Beyond the policy: what good AML practice looks like in 2026

At our latest AML Core Group session, we looked at a busy few months of AML developments, shared key takeaways from the Law Society Economic Crime Conference, discussed the SRA-to-FCA transition and worked through questions submitted by participants in advance.

During the lively session, led by Ruth Mittelmann-Cohen, VinciWorks’ Head of Legal Compliance, and Jen Dunlop, managing director of The Compliance Office, one message came through consistently and that is that having a policy is no longer enough. Firms need to be able to demonstrate that their AML controls are actually being applied, file by file.

We’ve brought together the key themes from the session, our responses to the questions raised and some of the practical approaches firms are putting into practice.

The AML Core Group sessions bring together UK legal professionals and compliance experts to discuss the latest developments in financial crime regulation.

AML Core Group meetings are by invitation only. Interested in participating? Reach out here →

News updates: what do recent SRA enforcement cases tell us?

AML enforcement against law firms has increased noticeably, and the SRA is looking closely at whether firms can demonstrate that their controls actually work.

Over the summer, Ash Clifford Limited was fined £19,000 following a desk-based review. Leadenhall Law Group was fined £16,000 after acting for a high-risk PEP on 14 property purchases without applying enhanced checks. Dean Wilson was fined £25,000 for failings in its policies, controls and procedures and its client and matter risk assessments, and Haworth & Gallagher received the £25,000 maximum for failing to keep its PCPs compliant and up to date.

None of these cases involved an actual money laundering incident. Several began with a remote desk-based review, and weaknesses in the control framework, or a lack of evidence that controls were applied, were enough to trigger enforcement. Good intentions and cooperation may reduce a fine, but they will not prevent one.

News updates: what does the government’s new AML strategy mean for firms?

On 15 September, the government published its Anti-Money Laundering and Asset Recovery Strategy 2026 to 2029. It signals a move away from low-value, tick-box compliance towards a more proportionate, intelligence-led approach focused on the highest risks.

Proposals of interest to the legal sector include a possible change to the SARs suspicion threshold, a new National Financial Intelligence Service using data and AI to improve intelligence sharing, and closer integration of legal and accountancy firms into the national financial intelligence system.

Much of this still requires consultation or legislation. Whether it reduces the compliance burden or simply shifts where effort is focused remains to be seen. For now, existing requirements remain firmly in place, but the strategy is worth reading in full.

News updates: how does the Carter-Ruck ruling affect disclosure to the SRA?

On 21 September, the High Court ruled in Carter-Ruck Solicitors and another v SRA that the SRA cannot use its section 44B powers to compel solicitors to hand over documents protected by a client’s unwaived legal professional privilege. Privilege can only be overridden by clear words from Parliament, and section 44B contains none.

The practical impact is significant. Many firms previously handed over privileged material while reserving their position. That is no longer an option. Disclosure to the SRA must now exclude privileged material, which means more work for firms in identifying and protecting it.

The SRA intends to seek permission to appeal, and the government could legislate to extend the power. In the meantime, firms should continue to cooperate with investigations while ensuring privileged material is identified before anything is disclosed.

Analysis: the key takeaways from the Law Society Economic Crime Conference

Jen led this discussion in which she opened with the point that the conference delivered two contrasting messages. The reassuring one was that the SRA views compliance in the sector as broadly good, and the Money Laundering Regulations are not changing, so firms doing the right thing should keep doing it.

The more concerning messages were that a change of regulator is coming sooner than anticipated, that AI is undermining traditional ID verification faster than expected, and that there are real concerns about whether firms apply their policies consistently. The consensus from the participants was that 

Is the SRA stepping back ahead of the FCA transfer?

No. The SRA confirmed it will continue AML thematic reviews and inspections until the point of transfer. After that, it will retain responsibility for sanctions, POCA and Terrorism Act conduct, and wider regulatory breaches. The SRA also confirmed it will carry out sanctions-specific inspections from November.

A question raised at the conference, and not fully answered, was why AML and sanctions supervision are being split at all when the risks are so closely linked. This feeds into concerns about double jeopardy. After the transfer, a single issue could lead to FCA action for an MLR breach, typically against the entity, and separate SRA action under the Principles or Codes, likely against individuals.

Asked whether firms should split their firm-wide risk assessment to suit two regulators, the panel was clear: keep a single, holistic document, precisely because the risks are interconnected.

Why is the focus shifting from policies to controls?

A recurring finding from SRA audits and thematic reviews is the gap between what firms’ PCPs say and what happens day to day. That gap is now what is being supervised. “We have a policy for that” will not satisfy either regulator. Firms need to demonstrate compliance on the ground.

A firm-wide risk assessment is of little value if it isn’t used, and SRA inspections or independent audits should not be the first place problems surface. Firms should be identifying issues through their own file reviews.

At the same time, the SRA warned against over-compliance, noting that smaller firms in particular are going too far on source of funds and source of wealth checks. The test is whether a step is taken because the policy requires it or because the firm has decided it is needed. Applying that test well depends on training, experience and a genuine understanding of the client and matter. The simplest control available is to document the decision.

How should firms prepare for data-driven supervision?

The FCA is heavily data-led and the SRA is moving in the same direction. The message from the conference was that firms are not short of data. They are short of ways to use it well.

The recommended starting point is a data audit covering clients, work types, jurisdictions, relationship ownership, sources of instruction, EDD volumes and PEP exposure, alongside how that data is stored and how it feeds into risk assessment. Many firms still rely on fragmented spreadsheets across departments, which makes reporting difficult.

