Fraud Risk Awareness for Legal Practice: A Guide for Solicitors and Firms

A practical guide to fraud risk in legal practice: fake law firm and impersonation scams, conveyancing and fee fraud, internal trust account controls, and what the SRA expects firms to do about it.

Learnsignal Education Team
10 min read
Updated

Fraud against solicitors and their clients rarely announces itself as a single, obvious threat. It shows up as a cloned website using a real firm's name, a forged completion statement, a bank mandate email that looks perfectly routine, or a trusted colleague quietly misusing access to client money. Each of these exploits a different weak point in how a firm operates, and each sits on the same regulatory territory: the Solicitors Regulation Authority (SRA) expects every firm, regardless of size, to identify its fraud risks and put proportionate controls around them. This guide sets out the broad landscape of fraud risk in legal practice and where to focus your firm's defences, alongside relevant CPD courses for legal professionals that build this awareness into ongoing training.

Solicitors are an attractive target for fraudsters for a simple reason: firms routinely hold client money, handle high-value transactions, and carry a level of public trust that criminals can borrow or exploit. That combination shows up across several distinct fraud types, and it is worth being precise about which one you are dealing with, because the warning signs and the controls that stop each are different.

Broadly, the fraud risks a firm and its clients face fall into four groups: fraud carried out against clients using a real or fake law firm's identity (impersonation and cloned-website scams); fraud built around a specific transaction, most visibly in conveyancing; fee and payment fraud aimed at the firm's own billing and banking processes; and internal fraud risk, where a firm's own systems and controls around client money and case files are tested from the inside. A firm that only trains staff on one of these misses the others.

Impersonation Scams: Fake Law Firms and Cloned Websites

One of the most persistent fraud risks facing the profession is impersonation — criminals setting up a website, letterhead, or email address that copies a genuine firm's name, SRA number, and solicitors' names, or in some cases inventing a firm that does not exist at all. The SRA maintains a public page on bogus and fake solicitors and regularly publishes dated scam alerts naming specific cloned firms and impersonated solicitors, because this is an ongoing and active threat rather than a one-off issue.

These scams typically work in one of two ways. In the first, fraudsters copy a real firm's details and use them to convince a victim — often someone already expecting to deal with solicitors, such as a homebuyer, an inheritance beneficiary, or someone pursuing a claim — that they are dealing with the genuine firm, then ask for an upfront fee or a payment to a "client account" that is really the fraudster's own. In the second, fraudsters build an entirely fictitious firm, sometimes lifting the name and practising certificate details of real solicitors who have no idea their identity is being used, to lend the operation false legitimacy.

For firms, the practical response has two parts. First, make it easy for the public and other professionals to verify you are real: keep your entry on the SRA's register current, be alert to reports that your firm's name is being misused, and act quickly by reporting to the SRA and Action Fraud if it is. Second, build staff awareness so that anyone receiving an unusual request that references your firm's name — a "second firm" acting on the same matter, a request to verify a solicitor's details, a payment demand that does not match your usual process — knows to check rather than assume. Because a convincing cloned website or phishing email is often the entry point for wider account compromise, this overlaps closely with a firm's cyber defences; see our guide to cyber incident and data breach response for law firms for how to handle a suspected compromise once it is under way.

Property and Identity Fraud in Conveyancing

Conveyancing remains the single area of legal practice most exposed to fraud, because it combines large sums of client money, tight completion deadlines, and transactions where the parties often never meet face to face. Identity fraud (a fraudster posing as the seller of a property they do not own), mortgage fraud, and payment diversion fraud targeting completion funds are all well-documented risks in this area, and they deserve treatment in their own right rather than a brief summary here. If conveyancing is a significant part of your practice, our dedicated residential conveyancing risk and fraud guide covers identity checks, source-of-funds verification, and bank mandate fraud in the depth the topic needs. The point for this broader guide is simply that conveyancing fraud is not a separate problem from firm-wide fraud risk — the same client verification, staff training, and escalation culture that protects against impersonation and fee fraud elsewhere in the firm should extend into the conveyancing team.

Fee Fraud and Payment Diversion

Separately from conveyancing, firms face fraud aimed directly at their billing and banking processes. Fee fraud can involve a fraudster submitting a fake invoice designed to look like it comes from a supplier or counsel, intercepting a genuine invoice and altering the bank details before it reaches the payer, or — increasingly — sending a spoofed email that appears to come from a partner or client asking finance staff to change payment details "with immediate effect." The tell-tale signs are familiar to anyone who has run fraud awareness training in any sector: urgency, a request to bypass the normal process, and a change to payment details that arrives by email rather than through a verified channel.

The core control is simple to state and easy to neglect under time pressure: never change bank details for a payment, whether outgoing or incoming, on the strength of an email alone. Any change should be verified by phone, using a number you already hold on file rather than one supplied in the message itself. Firms should also apply basic segregation of duties to payment authorisation, so that no single person can both instruct and approve a change to payment details, and should make sure this expectation is written into onboarding and refreshed regularly rather than assumed to be common sense.

