
The SRA is trying to solve a real problem.
Few people in the profession would argue against stronger protection for client money. Nor would many disagree with the broad lesson emerging from Axiom Ince: where too much power is concentrated in too few hands, and where internal challenge is absent, the risks to clients can be severe.
The SRA’s latest changes to the Authorisation of Firms Rules, which are still subject to LSB approval, need to be understood in that context. They are part of a wider package of reforms intended to strengthen safeguards around client money, improve oversight, and create better checks and balances within firms.
The aim is laudable. The question is whether the mechanism will work.
A near-term answer to a deeper problem
The SRA’s consultation response acknowledges that there are bigger questions still to be answered about whether the current model of solicitors holding client money remains fit for purpose. Those questions are complex and will not be resolved quickly.
So the new rules are, in effect, a near-term intervention. They are designed to reduce risk under the current system while more fundamental issues remain under review.
Of course, interim measures still need to operate sensibly in real firms. Otherwise, the profession will end up with rules that look attractive in policy terms but create additional pain points, uncertainty and unintended consequences.
What the draft rules actually say
The draft Authorisation of Firms Rules do not simply say that a sole owner cannot be a COLP or COFA.
For firms with more than one manager (partners, directors) or owner (shareholders, equity partners), the proposed rule applies where the firm, in its most recently completed accounting period, either:
- had annual turnover of more than £600,000; or
- held or received client money exceeding £2 million.
Where one of those thresholds is met, an individual cannot be designated as COLP or COFA if they are a manager or owner who has authority, whether under the firm’s constitution, governance arrangements or usual practice, to determine or direct significant management decisions relating to the structure or running of the firm.
For sole owner-manager firms, the position is different. If the sole owner-manager firm has annual turnover of more than £600,000, the sole owner-manager cannot be designated as either COLP or COFA.
If the firm is below that turnover threshold but exceeds the £2 million client money threshold, the sole owner-manager cannot be COFA, but can remain COLP.
There is also an exemption for certain firms that exceed the client money threshold because of anomalous transactions which are not representative of their usual or expected business activities (e.g. a one-off big settlement).
That is a more nuanced position than the original consultation proposal. The SRA has also increased the client money threshold from the originally proposed £500,000 to £2 million, which is a significant shift and shows that consultation feedback has had an impact.
But some very important practical questions remain.
The risk of separating titles, not power
The SRA’s underlying concern is easy to understand. Compliance officers are supposed to provide oversight. They must be able to identify, record and report serious breaches. If the same person who makes the most significant decisions is also responsible for overseeing the compliance of those decisions, there is an obvious risk that the safeguard becomes weaker.
That logic is sound. But the proposed rules raise a difficult question: does changing the identity of the COLP or COFA necessarily create meaningful challenge?
In some firms, it may. In others, it may simply move the title to someone less powerful, less informed and less able to influence behaviour.
That point came through strongly in the consultation response. Several respondents questioned whether a more junior or subordinate compliance officer would really be in a position to challenge a dominant owner or senior manager. The risk is that the rule separates the formal role, but not the real power.
Why is that important? Good governance is not just about who holds which title. It is about whether decisions can be challenged, whether concerns can be escalated, whether financial controls are genuinely independent, and whether the culture of the firm allows the compliance function to operate properly.
A firm could have separate role-holders and still have poor governance.
Another firm could have an owner-manager as COLP or COFA but strong systems, transparent reporting, external accountancy oversight, independent file review, and a culture where compliance issues are confronted rather than hidden.
The rule assumes that separation creates challenge. That may be true in many cases. It is not automatically true in all of them.
The owner-managed firm problem
The hardest cases are likely to be owner-managed firms just above the turnover threshold.
Take a firm with annual turnover of £650,000. It may be profitable, well run and highly regarded. But it may not have the internal management structure of a larger practice. The owner may be the person with the deepest understanding of the firm’s systems, accounts, people, clients and risks.
Under the draft rules, if that firm is a sole owner-manager firm, the owner could not be COLP or COFA.
That may create a serious recruitment problem.
Experienced COLPs and COFAs are not easy to find. These are personal regulatory roles. They require sufficient seniority, sufficient responsibility, technical competence, confidence, and a willingness to accept exposure if things go wrong.
For many smaller firms, there may be no obvious internal candidate. Recruiting externally is possible, but it will not be cheap. Nor is it always realistic to expect an experienced compliance professional to join a small owner-managed firm, take on personal regulatory responsibility, but have no equity, no partnership status and potentially limited influence over the person who ultimately controls the business. It also arguably places a ceiling on that person’s career progression: who’s going to want to take on such a serious role if they’re being told, in effect, that you’ll never be able to be part of the senior management more broadly?
Good luck recruiting that person at a sensible price. The risk here is that we move away from what the SRA has always expected from the compliance officers – senior, experienced, competent and committed people to people who are more junior, less experienced and, bluntly, less up to the job.
And what happens if the firm cannot find them, whether experienced or not?
