The policy was reviewed. The problem was it was still wrong.
A recent SRA enforcement decision is a useful reminder that having AML policies and review processes in place is not enough. What matters is whether they are compliant, current and working in practice.
Haworth & Gallagher was fined £25,000 in August after admitting a series of anti-money laundering failures stretching from February 2018 to September 2025. The SRA found that the firm had failed to maintain compliant policies, controls and procedures and had deficiencies in its client and matter risk assessments. During the investigation, the firm identified a further 89 live files within the scope of the Money Laundering Regulations on which no client and matter risk assessment had been completed.
No evidence of actual consumer or third-party harm was found. That did not prevent enforcement. In the SRA’s view, the deficiencies left the firm exposed to a real and ongoing risk of money laundering.
For compliance officers and law firm leaders, the most instructive part of the decision is buried a little deeper. The firm had AML policies. It had a client and matter risk assessment process. Its policies had even been reviewed and updated on a yearly basis. The problem was that successive versions remained non-compliant.
That distinction matters because areview is not the same as assurance. Regulation 19 of the Money Laundering Regulations requires firms not simply to establish AML policies, controls and procedures, but to maintain them and regularly review and update them. It is tempting to translate that into a recurring diary entry: annual AML policy review, complete, move on.
The Haworth & Gallagher decision is a useful warning against that approach. A policy can be reviewed every year and still fail to meet the regulatory requirement if the exercise does not identify deficiencies, respond to developments in law and regulatory guidance, or test whether the controls described in the document are actually operating in practice.
For senior management, the question therefore should not be: “When was our AML policy last reviewed?” It should be: “What evidence do we have that the review established that our controls remain compliant and effective?”
A meaningful review should consider changes to legislation and SRA guidance, the firm’s own risk profile and client workload, findings from file reviews, internal breaches or near misses, and any changes in client behaviour. It should also test whether written procedures bear any resemblance to what fee earners actually do. If the policy says every in-scope matter receives a documented risk assessment, sampling should tell you whether that is true.
Look beyond the existence of the form
The second lesson concerns client and matter risk assessments. The SRA has been explicit that these are not administrative decoration. They are intended to determine the level of due diligence required and, where appropriate, identify when enhanced due diligence and additional monitoring are necessary.
In Haworth & Gallagher’s case, the existence of a CMRA process counted in the firm’s favour to an extent. But the process did not prevent 89 additional live matters being identified without a CMRA. This is where firms need to distinguish between control design and control effectiveness.
A beautifully drafted procedure demonstrates that a control has been designed. It does not demonstrate that anyone follows it. For MLROs and compliance teams, that means assurance should extend beyond checking that a form exists. File sampling should ask whether the assessment was completed at the appropriate time, whether the risk rating makes sense, whether the reasoning is recorded and whether the resulting due diligence is consistent with the risks identified.
A page containing three ticks and the word “low” is unlikely to tell a regulator much about how a solicitor reached that conclusion.
Compliance needs a feedback loop
There is a broader governance lesson here too. Regulatory guidance, firm-wide risk assessments, matter-level risk assessments, training, file reviews and policies should not exist as separate compliance workstreams. They should inform one another.
If file reviews repeatedly identify weak source-of-funds enquiries, that should feed into training and potentially the firm’s procedures. If the firm’s work profile changes, the firm-wide risk assessment should change. If the firm-wide assessment changes, matter-level controls may need to change with it.
And if new SRA guidance or warning notices identify a weakness that resembles something in your own processes, somebody needs to ask whether the existing policy still stands up.
The SRA said the Haworth & Gallagher breach arose from insufficient regard being paid to the Money Laundering Regulations, published guidance and SRA warning notices. That is a useful reminder that maintaining a compliant framework means looking outward as well as inward.
No money needs to be laundered for there to be a problem
Perhaps the most important point for law firms to note is that AML enforcement does not depend on the regulator finding a money launderer in the client account. There was no evidence of actual harm in this case. Haworth & Gallagher did not financially benefit from the misconduct and its cooperation and remediation were taken into account when the penalty was set.
Yet the fine still reached £25,000. The regulatory concern is the exposure created by ineffective systems themselves. In other words, the absence of a bad outcome is not proof that the controls were good.
That makes AML assurance a leadership issue, not merely an MLRO problem.
Law firm leaders do not need to reperform every file review or become specialists in Regulation 28. They do, however, need sufficient management information to understand whether their firm’s AML framework works outside the compliance manual.
The useful questions are relatively simple. Are exceptions being identified? What themes emerge from file audits? Are the same weaknesses recurring? How quickly are remedial actions closed? Can the firm demonstrate why its controls remain appropriate to its current risk profile?
And, crucially, when the annual policy review comes round, can the person signing it explain what was actually tested?
Because the lesson from recent SRA enforcement is not that firms need more policies. It is that a policy can be reviewed, updated and neatly filed away every year and still be wrong.
The regulator is increasingly interested in what happens after the document is approved. Law firms should be too.soning, consistent processes and proper documentation are in a far more defensible position should they be scrutinised.
