Is Your AML Framework Compliant — or Just Untested

HaloAML Social Pic Larger

Is Your AML Framework Compliant — or Just Untested

Last week, Rooks Rider Solicitors was fined £25,000 for AML failures including non-compliant risk assessments, out-of-date policies and inadequate source of funds checks on conveyancing files. The failures ran for eight years before the SRA’s proactive supervision team identified them through a desk-based review.

Eight years. Not a firm that had never tried. A firm whose framework existed on paper but didn’t reflect what was actually happening on files.

This is exactly the problem the SRA said it would focus on in 2026 — and it is worth understanding what that means for your firm.

The Gap Between Policy and Practice

Most law firms in scope of the Money Laundering Regulations have AML policies in place. On paper, they conform to what the regulations require & the firm-wide risk assessment exists.

The question the thematic review is asking is not whether those documents exist. It is whether they reflect how the firm actually operates. That gap, between a policy that conforms to the legislation and a framework that works for your specific business, is where most firms are exposed. And it typically develops for straightforward reasons.

Policies are written to satisfy the regulations rather than to reflect the firm’s specific client base, transaction types, and risk profile. They are updated when rules change as a tick-box exercise but not actually reviewed against the firm or changes within it. The gap only becomes visible when someone tests the framework against what is actually happening.

The SRA is Now Looking More Systematically

One of the most significant changes in how the SRA operates in 2026 is the shift toward data-led supervision, taking a leaf out of the FCA’s book prior to the shift in AML supervision due to come in. Firms are increasingly being selected for review based on data analysis rather than random sampling, meaning the SRA can identify patterns of inconsistency across the profession before opening any individual investigation.

The SRA is also conducting significantly more proactive AML engagements than it was two years ago. The regulator is building the capability to find these gaps earlier and more systematically than it has before. And with the use of AI, firms will need to be ready.

A firm can pass an SRA review of its policy documents and still have the kind of file-level gaps the Rooks Rider case illustrates. That is exactly what a data-led, file-focused supervision approach is designed to find.

The Question Worth Asking Now

Most firms with AML policies in place believe they are compliant. The SRA’s consistent enforcement findings suggest that belief is often not tested against reality.

The thematic review is asking a specific question: does what your policies say match what your firm actually does? Not in theory but on files & in practice, for your specific client base and your specific risk profile.

The firms that come out of 2026 in the strongest position will be the ones that asked the question themselves.

Halo AML works exclusively with UK law firms and conveyancing practices.. If you want to understand where the gaps are before the regulator does, get in touch.


Shannon Grinnell
AML & Compliance Operations
shannon@haloaml.ai
Quadrant Court 49 Calthorpe Road, Edgbaston, Birmingham, England, B15 1TH