
For many law firms, the phrase “Regulation 21 audit” only becomes urgent when the SRA asks about it.
That is not ideal.
An independent AML audit should not be treated as a regulatory fire drill. Done properly, it is a structured review of whether your anti-money laundering framework works in practice, not just whether the right documents exist somewhere in the firm’s shared drive.
For managing partners, COLPs, MLROs and MLCOs, the immediate question is usually practical: what does an independent AML audit involve, what should we prepare, and how disruptive is it likely to be?
This guide explains the process.
🎧 Busy schedule? Click play below to listen to an audio version of this guide.
What is a Regulation 21 AML audit?
Regulation 21 of the Money Laundering Regulations requires firms, where appropriate to the size and nature of their business, to establish an independent audit function. In simple terms, this means arranging an objective review of the firm’s AML policies, controls and procedures.
The audit should examine whether the firm’s AML framework is adequate and effective, make recommendations where improvements are needed, and check whether those recommendations are implemented.
This is different from routine file review or day-to-day compliance monitoring. Internal supervision may tell you whether a file has an ID document on it. An independent AML audit should go further. It should test whether the firm’s risk assessments, client due diligence, source of funds processes, training, reporting lines and governance arrangements are properly designed and followed in real matters.
Why should you take Regulation 21 seriously? Because the SRA has dramatically doubled its proactive AML engagements, revealing persistent non-compliance in over a third of inspected firms. These breaches routinely lead to fines and public censure, which can in turn impact on a firm’s reputation and even panel membership.
The looming transition of professional legal services supervision to the Financial Conduct Authority (FCA) presents a severe compliance trap for law firms, as its data-heavy oversight model carries strict enforcement standards and enforcement powers. Now is the time to future-proof your firm.
Does the audit have to be external?
Not always, no.
“Independent” does not automatically mean “external”. LSAG guidance says the person conducting the audit may be internal or external, but must be independent of the function being reviewed. The SRA has taken a similar position: an audit does not necessarily have to be carried out by a specialist consultancy, but the person responsible for maintaining the AML framework should not be auditing their own work.
In practice, many firms choose an external audit because it is cleaner, easier to evidence, and less likely to be challenged. That is particularly true where the MLRO, MLCO or compliance team have designed the firm’s AML processes themselves.
When should a firm arrange an independent AML audit?
The SRA has previously said that most firms within scope of the Money Laundering Regulations should commission an independent audit, but there is no single fixed timetable that applies to every firm. LSAG guidance says firms should take a risk-based approach to audit frequency, taking account of the time since the last audit and any changes in the firm’s risk profile, structure or services. Annual audits may be appropriate for some firms, and higher-risk areas may justify more frequent targeted reviews.
As a practical rule, you should consider an audit if:
- the firm has not had one before;
- the firm carries out work within scope of the Money Laundering Regulations;
- the firm undertakes higher-risk work such as conveyancing, corporate, private client, trust or company services;
- the firm has grown, merged, opened new offices or changed its structure;
- there has been a change in MLRO, MLCO, COLP or senior management;
- internal file reviews are identifying recurring AML issues;
- the firm is preparing for, or responding to, SRA scrutiny; or
- the firm wants independent assurance before a problem arises.
If the firm decides it does not need an independent audit, that reasoning should be recorded. It is much easier to explain a documented risk-based decision than to reconstruct one later.
Step 1: appoint an internal audit lead
Even where the audit is external, someone inside the firm needs to own the process.
Usually this will be the MLRO, MLCO, COLP, COFA, practice manager or another senior person with access to the firm’s AML records and decision makers. Their role is not to influence the auditor’s findings. It is to coordinate documents, arrange interviews, explain systems, identify file lists and make sure the audit runs smoothly.
The best audit leads are organised, open and realistic. The worst approach is to treat the audit as an exercise in defending the firm. An independent audit is supposed to find gaps. The objective is not a perfect report; it is a useful one.
Step 2: agree the audit scope
Before the audit starts, agree what is being reviewed.
A proportionate Regulation 21 audit will usually cover:
- the firm-wide AML risk assessment;
- the proliferation financing risk assessment;
- AML policies, controls and procedures;
- client and matter risk assessment processes;
- client due diligence and beneficial ownership checks;
- source of funds and source of wealth controls;
- enhanced due diligence;
- PEP, sanctions and adverse media screening;
- internal reporting and SAR escalation;
- AML training and training records;
- employee screening where relevant;
- governance, reporting and senior management oversight;
- file testing; and
- implementation of previous audit or review recommendations.
The audit scope should reflect the firm’s risk profile. A small private client firm will not need the same audit design as a multi-office firm doing high-value conveyancing and corporate work. Equally, a firm should not exclude awkward areas simply because they are likely to produce findings.
Step 3: gather the core AML documents
A common reason audits take longer than expected is that the firm’s AML documents are scattered, out of date or owned by different people.
Before the auditor arrives, gather the core materials into one folder. At minimum, this should include the firm-wide AML risk assessment, AML policy, client and matter risk assessment templates, source of funds guidance, training records, internal reporting procedure, MLRO/MLCO appointment details, file review records and any previous audit or SRA correspondence.
