law firm regulatory compliance operational controls SRA

If there is one theme running through recent regulatory events, it is this: the compliance conversation is becoming less forgiving of superficiality.

That may sound obvious. Regulators have always said that firms need more than policies gathering dust on a shelf. But the tone now feels more pointed. Whether you look at the Law Society Compliance Conference 2026 or the SRA’s recent AML webinar, the message is strikingly similar. It is about whether a firm’s documents actually shape behaviour and support judgement.

In other words, it feels like the regulatory spotlight is moving from paper compliance to operational compliance.

Many firms that we speak to still feel as though they are in keep-up mode. They have a firm-wide risk assessment. They have an AML policy. They have source of funds procedures. They have role descriptions. They have AI discussions. They have some form of governance framework.

What the regulator increasingly seems to be asking, however, is a different question: yes, but does any of it really work? Is it meaningful?

Pressure on fundamentals, not shiny new concepts

One of the clearest impressions from the Law Society Compliance Conference was that, for all the discussion of AI, changing business models, possible changes to AML supervision, Companies House reform and other moving parts, the underlying theme was not novelty. It was on getting the basics right.

Firms still need good ethical judgement. They still need a culture where risks are spotted and acted on early. And they still need senior people who understand what the systems are for, rather than treating compliance as a parallel function that sits somewhere off to one side.

That is perhaps what makes the current mood feel more significant than the usual cycle of regulatory guidance and missives. The topics are familiar, but the regulatory approach appears to be hardening around them. There is a sense that the SRA wants to be seen as pragmatic and proportionate, while also becoming more focused on prevention, governance failings, business model risk and the consequences of weak operational control. That also fits with Sarah Rapson’s recent messaging about “fixing our foundations” and “rebuilding trust with both the public and the profession”. A regulator that wants to be more trusted is, almost by definition, going to be more interested in whether firms’ systems actually work in practice than whether they simply exist on paper.

AML is the clearest example of that shift.

The SRA is looking past paperwork and into behaviour

The recent SRA AML webinar was, on one level, about familiar building blocks: firm-wide risk assessments, AML policies, client and matter risk assessments, source of funds, audits and training.

But the real message went deeper. The concern was not simply whether firms had those controls written down. It was whether they were understood, used and embedded in day-to-day team behaviour.

Why is that important? Well, because many firms get fined by the SRA not because they have no framework at all. They feel the regulator’s wrath because their framework exists only on paper.

The case study used in the webinar illustrated that neatly. A fictional conveyancing file involving overseas sale proceeds and an initial possible PEP hit was used to show how different controls are supposed to work together. The point was not that there is always one correct answer. The point was that a proper AML response is cumulative. The firm-wide risk assessment should guide the fee earner. The client and matter risk assessment should not be completed in isolation. Source of funds evidence should be scrutinised, not just collected. Technology should assist, not replace judgement.

The strongest single theme was scrutiny. Not collection or mindlessly applying a procedure. Scrutiny.

That came through in the way the SRA dealt with the PEP issue. A possible match was not treated as something to be accepted blindly or dismissed lazily. The fee earner in the example had to think, compare details, check spelling, use open-source material and work out whether the result really related to the client in front of them. The same applied to source of funds. The material gathered only became useful if somebody understood what it proved, what it did not prove, and whether the overall picture made sense.

That is an important shift in emphasis. The SRA was not just saying “this is high risk so do more checks”. It was saying: understand why you are asking for a document, what risk it addresses, and whether the explanation makes sense.

The figures shared in the webinar reinforced the point. Of firms referred for investigation for lack of proper file-level risk assessment, 82% actually had a client and matter risk assessment process in place. The problem was that fee earners were not following it. That is a telling statistic because it captures the regulatory concern in one number. The SRA is not only worried about lack of controls. It is worried about controls that don’t work.

The same logic runs through its comments on suspicious activity reporting. In many matters where the SRA itself ended up submitting a SAR, the material was apparently already sitting on the file. The failure was not always a lack of information. It was a lack of scrutiny.

This is all quite uncomfortable, because it means firms cannot reassure themselves simply by pointing to the existence of documents. If the control is not live, it may as well not exist. And testing the effectiveness of controls is a much harder thing to do. It’s also why the legislators inserted the Independent AML Audit requirements into the Money Laundering Regulations.

The wider AML direction of travel

The Law Society conference discussions echoed that same theme, but also added a few practical warnings about what may be coming next.

There was repeated discussion about onboarding, future-proof processes, and the need for a reliable “single source of truth” for risk and client information. There was also a sense that firms should not sit back and wait for any formal change in supervisory model before improving their systems. The possibility of the FCA taking over AML supervision may not be imminent (it could take a couple of years – and there’s a possibility that government could run out of parliamentary time to enact the required legislation), but firms were clearly being encouraged to become more comfortable with data-led supervision and a more exacting environment. It’s a reasonable assumption that the FCA will take a different supervisory approach to the SRA, at least.

A few specific points stood out too: we are likely to see a more targeted enhanced due diligence regime in certain contexts, and the possibility of banks taking a tougher line on pooled accounts and firms’ due diligence around them – which has the potential to create real headaches and transactional bottlenecks.

