SRA investigations audits enforcement webinar

When the SRA contacts a firm, the first reaction is often heart-pounding anxiety. That is understandable. A letter or email from the regulator can feel loaded with peril, even where it is not accusing the firm of wrongdoing.

That was the central theme of our recent JBL Compliance webinar, When the SRA comes knocking: audits, investigations and what happens next. The session looked at the different ways firms may encounter the SRA, what may be happening behind the scenes, what tends to make matters escalate, and how firms can respond in a calm, organised and evidence-led way.

SRA contact is serious, but it is not automatically catastrophic. The JBL panel’s view was that firms are usually best served by understanding what type of contact they are dealing with, engaging constructively and showing that any issue has been understood and addressed. The webinar also reflected a wider shift in regulatory mood: SRA contact may become more common as the regulator moves towards more structured and proactive supervision, including the creation of senior supervision roles.

Why firms may hear from the SRA

One of the first points made in the discussion was that not all SRA contact is the same.

Liz Bond explained that contact broadly falls into different categories. Some contact is supervisory or thematic. That might involve information gathering about compliance in a particular area, looking for examples of good and poor practice, or identifying issues before they become serious. Other contact is more clearly investigatory, usually triggered by a complaint, a report from another regulator, or a self-report by the firm. A third category involves higher-risk forensic investigation work, often where there are serious concerns about client money, fraud, misappropriation or accounts rules compliance.

That distinction is noteworthy. A firm selected for an AML desk-based review or thematic exercise is not in the same position as a firm receiving a letter saying that a specific complaint is being investigated. The language of the initial letter can provide clues. Is the SRA asking for general policies, statistics and compliance documents? Or is it asking for a specific file, explanation or response to a defined allegation?

That said, even a general supervisory exercise needs careful handling. Liz noted that if the SRA asks for something broad, such as policies or information about residual balances, the firm still needs to be able to provide a proper response. A poor or delayed response may itself cause the matter to take a different route.

The panel also discussed how one form of contact can lead to another. The example was given of accountant’s report spot-check work, where a survey of 600 firms identified instances where firms had failed to engage accountants or had submitted reports significantly late, leading to regulatory investigation.

AML as the obvious starting point

AML reviews are now one of the most common ways firms encounter the SRA.

Ed Marshall made the point that firms in scope of the Money Laundering Regulations should expect, at some point, either an on-site visit or desk-based review of their AML policies and procedures. The important point for firms is preparation. If the SRA asks for policies, procedures and supporting records, the firm needs to be able to produce them. If it cannot, a relatively routine review can lead to a more reactive investigation, with deeper scrutiny of files and practice.

The panel was also careful to challenge a common assumption: that firms are being personally targeted. Ed’s experience at the SRA was that AML engagement was not based on a hidden “hit list”. The process involved firms in scope being worked through, with conveyancing and larger firms prioritised initially, and other firms following in due course.

The broader point is that firms should not wait for the letter before asking whether they could evidence their AML controls. The SRA will not be satisfied by attractive documents alone. If the policies are not being applied in practice, the paper trail may make the firm look worse rather than better.

The return of supervision?

A striking theme was the possibility of more proactive SRA supervision.

Sean Hankin suggested that increased engagement with firms is likely, as the SRA seeks to identify risks earlier and avoid situations such as Axiom Ince, SSB and PM Law becoming larger regulatory failures. The aim, as discussed in the webinar, would be to build a clearer picture of firms, the work they undertake and the risks that arise from that work.

Sophie Cisler raised the cultural challenge this creates. Other regulators have long used proactive visits that are closer to a regulatory check-in or “MOT”, where the regulator looks at systems, gives guidance and identifies improvements. The difficulty for the legal profession is that many firms still experience SRA contact as frightening or adversarial. A shift towards more supervision and guidance would require a change in mindset on both sides.

There was also an interesting historical point. The SRA, or its predecessor arrangements under the Law Society, previously had a Practice Standards Unit that undertook more proactive visits. Ed recalled that many firms were anxious before those visits, but relieved afterwards where the outcome was practical guidance rather than enforcement. In that sense, a more active supervision model would not be entirely new.

What happens behind the scenes?

From the outside, the SRA can appear impenetrable. One useful part of the webinar was the explanation of what may happen internally when a report is made.

