For years, AML audits have largely focused on policies, procedures and paperwork.
Do firms have a risk assessment?
Do they have a compliance framework?
Do they have customer due diligence records?
While these questions will remain important, they are unlikely to be enough in the years ahead.
The legal sector is preparing for one of its biggest regulatory transformations as AML supervision moves towards a future FCA-led model. At the same time, criminal threats are becoming more sophisticated, digital and international.
The result is a fundamental shift in what regulators are likely to expect.
Increasingly, firms won't simply need to show that compliance controls exist. They'll need to demonstrate that those controls are effective.
The latest compliance data suggests many legal firms still have work to do before reaching that level of maturity.
More than 450 AML compliance reviews were conducted by the SRA in 2024-25. Of those reviewed, 62% of firms were found to have at least one compliance gap. The most common failings included inadequate Source of Funds checks (38%), poor record keeping (31%) and insufficient risk assessments (27%). More than 180 firms required remedial action plans and 23 firms were referred for enforcement action.
Those figures suggest many firms are still focused on basic compliance foundations while regulators are already looking towards a more outcomes-based future.
The National Risk Register highlights a range of threats expected to affect the UK over coming years.
Three stand out for legal firms:
Financial crime continues to evolve through increasingly complex ownership structures, international networks and sophisticated laundering techniques.
Law firms remain attractive targets because of their role in property transactions, corporate structures and high-value client relationships.
Fraud remains one of the most significant risks facing UK organisations.
With Failure to Prevent Fraud legislation approaching, businesses are being encouraged to demonstrate that prevention is embedded within their operations rather than treated as an afterthought.
Criminals are increasingly combining cyber attacks, stolen identities and AI-generated fraud.
Traditional manual controls may become less effective against these newer threats.
The implication is clear.
Future AML audits will need to assess not only compliance procedures but also resilience against emerging risks.
We expect regulators to focus on five key areas.
Rather than assessing firms based solely on onboarding controls, regulators will increasingly examine how firms monitor risks throughout customer relationships.
Poor quality data creates blind spots for compliance teams.
Future audits are likely to focus heavily on whether firms can produce accurate, consistent and auditable records.
Manual files and fragmented systems make evidencing decisions difficult.
Digitised compliance systems provide regulators with greater transparency and accountability.
The FCA has already demonstrated its preference for tailored, risk-based frameworks rather than one-size-fits-all compliance approaches.
Technology alone will never guarantee compliance.
However, firms continuing to rely entirely on manual processes may find it increasingly difficult to justify those approaches as industry standards evolve.
Our research shows that 55% of AML checks within legal firms remain manual while only a minority are leveraging AI-driven risk scoring or sanctions screening.
The firms best positioned for the future will begin:
The future AML audit will not ask whether compliance exists.
It will ask whether compliance works.