The SRA sectoral risk assessment was substantially rewritten on 6 August 2026, adding three emerging risks that firms must now take into account under regulation 18(2)(a) when drafting a firm-wide risk assessment. Cash-intensive clients, passporting and Companies House checks are the new headings. Two older risk categories have been removed outright.

What has changed in the SRA sectoral risk assessment?

The document has been reorganised as well as rewritten, and the first change is on the cover. It is now the Sectoral Risk Assessment on anti-money laundering, terrorist financing, proliferation financing and sanctions. Sanctions and proliferation financing have moved into the title of a document that previously named only money laundering and terrorist financing, which matters because the sanctions regime applies across legal services generally, not only to work within scope of the Money Laundering Regulations.

The SRA produces the assessment under regulation 17 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. Firms pick it up at the other end, under regulations 18 and 18A, which require them to have regard to it and to any updates when creating and maintaining their own written risk assessment.

The SRA’s own summary of changes lists six substantive movements: global instability replacing the 2025 heading on economic uncertainty and capital flight, a rewritten technology section, three new emerging risks, new emerging sanctions risks on circumvention of the Russian regime, the integration of client account, PEP and supply chain risks into established risks, and the removal of risks relating to firm business models and external support.

The headline assessment has not moved. Money laundering risk in the legal sector remains high, with no significant change in vulnerabilities since 2020. Conveyancing still presents the greatest inherent risk, and the SRA notes that its MLRO’s published reports consistently list conveyancing as the area of law generating the highest number of reports.

Three new emerging risks

The emerging risks section now runs to five headings, with technology and global instability carried forward in revised form and three additions: cash-intensive businesses and high street crime, passporting, and company registration.

On company registration the SRA draws on the third progress report on parts 1 to 3 of the Economic Crime and Corporate Transparency Act 2023, which records that 920 companies entered expedited strike-off in the past year. That is the mechanism Companies House uses to dissolve companies that have given false information. The practical warning is about what happens next: criminals may still hold the original Companies House documentation and use it to prove their credentials, so the SRA tells firms to check that corporate clients are properly and currently listed.

The cash-intensive heading is blunter than it first appears. It covers nominee or “ghost director” arrangements, where a person unconnected to a business allows their name to appear on company documentation for a fee, and it ties those arrangements to organised crime including modern slavery. The SRA sets out where a firm is likely to meet this: commercial property work involving cash-intensive businesses, company matters involving unconnected directors, and transactions funded by businesses whose turnover or activity looks inconsistent with their size, age or apparent operations.

What does passporting mean in practice?

Passporting is the movement of a client from one office of a firm to another, and the risk is reliance. Where a firm treats due diligence done by another office, jurisdiction or business unit as sufficient without asking whether it remains appropriate for the instruction actually in hand, the SRA regards that as an inherent money laundering risk.

The point extends further than international structures. The same issue arises within the UK, and it arises where a firm relies on a prior instruction that was itself out of scope of the Regulations. A matter that falls within scope needs due diligence appropriate to the risk assessment for that matter, whatever was done for the client last time.

Technology risk is now about deepfakes

The technology section has been rebuilt around AI-enabled fraud, citing the Financial Action Task Force’s identification of it as an emerging threat and a separate FATF paper on cyber-enabled fraud. The concern is impersonation at onboarding and afterwards, and the SRA is explicit that the risk may be greater where a firm relies on remote verification or digital onboarding.

Firms that adopted video-based identity verification as a pandemic-era efficiency now have a regulator treating the assurance provided by digital identification services as a relevant consideration. The SRA points to the government’s Digital Identity and Attributes Trust Framework register.

What has been taken out?

Two things, and the deletions matter as much as the additions. Client account, politically exposed persons and supply chain risk are no longer emerging risks, having been folded into established risks, which is a change of framing rather than of substance.

The second removal is cleaner. Risks relating to firm business models and external support have been taken out on the basis that they are not specific to the AML sphere. A firm whose current assessment devotes a section to its own operating model can no longer point to the sectoral assessment as the reason for it.

Why It Matters

Regulation 18 makes the sectoral risk assessment a mandatory input to your firm-wide risk assessment, and the FWRA is the first document the SRA asks for on a proactive inspection or a desk-based review. A firm whose FWRA still tracks the 2025 version now has a gap it can be asked about, and three of the new headings, cash-intensive clients, passporting and Companies House checks, land on ordinary commercial property and company work rather than on anything exotic.

Sanctions moves into the title

The sanctions material is the most expanded part of the document and the part most likely to be skipped by a firm that files it under money laundering. Three emerging weaknesses are named, and all three are administrative rather than exotic: failure to meet reporting obligations by the deadline, exceeding the costs cap under the legal services general licence by a small amount, and acting after a licence had expired but before a new one came into force.

None of those describes a firm acting for a designated person in bad faith. They describe a firm losing track of a licence. The SRA also identifies over-reliance on automated screening tools as a common vulnerability, alongside inadequate understanding of ownership and control arrangements, which is the concept it flags as wider than beneficial ownership under the Money Laundering Regulations.

What should firms do before their next inspection?

The SRA does not prescribe a format, and this article is not a compliance opinion on any particular firm’s documents. What the source document does establish is that the assessment is one of the key documents requested on a proactive inspection or desk-based review, and may be requested in an investigation.

The 2025 National Risk Assessment sits behind all of this, and the SRA quotes it at paragraphs 5.193 to 5.196. One movement in the NRA is worth carrying across: the terrorist financing risk rating for trust and company services rose from low to medium, while legal services overall continue to be rated low. Firms offering trust and company services are told to be alert to the heightened rating.

Documented engagement is the practical test: a dated review recording which headings were considered, which were judged not to apply and why, is a different artefact from an assessment untouched since last year.

Further reading: the SRA’s Sectoral Risk Assessment, the 2025 National Risk Assessment, and the third progress report on the Economic Crime and Corporate Transparency Act 2023. We have also covered the transfer of AML supervision to the FCA, the Companies House identity verification deadline and, for the corporate client side, a director identity verification checklist.