AML Risk Appetite Statement for UK Law Firms

AML Risk Appetite Statement for UK Law Firms with Lady Justice statue and courtroom background

AML risk appetite statement law firms in the UK: This guide is for MLROs, compliance officers, managing partners, and risk leads at SRA-regulated law firms in England and Wales. You will learn what an AML risk appetite statement must contain under the Money Laundering Regulations 2017, how it connects to your firm-wide risk assessment, and how to build a statement that satisfies SRA inspection criteria and genuinely guides your firm’s client intake decisions.

Introduction

The SRA carried out 935 proactive AML engagements in the year to April 2025. Almost a third of firms were assessed as non-compliant; a further 54% were only partially compliant. The single largest driver of referrals: client and matter risk assessments that either did not exist or failed to evaluate money laundering risk. At the root of most failures was the same problem: firms had not clearly defined their risk appetite, leaving fee earners without a consistent benchmark for client and matter decisions.

An AML risk appetite statement fixes this. It is a written declaration of the ML/TF risk your firm will accept, defining which clients, matters, and geographies are in scope, which require enhanced scrutiny, and which the firm will not accept. Without it, your firm-wide risk assessment lacks an anchor.

Regulatory Framework

MLR 2017 (Regulations 18 and 19) requires in-scope firms to document a firmwide risk assessment and implement risk-based policies and controls. The risk appetite statement sits at the centre of both obligations.

The SRA’s Sectoral Risk Assessment (updated 31 July 2025) must be incorporated into every firm’s FWRA. It identifies legal sector ML/TF risk as remaining high, with particular vulnerabilities in conveyancing, corporate transactions, trust and company services, and client account management. The NCA’s March 2026 strategic assessment confirmed that serious and organized crime threats increased in 2025, a context that firms must reflect in their risk position.

The LSAG AML Guidance (HM Treasury approved, effective 23 April 2025) is the authoritative sector reference. SRA inspectors use it as their primary inspection framework; Section 2.5 sets out FWRA requirements, including risk appetite documentation.

FCA single supervisor trajectory: Legal and accountancy firms are expected to move under the FCA as a single AML supervisor. Firms building evidence-based risk appetite statements now are investing in infrastructure compatible with FCA-standard programme expectations.

AML Risk Appetite Statement Template

Statement SectionRequired Content
1. Purpose and ScopePractice areas, offices, and matter types covered; legal basis (MLR 2017 Reg. 18–19; LSAG Guidance 2025).
2. Overall Risk AppetiteThe firm’s general position: e.g., “We adopt a low-to-medium ML/TF risk appetite. We will not act where identified risk cannot be adequately mitigated.”
3. Client Risk AppetiteAcceptable client types (by entity type, jurisdiction, PEP status); clients requiring enhanced scrutiny; absolute exclusions.
4. Matter/Transaction Risk AppetiteAcceptable transaction types and value thresholds; matters requiring EDD or senior sign-off; matters the firm will not accept.
5. Geographic Risk AppetiteApproach to FATF high-risk jurisdictions; internal threshold for automatic EDD triggering.
6. Source of Funds / WealthThreshold for source of funds verification; approach where source cannot be verified; escalation pathway.
7. PEP PolicyDomestic PEPs (lower starting risk since January 2024); non-domestic PEPs; PEP associates; senior management sign-off requirements.
8. Escalation and ExceptionsWho approves exceptions, documentation required, and how exceptions are recorded and reviewed.
9. Review CycleAnnual minimum; triggers for out-of-cycle review (new SRA sectoral update, material change in practice or client base).

Key Best Practices

âś… Make the statement specific to your practice: The SRA has found generic templates that do not reflect a firm’s actual profile to be non-compliant. A conveyancing practice must address conveyancing-specific ML/TF risks explicitly.
âś… Distinguish absolute exclusions from enhanced scrutiny cases: A statement that only lists what the firm will not do does not guide the large middle ground where risk can be managed with the right controls.
âś… Align your PEP policy with the January 2024 domestic PEP change: Domestic PEPs now carry a lower starting risk than non-domestic PEPs. Your EDD procedures must reflect this distinction.
âś… Reference the July 2025 SRA Sectoral Risk Assessment explicitly: The SRA expects firms to incorporate it into their FWRA; citing it demonstrates an evidence-based, up-to-date approach.

Frequently Asked Questions

Is a risk appetite statement legally required for UK law firms?

Not by that exact name, but Regulation 18 MLR 2017 requires every in-scope firm to document a firm-wide risk assessment, and the SRA’s guidance explicitly states this must record the firm’s risk appetite. The SRA expects to see a clear written risk appetite position in every FWRA it reviews. Firms that cannot demonstrate one are consistently assessed as non-compliant.

How does the risk appetite statement relate to client and matter risk assessments?

The risk appetite statement is a firm-level policy; client and matter risk assessments are the transaction-level application of that policy. The SRA’s 2024-25 AML report found that client/matter assessments consistently failed because they were disconnected from the firm’s overall risk position, the exact gap the risk appetite statement closes.

How often should the risk appetite statement be reviewed?

At minimum annually, and whenever the SRA publishes a new sectoral assessment, the LSAG Guidance is updated, or there is a material change in the firm’s practice areas, client base, or geographic exposure.

How does Cascade support AML risk management for UK law firms?

Cascade can support UK law firms with AML risk management by centralising KYC/CDD information, client risk assessment, name screening, alert workflows, ongoing reviews and compliance records within its AML Software (SaaS Platform).

Which data providers does Cascade integrate with for sanctions and PEP screening?

Cascade integrates with three leading screening data providers: Acuris Risk Intelligence, LSEG World-Check, formerly Refinitiv World-Check, and Dow Jones. These integrations support screening for sanctions, PEPs, adverse media and other watchlist or regulatory risk data within Cascade’s AML/KYC workflows.

Cascade’s AML Capabilities for UK Law Firms

Cascade’s AML Software (SaaS Platform) supports UK law firms with KYC/CDD, client risk assessment, name screening, AML workflows, ongoing reviews and compliance reporting.

Its add-on modules extend the platform with automated treatment of name-screening alerts, digital communication for client onboarding, and AML reporting and analytics. These modules require the core AML Software platform.

Explore Cascade’s compliance workflow capabilities →

Disclaimer
This article is for general informational purposes only and reflects publicly available sources at the time of writing, including the Money Laundering Regulations 2017, SRA guidance, and the LSAG AML Guidance for the Legal Sector 2025. AML requirements, SRA supervisory expectations, and enforcement priorities change regularly. The template and framework provided here are illustrative starting points and do not constitute legal or professional advice. SRA-regulated law firms should assess their specific circumstances and consult qualified legal and compliance counsel before implementing any AML risk appetite statement or firm-wide risk assessment. Cascade makes no representation that this content reflects current regulatory requirements or that its use will ensure regulatory compliance.

Ready to Get Started?

Empower your compliance with the leading end-to-end AML KYC platform Cascade