This is our last COLP Insider before the Easter break, and we have a strong mix for you in this edition: some bigger-picture regulatory themes, some very practical compliance points, and a healthy dose of disciplinary cautionary tales.

We start with a long read on the common themes from recent conferences and events: that surface-level compliance is losing its value, and that regulators increasingly want to see controls that work, that are meaningful and actually capable of influencing behaviour. Alongside that, Sophie tackles the practical headache of counterparty sanctions screening, Liz takes on the “out of scope” conundrum, and we look at everything from Sarah Rapson’s latest messaging to the Companies House security issue and our next free webinar, AML: Anything but conveyancing?, on 1 April.

A final reminder too that there are now only a few places left on our COFA Masterclass (see you there at the buffet).

Have a great weekend, we’ll be back next month.

Jon and the team.

P.S. The new compliance learning platform is now live.

 


 

From paperwork to behaviour: what recent regulatory events mean for law firms

 

law firm regulatory compliance operational controls SRA

What do the Law Society Compliance Conference, the SRA’s recent AML webinar and the regulator’s latest messaging about ‘rebuilding trust’ have in common? Quite a lot, actually. This long read explores why regulators seem increasingly interested not just in whether firms have the right framework on paper, but in whether it actually works in practice.

 


 

The case for counterparty screening (and the case against pretending it’s easy)

 

Counterparty sanctions screening sounds simple in theory. Sophie Cisler explains why it is anything but. This article explores the case for screening, the strict liability problem at the heart of sanctions compliance, and the real-world obstacles firms run into when the person they need information about is not their client.

 


 

The out-of-scope conundrum (or the AML Hokey Cokey)

 

AML out of scope Money Laundering Regulations

Liz Bond tackles a point that causes real confusion in practice: what does “out of scope” actually mean? This article looks beyond the MLRs to the wider framework of POCA, sanctions, confidentiality and professional obligations, and explains why firms still need to stay alert.

 


 

News and guidance

SRA says it wants to fix the basics and rebuild trust

The SRA has published a statement from chief executive Sarah Rapson setting out its priorities for 2026, and the tone is notably self-aware. The regulator openly acknowledges concerns about slow casework, rising reports and being too reactive, and says its immediate focus will be on “fixing our foundations” and rebuilding trust with both the profession and the public.

The four priorities are operational excellence, improving collaboration, proactive risk identification and focusing on the biggest issues. In practical terms, that includes cutting investigation times, reviewing casework processes, improving triage and quality assurance, testing alternatives to full investigation, increasing engagement with the profession and becoming more transparent about regulatory action.

It remains to be seen how far this turns into real operational change, and a degree of healthy scepticism is understandable. The SRA is signalling that it wants to be seen as more modern, more proportionate and less purely reactive, but firms will judge that by what actually happens in practice. Those dealing with investigations, supervisory engagement or high-risk workstreams will no doubt be watching closely.

More than 20 Post Office-linked investigations are still live

The SRA has published an update on its investigation into solicitors and law firms linked to the Post Office Horizon scandal, describing it as the regulator’s largest ever investigation. More than 20 investigations remain live, including into those who acted for the Post Office and Royal Mail Group.

The regulator says it has made significant progress but is not yet in a position to move at full pace on many of the core cases. It points to two main reasons: the need to await the final report from the Public Inquiry, and the possibility of criminal investigations or prosecutions. That said, it expects to be able to move more quickly in some of the “post-scandal” cases, which sit outside the central issues being examined by the Inquiry.

For the profession, this is another reminder that the Post Office fallout is far from over. The legal and ethical themes being examined go to some of the most fundamental duties solicitors owe to the court, to the justice system and to the public.

Government wants fewer barriers to sharing economic crime intelligence

The Home Office has published a new Fraud Strategy for 2026 to 2029 alongside a call for evidence on economic crime information sharing. Government wants better sharing of intelligence across the public and private sectors, with fraud, money laundering and related offending firmly in scope.

The consultation is looking at the legal, operational and cultural barriers that still get in the way of effective data sharing, and it remains open until 18 May 2026. The strategy, meanwhile, sets out the wider plan for tackling fraud against individuals and businesses over the next three years.

It does not create an immediate new compliance duty for law firms, but it does reinforce the direction of travel: a greater expectation that regulated businesses will play their part in spotting and sharing intelligence about economic crime. Firms may want to keep this in mind when reviewing AML, fraud and sanctions procedures, particularly where questions of escalation, intelligence sharing and working with third parties arise.

Meanwhile, the National Crime Agency’s newly launched National Strategic Assessment 2026 says the serious and organised crime threat has increased overall and highlights how criminal markets are converging, global instability is creating new opportunities for criminals, and technology is making offending faster, more scalable and harder to disrupt.

