AML resources · UK law firms

The rules, in one place.

A short, honest map of the law and guidance that shapes client due diligence for solicitors — what each instrument covers, in plain sentences, with a link to the real source. This page describes the rules; it doesn't interpret them for your firm, and it isn't legal advice.

The Money Laundering Regulations 2017

Statutory instrument · SI 2017/692, as amended

The MLR 2017 is the core UK statute for anti-money-laundering compliance. For a law firm carrying out "relevant business" — conveyancing, company formation, trust and estate work, and more — it sets out the standing duties: a firm-wide risk assessment, written policies and controls, a nominated officer, staff training, customer due diligence at onboarding, and ongoing monitoring of the relationship for as long as it lasts.

Read the source on legislation.gov.uk →

↑ Back to top

Ongoing monitoring — Regulation 28(11)

MLR 2017, regulation 28(11)

Client due diligence doesn't end at onboarding. Regulation 28(11) requires firms to keep the documents, data or information held for due diligence up to date, and to monitor the business relationship on an ongoing, risk-sensitive basis — including scrutiny of transactions to check they're consistent with what the firm knows about the client. A dated record that a re-check found "no change" is itself the evidence an inspector is looking for; a re-screen that never runs, or never gets logged, is the gap that shows up first.

Read regulation 28 on legislation.gov.uk →

↑ Back to top

The SRA's AML supervisory role

Solicitors Regulation Authority

The SRA is the anti-money-laundering supervisor for solicitors and law firms in England and Wales under the MLR 2017. It publishes a sectoral risk assessment setting out where money-laundering risk concentrates in legal practice (conveyancing and company/trust work feature prominently), runs AML supervision visits and thematic reviews, and can take enforcement action — from a warning through to a fine or a firm's authorisation being affected — where a firm's systems and controls fall short.

Read the SRA's AML guidance →

↑ Back to top

LSAG guidance

Legal Sector Affinity Group

The Legal Sector Affinity Group — the legal-sector AML supervisors and professional bodies acting together — publishes detailed, Treasury-approved guidance on applying the MLR 2017 in legal practice: how to build a risk assessment, what due diligence looks like case by case, and how ongoing monitoring should work in a firm of any size. It's the sector's own reference for turning the regulations into a working policy.

Read the LSAG guidance →

We also publish a section-by-section mapping of what a FirmGuard check gives you under the April 2025 guidance — built to be filed as the EID&V tool documentation the guidance's Technology principles ask for. Read the LSAG mapping →

↑ Back to top

The UK sanctions regime

OFSI · the UK Sanctions List

Separately from AML due diligence, UK financial sanctions law prohibits dealing with the funds or assets of designated persons and entities. The Office of Financial Sanctions Implementation (OFSI) maintains the UK Sanctions List and the OFSI consolidated list of financial-sanctions targets — the register FirmGuard's screening checks against, alongside FCDO, OFAC and UN designations, refreshed daily.

Read the OFSI consolidated list on GOV.UK →

↑ Back to top

POCA — disclosure and tipping-off

Proceeds of Crime Act 2002, sections 330 & 333A

Section 330 of the Proceeds of Crime Act 2002 makes it an offence for a person in the regulated sector to fail to disclose knowledge or suspicion of money laundering to the firm's nominated officer or the National Crime Agency. Section 333A separately makes it an offence to "tip off" a client or third party in a way that's likely to prejudice an investigation once a disclosure has been made or is being considered — which is why FirmGuard's SAR workflow carries an explicit tipping-off warning at the point of escalation.

Read Part 7 of POCA on legislation.gov.uk →

↑ Back to top

See it against your own client file.

Run your first 50 checks free, no card — the audit pack it produces is the same one an inspector would ask to see.

Start free — 50 checks on us