Hello
A busy one this week. They couldn’t have just let us melt in peace…
The most significant update is the government’s confirmation that AML supervision for the legal and accountancy sectors will indeed move to the FCA under the new single professional services supervisor model. Until now, I’ve been highly sceptical that there was enough time and political will to get this over the line in this parliament, but it now looks like a done deal. It won’t happen overnight, but it is a significant shift. We are expecting a more data-driven supervisory style of AML regulation over time.
There is also a fresh consultation on notifying the SRA about law firm mergers, new high-risk jurisdiction lists to get to grips with, updated ICO complaints rules, and the news that the SRA is making its first Post Office misconduct prosecutions.
On the JBL Compliance side, we have new pieces on proposed Legal Ombudsman reform, a really interesting Compliance Spotlight interview, and a guide to the 2026 MLR changes.
Three dates for the diary: our COFA Masterclass is back by popular demand on 7 October in Birmingham, details below.
Sophie is speaking at an exclusive small group breakfast session in London next week (Tuesday 30 June) – all things AML. We have a couple of free tickets to give away on a first come first serve basis – reply to this email if you are interested.
And next Thursday we are doing a live webinar on the COLP and COFA changes (registration link below).
Have a great weekend.
Jon and the team
Legal Ombudsman fee increases: they fail, we pay
The Legal Ombudsman’s governing board is proposing a new case fee model that could see firms charged even where complaints are ultimately dismissed.
You heard that right. Under the proposals, all complaints accepted by LeO would attract a fee unless a waiver applies, with charges rising as the complaint progresses. Add in the time already spent investigating, responding, reviewing files and dealing with unhappy clients, and complaints become expensive long before any compensation or fee reduction is on the table.
This article looks at what the proposals mean for firms, why better first-tier complaint handling is only part of the answer, and why the OLC and SRA need to get much tougher with weak, tactical and AI-assisted complaints.
Compliance Spotlight: An interview with Julian Wintle, COLP of Redkite
In the latest Compliance Spotlight interview, Jonathon Bray speaks to Julian Wintle about what it really takes to build a scalable compliance function across a growing regional firm with 19 offices.
The conversation covers cyber risk, data retention, file reviews, AI adoption, leadership buy-in, complaints data and why compliance teams need to prove that controls are working in practice.
”If you want a genuine culture of compliance, it must be driven unreservedly from the top down. But if you're struggling for board buy-in, speak the language of business metrics: show them exactly how robust risk management impacts the bottom line.
SRA authorisations: why the hard work starts before the forms
SRA authorisation projects are often treated as form-filling exercises, which is a mistake.
Whether you are setting up a new firm, applying for ABS status, changing ownership, appointing new compliance officers or restructuring an existing practice, the real work starts before anyone logs into mySRA. You need to identify the regulatory triggers, map the people and entities involved, work out who needs approval, spot AML and BOOM issues, and explain the application in a way that gives the SRA confidence.
This article looks at what firms need to do before the forms, why authorisation projects get delayed, and how to put together a stronger application from the outset.
2026 Money Laundering Regulations amendments: what law firms need to do
The 2026 amendments to the Money Laundering Regulations are targeted rather than transformational, but that does not mean law firms can ignore them.
The changes affect enhanced due diligence, high-risk jurisdictions, pooled client accounts, trust registration, off-the-shelf companies and crypto-related risk. However, for most firms, this is not a rip it up and start again moment. (Try getting that out of your head).
News and guidance
AML supervision reform: FCA to become single professional services supervisor
The government has confirmed its final policy position on AML and counter-terrorist financing supervision reform. The FCA will take over AML/CTF supervision of professional services firms, including law firms, under the new single professional services supervisor model. The government says it wants to minimise burdens during the transition, but a move to the FCA is likely to mean more data, more thematic supervision, more consistency across professions and a stronger focus on systems, controls and evidence.
SRA refreshes AML and sanctions guidance
The SRA has refreshed several AML and sanctions guidance notes and warning notices, including its guidance on the financial sanctions regime, firm-wide risk assessments, money laundering and terrorist financing, and client and matter risk assessments. The changes are mostly housekeeping rather than substantive, but the SRA is clearly starting to knit its AML and sanctions materials together, reinforcing the link between the firm-wide risk assessment, policies and controls, client/matter risk assessments, CDD/EDD, ongoing monitoring, PEPs and sanctions.
