Firm-Wide AML Risk Assessment: A Guide for Law Firms

What MLR 2017 Regulation 18 requires of a law firm's firm-wide AML risk assessment: the risk factors to cover, documentation, and what SRA reviews look for.

Learnsignal Education Team
9 min read
Updated

For most solicitors, anti-money laundering compliance means client due diligence, source of funds checks and knowing when to file a suspicious activity report. But underneath all of that individual, matter-level compliance sits a governance obligation that belongs to the firm as a whole, not to any one fee earner: the firm-wide (or "practice-wide") risk assessment. Get this document wrong, or treat it as a box-ticking exercise, and every AML control built on top of it is built on sand.

This guide is a companion to our AML essentials guide for solicitors, which covers individual fee-earner obligations such as client due diligence and ongoing monitoring. Here, we step back to the governance level: what Regulation 18 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017, as amended) actually requires of a firm-wide risk assessment, what the SRA and Law Society expect to see, and how this single document underpins everything else in a firm's AML framework.

What Regulation 18 actually requires

Regulation 18 of the MLR 2017 requires every firm within scope of the regulations, including solicitors' practices, to take appropriate steps to identify and assess the risks of money laundering and terrorist financing to which its business is subject. This is a distinct obligation from client and matter-level risk assessment. It is carried out at the level of the practice as a whole, and it must be:

  • In writing. An informal or undocumented understanding of "where our risk lies" does not satisfy Regulation 18.
  • Proportionate to the size and nature of the firm's business. A two-partner conveyancing practice and a full-service commercial firm with an international client base will produce very different documents, but both must produce one.
  • Kept up to date. The assessment is not a one-off exercise completed at authorisation and then filed away. It must be reviewed and revised as the firm's risk profile, client base, services or regulatory environment change.
  • Approved at senior level. Firms are expected to have senior management, typically including the Money Laundering Compliance Officer (MLCO) and the partners or board, sign off the assessment and take ownership of its conclusions.

Crucially, this firm-wide risk assessment is meant to be the foundation for everything else. Regulation 19 then requires firms to have policies, controls and procedures that are proportionate to the risks identified in the Regulation 18 assessment. If the risk assessment is thin, generic or out of date, the policies built on it will be too — and that gap is precisely what SRA reviewers are trained to spot.

The risk factors a firm-wide assessment must consider

The MLR 2017 sets out the categories of risk that a firm-wide assessment has to address. In practice, most firms structure their assessment around five areas:

  • Client risk. The types of client the firm acts for, their ownership and control structures, whether they are politically exposed persons (PEPs) or connected to PEPs, and the source of their funds and wealth.
  • Geographic risk. Where clients are based, where funds originate, and any links to jurisdictions identified as higher risk by the UK government, the EU or FATF.
  • Product and service risk. The inherent AML risk of the work the firm undertakes. Conveyancing, company and trust formation, and handling client money have historically been flagged as higher-risk legal services; general advisory or litigation work is typically lower risk.
  • Delivery channel risk. How clients are onboarded and instructed — face to face, remotely, through an introducer, or via a third party — and the verification challenges each channel creates.
  • Transaction risk. The nature, size, complexity and pattern of transactions the firm handles, including unusual payment routes, third-party payments and cash-intensive matters.

Firms should also assess proliferation financing risk, either within the main firm-wide assessment or as a clearly linked standalone document, following updates to the regulations in recent years.

Where firms go wrong: common findings from SRA reviews

The SRA has published its own sectoral risk assessment for the legal sector, and expects every firm-wide assessment to reference it and explain how the firm's own risk profile compares. In its supervisory work, the SRA has repeatedly found the same weaknesses recurring across firms of all sizes:

  • A significant proportion of assessments reviewed made no reference at all to the SRA's sectoral risk assessment, despite this being an explicit expectation.
  • Assessments that inadequately considered the risk posed by different delivery and service channels, rather than treating them as a genuine risk factor.
  • A substantial share of assessments appeared to be based on generic templates, with text that had clearly been copied rather than tailored to the firm's actual client base, services and geography.
  • In some cases, firms had not produced a firm-wide risk assessment at all until the SRA specifically requested one — a red flag in itself, since it suggests the document exists to satisfy a regulator rather than to genuinely manage risk.

