This guide is written for solicitors, trainees and law students in England and Wales.
A firm-wide risk assessment is the document the SRA asks for first on a proactive inspection, and regulation 18(2)(a) requires firms to take the SRA’s sectoral risk assessment into account when drafting it. That sectoral document was substantially rewritten on 6 August 2026. This checklist sets out what the revised version covers, section by section.
What does regulation 18 actually require?
Two separate duties sit either side of the sectoral risk assessment, and they are often collapsed into one.
The SRA produces the assessment under regulation 17 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. Firms pick it up under regulations 18 and 18A, which require them to identify and assess their own risk, to keep a written record of it, and to have regard to the sectoral assessment and any updates when creating and maintaining that record.
The difference in wording repays attention. The SRA is required to produce; the firm is required to have regard. A firm that adopts the sectoral document wholesale has done neither, because having regard to something means engaging with it and reaching a view, which is a different exercise from reproducing it.
The sectoral assessment is expressly not a substitute for a firm-wide risk assessment. It sits alongside a firm’s own knowledge of its practice and clients, which is why a document that reproduces the SRA’s headings without applying them to the firm’s actual work is not doing the job the regulation describes.
This guide sets out what the source document requires. It is not an assessment of whether any particular firm’s document is adequate, which turns on that firm’s clients, services and controls.
Who this checklist is for
MLROs and MLCOs reviewing an existing firm-wide risk assessment against the current sectoral document. COLPs and COFAs who will be asked for it. Anyone in a firm that has not revisited its assessment since the 2025 version, which is now superseded in six substantive respects.
It is equally relevant to firms outside the obvious AML practice areas. Three of the new risk headings land on ordinary commercial property and company work rather than on anything exotic.
What changed in the 2026 revision?
The SRA publishes its own summary of changes, and the table below follows it. The 2026 document has also been retitled to cover proliferation financing and sanctions, where the previous version named only money laundering and terrorist financing.
| Area | Position in 2025 | Position in 2026 |
|---|---|---|
| Economic uncertainty and capital flight | Emerging risk, under that heading | Revised and expanded as “Global instability and uncertainty” |
| Technology | Emerging risk, general | Rewritten around AI-enabled fraud, deepfakes and remote onboarding, citing FATF |
| Cash-intensive businesses and high street crime | Not a separate heading | New emerging risk, covering nominee and “ghost director” arrangements |
| Passporting | Not a separate heading | New emerging risk, covering reliance on due diligence done elsewhere |
| Company registration | Not a separate heading | New emerging risk, drawing on Companies House strike-off data |
| Russian sanctions circumvention | Not identified as emerging | New emerging sanctions risk |
| Client account, PEPs, supply chains | Emerging risks | Integrated into established risks |
| Firm business models and external support | Risk headings present | Removed as not specific to the AML sphere |
The underlying assessment has not moved. Money laundering risk in the legal sector remains high with no significant change in vulnerabilities since 2020, and conveyancing continues to present the greatest inherent risk. The 2025 National Risk Assessment, quoted by the SRA at paragraphs 5.193 to 5.196, raised the terrorist financing rating for trust and company services from low to medium while leaving legal services overall at low.
Regulation 18 makes the sectoral risk assessment a mandatory input, and the firm-wide risk assessment is the first document requested on a proactive inspection or desk-based review. A document that still tracks the 2025 structure now has an identifiable gap, and the gap is visible without anyone reading the substance: three headings exist in the source that do not exist in the firm’s assessment.
The checklist
Emerging risks: the five current headings
- Technology. Does the assessment address AI-enabled impersonation at onboarding and during a matter, and does it record the position on remote verification? The SRA treats the assurance provided by digital identification services as a relevant consideration, and points to the government’s Digital Identity and Attributes Trust Framework register.
- Passporting. Does it deal with reliance on due diligence carried out by another office, jurisdiction or business unit? The point extends to movements within the UK and to reliance on a prior instruction that was itself out of scope of the Regulations.
- Cash-intensive businesses and high street crime. Does it cover nominee and unconnected director arrangements? The SRA names three encounters: commercial property work involving cash-intensive businesses, company matters involving nominee directors, and transactions funded by businesses whose turnover or activity looks inconsistent with their size, age or apparent operations.
- Global instability and uncertainty. Does it link jurisdictional instability to PEP connections, unverifiable source of funds and wealth, opaque ownership structures, and proliferation financing indicators?
- Company registration. Does it record a check that corporate clients are properly and currently listed at Companies House? 920 companies entered expedited strike-off in the past year, and criminals may still hold the original documentation.
Established risks: the five categories
- Products and services. Conveyancing, client accounts, third-party managed accounts, trust and company creation, tax advice, family offices.
- Client risk. PEPs including domestic PEPs, higher-risk sectors, familiar clients, anonymity and difficulty proving identity, intermediaries and agents.
- Transaction risk. Size and value, vendor fraud, cryptoassets, physical cash, cash property purchases, transactions outside the firm’s or client’s norms, products facilitating anonymity, new delivery mechanisms, pooled funds, complexity, supply chain.
- Delivery channel risk. Remote clients, combining services, third-party payments, irregular transfer methods.
- Geographic risk. FATF listings, the firm’s own market knowledge, and jurisdictions with significant corruption.
Sanctions
- Does the assessment treat sanctions as applying across legal services generally rather than only to work in scope of the Money Laundering Regulations? The SRA is explicit on this point.
- Does it engage with ownership and control, which the SRA describes as wider than beneficial ownership under the Regulations?
- Does it cover the three licensing weaknesses named: missed reporting deadlines, exceeding the costs cap under the legal services general licence by a small amount, and acting after a licence expired but before a replacement came into force?
- Does it address over-reliance on automated screening tools, which the SRA identifies as a common vulnerability?
Documentation
- Is the review dated?
- Does it record which headings were considered and judged not to apply, with the reason?
- Is it consistent with the firm’s policies, controls and procedures, rather than sitting apart from them?
What goes wrong most often?
Four patterns recur.
Reproducing the sectoral assessment. A firm-wide risk assessment that lists the SRA’s headings without applying them to the firm’s client base, services and jurisdictions has adopted the source rather than had regard to it.
Treating a removed heading as still live, or a moved one as new. Client account, PEP and supply chain risks are no longer emerging risks. They have become established risks, which is a change of framing rather than of substance, and a document describing them as novel is out of step with the current version.
Filing sanctions separately. The retitling is a signal. A firm that keeps a sanctions policy in one place and an AML risk assessment in another, with no cross-reference, is working against the structure of the document it is required to consider.
Leaving no audit trail. An undated assessment cannot show when it was last considered against a source document that is refreshed regularly, and the SRA says it will continue to refresh the sectoral assessment on a regular basis. The practical test on inspection is not whether a firm reached the same conclusions as the regulator, but whether it can show that it looked.
Official sources
- SRA Sectoral Risk Assessment, updated 6 August 2026
- National Risk Assessment of money laundering and terrorist financing 2025
- Third progress report on parts 1 to 3 of the Economic Crime and Corporate Transparency Act 2023
Related reading on this site: the transfer of AML supervision to the FCA, our director identity verification checklist, and the return of accountants’ reports under the client money rules.
Date last updated
7 August 2026. Next scheduled review: on publication of the next revision of the SRA sectoral risk assessment.