Anti-money laundering compliance has had a busy summer. On 30 June 2026, the Money Laundering and Terrorist Financing (Amendment) Regulations 2026, which amended the 2017 MLR, came into force. Five weeks later, on 6 August, the Solicitors Regulation Authority published a substantially revised sectoral risk assessment — its view of where the money laundering, terrorist financing, proliferation financing and sanctions risks in the legal sector now lie. Taken together they reset what a compliant anti-money laundering framework looks like, and every firm within the scope of the Regulations from the work types it undertakes will need to revisit its firm-wide risk assessment and its policies, controls and procedures.
Much of the revised assessment will be familiar. The SRA continues to rate the money laundering risk for the legal sector as high, with no significant change in the sector's underlying vulnerabilities since 2020. Conveyancing remains the highest inherent risk, for reasons every practitioner will recognise:
Trust and company services sit alongside conveyancing at the top of the risk table, and the position there has worsened because the 2025 National Risk Assessment moved that work from low to medium risk for terrorist financing and the SRA has followed suit.
What has changed is the emphasis. Buried in the section on transaction risk is a sentence that deserves to be pinned to the wall of every conveyancing team: "Transfer through a UK bank account does not by itself indicate that funds are legitimate”.
That directly challenges the most common excuse for a thin source of funds file. A bank transfer tells you how the money arrived, not where it came from. Properly evidenced source of funds and source of wealth enquiries remain the single most important control a firm has and this has become an issue that will always be examined closely at the SRA’s many current AML monitoring inspections.
The structure has also shifted. Client accounts, politically exposed persons and supply chain risk, described last year as emerging, are now part of the baseline, and a firm-wide risk assessment that still treats them as items to watch will look out of date. In the other direction, the SRA has dropped its commentary on firm business models, including consultant-led practices, as not specific to anti-money laundering.
The most substantial additions fall into five areas, and they share a common thread. In each case the SRA is warning against taking something at face value.
The first is cash-intensive businesses and high street crime. This follows the National Crime Agency's operation last October, in which police raided 2,734 premises — mini-marts, barbers, vape shops, nail bars and car washes — and seized £10.7 million. The assessment draws attention to so-called ghost directors, who lend their names to company documents for a fee, and to businesses who’s turnover or activities do not fit their size, age or apparent operations. Commercial property and company files for such clients are likely to be examined closely.
The second is what the SRA calls passporting — relying on due diligence carried out by another department, office or jurisdiction on an earlier matter without asking whether it remains adequate for the current instruction. "We have acted for this client before" is an observation, not a risk assessment, and residential conveyancing matters are always likely to have a higher risk profile than most other services that are also provided.
The third concerns the integrity of the Companies House register. In the past year 920 companies have entered expedited strike-off for providing false information, and criminals may still be presenting old Companies House documentation as current. A live Companies House search should be part of standard onboarding for every corporate client.
The fourth is technology. The assessment now focuses squarely on artificial intelligence, deepfakes and synthetic identities, warning that AI-enabled impersonation "may increase the risk of identity fraud and misrepresentation during client onboarding and throughout the life of a matter", particularly where firms rely on remote verification. A firm's AI policy therefore now needs to have a direct anti-money laundering dimension, and digital identity providers should be checked against the Government's Digital Identity and Attributes Trust Framework register. Cyber-enabled fraud, including mandate fraud, is highlighted in the same section.
The fifth, and the largest, is a new section on global instability, which brings sanctions risk firmly into the foreground. Sanctions obligations apply more widely than the Regulations: they attach to any matter involving a designated person or sanctioned jurisdiction, whether or not the work is within AML scope, and to payments through client or office account, including the firm's own fees. The standout addition is a subsection on the circumvention of Russian sanctions, pointing to goods routed through third countries that look innocuous on paper — printing inks, lubricants, paints and heat exchange units among them. Sanctions risk will not always announce itself through an obviously high-risk client or country. The SRA also lists the screening weaknesses it most often finds — over-reliance on automated tools, a poor grasp of ownership and control, and insufficient senior oversight. Also added to the mix are various licensing breaches, such as continuing to act after a licence has expired.
Running through all of this is a point the SRA makes explicitly: these risks rarely sit in neat boxes. The question for the fee-earner is not whether the client falls into one named category, but whether the whole picture — ownership, control, funding, geography, transaction value and urgency — makes sense.
None of this is advisory. Regulation 18(2)(a) requires a firm to take the SRA's sectoral risk assessment into account when preparing its own firm-wide risk assessment, and the SRA will ask to see that document during proactive inspections, desk-based reviews and investigations.
That activity is rising. The SRA's AML annual report for 2024–25 recorded 935 proactive engagements, almost double the year before, and fines have become more frequent and more severe, including against firms holding CQS and Lexcel accreditation. With supervision expected to pass to the Financial Conduct Authority at some stage in the next two years, scrutiny is likely to become closer still.
The amendments that took effect on 30 June 2026 are narrower but no less practical and there are four particular concerns to note in particular.
The first of these concerns pooled client accounts. Banks may continue to apply simplified due diligence to a pooled client account under regulation 37, but only where three conditions are satisfied:
Firms asked to provide that information need not disclose privileged material or breach confidentiality. The conditions apply only to accounts opened after the amendments came into force, but firms should expect banks to apply the same approach across the board, and should decide in advance who will handle such a request and what may properly be disclosed.
The second changes the geographic trigger for enhanced due diligence. "High-risk third countries" in regulation 33 has been replaced by countries subject to a Financial Action Task Force Call for Action — at present Iran, North Korea and Myanmar. Only a client established there now automatically requires enhanced due diligence. Countries on the FATF's increased monitoring list remain a risk factor under regulation 33(6), but no longer compel enhanced measures on their own. Please also note that we have already experienced a member firm being asked to recount these amended controls despite stating in their AML policy that they will never undertake any international work at all.
The third raises the threshold for transaction-based enhanced due diligence. Regulation 33(1)(f) now requires a transaction to be unusually complex or unusually large, rather than simply complex or large. That presupposes that a firm knows what "usual" looks like for its own client base.
The fourth change is a pair of technical changes to the Trust Registration Service: exempt trusts no longer count towards the de minimis limit, and existing trusts can now be closed immediately.
The sensible response is a single structured review. It starts with the firm-wide risk assessment, which should be rewritten against the August 2026 sectoral assessment:
Furthermore, where a risk does not apply, the reasons should be recorded.
The policies, controls and procedures then need to catch up with the Regulations — replacing high-risk third countries with Call for Action countries, retaining increased-monitoring jurisdictions as a risk factor, and defining what an unusually complex or large transaction means for the firm.
Several operational changes follow from the risk assessment itself.
Finally, all of this should be trained, recorded and tested, and a firm that has not had an independent anti-money laundering audit in the past twelve months would do well to commission one now, before the regulator arrives to do the job instead.