That is not a rhetorical question. Regulatory rules usually assume compliance is within the firm’s control. Recruitment markets are not.
A firm can decide to amend its policies. It can decide to improve its reconciliations. It can decide to commission an external review. But it cannot simply decide that a suitably experienced, affordable, willing COLP or COFA exists. We regularly get asked if one of our team can “be” the COLP for either a new firm or where a vacancy has arisen. The message is clear: people who can do these jobs, and do them well, are thin on the ground.
The drafting creates uncertainty
The final drafting also places a considerable interpretive burden on firms with more than one manager or owner.
The key wording is whether the individual has authority, under the constitution, governance arrangements or usual practice, to determine or direct significant management decisions relating to the structure or running of the firm.
That may be clear in some organisations. It will be much less clear in others.
Many firms operate through a mixture of formal documents, informal habits, inherited leadership structures and practical reality. The LLP agreement may say one thing. The management board terms of reference may say another. The way decisions are actually made may be different again. And sometimes, it’s only when there’s a major disagreement that any lack of clarity is addressed.
What counts as a “significant management decision”?
Does it include hiring and firing senior staff? Opening a new office? Changing bank mandates? Approving budgets? Taking on a new work type? Setting drawings? Agreeing insurance arrangements? Changing the firm’s approach to client account?
And what does it mean to “direct” such a decision?
The drafting is clearly aimed at individuals who can control major decisions about the firm. But in many partnerships and LLPs, influence is distributed unevenly. Some partners may have strong practical influence without formal unilateral power. Some may have formal voting rights but little day-to-day involvement. Some may lead departments whose decisions materially affect risk.
The SRA says it will not prescribe exactly how firms comply and that firms may be able to adjust governance or decision-making arrangements so existing role-holders remain eligible. That flexibility is welcome.
But it also means firms will need to form their own view on eligibility. Some will do that confidently. Others will want advice. Some will take an unnecessarily cautious view. Others may get it wrong.
That uncertainty is not ideal when the consequence is that a person’s approval as COLP or COFA may expire once they cease to be eligible.
Could governance have been a better route?
One of the more constructive points in the consultation response was the suggestion that the SRA could recognise alternative safeguards.
That feels like a missed opportunity.
If the real concern is unilateral control, the rules could focus more directly on preventing unilateral action in high-risk areas. For example, firms could be required to demonstrate:
- properly documented governance arrangements;
- dual authorisation for client account transfers above defined limits;
- independent oversight of residual balances and suspense accounts;
- regular reporting to a management board or compliance committee;
- a deputy COLP or COFA with real authority;
- external review of client account controls; and
- evidence that no single individual can control key financial or structural decisions without challenge.
Those safeguards may be more closely connected to the actual risk.
They also recognise that firms differ enormously. A high street practice, a regional LLP, a national volume firm and a private equity-backed ABS may all hold client money, but their governance realities are very different.
A single structural role-holder rule may be too blunt to reflect that variety.
The rise of fractional COLPs and COFAs?
One likely market consequence is an increase in outsourced or fractional COLP and COFA arrangements.
That may be unavoidable because some firms will have no realistic internal option. Others may decide that buying in an experienced external role-holder is easier than changing their ownership or management structure.
There is nothing inherently wrong with that. A good external COFA or COLP can bring independence, expertise and discipline. In some firms, that may be a significant improvement.
But there is a risk that fractional compliance becomes a workaround rather than a governance solution. A compliance officer who is close enough to understand the business, but independent enough to challenge it, can be highly effective. A compliance officer who is too remote from the day-to-day operation may become something closer to an external reviewer with a regulatory title.
The SRA’s policy objective is not simply to ensure that another name appears on the authorisation record. It is to strengthen the firm’s ability to identify, challenge and address risks.
If the rules create a market of external role-holders who are nominally independent but practically dependent on the dominant owner for appointment, information and continued instruction, the governance gain may be limited.
The SRA is right about the problem
None of this means the SRA is wrong to act.
Client money failures cause serious harm: they damage public confidence; they increase pressure on the compensation fund; they create wider costs for the profession and, ultimately, consumers.
The SRA is entitled to ask whether existing governance arrangements provide enough protection where significant sums of client money are held or where firms reach a certain scale.
It is also right to focus on the risk created by concentrated decision-making power.
But the profession is entitled to ask whether the answer lies in a role-separation rule that may be difficult to apply and harder still for some firms to implement, with arguably marginal risk mitigation gains.
Would the next would-be misappropriator of £60m really be put off by a few authorisation rules and notionally split titles? Or would they work around those rules to get what they want, putting in place pliable enablers into those compliance roles?
The SRA wants to prevent excessive concentration of power, which is clearly a legitimate regulatory aim.
The question is whether these rules will actually prevent the concentration of power, or merely require firms to move compliance titles away from the people who hold it, while leaving the rest of the profession to deal with the unintended consequences. Will the rules dilute the power, or will they just dilute the effectiveness and the intention behind the compliance officers regime?