Two warnings stood out. First, data can mislead. Completing risk assessments on 100% of matters means little if they are ineffective, and the SRA found 39% of the firm-wide risk assessments it reviewed were ineffective. Second, internal definitions must align with regulatory ones. An internal definition of “PEP” that differs from the MLR definition could distort what is reported, particularly to an FCA that will use the data to target reviews.

Structured fields make reporting easier, but firms also need to record the reasoning behind decisions, such as why a matter was assessed as low risk or why source of funds evidence was considered sufficient.

Has AI broken document-based identity verification?

This was one of the most striking themes of the conference. The panel argued that the profession spends too much energy on its own use of AI and not enough on criminals using AI against firms.

The figures quoted were stark. A full set of fake identity documents capable of passing a liveness test was said to cost around $15 and take around 15 minutes to produce, down from around $500 a year earlier. Less than 20 seconds of audio is reportedly enough to clone a voice, and the conversion rate from attempted to successful fraud was said to have risen roughly four and a half times in two years.

One panellist suggested that relying on a passport and three months of bank statements is no longer defensible. Not every attendee shared that view, nor did core group participants with one noting that “I didn’t take away that passports and bank statements were no longer the standard/or defensible.”

But the underlying point stands: ID tells you who the client is, not whether they are laundering money. With the main risk for law firms sitting in source of funds, easily fabricated bank statements carry limited evidential value. And as a core group member noted, the move towards greater non-face to face meetings is a growing risk

The conference offered no easy answers. Detection tools exist but are struggling to keep pace. The suggested approach is layered, combining NFC chip reads, physical inspection of documents, biometric liveness testing and, for very high-risk matters, meeting the client in person. Above all, it means genuinely knowing the client and asking whether what they provide makes sense. The concept of “decentralised vigilance” was also highlighted, with every fee earner playing a role rather than leaving scrutiny to a central compliance team. 

Where are we now on the SRA to FCA transition?

As Ruth noted, this core group session had to dedicate some time to the SRA to FCA transition. The Financial Services and Markets Bill, which gives the FCA its new AML role, completed its Lords stages on 15 September and had its Commons first reading the same day. Royal Assent is expected in February or March 2027. The first firms are due to move to FCA supervision before the end of 2028, with all firms expected to transfer by mid-2030, although there is speculation that this date could slip.

Following the government’s June 2026 decisions, the FCA will keep a single public register, and firms must register to carry out AML-regulated work. The regulation 58 fit and proper test will apply to law firms after the transfer, and the FCA will be able to appoint skilled persons and give directions. The regulation 72 protection for privileged material remains unchanged. The profession will continue to write AML guidance for FCA approval, and the FCA will be funded by fees on firms, subject to a separate consultation.

The FCA acknowledged at the conference that it has not yet engaged properly with law firms but said this will change in the coming months. It intends to take a risk-based, proportionate approach, starting with data the SRA already holds and requesting some additional information. It will also discuss with the sector how much of the LSAG guidance it adopts.

Several questions remain open, including how double jeopardy will be managed in practice, whether the fit and proper test will apply to MLROs and MLCOs, which tribunal will hear appeals and how a quicker process for minor fines will work.

How are compliance roles changing?

Change is coming on two fronts. The FCA is expected to interview MLROs and to want experienced, hands-on role holders, which is likely to end the MLRO role that exists in title only.

Separately, the Legal Services Board has approved SRA rules for firms with more than one manager and turnover above £600,000 or client money above £2m. In these firms, a person who can determine or direct significant management decisions cannot be the COLP or COFA. The SRA plans a phased start from January 2027, with larger firms first. The Law Society will debate the rules at its AGM on 14 October, but they remain approved unless the SRA changes them.

Where one senior person holds several roles, firms should plan them together, considering succession, time commitment and SRA approval, which must be in place before a new COLP or COFA starts.

Key dates to watch

There are several important milestones on the horizon for law firms:

  • 14 October 2026: The Law Society AGM will consider the new COLP/COFA rules.
  • Autumn 2026: The SRA is expected to publish detailed guidance on the new COLP/COFA requirements.
  • From January 2027: The new COLP/COFA rules will begin coming into force in phases.
  • February–March 2027: Royal Assent for the Financial Services and Markets Bill is expected, paving the way for the FCA’s new AML supervisory role.
  • April 2027: The new accountants’ report rules are due to come into effect.
  • Later in 2027: The Treasury plans to lay regulations for the new guidance model.
  • 2027: The UK’s next FATF evaluation is expected.
  • 2028–2030: The first firms are expected to move to FCA supervision before the end of 2028, with the aim of completing the transition for all firms by mid-2030.
  • Dates still to be confirmed: Further consultations are expected on FCA fees, minor fines and new supervisory powers.

What all this means for firms

Taken together, these developments point to a period of significant change for AML compliance in the legal sector. But the message from the Core Group was not just to prepare for a new regulator or keep up with new rules. It was to look closely at how AML compliance actually works.

Firms will need to demonstrate the link between their policies, their risk assessments and what happens on individual files. That means reviewing files, documenting decisions, using data effectively and making sure compliance responsibilities are understood across the firm.

As supervision becomes more data-driven and the move to the FCA gets closer, “we have a policy for that” is unlikely to be enough. Firms need to be able to prove it works.

Join us! Our next AML Core Group meeting will take place on 21 January 2027.

AML Core Group meetings are by invitation only. Interested in participating? Reach out here →