The SRA’s own inspection guidance gives a useful indication of what it expects firms to be able to produce. Ahead of an AML inspection, the SRA says it may ask for the firm’s AML risk assessment, proliferation financing risk assessment, AML policies and procedures, client risk assessment template, Regulation 21 audit records, AML training records, fee earner lists and matter lists.
Step 4: prepare a matter list for file sampling
A proper audit should not stop at policy review.
The SRA has said that it is difficult to evidence the effectiveness of AML controls without reviewing files, and that a compliant independent audit should include both a review of the firm’s AML policies and a sample of client files.
The auditor will usually ask for a list of matters from the relevant review period. Ideally, the list should identify:
- matter type;
- department;
- fee earner;
- open or closed status;
- client type;
- risk rating;
- whether the matter involved source of funds checks;
- whether enhanced due diligence was applied;
- whether the client was a company, trust, overseas entity or other non-natural person;
- whether sanctions, PEP or adverse media screening was carried out; and
- whether any internal suspicious activity report was made.
Not every case management system can produce this neatly. If yours cannot, do the best you can. The process of building the list is often revealing in itself. If the firm cannot easily identify its higher-risk matters, that may point to a wider issue in AML oversight.
Step 5: prepare staff for interviews
An AML audit will often include interviews with the MLRO, MLCO, compliance staff and selected fee earners and support staff. SRA inspections can also include interviews with the MLCO, MLRO and fee earners, so this is a useful rehearsal for regulatory scrutiny.
Staff do not need to be coached. They do need to understand the purpose of the audit, which is to test the effectiveness of the firm’s controls.
A good auditor is not looking for scripted answers. They are trying to understand whether the firm’s AML controls are embedded. Do fee earners know when to complete a risk assessment? Do they understand source of funds? Do they know when to escalate concerns? Do they know where the policy is? Are they using the firm’s systems, or working around them?
It is usually better for staff to be honest than polished. If people are unsure, that is useful evidence. It may show that the firm needs clearer guidance, better training or more practical supervision.
Step 6: check the evidence before the audit
Before the audit begins, carry out a quick internal sense check.
Are your AML documents dated and version controlled? Has the firm-wide risk assessment been approved by senior management? Do training records show who completed training and when? Are file review findings recorded? Are previous audit recommendations tracked? Are source of funds notes meaningful, or do they simply say “inheritance”, “savings” or “sale proceeds” without explanation?
You’re not trying to hide weaknesses here; you’re trying to avoid unnecessary confusion. If the firm has already identified an issue, tell the auditor what it is and what is being done about it.
Step 7: be ready to explain how the system works in practice
An AML audit is not just a document request.
The auditor will want to understand how matters move through the firm. How is risk assessed at onboarding? Who reviews high-risk matters? What happens if a fee earner disagrees with a risk rating? Can a file be opened before CDD is complete? How are sanctions alerts handled? Who monitors overdue reviews? How does the MLRO receive internal reports? What information reaches the board or senior management?
This is where many firms struggle. The written policy may be broadly acceptable, but the practical workflow is unclear. A fee earner may be using one process, the onboarding team another, and the compliance team a third. The audit should flush those issues out.
Step 8: agree how findings will be reported
Before the audit is finalised, agree the format of the report.
A useful report should not simply say “compliant” or “non-compliant”. It should identify what was reviewed, what sample was tested, what evidence was considered, what findings were made, the level of risk attached to those findings, and what action is recommended.
LSAG guidance says firms should keep records of audits, including the scope and sampling basis, records audited, findings and recommended actions, senior management or board discussions, and the firm’s response and implementation of actions.
The action plan is often the most valuable part of the process. It should be specific enough to be useful. “Improve source of funds” is not enough. “Update the source of funds procedure, provide targeted training to residential conveyancing, amend the file opening checklist and complete a follow-up review of 10 conveyancing files within three months” is much better.
Step 9: take the report to senior management
An independent AML audit should not sit in the MLRO’s inbox.
The findings should be reported to the firm’s senior management body. That does not mean every technical detail needs to be debated by the board, but senior leaders should understand the key risks, approve the action plan and make sure people have the time and authority to implement it.
This is also important evidence. If the SRA later asks what the firm did with the audit, you want to show that it was considered properly, not treated as a compliance document with no operational impact.
Step 10: follow up
The audit is not finished when the report is issued.
Regulation 21 refers not only to making recommendations, but also to monitoring compliance with those recommendations.
Create an action tracker. Assign owners. Set deadlines. Keep evidence of completion. For more serious findings, consider targeted follow-up testing. If the issue was poor source of funds evidence, review a fresh sample after training and process changes have been introduced. If the issue was inconsistent matter risk assessments, test whether the updated process is being used.
This is where an audit becomes a practical improvement tool.
Common problems we see in AML audits
Most AML audit findings are not about firms having no AML framework at all. The more common problem is that the framework exists, but does not operate consistently across the business.
A firm may have an AML policy, a firm-wide risk assessment, a client and matter risk assessment template, training records and file review processes. On paper, the structure looks reasonably complete. The audit question is whether those controls are understood, used and supervised properly.
