Happy first of the month

This week’s edition of COLP Insider covers the SRA’s proposed competence changes, the latest PM Law update, the Court of Appeal’s Dentons ruling, and a clear sign that the regulator is trying to rebuild trust through a more proactive supervision model.

Liz has written an article on the compliance risks surrounding crowdfunding, Ed has put together a really interesting AI blog, and Sophie has examined the Dentons case.

We also have new JBL resources to flag. Six online courses are now live, with more in production, and Compliance Corner tackles a deceptively difficult issue: what happens when confidentiality owed to one client prevents you from disclosing information that another client would reasonably want to know?

Disciplinary Watch is, once again, heavy on AML, Accounts Rules and the importance of responding to the regulator when it asks for information. No great surprises there, but plenty of useful reminders.

See you at our monthly webinar next Wednesday?

Pinch and a punch and all that!

Jon and the team

Everyone’s a winner in the Dentons AML case!

SRA Dentons AML case

The Court of Appeal’s Dentons AML judgment has been described variously as a win for Dentons, the SRA and the profession. But is it really that simple?

Sophie unpacks what the decision actually says about AML breaches, professional misconduct and the “seriousness” threshold.

Read the article

Navigating the agentic AI frontier: a compliance angle

agentic AI in law firms

Agentic AI promises something beyond ordinary prompt-and-response tools: systems that can set goals, plan actions and coordinate workflows with minimal human input.

But where does that leave supervision, professional authorisation, junior lawyer training and accountability?

Ed Marshall looks at the compliance risks behind the next wave of legal AI — from the “verification nightmare” to supervision problem.

Read the article

Crowdfunding – is it worth the risk?

crowdfunding risk for law firms

Crowdfunding can be a useful way for clients to raise money for start-ups, property projects, community schemes and new ideas. But for law firms, it can also create a messy source of funds picture.

In this article, Liz looks at why crowdfunding is a higher-risk area, what makes pooled contributions difficult from an AML perspective, and how firms can take a proportionate, risk-based approach before deciding whether they are comfortable acting.

Read the article

News and guidance

SRA consults on competence requirements

The SRA is consulting on new competence requirements for solicitors and firms. The proposals include a requirement for solicitors to keep records of how they review and address their learning and development needs, a mandatory annual discussion about ethics, and the ability for the SRA to require specific learning where it identifies concerns.

The consultation closes on 15 July 2026. If the proposals go through, firms will need to think about how they evidence competence without creating a cottage industry of pointless paperwork.

Start by looking at what you already have. Appraisals, file reviews, supervision notes, complaints analysis, breach logs and training records are all potential competence evidence. The challenge is joining them up into something useful.

Read the SRA announcement

Need some on-demand CPD?

PM Law update: £40m missing

The SRA has published a further update on support for clients affected by the intervention into PM Law. The investigation involves suspected improper removal or misuse of around £39.5m of client funds, across a group with multiple companies, offices and trading names.

The update gives a sense of the scale of intervention work: claims to the Compensation Fund, client enquiries, live files, insurance matters and the prioritisation of cases where there is a higher risk of harm.

In the wake of SSB and Axiom, this is not a good look for the profession.

Read the SRA update

Dentons: breach is not automatically professional misconduct

The Court of Appeal’s decision in the Dentons AML case is important. It rejects the idea that a breach of the Money Laundering Regulations, or of the SRA rules, automatically amounts to professional misconduct. The SRA still has to show that the conduct is “sufficiently serious”.

That is not the same as saying technical breaches aren’t worth worrying about. AML failures can still be serious, and the SRA will continue to use disciplinary and fining powers. But the decision is a useful reminder that professional misconduct is a separate thing.

Don’t take false comfort from the decision, but we wonder whether the SRA will think twice about trying to strong-arm firms into a regulatory settlement agreement (“plea deal”) for minor AML breaches.