None of that feels revolutionary in isolation. Taken together, though, it suggests a regulatory environment in which superficial compliance will cease to be of value.

Counterparty sanctions screening is a good example. The final question at the conference drew a clear and definitive answer from the assembled panel: firms should be conducting sanctions checks on counterparties as standard. That’s a significant shift from the approach previously signalled by the SRA. Whatever view one takes of the practicalities, the direction of thought is clear. Sanctions risk is no longer something firms can comfortably push to the margins.

Mazur and the drift of everyday practice

Another important conference theme was the continuing fallout from Mazur.

It’s tempting just to think of this as being purely about litigation teams. But arguably, the impact of Mazur should be a wake-up call, since is about the way firms allow working arrangements to evolve over time. In litigation, the line between support work and reserved legal activity is not always breached through an obvious decision. More often, it is crossed gradually. Role descriptions become outdated. Internal promotions are not matched by a review of practising requirements. People take on more responsibility informally. “Supervised” support work starts to include more legal judgement, more strategy, or more direct control of the matter than anyone originally intended.

That is why this issue applies beyond contentious work. If the underlying concern is drift into reserved activity, firms may need to revisit working arrangements across other reserved areas too, including conveyancing and private client. Many firms have “conveyancers” – technically non-qualified, but often extremely capable. What happens when they are more technically experienced and senior in the business than the solicitor who is supposedly supervising?

Again, the wider point is not really doctrinal. It is operational. Firms may be exposed not because they set out to breach the rules, but because their working practices changed without anyone properly stopping to assess the regulatory consequences.

Companies House reform and ACSPs

The Economic Crime and Corporate Transparency Act changes sit in the same category.

For firms involved in company formations and filing work, ACSP status and the staged introduction of identity verification requirements look likely to become a real operational issue over the next year.

One very interesting practical point emerging from the conference was that most firms have decided against registering as an ACSP and will therefore not be able to verify their client’s identity for Companies House purposes, nor will they be able to file Companies House documents on behalf of their clients. That points to a need for start putting in place outsourcing arrangements, policy positions and training for staff.

It is another example of compliance becoming more embedded in business design. Yes, on the face of it this is just a technical regulatory change – something compliance professionals are used to dealing with. But it is also a question about process, resourcing, service lines and risk appetite.

Culture is no longer a soft subject

Another notable strand running through the conference was the amount of attention given to culture and psychological safety.

Why do regulators care about this? Because it has a direct impact on ethics and doing the right thing. A firm where people do not feel able to ask awkward questions, escalate concerns, admit mistakes or challenge decisions is a firm in which operational compliance will fail sooner or later. It matters not one jot how elegantly drafted the policies were.

The comparisons with healthcare and aviation were telling. The aspiration is not a culture in which nobody makes mistakes. It is a culture in which mistakes and near misses are surfaced and learned from before they become disasters.

Of course, this is where the tension lies. It is easy to talk about openness and “just culture”. It is much harder to create that in a regulated environment where mistakes may still lead to reporting obligations, investigations or personal fear.

This links back directly to AML. The SRA’s own messaging makes clear that technical systems alone are not enough. If fee earners do not feel comfortable asking the “stupid question”, challenging a PEP match, querying an odd source of funds explanation or escalating a concern, then the policy framework will not save the firm.

AI is a governance issue before it is a technology issue

The conference’s treatment of AI also fits neatly into this broader story.

The most interesting discussions were not really about the technology itself. They were about governance, judgment, billing models and professional standards. AI may reduce the time needed for certain legal tasks, but that creates knock-on questions about pricing, trust, over-reliance and the temptation to misdescribe how work was done.

That is a particularly pertinent ethical point in a profession still heavily shaped by time recording. If a task takes five minutes with a system that once took five hours manually, firms need to think carefully about how they explain value, how they record time, and how they avoid the temptation to dishonesty overstate time spent.

Seen that way, AI is not a separate risk universe. It is another setting in which familiar professional risks can materialise: poor ethical judgement, supervision issues, confidentiality breaches, inaccurate output, reduced critical thinking and inappropriate charging practices.

That is why the governance angle is important. The real question is not “are you using AI?” (because the answer is likely to be yes), but “are you using it in a way that preserves judgement and keeps your professional standards intact?”

What firms should take from all this

The easiest mistake would be to see these issues as a disconnected list: AML, sanctions, Mazur, culture, AI. They are not disconnected.

They are all pointing in roughly the same direction. Regulators and representative bodies are increasingly concerned not with whether firms can describe a compliant framework, but with whether they can operate one. That means greater focus on judgement, embedded process, training, leadership, escalation, learning loops and the quality of operational thinking.

For firms, the practical questions are therefore quite simple, even if the answers are not.

  • Do your documents actually guide the people using them?
  • Do your people understand when something is unusual?
  • Do they know when and how to escalate?
  • Are your controls aligned with each other, or do they contradict one another?
  • Do your leaders understand the systems well enough to model the right behaviour?
  • Would someone on the file feel safe asking the awkward question?
  • And if the regulator looked past the paperwork and spent a day in your firm, what would they find?