the SRA monitors firms for ongoing compliance