Read the judgment

SRA leadership changes: a new supervision unit and a bid to rebuild trust

The SRA has announced changes to its senior leadership structure, including new executive roles covering supervision, risk, data and insight, general counsel/risk/compliance, and external affairs. The stated aim is to improve operational grip, decision-making timelines and proactive risk identification.

The interesting bit for firms is the emphasis on proactive supervision. We can expect more “knocks on the door” out of the blue – something we’ll cover at next week’s webinar.

We know that the SRA wants to spot risk earlier. Firms should assume that the regulator will increasingly expect ready access to evidence: policies, risk assessments, training records, file reviews, supervision notes and board-level compliance discussion.

Read the SRA announcement

Money Laundering Regulations: simplification, or risk of weaker controls?

Spotlight on Corruption has published a useful critique of the proposed changes to the UK’s money laundering rules. Some of the proposed changes are sensible, including better treatment of shelf companies, cooperation with Companies House and crypto-asset due diligence. Others are more controversial, particularly the narrowing of mandatory enhanced due diligence triggers.

Our view of the proposed Regulations is that simplification is not permission to relax. Even if the rules become less prescriptive in some areas, the firm still has to understand and manage the actual risk.

MLROs should keep this on the horizon. If the regulations change over the summer, AML policies, training, client/matter risk assessments and file review checklists will need to be revisited.

Read the Spotlight on Corruption article

Compliance corner: confidentiality vs disclosure

Q: We acted for Client A years ago. Client B now wants us to act against them. We know something from the old file that might help Client B, but we obviously cannot disclose it. Can we put up an information barrier and carry on?

A: Be very careful. This is one of those issues that sounds manageable until you follow it through properly.

Solicitors owe a continuing duty of confidentiality to former clients. If you obtained confidential information from Client A, that duty does not disappear when the retainer ends. At the same time, you owe Client B a duty to disclose information that is material to their matter. In broad terms, material information is information the client would reasonably want to know in order to make decisions or progress the matter…

Continue reading

This is not legal advice. If you have a question you would like us to answer in this section, feel free to send it to info@jblcompliance.com 

New JBL training resources

We now have six online compliance courses available:

  • Anti-money laundering
  • COLP and COFA
  • Legal professional privilege
  • Legal ethics
  • Confidentiality
  • Conflicts of interest

These are available to Gold clients immediately – your group manager will be able to give you the login details.

The courses are also available to purchase through the JBL shop, with group licence options for firms that want to roll training out across teams.

Visit the training area

Currently in production: How to start a law firm or ABS, New starter survival guide, COFA Masterclass, and Financial crime in depth (and many more planned).

Contact us about group licences for your firm

Free CPD

Next live session: When the SRA comes knocking – audits, investigations and what happens next

Date: Wednesday 6 May 2026 (12:00PM)

Our next free webinar looks at what actually happens when the regulator gets involved: desk-based reviews, thematic visits, investigations, information requests, self-reports, remediation, interviews and how to keep a sense of proportion when the email lands.

Sign up to the webinar – Join 135 others

Recording: AML – Anything but conveyancing!

Our session before Easter took a deliberately wider look at compliance problems outside the usual conveyancing examples. If you missed it, this is one worth catching up on, particularly for firms doing litigation, private client, corporate or mixed practice work.

Watch the recording here (passcode &KwfJB7+) – free link expires today.

COFA Masterclass – Practical, well received and coming back

Our recent COFA Masterclass with Sean Hankin and Liz Bond was a real success. The feedback was exactly what we hoped for: practical, grounded and directly relevant to the day-to-day reality of the role, rather than a dry run through the rules.

We are now taking expressions of interest for the next public session.

  • This was a really practical and useful course on the role, expectations and responsibilities of a COFA which, if I am honest, I expected to struggle through but it was the most useful course, on the subject, I have ever been on. A must for any COFA.
  • The COFA masterclass was an excellent opportunity to refresh my knowledge of the requirements of the COFA role with a team that have first hand knowledge of what to look out for.