Non-practising solicitors: annual roll application opens on 1 April

An important reminder for non-practising solicitors: the SRA’s annual exercise for those who want to remain on the roll opens on 1 April 2026. This applies to solicitors who do not hold a practising certificate but still want to stay on the roll of solicitors of England and Wales.

The application window runs from 1 April to 28 May 2026. The SRA says those who want to remain on the roll must apply each year and pay a £10 administration fee through mySRA.

Law Society tells the LSB to stick to its core oversight role

The Law Society has used its response to an LSB consultation to argue that the Legal Services Board should stay focused on its core oversight function, rather than straying too far into the territory of frontline regulators. The press release relates to the LSB’s proposed guidance on the new regulatory objective of promoting the prevention and detection of economic crime.

That in itself is an interesting regulatory skirmish. A focus on economic crime is obviously welcome, but there is a legitimate question about whether the LSB’s role is to set the framework and hold regulators to account, rather than becoming more interventionist in how that objective is pursued.

 


 

Compliance corner: What do we need to do about the Companies House security flaw?

Q: “I’ve seen that Companies House has been allowing unauthorised web filings on companies since October 2025. What does this mean for any company clients I have onboarded since then?

A: There’s been a lot of commentary about this frankly bizarre ‘hole in the fence’ at Companies House (CH), with an increasing focus on what CH knew and the extent of the issue. Official comms from CH seem to be focusing on encouraging people to check their own companies to make sure no unauthorised filings have crept on. But this isn’t much help for people who have used CH to look into companies that aren’t theirs – for example, companies which are clients or perhaps on the other side of a transaction, or linked to one.

For the moment, just take a breath. The situation is clearly continuing to evolve and information is patchy. Remember that correcting records is going to take time (people are only just becoming aware that their company records may be at risk) so this will need to be an ongoing exercise, certainly whilst we understand the extent of the malfunction. But there are some concrete things you can do for the time being:

 

    1. Advise all staff that this has happened – they need to be on heightened alert when they are thinking about company clients or counterparties.
    2. Speak to your company search provider – what’s their advice and can they reassure you about the validity of the data they returned to you during this period?
    3. Review your alerts – presuming you use the “follow this company” service at CH (if not, why not?) has everyone picked up and reviewed any email that alerts them to a change in a company client? This will be particularly critical over the next several weeks – as companies spot any unauthorised filings and seek to correct the position.
    4. Speak to your company clients – make sure they are aware of the issue.
    5. Consider whether you need to re-run searches  – or obtain some other data to reassure you. This  could be done:
        • In a blanket fashion;
        • On a more targeted basis, particularly looking at higher risk matters or where you know that the ownership is potentially more complex;
        • Through your client relationship: next time you speak to the client, ask them to reconfirm that the information you hold about the company is correct.
        • Any additional work is likely to require a conversation with your client about your fees.
    6. Build this into your wider ongoing monitoring procedure – use this as a learning experience and an opportunity to build in extra checks at particular junctures of the matter. Remind your team about reviewing risk profiles as the matter goes on.
    7. Check your own Companies House profile and contact details – ensure CH holds up-to-date email/contact details so you receive any notifications. Sign up to the “follow this company” service for your own business too.
    8. As a training point:
        • Remind everyone that CH is not infallible and should not be used as the only source of information.
        • Reinforce this is why ongoing monitoring is so vital: staff must be alert to, and analyse, any potential changes which arise as the matter goes on.

 

This is not legal advice. If you have a question you would like us to answer in this section, feel free to send it to info@jblcompliance.com 

 


 

Free CPD

 

Save the date: “AML: Anything but conveyancing!”

Our next free webinar will take place on 1 April at 12pm on Zoom and will focus on a part of AML compliance that often gets much less attention than it should: the risks arising in practice areas other than conveyancing.

We spend a lot of time talking about property work, and with good reason. But the Money Laundering Regulations, wider AML obligations and sanctions risks do not stop at conveyancing. In this session, we will look at how those issues can arise across other areas of legal practice (both in-scope and out-of-scope), and what that means in practical terms for firms trying to apply a genuinely risk-based approach.

Invitations will be sent to clients first and then released more widely, so keep an eye on your inbox for the invitation and registration link.

 

Recording now available: SRA Compliance Officer (COLP and COFA) Thematic Review

Our latest webinar takes a close look at the SRA’s recent thematic review of compliance officers, looking at what the regulator found and what it means in practice for COLPs and COFAs.

The session explores some uncomfortable findings from the review. While most compliance officers understood the broad outline of their roles, the SRA found significant gaps in deeper knowledge — particularly around the detailed responsibilities of the COLP role, record-keeping obligations, and the practical operation of compliance systems. In many firms, the review suggested that compliance still sits too heavily on one individual rather than being embedded across the business.

