This guide provides UK law firms and solicitors with a practical client acceptance workflow template covering SRA compliance requirements, decision-making frameworks, risk assessment integration, and implementation steps. You’ll learn how to structure a defensible client acceptance workflow that meets Money Laundering Regulations 2017 (MLR 2017) expectations, supports SRA supervision, and reduces operational friction during client onboarding.
Introduction
A client acceptance workflow that law firms in the UK must establish is more than a formality. The Solicitors Regulation Authority (SRA) expects firms to have documented, operating client acceptance procedures that comply with the Money Laundering Regulations 2017, integrate firm-wide risk assessment findings, and apply consistent decision criteria. SRA desk-based reviews and onsite inspections routinely examine whether client acceptance files demonstrate adequate due diligence performance, risk assessment reasoning, and documented client/matter decision outcomes.
Law firms operating in the scope of the regulations (conveyancing, trust and company services, financial advisory, and real property transactions) must conduct client due diligence at the beginning of each client relationship, assess risk based on the client and the matter, and document the decision to accept or decline. A structured client acceptance workflow ensures consistency, reduces reputational and regulatory risk, and creates the audit trail SRA examiners expect to find.
This resource explains what the regulations require, how to design a client acceptance workflow aligned to SRA expectations, and how to document decisions for examination readiness.
What is a client acceptance workflow for UK law firms?
A client acceptance workflow for law firms in the UK is a structured process for evaluating prospective clients before engagement, determining whether to accept or decline the relationship, and documenting the decision and rationale. The workflow integrates customer due diligence (CDD), risk assessment, screening, and approval steps.
For law firms, client acceptance workflow typically includes client identification and beneficial ownership verification; client risk categorization (low, medium, or high) based on firm-wide risk assessment findings; screening against sanctions, PEPs, and adverse lists; assessment of whether the matter is in scope of MLR 2017; matter-level risk assessment where applicable; approval or decline decision; and documentation in the client file.
This is distinct from general client onboarding. The client acceptance workflow specifically addresses regulatory compliance: confirming you understand who the client is, assessing regulatory and reputational risk, and documenting that decision before work commences. The SRA expects law firms to have written procedures that set out this workflow and to follow them consistently.
Why client acceptance workflow matters for UK law firms
Law firms face specific client acceptance risks. In SRA desk-based reviews and onsite inspections, inadequate client acceptance documentation is frequently cited as a deficiency. Common findings include missing client identification documents, incomplete beneficial ownership information (especially for company clients and trusts), no documented risk assessment, unclear screening evidence, missing approval records, and lack of supporting rationale for acceptance decisions.
These gaps create regulatory exposure. The SRA can issue warnings, require remediation plans, and impose administrative fines (up to ÂŁ25,000 for individual breaches; more serious cases go to the Solicitors Disciplinary Tribunal). Beyond regulatory risk, weak client acceptance creates operational and reputational risk: you may onboard clients later found to pose risk, your firm’s reputation can be damaged by association with money laundering activity, and you may face scrutiny from insurers and financial institutions.
Additionally, Law Society Practice Notes guidance and LSAG Guidance (updated April 2025) emphasise the importance of documented, risk-based client acceptance procedures. Firms demonstrating robust client acceptance workflows perform better during SRA examination and face lower enforcement risk.
SRA regulatory framework for client acceptance
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017), as amended, sets out client acceptance requirements for firms in scope.
Regulation 27-28: Customer due diligence (CDD) Firms must obtain customer identification information, verify identity using reliable documents, identify beneficial owners where applicable (>25% ownership threshold for companies), and obtain information on the purpose and nature of the business relationship.
Regulation 28(12)-(13): Client and matter risk assessment Firms must apply a risk-based approach, assessing risk at the client and matter level. Higher-risk clients warrant enhanced due diligence. Lower-risk clients may have simplified procedures (where applicable).
Regulation 18: Firm-wide risk assessment Firms must maintain a written, regularly updated firm-wide assessment of ML/TF risks. Client acceptance procedures should reference this assessment and apply its findings consistently.
Regulation 19: Policies, controls and procedures (PCPs) Client acceptance procedures must be documented in the firm’s PCPs, approved by management, and monitored for compliance.