Contact us for more information

Client account health-checks

Alongside the training, we’re offering client account health-checks to stress-test your systems before the SRA (or your reporting accountant) does, and targeted projects to clear stubborn residual balances in a way that keeps both the regulator and clients happy.

If your client account keeps you awake at night – or you’d like to make sure it doesn’t – we’d be very happy to talk.

Disciplinary watch

Minahan Hirst & Co Limited – AML policies and source of funds

Minahan Hirst & Co Limited agreed a regulatory settlement after an SRA AML desk-based review. The firm was fined £12,774 after its AML policies, controls and procedures were repeatedly found to be deficient between 2017 and January 2026. The SRA also found inadequate source of funds checks on two out of six reviewed files. The firm had, at one point, submitted its firm-wide risk assessment instead of compliant AML policies.

AML documents are not interchangeable. A firm-wide risk assessment identifies the risks; the policies, controls and procedures explain how the firm manages them. Firms also need to remember that source of funds checks must be evidenced on the file, not assumed from the general knowledge of the client or transaction.

Piper May Solicitors Ltd – failure to provide AML and sanctions data

Piper May Solicitors Ltd was fined £750 after failing to submit data requested by the SRA. The SRA said firms are required to respond promptly and provide full and accurate information when asked, and that the firm failed to remedy the breach after being given notice and reasonable time to do so.

SRA information requests are not optional admin. A failure to respond to a data collection exercise can itself become a disciplinary issue, even before the regulator gets to the underlying compliance position.

Taylor Rose Limited – accounts systems, reporting and residual balances

Taylor Rose Limited was fined £160,059 following a forensic investigation. The SRA found that the firm’s main client account had not been fully reconciled every five weeks, and that the reconciliation contained a significant number of unreconciled items. The firm also failed promptly to report possible Accounts Rules breaches and failed to return client money promptly.

This is a serious reminder for COFAs and finance teams. Reconciliations are not just a bookkeeping exercise; they are a core client money control. Persistent unreconciled items, delayed self-reporting and slow return of client money will be treated as systems failures, not minor technical slips.

We do client account health checks.

Nicholas Devlin – dishonest time recording and withdrawals from client account

Nicholas Devlin, a former associate solicitor in a wills, probate and inheritance team, was struck off after admitting dishonest time recording and authorising withdrawals from client account without corresponding invoices being sent. The Tribunal recorded examples of time being billed for documents not yet drafted or letters never sent. It also found that approximately £216,000 had been transferred from client accounts to pay bills that had not been sent to clients or paying parties. Mr Devlin admitted dishonesty, and the Tribunal said striking off was the only appropriate sanction given the deliberate and repeated nature of the misconduct.

Remember that time recording pressure is not mitigation for dishonesty. Supervisors need to look for patterns of early billing with little file movement, suppressed debt chasing, missing invoices, and client account transfers that do not match the billing record.

recLAW LLP – failure to provide AML and sanctions data

recLAW LLP was fined £750 after failing to submit data requested by the SRA in respect of its AML and sanctions requirements. The SRA noted that the firm failed to remedy the breach after notice and reasonable time had been given.

The SRA’s AML and sanctions data requests need ownership. Someone in the firm should be responsible for monitoring SRA communications, diarising deadlines and confirming submission. Small penalties still mean public publication.

Peter Bonner & Co – another failure to provide AML and sanctions data

Peter Bonner & Co was listed by the SRA as having received a £750 fixed financial penalty on 17 April 2026.

This appears to sit with the same recent cluster of fixed penalties for non-response to AML and sanctions data requests. The practical point is to treat regulatory data collection as a compliance deadline, not a background administrative task.

Sayers Solicitors LLP – and another!

Sayers Solicitors LLP was fined £750 after failing to submit data requested by the SRA in respect of its AML and sanctions requirements.

Riley Langdon Solicitors – inadequate firm-wide risk assessment

Riley Langdon Solicitors agreed a regulatory settlement and was fined £2,757 after an AML desk-based review. The SRA found that between June 2017 and December 2025 the firm failed to have an adequate firm-wide risk assessment assessing the money laundering and terrorist financing risks to which its business was subject.