SRA consultation: notifying the regulator about M&A
The SRA has opened a consultation on new notification requirements intended to help it identify and act on risk sooner. The initial proposals would require firms to notify the SRA about prescribed events, including mergers and acquisitions once they reach Heads of Terms or equivalent stage, and situations where a firm begins holding client money after previously telling the SRA that it does not. The most interesting thing about the proposal is that the new rule would give the SRA power to add more “prescribed events” as the risk landscape changes.
After Axiom Ince, SSB and other failures, the regulator wants earlier warning of risk events rather than finding out when the damage has already been done. Firms considering ownership changes, mergers, restructures or changes to client account arrangements should watch this closely.
List of high-risk jurisdictions updated
The FATF has updated its lists of jurisdictions subject to increased monitoring and those subject to a call for action. HM Treasury has also updated its Money Laundering Advisory Notice, which is particularly important because the new MLR changes narrow automatic mandatory enhanced due diligence for high-risk jurisdictions to FATF “Call for Action” jurisdictions from 30 June 2026. That does not mean the “grey list” becomes irrelevant. Firms must still consider FATF evaluations and geographical risk as part of their wider risk-based assessment. In practice, update your country risk lists and make sure fee earners understand that “not automatically mandatory EDD” does not mean “low risk”.
UK and US sanctions: useful government comparison
The government has published a comparative overview of UK and US economic sanctions authorities. For firms with international clients, US connections, dollar transactions or overseas offices, this is essential reading. It compares key features of the two regimes, including sanctions lists, licensing, record keeping and reporting. It is not a substitute for specialist sanctions advice, but it is a handy primer for risk teams trying to understand where UK and US obligations may overlap or diverge.
New data protection complaints law now in force
The ICO has announced that new data protection complaints rules are now in force. Organisations handling personal data must provide a clear way for people to raise data protection complaints, acknowledge complaints within 30 days, investigate them and tell the complainant the outcome. Law firms should check that their data protection complaints process is not buried in a generic privacy notice that nobody internally understands. This is a good moment to align your data protection complaints process with your client complaints process and subject access request workflow.
SRA refers two Post Office-related individuals to the SDT
The SRA has confirmed that it has referred two individuals to the Solicitors Disciplinary Tribunal in relation to conduct connected with the Post Office Horizon scandal. The SRA says the cases relate to conduct after the main events of the scandal. This remains one of the defining professional ethics stories of the modern legal profession. There are crucial lessons to be learned about independence, institutional pressure and whether lawyers are willing to say no when the client or organisation does not want to hear it.
You might also like
- Richard Moorhead’s Lawyer Watch blog has a powerful guest piece by Paul Gilbert on what it can cost lawyers to say no. It is a thoughtful reminder that ethics is not only about knowing the rules; it is about whether firms create the conditions in which people can challenge pressure, resist poor decisions and still feel supported.
- Today’s Conveyancer has a useful piece on AI, trusted data and legal judgment.
What to do this month
Register with HMRC as a tax adviser if you are in scope
This is the practical job to get done now.
HMRC’s new tax adviser registration rules are live. The window opened on 18 May 2026 and there is a three-month transitional period. From 18 August 2026, HMRC says unregistered tax advisers will not be able to interact with HMRC on behalf of clients and may face sanctions.
This does not just affect specialist tax departments. A firm will need to register if it is paid to interact with HMRC about someone else’s tax affairs. That can include submitting returns, making payments, sending documents, corresponding with HMRC or using HMRC online services on a client’s behalf. HMRC’s own factsheet specifically says that conveyancers submitting SDLT returns or paying SDLT on behalf of clients are caught.
Don’t leave it until August!
Compliance Corner: Can our conveyancing assistant give an undertaking?
Completion pressure has a habit of turning urgency into compliance risk.
This week’s Compliance Corner looks at a very practical question: can an experienced conveyancing assistant give an undertaking on behalf of the firm, or does it need to come from a solicitor?
The answer is less about job titles and more about authority, supervision, wording and control. Undertakings should never be treated as routine admin. If the firm gives one, it needs to know exactly what is being promised, who has approved it, whether the firm can definitely perform the undertaking, and how it will be tracked.
Read the full Compliance Corner post
This is not legal advice. If you have a question you would like us to answer in this section, feel free to send it to info@jblcompliance.com
Free CPD
Next free webinar: What the SRA’s COLP, COFA and accountants’ report reforms mean for your firm
Date: Thursday 2 July 2026
Time: 12pm
Location: Online by Zoom
The SRA has now confirmed the next stage of its client money safeguard reforms. The practical consequences for firms could be significant.
In this session we will cover:
- the new annual accountants’ report declaration requirement;
- what firms will need to submit and when;
- the new restrictions on who can be COLP and COFA;
- how the £600,000 turnover and £2m client money thresholds work;
- what owner-managed firms should be thinking about now;
- whether “separation of powers” will actually improve governance; and
- what firms should do before the rules come into force.
