When Having a Policy Isn’t Enough: What a Recent £25,000 SRA Fine Actually Shows

HaloAML Social Pic Larger

When Having a Policy Isn’t Enough: What a Recent £25,000 SRA Fine Actually Shows

On 30 June 2026, the SRA published a settlement agreement fining a law firm £25,000 for anti-money laundering control failures. Read quickly, it looks like another line in a growing list of enforcement notices. Read closely, and it says something most firms don’t want to hear: the policy isn’t the finish line

According to the SRA’s settlement notice, the firm breached its obligations to have effective governance structures, systems and controls in place, and to keep up to date with the law governing its work, from November 2019 through to December 2025 — a six-year period.

A policy the firm knew it needed — years before it existed

What makes this case worth reading in full, rather than skimming for the fine amount, is buried in the SRA’s own reasoning. The firm had recognised, several years earlier, that it needed to implement policies, controls and procedures (PCPs) — but didn’t actually put them in place until much later. The firm self-reported the failure and had already fixed it before the SRA’s investigation began.

That alone tells you something about how these failures happen. Not through ignorance. The firm knew exactly what was required. It simply didn’t get done, for years, until a regulator was involved.

The policy went in. The files still didn’t hold up.

Here’s the part that matters most for anyone assuming a finished policy is the finish line. Once the SRA reviewed the firm’s files, it found missing or insufficient information across multiple files — even after the PCPs had eventually been implemented. The SRA assessed this as “more serious” conduct precisely because the lack of procedure had impacted at file level.

Putting a policy in place, even a reasonable one, doesn’t automatically change what happens during a regulator review. The SRA didn’t stop at checking whether the firm had documents on record. It opened live files and looked for the gap between the policy and the practice — and found one.

Cooperation and good faith didn’t move the number

The SRA scored the harm as medium — not because any client suffered a loss, but because the firm’s conduct left it moderately vulnerable to money laundering risk, particularly in its conveyancing work. No client was harmed. The firm cooperated fully with the AML Proactive Supervision and Investigation teams, made an early self-report, and had already rectified the failing before the regulator’s involvement.

None of that changed the outcome. The fine still landed at the maximum end of the SRA’s scale. In the SRA’s own reasoning, the length of the non-compliance, and the fact the firm had known what to do and delayed, made the conduct more serious — not less.

The question worth asking

For firms trying to work out where they stand, here’s the honest test: if you’re asking the question, you’re already behind. You need to be certain your framework works — not just as a document, but in how it applies to your firm’s specific risk and operations, from the MLRO through to the person handling admin on a file.