Sean explained that reports initially go through triage and the Assessment and Early Resolution Team. Historically, he said, the SRA applied an assessment threshold test looking at whether there was a potential breach, whether it would be serious enough to justify action if proved, and whether there was enough evidence. More recently, the test had been adapted into five broad aspects: seriousness, intent and motivation, harm and impact, patterns or systemic risks, and insight and remediation.

Those factors are highly practical for firms. They show what the regulator is likely to be looking for:

  • Was this serious?
  • Was it deliberate, reckless or a genuine mistake?
  • Was there harm to clients, the public or the administration of justice?
  • Is this isolated, or part of a pattern?
  • Has the firm shown insight and taken remedial action?

Not every report passes that threshold. Many cases close with no further action. The examples discussed included service issues more properly dealt with by the Legal Ombudsman, complaints unsupported by material evidence, minor or technical self-reported breaches, matters outside the SRA’s jurisdiction, and private legal disputes.

Where matters do progress, they may follow a desk-based route or a forensic investigation route. Desk-based investigations may involve the SRA calling for a file and corresponding remotely. Forensic investigations are more likely where client money is at risk, the accounts rules are central, large volumes of material need to be reviewed, or interviews and witness statements are required.

Why client money remains such a red flag

The panel repeatedly returned to client money.

Sean noted that some of the most serious SDT cases, particularly those involving strike-off, are often linked to client money. That is unsurprising. Client money is one of the areas where the public places the highest degree of trust in solicitors. If client money is misused, or there is a client account shortage, the firm may effectively be using one client’s money to support another client’s position. The longer that continues, the harder it can be to recover the position.

That does not mean every accounts issue will result in severe action. But where client money is at risk, the regulator is likely to treat the matter as inherently serious.

The Enforcement Strategy should not be an afterthought

Another strong message was that firms should understand the SRA Enforcement Strategy before they ever need it.

Ed described the Enforcement Strategy as the document that was open on his screen every time he had an investigation. It helped him assess aggravating and mitigating factors: harm and impact, whether there had been human error, whether the issue was a one-off, whether the firm had apologised, and whether the firm had improved its processes.

For firms, this is not an academic document. It tells you what the SRA is likely to judge you against. If a response can properly show that an issue was isolated, that no real harm occurred, that the firm has apologised where appropriate, and that procedures have been improved, the firm gives the investigator material that may support a more proportionate outcome.

The same point applies to constructive engagement. Sean highlighted that silence is dangerous. If a firm needs more time, it should say so and explain why. Simply failing to respond may cause the investigator to wonder whether the firm is hiding something, whether there are wider issues, or whether the firm does not take its regulatory obligations seriously.

How to set the right tone

The panel discussed the tone firms should take in correspondence with the SRA. The consensus was that firms should be professional, constructive and clear.

This is not about being submissive. Firms are entitled to explain, clarify and, where appropriate, disagree. But being unnecessarily combative rarely helps. Sophie suggested that firms should try to understand the SRA’s concerns, address them properly and work towards de-escalation.

There was also a useful warning against becoming too narrow. If the SRA asks ten questions, the firm should answer those questions. But if there is additional information that properly explains the position, the firm should consider providing it. Sean’s point was that the firm should not restrict itself so tightly that it withholds helpful context that could assist the investigator in reaching a swift conclusion.

At the same time, that does not mean flooding the SRA with irrelevant material. The better approach is to be complete, organised and targeted. Give the regulator what it needs to understand the position, but do so in a controlled way.

Deadlines are serious, but not always immovable

The panel also discussed response deadlines. Ed explained that an initial investigation letter may commonly ask for a response within 14 days. There can be flexibility, particularly at the start of a matter, if the firm needs a short extension for a good reason.

The practical lesson is simple: ask early, explain properly and do not let the deadline drift. A justified request for a short extension is very different from silence, delay or repeated procrastination.

That distinction becomes even more important where the SRA uses formal information-gathering powers, such as a section 44B notice. Liz noted that where the SRA asks for information under such powers and gives a deadline, firms should take particular care to respond properly and on time.

Dentons, AML breaches and misconduct

The webinar also touched on the recent Dentons AML case, although the panel was careful not to overstate its significance.

