Compliance can be a lonely place.

Most COLPs, COFAs, MLROs and risk professionals are expected to advise on a huge range of issues, often with limited visibility of how other firms are approaching the same problems. Anti-money laundering, client account controls, conflicts, complaints, data protection, privilege, artificial intelligence, supervision, training, regulatory change – it all finds its way to the compliance team eventually.

That is why we started the Compliance Spotlight series. The aim is to share practical experience from people doing this work in real firms, under real pressure, with real commercial constraints.

For this edition, Jonathon Bray spoke to Victoria Jordan, AML & SRA Accounts Rules Partner in the risk and compliance team at JMW. Victoria has an unusually rounded perspective. Before moving into in-house compliance, she worked as a forensic investigation officer at the Solicitors Regulation Authority. She has seen the profession from the regulator’s side, and now advises from within a large full-service law firm.

The conversation covered her route into compliance, the importance of senior support, why JMW has a trainee seat in its risk and compliance team, the limitations of the “all-knowing compliance officer” model, the move towards FCA supervision of AML and compliance fatigue.

From intervention work to compliance

Victoria did not begin her career expecting to become a compliance specialist. Like many solicitors, she entered the profession because she wanted to help people. But during her training, she was exposed to intervention work through a firm that acted on the SRA’s intervention panel.

That experience changed her view of what regulatory work could achieve.

“I went on site to a firm where the owner had been misappropriating client money,” she says. “The knock-on effect for clients and staff was far-reaching. Court hearings were still listed. Limitation dates were still expiring. Conveyancing chains did not just hold off.”

For Victoria, the attraction of regulatory work was not the rules for their own sake. It was the practical impact of stopping harm.

“I felt like I was helping people because I was stopping someone doing something they should not be doing. You think you can trust a solicitor, and you should be able to trust a solicitor, but there are people who do the wrong thing, either on purpose or inadvertently.”

That led her to the SRA, where she worked as a forensic investigation officer.

One reported case that has stayed with her was the Hetherington matter, involving a dubious investment scheme connected to car parking spaces and storage spaces.

“People were promised amazing returns which were never going to happen,” she says. “I led in shutting down that firm. It was really sad because we took witness statements from people who had lost their life savings and whose relationships had broken down because of the stress of realising they had been conned .”

It is a reminder that compliance work, at its best, is not an abstract regulatory exercise. It is about protecting clients, the profession and the integrity of legal services.

Moving in-house changes the perspective

Victoria is careful not to overstate the criticism of regulators. She saw valuable work being done at the SRA. But moving into a large law firm gave her a different appreciation of how difficult implementation can be.

“Going from the regulator to advising in-house, you realise how impractical some rules and regulations can be,” she says.

Practical understanding runs through much of Victoria’s approach. Good compliance is not just about knowing what the rule says. It is about understanding how the firm actually works, where the data sits, who owns the process and what pressure fee earners are under.

A partner role in risk and compliance

Victoria is a partner at JMW, but does not have a fee-earning caseload.

That remains relatively unusual. Risk and compliance professionals often operate at a senior level, but without the status or visibility given to senior fee earners. At JMW, Victoria sees her title as part of a wider signal from management.

“It is something the firm supported to show that they value risk and compliance roles within the firm,” she says. “There is definitely a desire from the senior management team to show the rest of the firm that they really do support the risk and compliance team.”

That support is not just symbolic. It affects how the rest of the firm sees the compliance function.

“They want to show that risk and compliance is not just a tick-box exercise, or all those negative words you sometimes hear around compliance, like ‘business prevention team’.”

In Victoria’s view, that recognition is also commercial. Firms that treat compliance as something to be fixed only after the event usually pay more for the mistake.

“For JMW to continue its progression and growth, they know they need to get it right, because it is costly when you are trying to fix things retrospectively, or if you get things wrong.” This is not only financially but also reputationally.