In the webinar we discuss:

 

    • The most striking findings from the thematic review
    • Why knowledge gaps in the COLP/COFA roles are important in practice
    • The risks of the “single compliance hero” model
    • Practical steps firms can take to strengthen governance and capability

 

If you are a COLP, COFA, MLRO, managing partner or practice manager, this session will help you sense-check your firm’s approach against the regulator’s expectations.

Watch the recording (passcode: %dxT7V8h) — available for 14 days only.

 

COFA Masterclass – only a few spaces left

 

 


 

Client account health-checks

Alongside the training, we’re offering client account health-checks to stress-test your systems before the SRA (or your reporting accountant) does, and targeted projects to clear stubborn residual balances in a way that keeps both the regulator and clients happy. If your client account keeps you awake at night – or you’d like to make sure it doesn’t – we’d be very happy to talk.

 


 

Disciplinary watch

Kennedys Law LLP has been fined £18,000 after the SRA found that, during a commercial property transaction between 2016 and 2018, its client account was used as a banking facility. The regulator said the payments did not relate to an underlying legal transaction and found that the firm had failed to prevent its staff from allowing this to happen. The case is another reminder that the SRA continues to take a firm line on what is now rule 3.3 of the Accounts Rules: even where there is no allegation of dishonesty, and even where the underlying matter may look commercially convenient, the regulator is likely to treat any use of client account falling outside a genuine underlying legal transaction as a serious breach.

Martin John Welch has been fined £2,387 after the SRA found that his former firm failed to obtain accountants’ reports for four consecutive accounting periods. The regulator also found that residual client balances remained on the client account long after the firm had been acquired, with some dating back many years.

Hyland Fitzwater Limited has agreed to pay a £5,647 fine following an SRA AML investigation triggered by a desk-based review. The regulator said that on five of the six files reviewed, the firm had failed to maintain records of client and matter risk assessments, leaving it unable to demonstrate that it had properly assessed risk or applied proportionate due diligence.

EDMC Legal Limited has been fined £2,268 after an SRA desk-based AML review identified deficiencies in its compliance with the Money Laundering Regulations. The regulator said the firm had failed to put in place an adequate firm-wide risk assessment between January 2020 and December 2025, despite repeated guidance on what a compliant assessment should contain.

Jude Sebastian Fletcher has been struck off after the SDT found that he misappropriated £1m and used false bank records to conceal what was happening. The tribunal found that the firm’s officers were unaware of the bank accounts, that Fletcher had sole access to them, and that there was ultimately a £2.1m client account shortfall. It said the misconduct involved repeated dishonesty connected to false bank statements and the removal of client funds, and concluded that strike-off was the only appropriate and proportionate sanction.

Shafiq-ul Hassan has been suspended for two years in a case the SDT itself described as finely balanced. The tribunal found that, at meeting about a property dispute, he made untrue statements about ownership of the property and suggested that an adjournment could be obtained by lying to the court. It also found further misconduct in relation to a purported surveyor’s report and an unfulfilled undertaking, although the later allegations were not found to be dishonest. The striking feature is sanction: the tribunal expressly acknowledged the orthodox position that dishonesty will ordinarily lead to strike-off absent exceptional circumstances, but concluded that this case fell within the narrow residual category because the dishonesty was brief, confined to a single matter, involved no personal gain and arose in what it saw as unusual circumstances where Mr Hassan believed his client was at risk of coercion and harm.

Laura Bailhache has been rebuked by the SRA after failing to provide a specimen of blood when lawfully requested to do so by police. The regulator said the conduct was serious enough to warrant sanction because it amounted to an intentional refusal to cooperate with law enforcement and undermined public trust and confidence.

Birchwood Solicitors Limited has agreed to pay a £6,353 financial penalty after an SRA AML review found longstanding deficiencies in both its firm-wide risk assessment and its policies, controls and procedures. The regulator said the firm did not have an adequate FWRA in place between June 2017 and July 2025, and that its documented PCPs were still not compliant when reviewed.

Gboyega Ajibola Okunniga has been struck off by the SDT after it found that he misled Coventry County Court by fabricating the existence of a merger to explain why client money had been paid into his personal bank accounts. The tribunal also found that he issued invoices for sums not owed to the firm and sent misleading letters on firm headed paper falsely describing himself as “Head of International Trade and Arbitration”.

