
The role of a Head of Compliance or Compliance Officer for Legal Practice (COLP) can frequently feel like a lonely pursuit. Many professionals are forced to operate on gut instinct, quietly questioning whether their strategic priorities align with their peers or if they are focusing on the right risks. This compliance spotlight series was conceived precisely to dismantle that isolation, offering a platform for peer benchmarking and encouraging legal leaders to reflect on the broader operational issues that exist far beyond routine anti-money laundering (AML) checks.
In this edition, Jonathon Bray sits down with Julian Wintle, the Head of Risk & Compliance at Redkite Solicitors. Redkite is a full-service regional law firm, with roots dating back to 1898, advising individuals, families and businesses across Wales and England through a broad network of offices and specialist teams.
This interview delves into the reality of managing risk across a rapidly expanding firm, the human side of cyber security, and how to introduce artificial intelligence without sparking a regulatory “wild west”.
An accidental path to compliance leadership
JB: Julian, thank you for taking the time to share your insights. To start at the beginning, how exactly did you find your way into legal compliance? Did you choose it deliberately, or did you “fall into it” like so many other compliance leaders?
JW: Yes, I too fell into it! It has been about four years now. I had spent a significant portion of my career in a large commercial firm, where my responsibilities had naturally shifted from pure lawyering to man-management and operational oversight. When I joined Redkite, I initially wore multiple hats: performing litigation alongside regional management duties. However, I found myself increasingly drawn to the non-lawyering aspects of the business. Having done my fair share of fee-earning, I was actively looking for an opportunity to pivot away from it.
I made my career ambitions known within the business, which led to a “tap on the shoulder” from our CEO, who informed me that our Head of Compliance was stepping down. Initially, it was pitched to me as a part-time opportunity because I maintained other management responsibilities. But I can assure you, it is certainly not a part-time role now!
JB: Did you experience a culture shock making that transition from traditional practice to a dedicated compliance leadership role?
JW: Not a total shock, primarily because the role beautifully leveraged my litigator’s mindset and my past management experience in building structured processes. However, the real surprise was the sheer volume of work required to shape the compliance function into something I was entirely comfortable with. At the time, the firm’s compliance structure was conventional and perfectly adequate for our size then, but it was essentially a blank canvas. Redkite has grown rapidly through acquisitions and now spans 19 geographically distinct offices. The older, conventional compliance methods simply would not function in an organisation of our current scale. I took it as an exciting project to design and implement robust, process-driven controls that could scale alongside the firm.
The premium on culture: securing leadership buy-in
JB: Compliance is increasingly recognised as a distinct, viable career path commanding serious professional value, but it relies heavily on having the right corporate environment. What advice would you give to someone stepping into their first senior compliance role today, particularly if they lack a supportive leadership team?
JW: My single most important piece of advice is to get an absolute commitment to a culture of compliance from the senior management team. If that commitment comes from the top, it will pervade through the entire business; conversely, if leadership is indifferent, that indifference will trickle down just as quickly. I have been exceptionally fortunate at Redkite because I have essentially been pushing an open door – our leadership is highly respectful of compliance.
However, if you find yourself in an organisation where you are struggling to be heard, you must find a way to align compliance goals directly with core business objectives. Look for a like-minded ally on the board who is mindful of risk, and learn to speak the language of business metrics. For example, take it down to brass tacks: demonstrate to the board how robust risk assessments and rigorous internal controls can directly reduce professional indemnity (PI) insurance premiums. We had that exact face-to-face conversation with our brokers and insurers during renewal, showing them the empirical evidence of our compliance processes. When you can return to the board and prove that your compliance framework has saved £10,000, £20,000, or £30,000 in hard cash on your PI premium, even the most sceptical leaders suddenly start seeing the true commercial value of what you do.
JB: That is an excellent point. But what about the layer just below the executive suite? Influencing partners and team leaders can often be an entirely different battle.
JW: Yes, it is often the bigger practical challenge. Non-executive partners, senior lawyers, and department heads frequently have highly diverse, and occasionally militant, views on compliance. They are focused on their personal targets and fee-earning, meaning compliance features less prominently on their radar. This challenge is amplified when, like Redkite, a firm grows via acquisitions, as you are constantly trying to align completely disparate legacy cultures into a single corporate mindset. This is exactly why you need an unyielding mandate from the executive leadership; it gives you the institutional backing to tell resistant colleagues, “This is not optional; this is simply how we do things here”.
The sleep thief: confronting cyber risk and the data comfort blanket
JB: Before our conversation, you highlighted cyber security as the issue sitting at the absolute top for the coming year. Why does this particular risk keep you awake at night?
JW: Because with cyber security, it is strictly a question of when, not if. You can invest heavily in sophisticated technical software to block external threats, but human risk remains our single greatest vulnerability. How do you completely stop a busy employee from clicking a highly convincing, dodgy phishing link? Because of this, having an airtight, fully tested contingency plan is vital for when a breach occurs.
Directly linked to this is what I consider a massive “hidden risk” that law firms simply do not talk about enough: data retention. From a regulatory and risk perspective, the sheer volume of data legal practitioners hold onto is incredibly dangerous. Traditional lawyers tend to treat data as a psychological comfort blanket, hoarding old files and emails indefinitely “just in case” it might be needed in the future. But when a cyber-incident inevitably happens, the ultimate scale and severity of the disaster will be determined entirely by the volume of data exposed. If an attacker compromises an email account and finds a ten-year-old un-archived thread containing highly sensitive client information, that is a catastrophic failure of data hygiene.
JB: So how do you go about practically dismantling that “comfort blanket” mindset?