Putting trainees into the compliance team

One of the most interesting features of JMW’s approach is that the risk and compliance team takes trainees.

It is not a mandatory seat, but the firm has been running the placement for around two years and is now on its fourth trainee.

“We have a trainee in our department, which is unique,” Victoria says. “That was because the senior management team wanted to show that it is an important area of the business.”

The purpose is not simply to create future compliance specialists, although that may happen. It is also about spreading compliance understanding into the wider firm.

“The trainee can go out and spread the word,” she says. “Not just while they are training, but throughout their career. They can take the lessons they have learned from being in our department into other practice areas.”

That point is worth pausing on. Many firms struggle to make compliance feel relevant to junior lawyers. A risk and compliance seat gives trainees early exposure to the machinery of the firm: why checks are needed, why policies exist, how client money risks arise, how conflicts are assessed and why systems matter.

Victoria’s hope is that trainees leave the seat with confidence, not just knowledge.

“Hopefully they will have a better understanding of it all, but also the confidence to say, ‘Maybe that is not the right thing,’ or, ‘Maybe we should do something a different way,’ or, ‘Have you read that policy?’”

The myth of the all-knowing compliance officer

A recurring theme in the conversation is that no one person can know everything.

That may sound obvious, but many compliance officers still feel they are expected to have an instant answer to every query. Victoria pushes back against that idea.

“Not everybody can have the answer to everything,” she says. “Risk and compliance is such a wide area that you need people with specialisms, and you need to bring them in at the right time.”

At JMW, issues are triaged through the risk and compliance team, but the answer may involve other specialists across the business.

“We deal with money laundering issues, client account issues, professional negligence, conflicts of interest and everything else,” she says.

Privilege is a good example. If a compliance issue involves a possible disclosure to the National Crime Agency, the question may not be purely regulatory. It may require specialist privilege advice.

“I am better talking to one of our commercial litigation lawyers who deals with privilege on a daily basis than just sitting at my desk trying to work it out on my own and stressing.”

The same applies to data protection. JMW has a data protection lead within the risk and compliance team, reflecting the technical nature of that area.

For smaller firms, the same principle still applies, even if the internal resource is not available. The COLP, COFA or MLRO may hold the formal title, but that does not mean they should operate in isolation. Good compliance often depends on knowing when to bring in the right expertise.

AML supervision and the FCA: start with the data

When asked what is on her radar, Victoria is quick to mention the proposed move of AML supervision from the SRA to the FCA.

“The shift to the FCA from the SRA for AML supervision,” she says. “From talking to other people in the profession, the FCA seems much more data driven, so we are trying to get our ducks in a row and make sure we have all the data to hand easily.”

That phrase — “data to hand” — captures a practical challenge for many firms.

Most firms can get to the information eventually. The question is how easily, how consistently and how much manual intervention is required.

There is still uncertainty about the detail of the regulatory transition. Victoria’s response is pragmatic: focus on what the firm can control now.

“There is still a lot up in the air, but we’ve got a team to help with the transition including a full-time AML lead and an SRA Accounts Rules and AML Advisor.”

Client money reform and the gap between intention and implementation

Client money is another major issue on Victoria’s radar.

“The SRA, rightly so, is keeping a close eye on client account,” she says. “As solicitors and law firms, we are trusted with client money and it should be treated as sacrosanct.”

No one in the profession wants to see another major client money failure. Victoria recognises the pressure on the SRA to act, particularly after recent high-profile collapses.

But she is concerned that some reforms may not address the true problem.

“My worry is that, in the haste to show they are doing something, they may miss the true target.”

The proposed requirement to notify the SRA of certain mergers and acquisitions is a good example. Earlier visibility may sound sensible. The harder question is what happens next.

“If the SRA wants to know about mergers, who will the information be passed to internally?” Victoria asks. “Who will have the knowledge to say whether something is sustainable or suitable?”

Her concern comes from experience. At the SRA, forensic investigation officers had a wide remit, but assessing the financial stability of a law firm or the commercial viability of a transaction is a specialist task.