Reserve your space now – over 200 people have already registered and spaces are limited.
Recording: SRA authorisations webinar
Our most recent webinar looked at SRA authorisations, including new firm applications, ABSs, compliance officer changes and ownership changes.
The main takeaway was that authorisation should not be treated as a form-filling exercise. The forms are only part of the process. The real work is identifying the regulatory trigger, mapping the people and ownership structure, spotting AML and PII issues, and presenting the SRA with a clear, coherent explanation of what is changing and why approval is needed.
Some practical points from the session:
- A structure chart is often the best starting point, especially where there are corporate owners, holding companies, group structures or non-lawyer involvement.
- PII should be explored early, particularly for new firms or higher-risk work types.
- AML approvals, DBS checks and certificates of good standing can all add delay if they are not factored into the timetable.
- COLP and COFA changes need proper runway. Firms must have those roles covered at all times, and the emergency approval route is only for genuine emergencies.
- Ownership changes can be more complex than they look. The SRA may need to look up the ownership chain to identify who ultimately owns or controls the firm.
Watch the recording (available free for 14 days) – use password JBLAUTH
New JBL Compliance training resources
AML refresher training course
Our AML refresher is now available through the JBL Compliance LMS, our on-demand training platform.
It is suitable for whole-firm rollout and is designed to give relevant employees a practical, risk-based understanding of AML obligations.
The course includes around 6 hours of training materials over:
- 9 modules (stagger it over several weeks)
- 28 interactive exercises
- 1 final assessment
Every learner receives a certificate on successful completion.
The training covers:
- POCA
- The Terrorism Act
- The Money Laundering Regulations
- LSAG and SRA expectations
- Understanding AML risk
- Client due diligence
- Suspicious activity reports
- Sanctions compliance
Bespoke options are available where firms want the material tailored to their own risk profile, work types, policies and internal reporting routes.
The course is available as a standalone licence, a group licence, or as part of a subscription to all JBL Compliance courses. The library is constantly updated.
Subscribers get access to all courses, templates, Insights, and webinar recordings.
JBL Compliance Insights: How to handle complaints in the age of AI
AI is starting to change the shape of client complaints. Firms may now receive long, highly structured complaint letters with multiple sub-issues, legal terminology, repeated arguments and further AI-assisted replies after each response.
We can’t dismiss the complaint because AI may have been used. The underlying concern may still be genuine. But firms do need a controlled process.
Our latest JBL Compliance Insight looks at how to manage AI-assisted complaints proportionately, without being drawn into endless correspondence. It covers triage, internal reviews, senior management support, use of AI by the firm, record keeping and learning from complaints data.
JBL Compliance Insights are short, specific training modules available in the LMS library for clients and paid subscribers, with lots more in production.
Think of this as a free sample…
COFA Masterclass – 7 October 2026, Birmingham
Our COFA Masterclass is back, and we are now taking bookings.
This is a full-day, in-person course for COFAs, finance managers, partners and anyone responsible for client account controls. The session will be led by Sean Hankin and Liz Bond: two former senior SRA experts with deep practical experience of Accounts Rules compliance across the profession.
We will cover the areas that regularly cause issues in practice, including reconciliations, banking facilities, residual balances, suspense ledgers, mixed receipts, breach reporting and what a COFA should be checking before signing anything off.
- Date: Wednesday 7 October 2026
- Location: Birmingham, venue TBC
- Price: £495 + VAT
Places are limited to keep the small group dynamic and we are taking bookings now.
To reserve a place, contact sam@jblcompliance.com
”This was a really practical and useful course on the role, expectations and responsibilities of a COFA which, if I am honest, I expected to struggle through but it was the most useful course, on the subject, I have ever been on. A must for any COFA.
Previous Masterclass delegate
Disciplinary watch
City Law Firm Limited, trading as St John Legal, agreed to a £13,684 penalty after acting for a non-domestic PEP and associated companies across a significant number of property and refinancing matters without adequate source of wealth, source of funds and enhanced PEP checks.
Vincents Solicitors Limited was rebuked after an AML desk-based review found missing client and matter risk assessments on seven out of eight files.
Rooks Rider Solicitors LLP was fined £25,000 after the SRA found that its historic firm-wide risk assessments failed to address the required risk factors. The firm had improved its position by the time of the decision, but the case is another example of historic AML weaknesses still being pursued.