JW: It requires a dual approach of “hearts and minds” education combined with strict technical controls. You have to sit down with partners and paint a vivid picture of the “what ifs.” You ask them: What will you say to a loyal client of twenty years when you have to admit that a hacker stole their private data simply because you left it sitting in your email inbox rather than storing it correctly in the case management system?
Simultaneously, you have to remove some of that autonomy from them. At Redkite, we are actively looking at data segmentation and restricting internal access. Does every member of staff truly need unrestricted access to the entire case management system, or should access be restricted to specific teams? By blocking off random local drives and tightly controlling access permissions, you structurally limit the damage an attacker can do if they manage to compromise an individual’s credentials.
Beyond the checklist: the ‘would I buy it’ file review
JB: I am fascinated by how Redkite has evolved its file review processes. Most law firms treat file reviews as a dry, tick-box compliance exercise. How are you doing things differently?
JW: We completely redesigned our file reviews to move beyond basic regulatory compliance checklists and actively incorporate client service quality metrics. When you look at Legal Ombudsman (LeO) statistics, the most common drivers for complaints are entirely uniform across the industry: delays, poor communication, failure to update clients, and unexpected cost updates. We are not unique; we see those exact same themes surfacing in our internal data.
To combat this, our file reviews ask qualitative questions with detailed comment boxes, such as: Has the client been serviced appropriately? The ultimate benchmark we use is the “mum test”: Would I be happy if my own mother received this level of communication and service from her solicitor?
If a file fails that qualitative test, we don’t just issue a corrective action and move on. We use a “carrot and stick” approach. The stick is that fee-earners who fail are placed on an increased review schedule, effectively a “naughty step”, where a higher percentage of their files are automatically audited until they demonstrate sustained improvement. The carrot is our shift toward true compliance business partnering. We take that data directly to the heads of departments and collaborate on proactive remediation plans. If a team is under pressure, we will deliver targeted training on how to manage client expectations, track initial quotes, and communicate cost adjustments well ahead of time, rather than waiting for a formal complaint to land.
JB: That client-centric focus ties closely into team culture. You have previously mentioned that your compliance team is structured somewhat uniquely compared to other firms.
JW: Yes, there is nobody else in my compliance team who is a qualified lawyer or an aspiring would-be lawyer. They are individuals chosen entirely because they possess a genuine passion for client service, an innate desire to “do the right thing,” and a curiosity to understand the underlying why behind regulations rather than treating them as a tick-box hurdle.
Legal training inherently instils a highly defensive, “batten down the hatches” mindset. Lawyers are taught to believe they must be perfect, and if a mistake happens, their immediate instinct is to defend it or argue it through. Non-lawyers do not carry that professional baggage. When a client grumble or a complaint comes in, a non-lawyer tends to approach it with an open, constructive mind, putting themselves directly in the client’s shoes to figure out how to put it right and what the business can learn from it. That perspective is incredibly powerful for driving continuous improvement.
Managing the wild west: controlled artificial intelligence adoption
JB: Let’s talk about a major talking point for every compliance professional right now: Generative AI. How are you balancing that opportunity against the obvious risks?
JW: We fundamentally recognise that there is a massive existential risk to our business if we fail to adopt AI. We simply cannot afford to be left behind. However, a blanket ban is completely counterproductive. If you impose a total prohibition, human nature dictates that fee-earners will simply use open-source AI products unsanctioned. That creates a highly dangerous “wild west” scenario where confidential client data is actively leaked into open public models like standard off-the-shelf ChatGPT.
When we reviewed our system reports, we actually identified a few individuals who were bypassing our official restrictions to experiment with AI tools. Rather than punishing them, we immediately brought those exact people into our official pilot project group. They became our core testing team because they had the appetite for it, but now they operate within strict corporate guardrails.
Our primary guardrail is technological: we exclusively use professional-grade software like Lexis+ AI and Microsoft Co-Pilot, which operate strictly within our secure internal environment and guarantee that client data is never trained out.
Secondly, we maintain a strict “two lines of defence” human protocol. No AI-generated output is ever sent out or relied upon blindly; it must be rigorously supervised and checked by a designated supervisor who understands the fallibility of the tech and the inherent risk of hallucinations.
Finally, we have explicitly updated our terms of business to inform our clients that we utilise AI tools within a controlled, secure environment to enhance our services.
Looking down the track: a data-driven regulator
JB: Looking ahead, how do you see regulatory expectations shifting, and how should firms prepare?
JW: Even if the change in AML supervision doesn’t materialise in this Parliament, we are anticipating that the SRA will inevitably follow the lead of the Financial Conduct Authority (FCA) and transition into a deeply data-driven regulator. The SRA’s recent AML data-collection exercises are a clear flavour of what is coming down the track. The day of reckoning is approaching where simply showing a regulator a pristine, beautifully written AML policy document will no longer be enough. Regulators will demand empirical proof and data demonstrating that your internal controls are actually functioning effectively in practice.
At Redkite, we have already future-proofed our workflows. For instance, our case management system features hard technical stops: a fee-earner physically cannot progress a matter unless a compliant AML risk assessment has been completed within a strict timeframe. We pull daily reports on this, meaning if the SRA walks through our door tomorrow, I can instantly provide them with clean, aggregated data proving our compliance rate.
If you are a smaller firm without a dedicated compliance team, you must start auditing your data readiness today. Ask yourself: What data can we currently extract from our systems? How can we prove our controls work? You do not need to build a bespoke, multi-million-pound framework; even a disciplined protocol of pulling and documenting weekly file samples will give you the necessary evidence to satisfy a data-driven regulator when they come knocking.