In our experience, the same weaknesses tend to appear repeatedly.
One of the most common is a disconnect between the firm-wide risk assessment and the day-to-day handling of files. The firm-wide risk assessment may identify conveyancing, private client work, company structures, overseas clients or high-value transactions as higher risk, but the file-level controls do not always reflect that. Fee earners may be completing the same risk assessment process for every matter, regardless of the actual risk profile.
Another frequent issue is that matter risk assessments are treated as a file-opening form rather than a live risk tool. They are completed at the start of the matter, often with very little explanation, and then never revisited. That becomes a problem if the risk changes: a new source of funds emerges, a transaction structure becomes more complex, a client’s behaviour changes, or new information comes to light.
Source of funds is another area where firms often look more exposed than they realise. The file may contain documents, but the file note does not explain the fee earner’s thinking. There may be a bank statement, a gifted deposit letter or evidence of a property sale, but no clear assessment of whether the explanation makes sense in the context of the transaction. Auditors and regulators are not just looking for documents. They are looking for evidence that someone has understood and assessed them.
Training can also be weaker than the records suggest. A firm may be able to show that staff have completed annual AML training, but still struggle to demonstrate that the training is role-specific, understood, or connected to the firm’s own risk profile. The question is not simply “has everyone done AML training?” It is whether the training helps people spot and respond to the risks they actually encounter.
We also see problems with escalation. Fee earners may know who the MLRO is, but be less clear about when a concern should be escalated, what should be recorded, how tipping off risks are managed, or what happens after an internal report is made. In some firms, the MLRO carries a lot of personal knowledge, but the process around them is under-documented.
Finally, many firms struggle with evidence of oversight. Senior management may take AML seriously, but the records do not always show meaningful review, challenge or follow-up. Previous audit findings, file review issues or training gaps may be discussed informally but not tracked through to completion. That creates a regulatory problem because the firm cannot easily show that it identified weaknesses and acted on them.
These are not unusual findings, and they do not necessarily mean a firm is in serious difficulty. But they are exactly the sort of issues that an independent audit should bring to the surface before the SRA does.
A good audit report should help the firm distinguish between technical gaps, process weaknesses and genuinely higher-risk failures. It should also give the firm a realistic action plan. There is little value in a long list of theoretical recommendations that nobody has time to implement. The output needs to help the MLRO, MLCO, COLP and senior management decide what to fix first.
Preparing the documents without duplicating the audit
It is worth gathering your AML documents before the audit starts, but the aim is not to produce a perfect bundle for the auditor. The aim is to make the audit efficient and to give the auditor a clear view of how the firm’s AML framework is supposed to work.
There is also a useful discipline in doing this. If documents are difficult to find, undated, inconsistent or owned by different people, that may itself tell you something about the maturity of the firm’s AML controls.
Rather than repeating the full list here, we have created a separate Pre-Audit Document Checklist exclusively for COLP Insider subscribers (our free newsletter). It sets out the core policies, risk assessments, training records, file information and governance documents that firms should gather before an independent AML audit or gap analysis.
The checklist is not a substitute for the audit. It is a preparation tool. It helps you get the basic materials in one place, so the audit can focus on the more important question: whether the firm’s AML controls are actually working in practice.
Download the Pre-Audit Document Checklist.
Final thought
An independent AML audit should not be approached as a pass/fail test.
The better question is: would this audit help the firm understand whether its AML controls are actually working?
If the answer is yes, the audit is doing its job. It should give senior management a clear view of the firm’s current position, give the MLRO and MLCO practical recommendations, and give the firm evidence that it is taking its AML obligations seriously.
And if the SRA does come knocking, the firm will be in a much stronger position if it can produce a recent, properly scoped audit, a clear action plan and evidence that recommendations have been implemented.
Phase 1: Preparation & PCP analysis
Objective: Evaluate structural gaps before the SRA does.
Core steps:
- Review firmwide risk assessment and template CMRAs.
- Audit current policies, controls, and procedures (PCPs).
- Review training records.
- Verify alignment with current regulatory standards.
Documentation required:
- Written policies and manuals
- Risk assessments
- Training logs
Phase 2: Live file sampling & testing
Objective: Ensure operational daily practice mirrors documented policy.
Core steps:
- Draw a random sample across core fee-earner files.
- Audit source of funds (SoF) verification trails.
- Check client risk assessments (CMRAs) and any indicated follow up.
Documentation required:
- Matter files and ledger notes
- Completed CMRAs
Phase 3: Interviews & staff benchmarking
Objective: Confirm structural compliance is embedded in firm culture.
Core steps:
- Conduct brief interviews with fee earners, management and support staff.
- Benchmark staff AML and regulatory awareness.
- Test response readiness for desktop audits.
Documentation required:
- Staff list
- Training records
- Interview notes
Preparing for an independent AML audit?
Download our free Pre-Audit Document Checklist below to see the core documents, records and file information your firm should gather before the review starts.
JBL Compliance also carries out independent AML audits and AML gap analyses for SRA-regulated law firms. If you would like an objective review of your AML framework, we can help you scope the audit, test your files and produce a clear action plan for senior management.