These findings matter because a copied or generic risk assessment is, in the SRA's eyes, close to no risk assessment at all. Inspectors are not looking for a polished document; they are looking for evidence that the firm has genuinely thought about its own risk exposure and can demonstrate that thinking with specifics — named jurisdictions, named service lines, real client segments.

Documenting and keeping the assessment current

A defensible firm-wide risk assessment typically includes:

  • A clear statement of methodology — how risk was scored or weighted, and who was involved in the assessment.
  • Evidence that each of the required risk factors (client, geographic, product/service, delivery channel, transaction) was considered against the firm's actual practice areas and client base.
  • An explicit comparison to the SRA's sectoral risk assessment, noting where the firm's risk profile aligns with or diverges from the sector norm.
  • A record of senior management review and sign-off, with a date.
  • A defined review cycle — commonly annual as a minimum — plus a trigger-based process for ad hoc review whenever the firm takes on a new service line, opens in a new location, changes its client base, or a relevant regulatory or geopolitical event occurs.

The assessment should not sit in isolation. It needs to feed directly into the firm's AML policies, controls and procedures required under Regulation 19, into the risk-based approach applied to individual client and matter risk assessments, and into the firm's training programme, so that staff at every level understand where the firm's own risk actually lies rather than working from a generic checklist.

Who owns this, and how it fits into wider AML governance

Responsibility for the firm-wide risk assessment sits with senior management, and day-to-day ownership typically falls to the MLCO, working closely with the MLRO and compliance staff. Because this is a governance-level obligation rather than a fee-earner task, it is covered in depth in our companion guide, AML governance for MLROs, MLCOs and compliance partners, which looks at the broader responsibilities these roles carry, including how the firm-wide risk assessment connects to internal reporting lines and to decisions about filing suspicious activity reports. On that last point, our guide to suspicious activity reports and tipping-off sets out how individual SAR decisions should be informed by, and consistent with, the risk picture the firm-wide assessment establishes.

Getting ready for an SRA inspection or thematic review

When the SRA carries out a firm visit, desk-based review or thematic review, the firm-wide risk assessment is typically one of the first documents requested. Firms that come through these reviews well tend to share a few traits: the assessment is dated and version-controlled, it is referenced explicitly in the firm's AML policy, it demonstrably shaped decisions such as enhanced due diligence triggers or restrictions on certain instructions, and staff across the firm — not just the MLRO — can explain in their own words what the firm's key risks are and why. Preparing for inspection readiness is therefore less about producing a document for a single audit and more about building an assessment the firm actually uses.

Frequently asked questions

Is the firm-wide risk assessment the same as a client or matter risk assessment?
No. The firm-wide assessment under Regulation 18 looks at the practice as a whole — its client base, services, geography and delivery channels in general. Client and matter risk assessments apply that framework to an individual instruction. A firm needs both, and the client-level assessments should be consistent with the risk factors identified at firm level.

How often does the firm-wide risk assessment need to be updated?
MLR 2017 requires it to be kept up to date rather than fixed to a set schedule, but most firms adopt at least an annual formal review, supplemented by ad hoc updates whenever the firm's risk profile changes materially — for example, a new office, a new service line, or a significant shift in client base.

Who should be involved in preparing it?
Senior management ownership is expected, usually led by the MLCO working with the MLRO and compliance function, but input from partners and fee earners across different practice areas helps ensure the assessment reflects how risk actually arises in day-to-day client work, rather than being drafted in isolation by compliance staff.

What happens if a firm doesn't have one, or the SRA finds it inadequate?
The SRA can and does take enforcement action where firms have no firm-wide risk assessment, or where the assessment is clearly generic, outdated or unconnected to the firm's actual policies and controls. Beyond the regulatory risk, an inadequate assessment undermines every other AML control the firm relies on, since client due diligence, enhanced due diligence triggers and staff training should all be calibrated against it.

Building genuine AML governance capability

A firm-wide risk assessment that genuinely reflects how a practice operates, rather than a template pulled from elsewhere, is one of the clearest signals of AML maturity a firm can show a regulator. Building that capability starts with making sure MLROs, MLCOs, partners and compliance staff understand not just the letter of Regulation 18 but how to apply it to their own firm's risk profile. Learnsignal's CPD courses for legal professionals include AML training designed for exactly this audience, covering firm-wide risk assessment, governance responsibilities and inspection readiness in the depth an SRA review expects. Explore our legal CPD catalogue to find the right course for your MLRO, MLCO or compliance team.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Legal CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans