AML Controls that actually work
At Teal, we spend a lot of time reviewing files, conducting audits and providing feedback to firms, and sometimes this means talking about where their controls are falling short. The recent SRA webinar on AML Controls seemed very familiar, because the themes they raised are the same ones we see played out on files, time and again.
Â
The case study that says it all….
The webinar walked through a fictional conveyancing matter: a mother and son purchasing a £250,000 property, funded by proceeds from a French property sale, referred in by an existing client. Classic scenario. What I found most instructive was the PEP flag. The e-verification report flagged the son as a potential PEP, but when the fee earner looked more closely, the name was misspelt. They ran the search again with the correct spelling. No match. False positive confirmed. Matter proceeds, appropriately.
Â
That’s the kind of scrutiny that separates good practice from a tick-box exercise. I often see files where a screening flag had been noted and then nothing. No investigation. No rationale. Just the document sitting on file, unexamined.
Â
The same pattern showed up with the bank statement. The first one didn’t show the funds were available. A less diligent fee earner might have filed it and moved on. Instead, the question was asked, and it turned out to be the wrong statement attached in error. The updated one clearly showed the sale proceeds. Problem solved, rationale documented.
Â
The firm-wide risk assessment: more than a template
One of the things the webinar did really well was showing how the firm-wide risk assessment (FWRA) should function as a living guide, not a document that gets signed off once a year and filed away.
Â
In the case study, the FWRA was doing genuine work. It confirmed conveyancing as high risk, flagged that overseas funding is unusual for the firm, and set out that PEP matters require senior management approval. That’s a well-constructed FWRA. It’s tailored. It actually helps a fee earner make decisions.
Â
However the SRA’s research data told a different story. Of 451 firms engaged through compliance plans last year (where the SRA give firms a list of issues they need to attend to post audit); 355 had received feedback on their FWRA, and 151 were still using basic, untailored templates. From my audit experience, I know exactly what those look like: generic headings, generic risks, nothing that would help a fee earner dealing with an actual client on an actual file. Firms using the SRA template as a guide are often not providing enough detail and that’s likely to be an issue. In future providing data to the regulator will become far more important, so think about how you can gather it.
Â
The patterns described were familiar:
- Client and matter risk assessments completed as a formality, without detail.
- High-risk factors noted, but only standard due diligence applied.
- Source of funds treated as a document collection exercise, with pages of bank statements and no evidence that anyone had actually read them.
- And the statistic that stayed with me: 82% of firms referred for failing to risk-assess at file level actually had a process in place. It just wasn’t being followed. That’s not a policy problem. That’s a culture problem, and it’s going become a major issue. The controls firms have in place to check compliance at file level and ensuring staff buy in, are the responsibility of management. Documented policies that are not being followed in practice suggest management don’t actually do any managing, which means a lack of control and that isn’t going to be acceptable in future.
Â
Audits and file reviews
The webinar noted that firms are carrying out more audits, which is positive, but not all of them are meeting the requirements of Regulation 21. Ongoing file reviews (Regulation 19) and the independent Regulation 21 audit serve distinct purposes. The first is a day-to-day control, the second is a formal, independent scrutiny of your policies and procedures as a whole. Conflating the two or treating audit findings as a paper exercise nobody acts on, is a gap.
Â
What good looks like
The SRA also noted it does see good practice, and it’s worth naming what it looks like. Consistency is the hallmark. When the FWRA, the AML policy, and the client and matter risk assessment all work in unison, and where deviations are explained with clear rationale, that’s a firm that understands what it’s doing and why.
Â
When we conduct independent audits, the most telling question is simply: why? Why did you rate this matter as high risk? Why did you not escalate this to the MLCO? Why does your client and matter risk assessment say low risk when your FWRA identifies this transaction type as medium risk?
Â
A fee earner who can answer those questions clearly, confidently, and with reference to the file is demonstrating exactly what good looks like. What raises concern is not always a wrong answer, but no answer at all, with sections of the client/matter risk assessment left blank or no summary of the risks and the purpose and nature of the instruction. Or an answer that amounted to “because that’s what we do.” That tells us the control exists on paper but hasn’t been understood in practice. A ‘standard matter for a longstanding client’ (and therefore low risk) suggests a lack of engagement with regulatory requirements.
Â
Good looks like: Fee earners who can explain their decisions; File reviews used as a training tool, not just a compliance exercise; Policies that are genuinely accessible; And senior management who are engaged, who understand the regulations and don’t create a culture where fee earners feel they can’t ask questions or escalate concerns. The SRA noted that around 8% of MLCOs and MLROs interviewed last year didn’t have sufficient understanding of their own role. That’s a culture signal, not just a training gap. Don’t be surprised that this will be an area the FCA will tighten up on when the proposed AML supervision changes are implemented.
Â
Don’t wait for an inspection to find your gaps.
If you would only find issues under scrutiny, that’s a problem, because you won’t always have warning before the notice of inspection arrives. Pull a selection of files and stress-test them against your FWRA. Test your e-verification system. Look at your source of funds documentation, really look. And ask whether your fee earners know where to go when they’re uncomfortable with a transaction.
Â
The SRA’s thematic focus this year is on policies, controls, and procedures, and how well they work in practice. That reflects exactly what the data is showing, firms have policies, but the question is whether those policies are alive in the work.
Â
Having seen the results of SRA inspections which go badly and then supporting firms in raising standards and sometimes mitigating penalties, we at Teal Compliance can see that the gap between a compliant firm and a non-compliant one is not usually the policy documents. It’s the culture, the scrutiny, and the genuine understanding of why the controls exist. Get that right, and the correct paperwork follows and no headaches!
Get in touch
At Teal, we’re here to support your journey towards compliance that works.
We understand that compliance can be a daunting word, but it’s also the key to unlocking your firm’s full potential.
Our experts at Teal Compliance are here to help. Get in touch today to explore tailored solutions and ensure your firm stays ahead of regulatory requirements.