“I am not an accountant,” she says. “I do not have the expertise to say whether something is financially stable other than looking at it at a high level.”

That does not mean the regulator should do nothing. It means regulatory reform needs to be matched with the right resource, expertise and process.

“They may have good intentions, but do they have the resources and talent to make it work?”

Compliance fatigue

Away from the headline reforms, Victoria identifies a quieter risk: compliance fatigue.

“I worry that sometimes we ask too much of fee earners,” she says.

JMW is a full-service firm, which means different departments carry very different risk profiles. Some are high risk from an AML perspective. Others are low risk or outside the regulated sector.

The difficulty is finding the right baseline without making every process feel equally urgent.

“We try to have different approaches for different departments, but we also have a base level for low-risk departments which is higher than they need,” Victoria says. “Partly because we are mindful about passporting and partly because we are worried about clients becoming frustrated if they move from one department to another and are asked for certain information again.”

This is a familiar problem. Firms want consistency, but consistency can create unnecessary friction. Firms want strong controls, but too many messages can blur the priorities.

“Sometimes I do worry that we are telling fee earners they have to look out for everything,” she says. “Money laundering, residual balances, conflict checks. If you say that everything is a risk, then it can be difficult to prioritise.”

Training is part of the same issue.

“You could give fee earners training every week, or ask for time in every team meeting, but then they are not fee earning and it all becomes too much and people will stop listening.”

For Victoria, the challenge is not whether compliance messages should be delivered. It is how to make sure they land.

“That is probably one of the biggest decisions for us as a team: where do we really need to focus the messages we are giving fee earners?”

Her preference is for practical, tailored training with examples that feel real to the audience.

“You need bespoke training with real-life examples for any of it to sink in.”

AI: opportunity vs. risk

No modern compliance conversation can avoid artificial intelligence.

At JMW, the approach is collaborative. IT leads on the technical side, but risk and compliance are closely involved.

“It needs to be led by IT because they have more knowledge about generative AI and the different tools,” Victoria says. “But we also need to put guardrails in place because there have been many examples in the profession of hallucinations and what can go wrong.”

Victoria’s biggest concern is not that senior specialists will be fooled by every AI output. It is that junior staff may not yet have the experience to spot when something is wrong.

“In trials, I asked the firm’s approved AI to put together a PowerPoint presentation on the SRA Accounts Rules,” she says. “Some of the content it produced was clearly wrong, but it was presented confidently by the system and it was only clearly wrong to me because of my experience.”

That is the danger. An inaccurate output can look polished. It can sound plausible. It may even be presented with confidence.

“I would worry that a more junior person would not spot it,” she says. “In that situation, it could go out as training material to the firm, and then it is not just one person who has got it wrong – the whole firm is learning something that is incorrect.”

Controlling unsanctioned AI use

JMW has policies and communications in place to make clear which AI tools staff can use. But Victoria is realistic about the limits of policy documents.

“A policy on its own is not enough,” she says.

The firm’s approach combines communication, approved systems and monitoring.

“We have had several communications go around the business making it clear how colleagues can understand whether they are using AI that is protected within our work system, rather than an open AI tool.”

Importantly, JMW is not simply saying no to everything outside the approved system.

“We are not just saying that our approved AI application is the best and only one we will ever use,” Victoria says. “If someone thinks there is something better out there, they should not just go and use it on their own. They should submit a request to our Solution Delivery team, who will liaise with Cyber Security and other internal stakeholders”

That approach recognises the reality of modern legal technology. If firms only block tools, they may push use underground. If they create a route for proper assessment, they are more likely to hear about the tools people want to use before they become a confidentiality or data protection problem.

Advice for new compliance leaders

Victoria’s advice to someone stepping into a senior compliance role is refreshingly simple.

“Be open and honest about what you do not know,” she says. “You do not have the answer to everything and you need support around you.”