Darren Hanison, former sole principal of Fortitude Law, has been struck off after the SDT found a pattern of serious misconduct across multiple medical negligence and product liability matters. The tribunal found that he settled claims without properly taking instructions, misled clients about offers, deductions and costs, retained part of a settlement to which he was not entitled, reassured a client that she was protected by ATE insurance when she was not, and then went on to mislead both the SRA and other solicitors about that insurance position. Matters became even more serious when the tribunal found that false ATE schedules had been created, a misleading professional indemnity insurance proposal had been submitted, and a falsified expert report had been filed at court.

Rachel Parker has been struck off after admitting that, while at Buckles Solicitors, she repeatedly told clients, colleagues and others that probate applications had been submitted and chased with the Probate Registry when that had not in fact happened. The SDT recorded a series of probate matters in which clients were given holding updates suggesting grants were with the Registry, expected shortly, or being chased, when in some cases no application had yet been made at all. In one matter, for example, a client was told the application was already with the Probate Registry, but the papers were only actually submitted later; in another, beneficiaries were told that grant applications had been made and grants were expected within three to four months, yet the file showed no application had been made.

Collier Littler LLP has agreed to pay a £5,687 fine after an SRA AML review found weaknesses in both its firm-wide risk assessment and its file-level risk assessment process. The regulator said the FWRA was not properly tailored to the firm and contained inaccurate or outdated information, while on five of the six files reviewed the client and matter risk assessment had only been completed after the SRA asked to see the file. Retrospective CMRAs are unlikely to impress the regulator.

Gemma Clarke has been made subject to a section 99 disqualification order, meaning she cannot work as an employee, manager, COLP or COFA in an SRA-regulated licensed body. The SRA said that while working as a senior paralegal at Knights Professional Services, she had been convicted in 2024 of two offences of stalking involving serious alarm or distress, as well as criminal damage. The case is another example of the regulator treating serious conduct outside the office as capable of making someone unsuitable to work in legal practice.

Ross Wenman has been made subject to a section 43 order (strike off) after admitting that, while working as a senior company secretarial assistant, he misled the firm about a missed Companies House filing deadline and then altered proof of delivery documents to make it appear that the accounts had been delivered on time. The SRA found the conduct dishonest.

 


 

Independent AML audits

 

Regulation 21 independent AML audit for law firms

Law firms must ensure the effectiveness of their AML controls through regular audits. An independent AML audit is crucial for identifying gaps in your firm’s anti-money laundering controls and ensuring adherence to regulatory standards.

Our expert team conducts thorough reviews of your AML systems and processes, providing actionable insights and recommendations to strengthen your firm’s compliance framework. Stay compliant, avoid regulatory penalties, and maintain the trust of your clients.

Included in the audit:

 

    • In-depth analysis of AML policies and controls
    • Team interviews
    • File reviews
    • Customised report and recommendations
    • Debrief

 

Formats Available: Online | In person | Hybrid

Act Now: Contact us for a free consultation and safeguard your firm against AML risks

 


 

What we do – contact us for further information about our services

 

    • Outsourced COLP and COFA support
    • COLP and COFA coaching
    • Compliance audits
    • NEW: Client account health checks
    • NEW: Residual balance projects
    • New firm and ABS applications
    • Independent AML audits (Regulation 21)
    • Training (online, remote, on demand)
    • AML and GDPR workshops
    • PII reviews
    • Remote file reviews
    • TPMAs
    • Escrow accounts
    • AML and sanctions searches

 

 


 

Older posts

 

The hidden cost of non-compliance: firefighting isn’t free

 

cdd source of funds LSAG

 

We often think about the “cost of non-compliance” in terms of fines, investigations and awkward conversations with insurers. But the real cost often lands much earlier and much closer to home: the extra touchpoints, rework and frantic internal to-and-fro that kicks in when your onboarding process isn’t watertight.

In this short piece, we look at how seemingly small oversights can quickly turn into a time sink for fee earners, compliance, accounts and the client. Heads of Department take note: if it feels like your team is constantly chasing documents, repeating questions and reopening files, this is for you.

 


 

Deputy COLP/COFA: the simplest resilience upgrade your firm can make

 

deputy colp and cofa

 

Many firms rely on a single person to carry the compliance burden — the COLP or COFA who has “always done it”. It feels reassuring, but it also creates a hidden risk.

What happens if that person leaves suddenly? Or simply burns out?

In this post we explore the case for deputy compliance officers as a simple way to build resilience, continuity and shared understanding of the firm’s regulatory responsibilities.

 


 

What “the COFA who trusted the numbers too much” should have known

 

COFA reconciliation training

 

When we last met Alison, she was the COFA who trusted the numbers too much.

A qualified accountant’s report and two years of regulatory uncertainty showed how quickly things can unravel when a COFA signs off figures they don’t fully understand.

In this follow-up piece, we step back from Alison’s story and look at what she should have known: the practical skills, questions and warning signs every COFA needs to protect themselves.