The FWRA is still the first document the SRA will look for. It needs to be specific to the firm, reflect the practice areas, client base, geography, delivery model and transaction types, and be reviewed when the risk profile changes.

Jack Medlicott – falsely witnessing signatures

Jack Anthony Medlicott was struck off after signing two leases to confirm that he had witnessed the signature of another person when that was untrue. The Tribunal found that he knew Person B was not present and that what he was signing was untrue. It rejected the suggestion that this was mere incompetence, finding dishonesty and lack of integrity. The Tribunal also noted that a solicitor acting with integrity would have maintained the initial refusal to sign, notwithstanding client pressure.

“The client asked me to” is never a defence to certifying something false. Witnessing, certification and execution formalities are basic trust functions. If a solicitor’s name appears on a document as witness, certifier or signatory, it must be true in fact.

Harpreet Singh Nijjar – unauthorised ownership

Harpreet Singh Nijjar, a non-lawyer owner and manager of BGM Law Ltd, was made subject to a section 99 disqualification order after the SRA made a finding of dishonesty. The SRA found that he acquired BGM without notifying and seeking prior SRA approval, acted as a manager and owner without authorisation, caused or allowed BGM to be used as a vehicle for fraud, and failed to cooperate with the SRA’s investigation. He was disqualified from acting as Head of Legal Practice, Head of Finance and Administration, manager or employee of an SRA-regulated licensed body.

ABS ownership and management authorisation and controls are not technicalities. Non-lawyer ownership and control must be approved before it happens, not tidied up later. Firms need robust controls around ownership changes, Companies House filings, investor arrangements and who is actually directing the business.

We are currently producing an on-demand course covering authorisation.

Sukhuir Talwar – unauthorised ownership and misleading PII information

Sukhuir Talwar, another non-lawyer manager linked to BGM Law Ltd, was also made subject to a section 99 disqualification order after a finding of dishonesty. The SRA found that he acquired BGM without notifying and seeking approval, acted as owner and manager without authorisation, and misled the SRA about the firm’s professional indemnity insurance in a bulk renewal form.

Misleading the regulator on insurance status is likely to be viewed as extremely serious because it goes directly to client protection.

Corbin & Hassan (UK) LLP – FWRA, CMRAs and source of funds

Corbin & Hassan (UK) LLP agreed a regulatory settlement and was fined £4,631 following an AML desk-based review. The SRA found failings in the firm-wide risk assessment, client and matter risk assessments and source of funds documentation. The firm failed to have an appropriate FWRA up to 11 March 2025, failed to carry out CMRAs on all six reviewed files, and failed to carry out adequate source of funds checks on three of six reviewed files.

This is the classic AML enforcement pattern: FWRA, CMRA and SoF. The SRA is not just asking whether the firm has AML documents; it is checking whether those documents translate into file-level risk assessment and evidence.

Alexander William Bruce Lee – conflict in trustee role

Alexander William Bruce Lee was fined £30,000 by the SDT in relation to his role as director and part-owner of Global Security Trustees Limited, which acted as security trustee for LCF bondholders, while he had previous and subsequent instructions for London Capital & Finance. The Tribunal found that there was an obvious conflict, or significant risk of conflict, and that the allegation was proved in full. It noted that LCF had raised £237m from retail investors, that Mr Lee was not alleged to have acted fraudulently or dishonestly, but that he had placed himself in a conflicted position and remained there as matters deteriorated.

This is a sophisticated conflicts case. The lesson is that a solicitor cannot assume a fiduciary or quasi-independent role for one set of stakeholders while remaining too close to another party whose interests may diverge. If your role is to protect beneficiaries, investors, lenders or other third parties, you need to be able to demonstrate real independence.

Nicholas Gee – missing AML risk assessment records

Nicholas Gee agreed a regulatory settlement and was fined £725. The SRA found that between 2017 and 2026 the firm failed to maintain records of its risk assessment under Regulation 28 of the MLRs, meaning it could not demonstrate that the measures it had taken were appropriate to the risks. The firm later implemented a compliant CMRA and completed CMRAs for all active files in scope.