LSAG Guidance (2025) The Legal Sector Affinity Group Guidance (approved by HM Treasury, effective 23 April 2025) provides detailed guidance on client acceptance, beneficial ownership identification, and risk assessment. It constitutes official guidance for SRA-regulated firms.
SRA approach: The SRA expects firms to follow a risk-based approach proportionate to firm size, nature, and risk profile. Sole practitioners have fewer formal requirements than larger firms, but all must comply with MLR 2017. The SRA’s supervisory theme on firm AML governance indicates it prioritizes oversight of client acceptance procedures.
Client acceptance workflow process for UK law firms
Implement a structured client acceptance workflow law firms in the UK should follow:
Step 1: Pre-engagement client identification
Collect basic client information: name, contact details, business/occupation, date of birth (individuals), and company registration details (entities). For entities, request organizational documents confirming ownership structure.
Step 2: Beneficial ownership identification
For individual clients, identify the beneficial owner (the client themselves). For company/partnership/trust clients: identify all beneficial owners (>25% ownership threshold). Use company searches (Companies House), trust documentation, or beneficial ownership declarations.
Step 3: Firm-wide risk assessment context
Reference your firm-wide risk assessment. Identify your firm’s overall ML/TF risk profile. Consider whether the client or matter type aligns with higher-risk areas identified in your assessment.
Step 4: Client risk categorisation
Assign a risk rating (low, medium, high) based on client type, jurisdiction, business profile, and source of funds. Document the reasoning. Refer to LSAG Guidance risk factor tables for consistency.
Step 5: Screening
Screen the client and beneficial owners against sanctions lists, PEP databases, and watch lists. Document vendor, screening date, and results. Investigate and document any alerts.
Step 6: Matter scope assessment
Determine whether the matter is in the scope of MLR 2017. If in scope (property transaction, trust administration, company formation, etc.), matter-level risk assessment applies. Document the scope determination.
Step 7: Client acceptance decision
Document your decision: accept or decline. If accepted, note any conditions or enhanced due diligence required. If declined, note the reason.
Client acceptance decision matrix template
Use this template to document client acceptance decisions:
| Client acceptance criterion | Assessment | Risk level | Approval | Comments |
|---|---|---|---|---|
| Client identification | Documents obtained, identity verified | Low/Med/High | Yes/No | Specify doc type (passport, company house extract, etc.) |
| Beneficial ownership | Verified, >25% threshold confirmed | Low/Med/High | Yes/No | Note ownership percentage and chain if complex |
| Screening results | Sanctions/PEP/watch lists checked, alerts investigated | Low/Med/High | Yes/No | Vendor name, date, any alert disposition |
| Firm-wide risk assessment relevance | Client/matter type assessed against firm ML/TF risk profile | Low/Med/High | Yes/No | Note applicable risk factors (jurisdiction, sector, complexity) |
| Client risk category | Low/Medium/High assigned with rationale | Low/Med/High | Yes/No | Document factors driving rating (e.g., high-risk jurisdiction, complex UBO) |
| Matter scope (if applicable) | In/out of scope of MLR 2017 determination | N/A | Yes/No | Note the type of work if it is in scope (conveyancing, TCSP, etc.) |
| Source of funds/wealth (if high-risk) | Verified, documented | Low/Med/High | Yes/No | For high-risk clients, the source should be verified |
| Due diligence completeness | All required information obtained | Low/Med/High | Yes/No | Flag any gaps; remediate before file closure |
| Conflict of interest check | Conducted; no conflicts identified | N/A | Yes/No | Note any potential conflicts and how managed |
| Client acceptance decision | Accept/Decline documented and authorized | N/A | Yes/No | If declined, note the reason (e.g., unacceptable risk, scope limitation) |
| Overall Decision | Accept/Decline | Signed & Dated |
Common client acceptance deficiencies in UK law firms
SRA inspections frequently identify these gaps:
Missing or incomplete client identification: The firm lacks copies of identity verification documents, or documents are expired/illegible.
Weak beneficial ownership documentation: For company clients, the firm cannot readily locate the company registration extract or has unclear beneficial owner identification (especially for trusts, partnerships, and multi-layered structures).
No documented risk assessment: The client was assigned a risk level, but the file lacks an explanation of factors driving the assessment.
Incomplete screening records: Firm cannot evidence what was screened, when, against which lists, or what the results were. Alerts exist, but disposition is unclear.
