AML Compliance for Law Firms: A Practical Checklist
A practical AML compliance checklist for UK law firms; what the regulations require and how to build a process that holds up.
A practical AML compliance checklist for UK law firms; what the regulations require, who needs to do what, and how to build a process that holds up when the SRA comes to inspect.
Anti-money laundering compliance is one of the areas where UK law firms are most heavily regulated; and one of the areas where firms are most commonly found wanting. The SRA has stepped up its AML inspections, and the penalties for non-compliance are significant: fines, regulatory intervention, and reputational damage.
The challenge is that AML compliance is not a single task; it's a set of processes that must run throughout the client lifecycle, from onboarding to matter closure. This checklist covers what the regulations require and how to build a process that holds up.
The legal framework
UK law firms are subject to:
- The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 (as amended); the primary AML regulations
- The Proceeds of Crime Act 2002 (POCA); criminalises money laundering and requires firms to report suspicious activity
- SRA Code of Conduct; requires firms to have effective AML procedures
The regulations apply to all firms that are "obligated entities" under the regulations; which includes all SRA-regulated firms that provide legal services in the UK.
The checklist
1. Appoint an MLRO
Every firm subject to the AML regulations must appoint a Money Laundering Reporting Officer (MLRO). The MLRO is responsible for:
- Receiving internal reports of suspicious activity
- Deciding whether to make a report to the National Crime Agency (NCA)
- Overseeing the firm's AML procedures
- Training staff on AML obligations
The MLRO should be a senior person in the firm; typically a partner or the compliance officer. In small firms, the MLRO may also be the compliance officer for legal practice (COLP).
2. Conduct a firm-wide risk assessment
The regulations require every firm to conduct and document a firm-wide AML risk assessment. This assessment considers:
- The firm's client base
- The services the firm provides
- The geographic areas the firm deals with
- The transaction types the firm handles
- The delivery channels (face-to-face, online, intermediary-introduced)
The risk assessment must be documented, reviewed regularly (at least annually), and updated when circumstances change. The SRA will ask for it during an inspection.
3. Customer Due Diligence (CDD)
For every new client, the firm must conduct customer due diligence. This means:
- Identifying the client; verifying their identity using reliable, independent source documents (passport, driving licence, biometric verification)
- Identifying the beneficial owner; if the client is a company or trust, identifying who ultimately owns or controls it (typically anyone with 25% or more ownership)
- Obtaining information on the purpose and intended nature of the business relationship; why is the client instructing the firm, and what is the matter about?
CDD must be completed before the firm establishes a business relationship or carries out a transaction. In exceptional circumstances, it can be completed during the relationship; but only if necessary to avoid interrupting the transaction, and only if the risk of money laundering is not high.
4. Enhanced Due Diligence (EDD)
Enhanced due diligence is required for:
- High-risk clients; politically exposed persons (PEPs), clients in high-risk jurisdictions, clients in cash-intensive businesses
- High-risk transactions; large or complex transactions, transactions with no apparent economic purpose, transactions involving high-risk jurisdictions
- Clients identified as higher risk in the firm's risk assessment
EDD involves:
- More detailed identity verification
- More information about the source of funds and source of wealth
- More frequent monitoring of the relationship
- Senior management approval of the relationship
5. Source of funds and source of wealth
For transactions involving significant sums (particularly conveyancing and probate), the firm must verify the source of the client's funds and, where relevant, the source of their wealth.
Source of funds; where the money for this specific transaction comes from (e.g., sale of a previous property, savings, mortgage, inheritance)
Source of wealth; how the client accumulated their overall wealth (e.g., employment income, business ownership, investments)
The firm must obtain and retain evidence of source of funds; bank statements, sale completion statements, mortgage offers, payslips. The Checkboard integration in OrdoLux supports this by capturing source of funds documentation as part of the verification process.
6. Ongoing monitoring
AML compliance does not stop at onboarding. The firm must monitor the client relationship throughout the matter and be alert to:
- Transactions that don't match the client's profile
- Changes in the client's circumstances
- Information that suggests the client may be involved in money laundering
- Transactions that are unusually complex or have no apparent economic purpose
Ongoing monitoring is particularly important for long-running matters (e.g., probate administration, litigation) where the client's circumstances may change during the matter.
7. Record-keeping
The firm must keep records of:
- All CDD and EDD checks; for at least 5 years after the end of the business relationship
- All transaction records; for at least 5 years after the transaction
- All internal and external AML reports; for at least 5 years
- The firm-wide risk assessment; current and historical versions
These records must be retrievable; if the SRA asks for evidence of a check done 3 years ago, the firm must be able to produce it. See our guide on document management for how to structure record-keeping.
8. Staff training
All staff who handle client money or client information must receive AML training:
- At induction
- At least annually thereafter
- When regulations change or the firm's risk profile changes
The training should cover:
- The firm's AML procedures
- How to identify suspicious activity
- How to report concerns to the MLRO
- The legal framework and the firm's obligations
Training records must be kept; the SRA will ask for evidence that training has been completed.
9. Policies, controls, and procedures
The firm must have documented AML policies covering:
- Client onboarding and CDD/EDD procedures
- Source of funds and source of wealth verification
- Ongoing monitoring
- Internal reporting of suspicious activity
- Record-keeping
- Staff training
- The firm-wide risk assessment
These policies must be approved by senior management, communicated to all staff, and reviewed at least annually.
10. Suspicious Activity Reports (SARs)
If the MLRO suspects that a client is involved in money laundering, they must:
- Consider whether to make a report to the NCA
- If they decide to report, submit a SAR to the NCA
- Not tip off the client that a report has been made (tipping off is a criminal offence)
- Not proceed with the transaction without consent from the NCA (if consent is required)
The decision-making process; whether or not a report is made; must be documented. If the MLRO decides NOT to report, the reasoning must be recorded.
Where OrdoLux fits
OrdoLux integrates Checkboard for KYC, AML, PEPs and sanctions screening, with results filed automatically to the matter and a full audit trail of every check. The compliance gate prevents matters from proceeding to key stages (exchange, billing) until checks are complete.
OrdoLux also includes SRA-compliant client and office account ledgers, SharePoint document storage for 5-year record retention, and Stripe for client payments with automatic ledger allocation.
See all features or book a demo.
Limited offer
6 months free — founding firm access
We're inviting a small number of UK law firms to join OrdoLux as founding customers. Full platform access, completely free for 6 months. No credit card. No catch. When we have enough firms on board, this offer closes.
Apply for founding access →Try OrdoLux — legal case management software built for UK solicitors
Matter management, time capture, billing and AI tools in one platform. Rolling monthly, no lock-in, £50 + VAT per user.
Book a free demo Learn more