The SRA Compliance Toolkit: How to Prepare for Your Firm Assessment

SRA compliance toolkit and firm assessment guide

What the SRA Compliance Toolkit covers, how to prepare for a firm assessment, and the practical steps every firm should take.

What the SRA Compliance Toolkit covers, how to prepare for a firm assessment, and the practical steps every UK law firm should take before the SRA comes knocking.

The SRA's approach to regulation has shifted over recent years. It is less about annual reporting and more about proactive supervision; the SRA identifies firms it wants to inspect, requests information, and conducts assessments. The firm that is prepared is the firm that passes without stress. The firm that isn't finds itself scrambling to produce documents, policies, and records that should have been in place all along.

This guide covers the SRA Compliance Toolkit, what an assessment involves, and how to prepare.

The SRA Compliance Framework

The SRA regulates firms through several mechanisms:

  • SRA Code of Conduct; the rules that all firms and solicitors must follow
  • SRA Accounts Rules; the rules on client money (see our dedicated guide)
  • SRA Transparency Rules; requirements on publishing pricing and service information
  • Anti-money laundering regulations; as covered in our AML compliance checklist
  • SRA Indemnity Insurance Rules; requirements for professional indemnity insurance

The SRA also publishes thematic guidance on specific areas; technology, AI use in legal practice, data protection, and diversity reporting.

What the Compliance Toolkit covers

The SRA expects every firm to have documented systems and controls covering:

Governance and management

  • Firm structure; who owns the firm, who the managers are, who the compliance officers are
  • COLP (Compliance Officer for Legal Practice); responsible for ensuring the firm complies with the SRA Code of Conduct and other regulatory requirements
  • COFA (Compliance Officer for Finance and Administration); responsible for ensuring the firm complies with the Accounts Rules
  • MLRO (Money Laundering Reporting Officer); responsible for AML compliance

In many small firms, one person holds multiple roles. The SRA accepts this; but the firm must document who holds each role and what their responsibilities are.

Policies and procedures

The SRA expects firms to have documented policies covering:

  • Client care and complaints handling; how the firm handles client complaints, including the requirement to signpost to the Legal Ombudsman
  • AML; the firm's AML risk assessment, CDD procedures, and SAR process (see our AML checklist)
  • Conflict of interest; how the firm identifies and manages conflicts
  • Data protection; GDPR policies, breach response plan, subject access request process
  • Equality and diversity; the firm's approach to equality, diversity, and inclusion
  • Supervision; how the firm supervises junior staff, trainees, and support staff

Financial controls

  • Client money; how client money is held, reconciled, and used
  • Accounting records; the firm's accounting system and the audit trail
  • Reporting; how the firm reports to the SRA (annual reporting, notifiable events)

Client-facing information

  • Client care letters; the information provided to clients at the outset of the matter
  • Cost information; estimates, billing arrangements, and how changes are communicated
  • Transparency Rules; the firm publishes certain pricing information on its website (for certain services; see below)

The SRA Transparency Rules

The SRA Transparency Rules require firms to publish certain information on their website:

  • Price information for certain services; conveyancing (residential sale and purchase), probate (simple and complex), motoring offences (certain types), employment tribunal claims (unfair dismissal and redundancy), and licensing (certain types)
  • Service information; description of the services, what's included, what's not included, typical timescales
  • Complaints information; how to complain, the firm's complaints procedure, and the right to complain to the Legal Ombudsman
  • Diversity data; the firm must publish diversity data (or explain why it hasn't)

Many firms publish the minimum required information and treat it as a box-ticking exercise. Firms that do it well; publishing clear, useful pricing information; build trust with potential clients and comply with the rules at the same time.

How to prepare for an assessment

Step 1: Conduct a self-assessment

Before the SRA arrives, conduct your own assessment. Walk through the SRA's compliance framework and check:

  • Are all required policies documented, current, and communicated to staff?
  • Are the COLP, COFA, and MLRO roles assigned and documented?
  • Is the firm-wide AML risk assessment completed and up to date?
  • Are client account reconciliations up to date (within the 5-week requirement)?
  • Are client care letters complete and compliant?
  • Are complaints being handled within the SRA's expected timescales?
  • Is the firm's website publishing the required transparency information?

Step 2: Review your files

The SRA may ask to see matter files. Pick 5-10 random files and check:

Step 3: Review your financial controls

Check:

  • Client account reconciliations are up to date
  • No unauthorised transfers from client to office account
  • All disbursements are documented
  • The firm's reporting accountant has been engaged (if required)
  • PII cover is in place and adequate

Step 4: Review your website

Check the transparency rules compliance:

  • Pricing information is published for the required services
  • Service descriptions are accurate
  • Complaints procedure is published
  • Diversity data is published or an explanation is given for why it isn't

Step 5: Review your staff training

Check:

  • All staff have received AML training (within the last 12 months)
  • All staff have received data protection training
  • New staff received compliance training at induction
  • Training records are documented

What happens during an assessment

The SRA typically:

  1. Requests information in advance (policies, records, audit trails)
  2. Conducts interviews with the COLP, COFA, and fee earners
  3. Reviews matter files (usually a random sample)
  4. Reviews the client account and accounting records
  5. Reviews the firm's website for transparency compliance
  6. Issues findings; which may range from "no action needed" to "improvement required" to formal regulatory action

The assessment is not a surprise exam. The SRA will tell you what they want to see in advance. The firm that can produce the documents quickly and confidently is the firm that has the least stressful assessment.

Where OrdoLux fits

OrdoLux is SRA-compliant by design; with client and office account ledgers that meet the Accounts Rules, Checkboard for KYC/AML with results filed to the matter, SharePoint document storage with per-matter access controls and full audit trails, and mandatory 2FA across the platform.

OrdoLux also includes Stripe for client payments with automatic ledger allocation, 350+ HMCTS court forms filed to the matter, time recording with daily timesheets, and e-signature; all in one platform that makes the SRA's file review straightforward.

See all features or book a demo.


Limited offer

6 months free — founding firm access

We're inviting a small number of UK law firms to join OrdoLux as founding customers. Full platform access, completely free for 6 months. No credit card. No catch. When we have enough firms on board, this offer closes.

Apply for founding access →

Try OrdoLux — legal case management software built for UK solicitors

Matter management, time capture, billing and AI tools in one platform. Rolling monthly, no lock-in, £50 + VAT per user.

Book a free demo Learn more

← Back to the blog

Explore related guides