Internal Fraud Risk: Trust Account Controls

The fraud risks discussed so far are largely external — criminals targeting the firm or its clients from outside. But a complete fraud risk picture has to include the possibility that controls fail, or are deliberately circumvented, from within the firm itself. Client account is the obvious focus: the SRA Accounts Rules exist precisely because client money needs to be kept separate, properly recorded, and reconciled, and a firm's internal fraud risk is largely a question of how robust those controls are in practice, not just on paper.

Sound internal controls typically include: regular, independent client account reconciliations rather than reconciliations carried out by the same person who authorises payments; dual authorisation for transfers above a set threshold; restricted and logged access to client account systems; a clear escalation route for anyone who spots an anomaly, including protection for staff who raise concerns in good faith; and periodic, unannounced spot-checks rather than relying solely on scheduled reviews. None of this assumes bad faith on the part of staff — the same controls that catch a deliberate fraud also catch an honest error before it becomes a much larger problem, which is exactly why the SRA treats robust financial controls as a baseline expectation rather than an optional extra.

How the SRA Expects Firms to Manage Fraud Risk

The SRA does not regulate fraud risk through a single rule that firms can tick off. Instead, it sits inside the wider risk management expectations of the SRA Standards and Regulations: firms are expected to have effective governance, systems, and controls in place that are proportionate to the nature and scale of their practice, and to be able to show that risks — including fraud risk — have actually been identified and addressed, not just referenced in a policy document that nobody has updated in years. That expectation runs alongside, and overlaps with, a firm's anti-money laundering obligations, since many fraud typologies (fee fraud, conveyancing fraud, impersonation scams used to launder proceeds) are also flagged through AML controls and suspicious activity reporting.

In practice, this means fraud risk should not sit in isolation from your firm's wider risk assessment. If your firm already carries out a firm-wide AML risk assessment, fraud risk belongs in the same conversation — the same client due diligence, source-of-funds checks, and staff training that reduce money laundering exposure also reduce fraud exposure, because the two overlap so heavily in practice. Our guide to firm-wide AML risk assessment for law firms sets out how to build and document that assessment, and our guide to AML governance for MLROs, MLCOs, and compliance partners covers who in the firm should own fraud and financial-crime risk, and how that responsibility should be structured and reported on.

A Practical Fraud Risk Checklist

Fraud typeTypical warning signPrimary control
Impersonation / cloned firmUnfamiliar "second firm" or unverified solicitor contacting a client or counterpartyVerify SRA registration; monitor for misuse of your firm's identity; report promptly
Conveyancing / identity fraudSeller who avoids face-to-face contact; last-minute change of bank details near completionRobust ID and source-of-funds checks; verified bank details by phone, not email
Fee fraud / payment diversionUrgent email requesting a change to payment detailsCallback verification using a known number; segregation of payment duties
Internal / trust accountReconciliations that are late, incomplete, or done by the person who also authorises paymentsIndependent reconciliations; dual authorisation; access logging; spot-checks

Building Fraud Awareness Into Everyday Practice

Policies and controls only work if the people applying them recognise a problem when they see one. That means fraud awareness needs to be part of induction for new joiners, refreshed periodically for existing staff, and reinforced whenever a new scam type starts circulating in the profession — the SRA's scam alerts are a useful ongoing source for exactly that kind of update. It also means creating a culture where raising a suspicion, even a wrong one, is treated as good practice rather than an inconvenience, since the cost of a five-minute verification call is trivial next to the cost of a fraud that succeeds because nobody wanted to seem overly cautious.

Frequently Asked Questions

Is fraud risk the same as money laundering risk for a law firm?

They overlap heavily but are not identical. Money laundering is about disguising the origin of criminal proceeds, while fraud is the underlying crime that often generates those proceeds in the first place — a fee fraud or impersonation scam, for example, is fraud, and moving the resulting money through the financial system is money laundering. Firms should treat the two as connected risks covered by related, but not identical, controls.

What should a firm do if it discovers its name is being used by a fake law firm?

Report it to the SRA and to Action Fraud, warn any clients or contacts who may have been approached, and consider a note on your own website confirming your genuine contact details and SRA number so the public has a way to check. The SRA's scam alerts page shows the kind of detail typically published once a report is confirmed.

Do sole practitioners and small firms need to worry about this as much as large firms?

Yes — arguably more so, because smaller firms often have fewer people involved in authorising payments, which makes segregation of duties harder to achieve and internal controls more important to get right, not less. Fraudsters do not target firms by size; they target weak verification processes, which can exist anywhere.

How often should fraud risk be reviewed?

At minimum, annually alongside your firm-wide risk assessment, and immediately after any incident, near-miss, or change in how the firm processes payments or handles client onboarding. Fraud typologies evolve quickly, so a fraud risk assessment that has not been touched in several years is unlikely to reflect current threats.

Fraud risk in legal practice spans impersonation scams, conveyancing fraud, fee fraud, and internal controls around client money — and staying ahead of it depends on keeping staff knowledge current as the threats evolve. Learnsignal's CPD courses for legal professionals cover fraud awareness, financial crime, and risk management as part of a structured, trackable CPD programme, helping firms meet their training obligations while building the everyday vigilance that stops fraud before it succeeds.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Legal CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans