
I may not have switched on my brain so far this week but Tuesday’s Court of Appeal decision in Dentons UK and Middle East LLP v Solicitors Regulation Authority Ltd [2026] EWCA Civ 508 is not the easiest thing to follow.
Just like a child on Sports Day, I’ve seen commentary out there asserting:
- It’s a win for Dentons
- It’s a win for the SRA
- It’s a win for the profession
Can it really be all of these? Or are we getting ahead of ourselves?
What’s going on?
The proceedings arise out of work done by Dentons between 2013 and 2017 for “Client A”, treated internally as a politically exposed person and high AML risk. The SRA’s case focused on whether the firm took “adequate measures” to establish source of wealth and source of funds, as required by regulation 14 of the Money Laundering Regulations 2007.
In March 2024 the SDT found Dentons had breached regulation 14, but dismissed the SRA’s allegations that this amounted to breaches of Principle 7 of the SRA Principles 2011 (comply with legal and regulatory obligations) and Outcome 7.5 of the 2011 Code of Conduct (comply with legislation applicable to the business, including AML).
The SDT’s rationale was that, on the facts found, the breach was not “serious, reprehensible or culpable” enough to justify the label of professional misconduct.
In 2025 the High Court quashed that decision, essentially accepting the SRA’s “strict” approach that a proved legal breach automatically establishes a professional breach, and sent the matter back to a fresh SDT panel.
The Court of Appeal upheld the High Court’s decision to set aside the SDT’s dismissal of the core “Principle 7 / Outcome 7.5” allegation, meaning the case can be reconsidered.
But it rejected the High Court’s underlying reasoning on one point of wider importance: the court held that an allegation of professional misconduct under the SRA Principles and Code carries an inherent requirement of seriousness. A breach of legislation (including AML legislation) is not, therefore, automatically misconduct.
However, it modified the original SDT judgement on this question, which was whether “serious, culpable and reprehensible conduct” had been proved. The Court of Appeal held that this was not the correct test to use.
In framing the test, the Court endorsed an objective professional-standard lens: whether the conduct would be regarded by competent and reputable solicitors as sufficiently serious to be categorised as professional misconduct.
It also indicated unease with the SDT’s characterisation of the breach as “entirely inadvertent”, noting difficulties with that conclusion given the risk indicators recorded within the firm.
However, the Court of Appeal did not itself make the misconduct finding; it left it to the tribunal to decide, on those findings, whether the seriousness threshold is met and, if so, what sanction follows.
The practical effect is a more focused rehearing rather than a full-scale rerun of every allegation.
What’s the effect?
For the SRA, the judgment may limit the attraction of a “strict liability” route to misconduct where an underlying legal breach is proved. Therefore, it is fair to say that a breach of the AML regulations is not going to automatically be a misconduct breach.
It may also reduce the broader use of Regulatory Settlement Agreements which are often used in AML breach cases particularly. Our article here considered whether these are always used fairly and appropriately: the Dentons case may help to inform a shift in how the SRA uses them.
For firms, it is not a get out of jail-free card either: the court has made clear that AML compliance failures can still amount to misconduct where they cross the seriousness line. It has signalled that tribunals should not assume that “good faith” or an absence of deliberate wrongdoing automatically keeps a breach on the “technical” side of that line.
The case is also a reminder that inherited relationships (post merger, post acquisition, or via lateral moves) create particular governance stress-tests: this all stemmed from the fact that a legacy firm hadn’t followed the Dentons centralised approach.
Is this as exciting as we are led to believe?
(Ok, “exciting” here is used loosely).
There is always a tendency to focus on the outcome of one specific case and apply those broadly. Sometimes this is absolutely the correct thing to do, because those outcomes would indeed be more global (Mazur, I’m looking at you). However, it’s not always the case and may not be so here – so far, at least.
The regulations used in the Dentons case are old: it’s the 2007 Money Laundering Regulations, and the 2011 SRA Principles and Code of Conduct. The underlying foundations are similar, but the fact remains is that this case does have a historical slant. In particular, the 2019 Principles and Codes are more brief.
In theory, the SRA’s current Enforcement Strategy should automatically apply the seriousness test, albeit not on the objective standard applied by the Court of Appeal.
As we march forward, there are going to be more cases where these “newer” regulations are the ones applied, and this will be more helpful, as these are the ones which are going to be largely more relevant.
Additionally, AML breaches will often turn on the application of the risk-based approach: it may be arguable in some cases that an alleged AML breach wasn’t, in fact, an AML breach, meaning that any associated misconduct could fall away.
The history of the case itself is also not necessarily helpful. Each judgment has turned on different points, and several tensions remain. Not least is the quite basic point noted by the Court of Appeal, which is that the SDT did not seem to consider the fact that the firm had not asked source of funds questions. As above, the SDT had asserted that the breach was “inadvertent”: this sits uncomfortably with what we (don’t) know at the moment. If no source of funds checks were indeed undertaken then, particularly in light of what we understand about Client A, this could be a big problem. The fact that there is no “automatic” misconduct issue may become less emphatic if this AML breach is, in fact, serious enough to warrant a misconduct finding.
Finally, there is the potential of an uncomfortable message going out towards the profession. This judgement may uphold the fact that not every AML breach is automatically misconduct: that doesn’t mean, however, that every AML breach is ok.
There is a danger that, in embracing the judgement too fulsomely, we lose sight of the fact that AML breaches – whether inadvertent or deliberate – are not good things. They are things that we must, and must want to, avoid. Many MLROs and Compliance Managers may have used the potential of a misconduct finding as a stick to bolster AML compliance amongst their solicitors: it’s a valid thing to do, and it will remain so.
Regardless of this judgment, we should set a high bar for AML compliance: we have policies and procedures for a reason, and they need to be followed.
What happens next
Back to the future, back to the SDT. Using the factual findings already made, the tribunal will need to decide whether Dentons’ AML breach meets the Court of Appeal’s “sufficiently serious” threshold for a breach of Principle 7 and Outcome 7.5, and, if it does, what sanction is appropriate.
Let’s see what happens next. Any wider themes from the case need to reflect this final stage.


