For law firms, anti-money laundering compliance can sometimes become a box-ticking exercise: the client has been identified, the sanctions and PEP checks have been run, manually or automatically, the form has been completed, and the file can move forward. Ticked.
But completing an AML checklist is not the same as understanding risk. A firm can have sophisticated compliance software, detailed policies, and regular training, yet still fall short if fee earners are not applying professional judgement to the particular client or matter in front of them.
That distinction is increasingly important. The Solicitors Regulation Authority (SRA) continues to identify client and matter risk assessments as an area where firms need to improve. In its 2024/25 AML reporting, the SRA found that 39% of the client/matter risk assessments were deemed ineffective, with 16% of files either lacking a client and matter risk assessment or having an incomplete one.
The message here is pretty clear: AML compliance can’t be reduced to proving that checks have been completed. The question is whether solicitors can demonstrate that they understood the risks, considered them, and made a reasoned decision about what to do next.
A quick terminology recap. A client risk assessment is concerned with the risks associated with the individual or company; whereas a matter risk assessment considers the risks associated with the particular legal work being undertaken.
The distinction matters. A long-standing corporate client might ordinarily present a relatively low client risk, but a particular transaction could introduce unusual jurisdictions, complex ownership structures, unexplained funding or other risk indicators. Equally, a client who is not obviously high risk may become higher risk because circumstances change during the relationship.
The SRA's guidance makes it clear that firms should consider both the client and the matter, understand why the services are required, consider source of funds, remain alert to information that doesn’t fit the existing assessment, and document the steps taken. That is fundamentally a judgment exercise.
A risk rating of “medium” or “low” on its own says very little. The more important question is why the fee earner reached that conclusion.
A useful risk assessment should therefore be able to answer questions such as:
AML processes often concentrate heavily on onboarding: identify the client, complete the checks, and decide whether the matter can start. But the decision to continue acting is also a risk-based decision.
The fact that a client passed onboarding six months or five years ago doesn’t mean that the risk remains unchanged. Legal regulators specifically warn firms not to assume that an existing or long-standing client is necessarily lower risk. They also expect firms to review assessments when important new information emerges or at key stages in the relationship. That means a firm should be able to explain, at any point in the relationship: What do we know about this client and matter, what has changed, and why are we still comfortable acting?
This is where the difference between a compliance exercise and a genuine risk-based approach becomes clear. If a new instruction is inconsistent with the client's previous activity, if beneficial ownership changes, if the source of funds becomes unclear, or if a new jurisdiction becomes involved, the original assessment may no longer be sufficient. “Checks were completed at onboarding” is not an answer to those questions.
One of the most important things firms must show to regulators is the evidence that they carried out checks, not just claim they have.
There is nothing inherently wrong with using a standardised form. In fact, a consistent framework can help firms ensure that important risk factors are considered.
The problem arises when the form becomes the assessment. The SRA has reported seeing firms use tick-box approaches with simple yes/no questions and no opportunity to capture the reasoning behind the assessment. It has also identified firms relying too heavily on generic templates or using templates that have not been tailored to their own work and risk profile.
This creates several risks:
When a fee earner repeatedly encounters similar instructions, there is a natural temptation to follow the familiar pattern: same client type, same matter type, therefore same answers. But repetition does not remove risk.
Risk doesn’t always fit neatly into predefined categories. A client may have an unusual but legitimate explanation for a transaction, or a particular source of wealth may require further investigation. A form that only permits a risk rating and a series of tick boxes leaves little room to record that context or explore it further.
The SRA's template specifically asks firms to record the reason for a risk rating. This is not an administrative detail: the rationale helps the firm understand the assessment when it is reviewed later and provides a basis for identifying changes.
Risk scoring can be useful, but a numerical score should not be mistaken for a conclusion. Different firms may assign different scores to the same risk factor. The SRA highlights examples of firms allocating different weightings to factors such as geography or familiarity with a client. Its guidance emphasises that the assessment should be tailored to the firm's circumstances and that individual client and matter circumstances must be considered.
The overall score should therefore be treated as an indicator rather than an answer. A client does not become low risk because a spreadsheet says so.
One of the most important characteristics of a genuine risk-based approach is that it is dynamic.
Under regulation 28(11) of the Money Laundering Regulations, ongoing monitoring is mandatory and risk assessments should be reassessed at appropriate intervals. Changes in beneficial ownership, for example, or changes in the client's business or address, and other new information can all affect the risk profile.
The purpose is not to make lawyers repeatedly complete paperwork for its own sake. It is to ensure that the firm's understanding of the client remains aligned with reality.
A robust process does not necessarily need to be complicated. It needs to make good judgment easier and poor judgment harder.
Here are some useful tips I have gathered working alongside solicitors and law firms:
Firms should have a standard approach to assessing clients and matters, rather than allowing every fee earner to develop their own process.
Why not start with the SRA’s client and matter risk assessment template and tailor it around your firm’s risk profile, practice areas, and client base.
A good assessment should not only ask for a risk rating. It should ask the person completing it to explain the reasoning behind that rating. The objective is to create a record that another person can understand later.
The risk assessment should lead somewhere. If the risk is higher, the firm should be able to identify what additional measures are required. This may include enhanced due diligence, additional source of funds information or senior approval, depending on the circumstances.
The assessment should therefore not sit separately from the firm's customer due diligence process. It should help determine what level of diligence is appropriate.
“Reviewed” should not simply mean that a box has been ticked again. The person reviewing the assessment should consider whether anything has changed and record that conclusion.
This is where AML technology has an important role. Automated checks can gather and verify information, screen individuals and businesses against relevant databases, identify potential sanctions or PEP issues and provide evidence of checks undertaken. Software such as SmartSearch can also support configurable risk assessment workflows and ongoing monitoring.
Used properly, AML technology can help a firm build a more efficient process: collect information → verify it → identify risk indicators → assess the client and matter → decide what further due diligence is required → document the rationale → monitor for change.
But if the technology can identify information and risk indicators, the firm still needs to interpret them in the context of the client and the matter.
The strongest AML process is not necessarily the one with the longest questionnaire or the most checks. It is the one that shows a firm understood the risk and had a defensible reason for continuing the relationship. This is so much more than being able to demonstrate that a series of boxes was completed.
The strong focus on client and matter risk assessments by regulators should therefore be viewed as more than another compliance requirement. It is an opportunity for firms to make AML part of everyday legal judgment.
If you are looking to strengthen your onboarding and risk assessment processes, I'd be happy to share my experience and discuss what works in practice. 2
Give me a shout: book a discover call
https://news.sra.org.uk/solicitors/guidance/client-and-matter-risk-assessments/
https://www.sra.org.uk/sra/research-publications/aml-annual-report-2024-25/
https://guidance.sra.org.uk/sra/research-publications/aml-annual-report-2022-23
https://news.sra.org.uk/solicitors/resources/money-laundering/client-matter-risk-template
https://news.sra.org.uk/news/events/on-demand-events/anti-money-laundering-matter-risk-assessments/