John Howe & Co Solicitors Limited agreed to an £18,453 penalty following AML failings, including a lengthy period with no firm-wide risk assessment and later non-compliant risk assessments.
Jones Law Partnership was fined £7,696 for having no documented firm-wide risk assessment between 2017 and September 2024. Again, the SRA’s message is the FWRA is not optional and cannot be reconstructed only when the regulator asks for it.
Gabbitas Robins was fined £11,008 after an AML inspection found no client and matter risk assessments on all nine sampled files and failures around ongoing monitoring and source of funds on several files. Policies alone are not enough if the file does not show the process being followed.
Macmillans Solicitors LLP was fined £1,852 for deficient AML policies, controls and procedures, and a non-compliant firm-wide risk assessment.
Barrett Solicitors Limited received a fixed penalty for failing to submit workforce diversity data after the SRA’s request and failing to remedy the breach. These data exercises are easy to underestimate, but the SRA is perfectly willing to issue fixed penalties where firms ignore them.
Gems Legal Services Limited was rebuked after failing to comply with an undertaking to discharge an interim charging order on completion. The undertaking had been given without the firm having proper contact with the original creditor, and repeated chasers followed.
Habibur Choudhury and Archstone Solicitors Limited were fined jointly and severally after a long-running failure to comply with Transparency Rules requirements and conditions on the firm’s authorisation. The tribunal found the Dentons seriousness threshold was met, with the main harm being the apparent indifference shown to the regulator.
Grenville Young was suspended for 24 months and ordered to pay a £20,000 fine after failing to cooperate with SRA investigations and after issues arising from the closure of his firm.
Shashi Patel was struck off following a wide range of findings, including misleading information connected with PII, client account shortages, inadequate reconciliations, residual balances, failure to file an accountant’s report, lack of an adequate firm-wide risk assessment and broader failures to cooperate.
William Dooley was struck off after creating false correspondence and emails, and misleading his supervisor about an appeal deadline extension. The tribunal found dishonesty and concluded that strike-off was required. It is the familiar lesson: mistakes can often be managed, but fabrication usually cannot.
Brooke Middleton, a paralegal, was made subject to a section 43 order after dishonestly telling colleagues that an email had been sent earlier than it had and altering a case management timestamp. Junior staff need to understand that changing a record to make a mistake look better can end a legal career before it has properly begun.
What we do
- Outsourced COLP and COFA support
- Learning management system for multiple users
- Bespoke training – remote and in person
- Compliance audits
- New firm and ABS applications
- Independent AML audits
- AML and sanctions support
- SRA Accounts Rules and client money reviews
- File reviews
- SRA reports and notifications
- Escrow accounts for law firms
Contact us if you need help with any of the issues in this newsletter.
Separation of powers sounds sensible. But can law firms make it work?
The SRA is trying to solve a real problem. Too much control in too few hands can create obvious risks, especially where client money is involved.
But will the new COLP/COFA restrictions really create better governance, or will some firms simply move the compliance titles to people with less power, less authority and less ability to challenge?
In this article, we look at the proposed new rules, the £600,000 turnover and £2m client money thresholds, the difficult position for owner-managed firms, and whether separation of titles is the same thing as separation of power.
OpenAI, Anthropic and the rise of the compliance technologist
For years, legal conferences have asked whether AI will replace lawyers. That is probably the wrong question.
As AI becomes embedded into client onboarding, drafting, knowledge management, supervision and compliance monitoring, the more interesting question is: who is going to govern all of this?
This article argues that compliance professionals may be unexpectedly well placed for the next stage of legal AI. Law firms will need people who understand regulation, risk, operations and technology. Will the “compliance technologist” soon become one of the most valuable people in the room?
Independent AML audits for law firms: how to prepare for a Regulation 21 audit
For many firms, an “independent audit” only becomes urgent when the SRA asks about it during a visit.
An independent AML audit should be treated as a proactive control. Done properly, it is a structured review of whether your AML framework works in practice, not just whether the right documents exist somewhere in the shared drive.
However, nobody likes being audited. This guide explains what to prepare, what the auditor is likely to ask for, how file sampling works, and how to make the process useful rather than unnecessarily painful.
The file review fix: shifting the narrative on supervision
Do we have to do file reviews? How do we get people to engage with them? Is there a way to make the process less miserable?
Sam’s latest article looks at file reviews as part of effective supervision, not just another form to complete. The core idea is simple: if file reviews are treated as a collaborative learning exercise, rather than a compliance chore, they can improve quality, culture, supervision and risk management at the same time.
There is also a practical suggestion for firms willing to try something different: take a team off timetable for an afternoon and review files together.



