
We are regularly reminded that that laundering is a major issue for the UK legal sector, and of the need for firms to have proper checks and safeguards in place – not just to comply with the rules, but to protect the profession’s reputation.
So what happens if your firm is not covered by the Money Laundering Regulations (MLRs)? Which parts of the wider financial crime framework still apply, and what are you supposed to do about them? Plenty of firms play it safe and carry out full AML checks on all clients and matters. Which, to be fair, is a sensible approach. But it is still worth looking more closely at what “out of scope” really means in practice.
What work generally falls within scope?
Scope can be nuanced and depends on the precise service being provided, not simply the label attached to the department or matter. Work that will usually fall within scope includes:
- Conveyancing and commercial property
- Commercial and corporate work
- Transactional work – including the sale and purchase of commodities and business entities
- Trust and company work
- Tax (other than litigation involving His Majesty’s Revenue and Customs or the simple paying of Stamp Duty Land Tax)
- Probate matters where you are managing the assets of the estate under instruction from the executors or as the executor or creating a trust as a part of the surrounding arrangements
However, even if a matter is not in scope, there are still legal and regulatory frameworks that apply.
Proceeds of Crime Act (POCA)
POCA applies to all firms and sets out offences such as concealing, transferring, or possessing criminal property. Liability arises if a firm knows or suspects funds are criminal.
There are some key differences between the MLRs and PoCA:
| POCA | MLRs |
|---|---|
| Applies to all firms | Only apply to firms offering services at a higher risk of money laundering |
| Applies automatically | Require notification to, and approval from, the SRA of specific role holders |
| Sets out the underlying AML offences and defences | Set out regulatory requirements including policies, controls and procedures |
| Applies to money, heritable or moveable property, intangible or incorporeal property | Apply by reference to the services being provided, rather than simply whether money is being received for fees or held as client money |
| How firms comply with the Act is up to them | Create a mandatory framework with minimum requirements |
So even if your firm is not covered by the MLRs, it must still comply with POCA and implement effective systems to detect and prevent money laundering.
Suspicious Activity Reporting
If your firm isn’t covered by the MLRs, you don’t have to officially appoint a Money Laundering Reporting Officer (MLRO), though it is recommended by the SRA. Even if you don’t appoint an MLRO, you still need solid checks and systems to spot and stop money laundering, just like firms that are regulated under the MLRs. If you think something is not quite right and there’s no MLRO, you can still send a report straight to the NCA using their online portal.
Just like in the regulated sector, if you know or suspect money laundering, you need to think carefully about disclosure obligations. However, the position is not exactly the same in every case, and the specific failure to disclose offences depend on whether you are operating in the regulated sector and, if so, in what capacity.
As ever, this sits alongside the firm’s wider duties of confidentiality and the possibility of legal professional privilege. That means suspicion should be escalated and assessed carefully, rather than assuming that every concern can simply be reported externally.
Tipping off offences
Under section 333A of PoCA, it’s against the law to let someone know they’re the subject of a Suspicious Activity Report (SAR) if the case falls within the regulated sector. However, if your firm falls out of scope of the AML regime, think very carefully before telling someone about a SAR, as it could still break the rules or go against professional standards. Letting someone know about a SAR might also put people and the firm at risk.
On top of that, section 342 of PoCA makes it a crime to do anything that could mess up an investigation. This covers giving away information that could get in the way of investigators, tampering with documents, or letting someone else tamper with paperwork related to the case.
Terrorism Act 2000
We sometimes forget about terrorist financing, but it remains important. It is a criminal offence, and terrorist financing and money laundering can go hand in hand.
Like POCA, the offences are set out in legislation and can apply more broadly than the MLRs. Although the chances of terrorist financing being run through law firms are slim, it is possible, and any attempt should be flagged during the onboarding process.
Sanctions
Sanctions compliance is relevant to all firms providing legal services, regardless of whether they are in scope of the MLRs. So even if your firm is out of scope, it should assess its exposure to sanctions risk, carry out proportionate screening and checks where appropriate, and have procedures in place to halt activity if a sanctioned party is identified. Breaching sanctions can result in severe penalties, including criminal prosecution and substantial fines.
The Criminal Finances Act 2017
The Criminal Finances Act 2017 brought in corporate offences aimed at stopping businesses from failing to prevent the criminal facilitation of tax evasion, and every business — including law firms — has to take this seriously. If someone acting for or on behalf of a law firm criminally facilitates tax evasion, the firm could be in difficulty unless it can show that it had reasonable prevention procedures in place.
So whether or not you are in scope of the MLRs, you need to have clear policies and make sure staff know the signs of tax evasion and what to do about it. That means carrying out proper risk assessments, monitoring transactions, and making sure everyone knows their responsibilities. If you don’t get this right, the firm could face criminal charges, hefty fines, and damage to its reputation. So, in real terms, all firms need to stay sharp, keep records of what they’re doing, and regularly check their compliance processes to keep themselves and their clients safe.
SRA Code of Conduct
Even if the MLRs don’t apply, law firms still have to follow the SRA Code of Conduct. This means you need to know who your clients are and only act on genuine instructions, no matter what type of work you’re doing — even if it’s outside the AML regime. That’s not the same as full client due diligence, which is all about checking and verifying the details a client gives you.
The SRA doesn’t lay out exactly how you should ‘identify your client’, but it does expect firms to have proper systems in place and to keep clear records showing what checks have been done.
The Code says you should identify who you are acting for in relation to any matter. The SRA has made clear that this is not the same as saying full MLR-style verification is required in every out-of-scope matter, but it does mean you should be satisfied that you know who your client is and that anyone instructing you on their behalf is properly authorised to do so. Regulation 28(10) of the MLRs illustrates the sort of issue that arises in in-scope matters, where you must identify and take reasonable measures to verify the identity of a person purporting to act on behalf of a customer.
And don’t forget, rule 5.1 of the SRA Accounts Rules says you should only take client money out of a client account if it’s for the reason you’re holding it in the first place, which is a safeguard against money being passed to criminal third parties, such as damages received in litigation.
How to keep safe
The simplest and safest way is to treat all clients and matters as if they are in scope of the MLRs but, at the very least, you should:
- identify the client
- have some knowledge of the client and the type of work involved
- know whether the instructions are taken from the client in person, online or via third parties
- complete sanctions checks where appropriate
- flag any concerns
- monitor the matter as it progresses for any key changes
- monitor financial transactions


