The AML rules may not be changing dramatically overnight, but the expectations around how firms apply them are becoming clearer. At our latest AML Core Group, the Best Practice AML Forum gave participants an opportunity to put the practical questions on the table: How are other firms preparing for the FCA? What does a good file review look like? How much evidence is enough for source of wealth? And how do you make sure AML processes work consistently across different offices and practice areas?
The forum highlighted a common theme, that good AML compliance is not about having the most complicated process. It is about having controls that are proportionate, understood by the people using them and capable of standing up to scrutiny.
The AML Core Group sessions bring together UK legal professionals and compliance experts to discuss the latest developments in financial crime regulation.
AML Core Group meetings are by invitation only. Interested in participating? Reach out here →Here are some of the key practical approaches based on participants’ most burning questions:.
Preparing for FCA supervision: focus on your data now
Most firms are still monitoring developments rather than trying to anticipate exactly what the FCA will require. The advice from the group was not to start rebuilding AML programmes before the new supervisory framework is in place.
There is, however, one area where firms can make useful progress now: understanding their data.
Firms should be mapping what data they hold, where it sits, how it is captured and whether they can actually analyse and report on it. That means looking beyond whether information exists and asking whether it can be pulled together when a regulator wants to understand the firm’s risk profile.
This is already relevant to the SRA’s increased focus on data and is likely to become even more important under the FCA.
The same principle applies to file reviews. Several recent SRA enforcement cases have involved firms having good policies on paper but failing to demonstrate that those policies were actually being followed. A review that simply checks whether a risk assessment form exists is no longer enough. Firms need to check whether the assessment was substantive and whether it makes sense in the context of the client and matter.
Which recent SRA actions should prompt a review of controls?
BRR Law, William Heath & Co and HMG Law were each fined the £25,000 cap for the same failing: having PCPs in place that were not followed, and not identifying this through supervision or file reviews. A file review that only checks a risk assessment exists is no longer enough. The SRA is opening files to see whether the assessment was actually carried out and was substantive.
Keeping policies current without creating unnecessary complexity
Keeping up with changes to the Money Laundering Regulations is a significant task, particularly for firms operating across multiple jurisdictions.
For firms with UK and EU operations, the upcoming EU Anti-Money Laundering Regulation (AMLR) adds another layer. AMLR takes effect from 10 July 2027, but there are already differences worth understanding.
These include the beneficial ownership threshold, the treatment of domestic PEPs, ongoing monitoring and the way group-wide risk information needs to be shared.
One practical approach is to compare the firm’s existing policies against both regimes and then decide whether to operate a single process based on the higher standard or maintain separate UK and EU approaches.
Neither approach is automatically right. The important thing is to make the decision deliberately and understand what it means for onboarding, ongoing monitoring and risk assessment.
How does the Economic Crime and Corporate Transparency Act fit with AML work?
The most significant change for AML is Companies House identity verification, which should improve the reliability of its data, although it still cannot be relied on alone.
Failure to prevent fraud is generally treated as a separate programme. Large organisations meeting the thresholds should have reasonable fraud prevention procedures in place, and any firm that has not yet assessed its procedures against the Home Office guidance should do so urgently.
How do firms approach source of funds and source of wealth?
Both are required. One cannot be done in isolation, as each contributes to the overall risk profile of the client and matter. Where EDD applies, sign-off should sit with a director or the MLRO, in line with the firm’s PCPs.
For complex source of wealth, such as high-risk jurisdictions or cryptoassets, the question is whether the overall picture makes sense. Firms should consider whether a document can be independently verified, whether another regulated professional has reviewed it, whether it is on public record and, for crypto, whether it was traded through an FCA-regulated provider. The origin of the initial investment matters as much as the current value. For very high-risk matters, specialist crypto screening can check for exposure to sanctioned wallets.
The question is not whether a document has been provided, but whether it can be checked and whether the amount and route make sense.
Risk assessments need to show the thinking
How much detail should go into client and matter risk assessments? There is no requirement for every firm to use the SRA’s template. What matters is that the firm’s approach allows someone reviewing the file to understand why the firm reached its conclusion and why the information available was considered sufficient.
That is particularly important if a matter is later reviewed by an auditor or regulator.
The SRA has repeatedly warned against tick-box compliance, and a form containing a series of completed boxes does not necessarily demonstrate that a meaningful assessment took place.
Detailed file reviews are therefore an important part of testing whether the firm’s approach works. They should be carried out by someone who understands AML compliance and can assess not just whether the paperwork is complete, but whether the underlying decisions make sense.
Ongoing monitoring needs to continue beyond onboarding
CDD does not end when a client is onboarded. Firms need to think about what could trigger a review during the relationship.
That might be particularly straightforward in some practice areas. Conveyancing, for example, has defined stages where a matter can be reviewed. In other areas, firms may need to focus more on whether the client’s instructions or circumstances have changed.
One approach discussed was to update client and matter risk assessments to reflect ongoing monitoring and consider reviews when there is a new instruction or, depending on the firm’s risk-based approach, periodically during the relationship.
The key issue is if anything changed that could alter the client’s or matter’s risk.
Identifying the person giving instructions
Firms also questioned how they identify and verify the individual actually giving instructions.
Electronic ID verification is widely used, including solutions involving liveness testing or biometrics. Other approaches include checking a passport or driving licence and verifying the individual through a video call or an in-person meeting.
Whatever method is used, the important point is to record the check as part of the firm’s CDD evidence.
This is becoming particularly relevant as AI makes fraudulent identities and synthetic documents increasingly sophisticated. Traditional documents may still form part of a firm’s process, but firms need to consider how they can establish that the person behind the identity is genuine.
AI in AML: keep confidentiality and human oversight at the centre
AI is increasingly being considered for onboarding and ongoing monitoring, but the discussion highlighted two important safeguards.
First, client confidentiality needs to be protected. Firms need to understand what data is being used, where it goes and how it is handled.
Second, there needs to be human oversight. AI may assist with processes such as identifying potential risks or analysing information, but the final compliance decision should remain with an appropriately responsible person.
The question for firms is therefore not simply whether AI can make a process faster. It is whether the firm can demonstrate that the technology is being used appropriately, securely and with sufficient human oversight.
What good AML practice looks like
The Best Practice Forum showed that firms are dealing with many of the same practical challenges, from preparing for a new regulator to deciding what evidence is enough for source of wealth.
But the forum also reinforced an important point: there is no single AML process that will work for every firm or every client.
Good practice means having a clear framework, applying it consistently and being able to explain the decisions made along the way. It means testing policies through meaningful file reviews, understanding the data the firm holds and making sure risk assessments reflect the reality of the client and matter.
As supervision becomes increasingly focused on evidence rather than policies alone, those practical disciplines will matter more than ever.
Join us! Our next AML Core Group meeting will take place on 21 January 2027.
AML Core Group meetings are by invitation only. Interested in participating? Reach out here →