The document every other AML control is built on — and the one the SRA still finds thin.
If your firm is within scope of the money laundering regulations, you must have a written firm-wide risk assessment. It is not optional, it is not a formality, and it is usually the first document requested when the SRA comes looking.
We review yours, tell you plainly what is missing, and give you what you need to put it right.
The terminology causes more confusion than the requirement does.
If you are unsure whether you have a PFRA, you almost certainly do not.
Your risk assessment is the backbone of the policies, controls and procedures you are required to have under regulations 18 to 21. Everything downstream — your due diligence approach, your training, your monitoring — is supposed to follow from it.
Get it wrong and every control built on top of it inherits the error.
The requirement has been in force since 2017, and the SRA has been clear that some firms still need to familiarise themselves with what regulation 18 actually asks for.
Two failings come up repeatedly:
Not taking account of the SRA's own sectoral risk assessment. Regulation 18(2)(a) requires you to have regard to it. The SRA has recorded a broad concern that firms have not done so. This is an easy finding for an inspector to make and an easy one to avoid.
Insufficient depth. The SRA has acknowledged that the overall quality of firm-wide risk assessments has improved, while noting that many still lack the depth expected. It expects a firm to define what higher risk looks like in its own context — including large or unusually complex transactions — rather than restating generic risk categories.
A risk assessment that would fit any firm in England and Wales is not a risk assessment of your firm.
Sanctions compliance is mandatory, carries strict liability, and moves fast — with organisations and individuals being added almost daily. The SRA is now actively asking firms what steps they take to comply, and we expect it to follow the pattern it set with AML: initial questions first, audits after.
Your sanctions position needs its own risk assessment and its own screening procedure. It is not covered by your AML work.
A remote review of your current risk assessments and policy documents against the requirements as they stand today, with a written report setting out what needs to change. Where you need a document you do not have, a template can be provided and customised from information you supply.
Work is carried out remotely unless separately arranged.
One-off charge, payable up front.
That is the common route to this page — an inspection notice, an audit, a client's due diligence questionnaire, or the SRA's annual return. If you are on a deadline, say so when you contact us and we will tell you honestly whether we can meet it.