Sophie explained that the case raises an important question: does an AML breach automatically amount to professional misconduct? The answer from the recent decision, as discussed in the webinar, appears to be no. There is no automatic relationship. But Sophie was also clear that firms should not take the wrong message from this. AML breaches remain serious, and in some cases an AML breach may properly support a misconduct finding depending on the facts.

There was nuance here. Where AML obligations are risk-based, there may be room to argue about whether there has been a breach at all. If the alleged technical breach is not made out, the misconduct allegation may fall away. But the panel warned against a lazy conclusion that AML breaches are “only firm-level issues” or that individuals do not need to take personal responsibility.

The discussion also linked Dentons to regulatory settlement agreements. Sophie noted that some significant AML fines have arisen through RSAs, and that firms should not be too quick to sign without advice. Jonathon observed that RSAs can feel like “agreements” in quotation marks, because many firms feel they have little practical choice. The lesson is not that firms should be aggressive. It is that they should understand what is being alleged, whether the alleged breach is accepted, whether misconduct is properly made out, and whether the terms of any RSA are appropriate.

Getting advice is not an admission of guilt

One of the clearest practical points came from Liz: getting external advice does not make a firm look guilty.

In fact, the panel’s view was that it can help both sides. External advice may provide perspective, reduce tension, help the firm structure its response, avoid pitfalls and keep information flowing. From the SRA’s perspective, a good adviser can act as a constructive buffer and help produce a more organised response.

This is particularly relevant where the issue involves possible dishonesty, client money, AML enforcement, senior people, regulatory settlement agreements, potential SDT referral or complex privilege questions. But the wider point applies to many SRA interactions: a fresh pair of eyes can help the firm take a breath and avoid making the position worse.

Possible outcomes

The possible outcomes of a “successful” prosecution range from no further action through to intervention and strike-offs.

Sean explained that over 90% of reports end up with no further action. Where action is taken, the possible outcomes may include advice or guidance, warnings, rebukes, fines, practising certificate conditions, regulatory settlement agreements, referral to the Solicitors Disciplinary Tribunal and, in the most serious cases, intervention into the firm. These outcomes are not always mutually exclusive.

The discussion also made the point that public record consequences can be important. Even where a sanction is not at the most serious end of the spectrum, a published outcome may have reputational and professional consequences for the firm or individuals involved.

What firms should do if the SRA contacts them

The practical framework is not complicated, but it does require discipline.

The firm should first identify what kind of contact it has received. Is it supervisory, thematic, AML-related, complaint-driven, forensic or part of a formal investigation? The answer affects both urgency and strategy.

Next, someone senior should take control. The panel noted in the preparation discussion that it can be helpful for a senior person who is not directly connected with the underlying matter to coordinate the response, giving the process as much internal independence as possible.

The firm should preserve relevant documents, files, emails, ledgers, policies, risk assessments, attendance notes and internal communications. It must not retrospectively create documents to fill gaps. If something does not exist, the better course is to be honest about that and explain what has been done to address the issue.

The firm should also undertake a proportionate internal investigation before responding. “Promptly” does not mean firing off an incomplete answer before anyone understands what happened. It means dealing with the matter quickly, seriously and with enough care to provide a proper response.

Finally, the response should be evidence-led. Frms are not protected simply because they have “fantastic shiny policies”. The SRA wants to see what happens in practice.

Practical takeaways

If the SRA contacts your firm:

  • Read the letter carefully and identify what type of contact it is.
  • Diary the deadline immediately.
  • Appoint one senior person to coordinate the response.
  • Identify relevant files, emails, attendance notes, ledgers and compliance records.
  • Do a short internal investigation before responding.
  • Ask for an extension early if one is genuinely needed.
  • Respond constructively, not defensively.
  • Do not ignore the SRA, delay without explanation or drip-feed incomplete answers.
  • Do not create documents retrospectively.
  • Use the SRA Enforcement Strategy to understand aggravating and mitigating factors.
  • Be honest about gaps, but explain context and remediation.
  • Get external advice where the issue is serious, complex or personally sensitive.

JBL Compliance helps firms prepare for and respond to SRA contact, including AML reviews, regulatory enquiries, self-reports, remediation plans and compliance systems reviews. The best time to put those arrangements in order is before the SRA comes knocking.

The recording of this webinar is available to COLP Insider subscribers.