If it is not recorded, the SRA will treat it as not done. This is particularly true for client and matter risk assessments. Firms should be able to show why a matter was low, medium or high risk, and what practical steps followed from that assessment.

BRR Law – long-running absence of client and matter risk assessments

BRR Law agreed a regulatory settlement and was fined £25,000. The SRA found that between June 2017 and January 2025 the firm failed to conduct client and matter risk assessments. The SRA noted that, at the time of inspection, the firm’s FWRA, policies and CMRA form were compliant, but the historic absence of CMRAs remained a serious breach.

Retrofitting AML compliance after an inspection does not erase historic breaches. Firms should review older active files, not just new matters, and ensure that current compliant processes are genuinely embedded.

Bryan O’Connor & Co – AML policies and CMRAs

Bryan O’Connor & Co agreed a regulatory settlement and was fined £7,982. The SRA found that between June 2017 and September 2024 the firm failed to establish and maintain AML policies, controls and procedures, and that between September 2024 and October 2025 its policies were still not fully compliant. It also found that between June 2017 and August 2025 the firm failed to maintain Regulation 28 risk assessment records, so could not demonstrate that its measures were appropriate to the risks.

Updating the AML policy is only half the job. Fee earners need training on the new CMRA process, supervisors need to check it is happening, and the firm needs an audit trail showing that the updated controls are being applied on live files.

Independent AML audits

 

Law firms must ensure the effectiveness of their AML controls through regular audits. An independent AML audit is crucial for identifying gaps in your firm’s anti-money laundering controls and ensuring adherence to regulatory standards.

Our expert team conducts thorough reviews of your AML systems and processes, providing actionable insights and recommendations to strengthen your firm’s compliance framework. Stay compliant, avoid regulatory penalties, and maintain the trust of your clients.

Included in the audit:

      • In-depth analysis of AML policies and controls

      • Team interviews

      • File reviews

      • Customised report and recommendations

    • Debrief

Formats Available: Online | In person | Hybrid

Act Now: Contact us for a free consultation and safeguard your firm against AML risks

Complaints in the age of AI: A survival guide for law firms

complaints AI generated When a 16-page complaint lands in your inbox, the chances are AI has entered the chat. Sophie Cisler offers a practical framework for handling AI-generated complaints with clarity, proportion and a bit more backbone.

AML: Anything but conveyancing! (A webinar write up)

AML webinar write up - conveyancing, private client, litigation A useful reminder that AML risk does not begin and end with conveyancing. This webinar write-up explores the blind spots that can open up when firms treat property as the only serious risk area, and looks instead at private client, trusts, litigation, corporate work and pooled investment structures. The message is a practical one: better risk assessments, better training and better recording of professional judgement are needed if firms want a genuinely risk-based AML framework. The recording link is in the Free CPD section, above.

Who supervises the supervisor? (Updated blog)

SRA effective supervision Effective supervision is one of those things firms often assume they have covered until something goes wrong. The SRA’s guidance makes clear that supervision must be risk-based, active and properly resourced, with supervisors having meaningful oversight of live work rather than occasional after-the-event checks. For any firm using junior fee earners, consultants or remote teams, this is a useful reminder that supervision has to work in real life, not just on the structure chart.

As you were: Court of Appeal rejects Mazur madness

mazur appeal allowed Mazur sent a shockwave through litigation teams. Now the Court of Appeal has restored a more workable view of how legal work is actually delivered. This piece looks at what the judgment means, why so many firms may have overreacted, and whether the profession was given enough clarity while the appeal was still pending.

LeO complaints are rising, but the real story is more complicated

LeO Legal Ombudsman complaints Complaints are rising, LeO is under pressure, and the underlying themes are stubbornly familiar. But before we assume this is simply a story of falling service standards, there is a more nuanced picture emerging.