Missing source of funds verification for high-risk clients: High-risk client accepted without documented assessment of the source of wealth or funds.
Lack of matter scope clarity: The file doesn’t evidence whether work was considered in the scope of MLR 2017 or what scope determination criteria were applied.
No supervisory approval: Client acceptance decision not authorized by a manager or compliance officer as required by firm procedures.
Generic or missing file documentation: Acceptance rationale is absent or generic (“standard conveyancing,” “low risk”) without supporting detail.
Best practices for client acceptance workflows in UK law firms
Document everything: Maintain a client acceptance checklist or template in the client file. Record who collected information, when, and what decisions were made.
Reference firm-wide risk assessment: When categorizing client risk, reference your firm-wide assessment. Note which risk factors (jurisdiction, sector, and transaction complexity) drive your categorization.
Use consistent scoring criteria: Develop documented criteria for low/medium/high categorization. Apply them consistently so all fee earners understand expectations.
Manage matter scope consistently: Develop a written flowchart or checklist to determine whether work is in the scope of MLR 2017. Train staff so scope determination is consistent.
Screen early: Conduct screening at client acceptance, not after engagement. Document that screening occurred before work began.
Keep screening evidence: Maintain copies of screening reports, alerts, and your alert disposition notes in the client file. If you decide an alert is not a blocker, document your reasoning.
Beneficial ownership clarity: For entity clients, obtain and retain company registration extracts (Companies House), trust deeds, or partnership agreements so the ownership structure is clear and auditable.
Supervisory review: Establish a process for managers or compliance officers to spot-check client acceptance files for completeness and consistency.
FAQs
Do sole practitioners need a documented client acceptance workflow?
Yes. The Money Laundering Regulations 2017 apply to all firms in scope, including sole practitioners. You must have written policies, controls, and procedures (PCPs) that include client acceptance procedures. These should be documented and followed consistently. The SRA expects you to maintain client files evidencing CDD and risk assessment, even as a sole practitioner.
What’s the difference between client risk assessment and matter risk assessment?
Client risk assessment evaluates the risk the client themselves poses (jurisdiction, business, and beneficial owner profile). Matter risk assessment evaluates the risk of the specific work you’re doing for that client (e.g., a conveyancing transaction or trust administration). Both should be documented. For some clients, you may have a consistent client risk rating applied across matters; for others, matter-level risk may vary depending on the transaction.
What is Cascade, and how does it help with AML compliance?
Cascade is an AML compliance technology provider focused on helping regulated businesses manage and automate key parts of their anti-money laundering processes.
Its AML Software (SaaS Platform) can support compliance teams by bringing AML workflows into a more structured, technology-enabled process, helping organizations manage activities such as customer risk assessment, screening, alert handling, onboarding communications, reporting, and analytics.
What data sources does Cascade integrate with for customer screening?
Cascade integrates with three leading screening data providers: Acuris Risk Intelligence, LSEG World-Check, formerly Refinitiv World-Check, and Dow Jones. These integrations support screening for sanctions, PEPs, adverse media, and other watchlist or regulatory risk data within Cascade’s AML/KYC workflows.Â
Explore Cascade’s AML compliance capabilities for law firms
Managing client acceptance at scale requires documented procedures that demonstrate consistency and supervisory oversight. Many law firms rely on manual spreadsheets and email, creating documentation gaps and compliance risk during SRA inspections.
Cascade helps law firms operationalize their client acceptance workflow. From intake data collection and automated screening through to client file management and supervisory approval tracking, Cascade provides the infrastructure to make client acceptance examination-ready and compliant with MLR 2017 and SRA expectations.
Explore Cascade’s compliance workflow capabilities →
Disclaimer
This article is for general information only and is not legal, regulatory, or compliance advice. AML requirements, client acceptance standards, and SRA supervisory expectations vary by firm type, size, and risk profile and evolve continuously. The regulatory information and SRA guidance reflect publicly available sources as of the publication date but may not reflect recent guidance updates, enforcement priorities, or your specific regulatory context.
This article does not establish a solicitor-client relationship or compliance consultant relationship. Before implementing specific client acceptance procedures, interpreting SRA requirements, or making material compliance decisions, consult with qualified legal counsel, your compliance officer, and the Solicitors Regulation Authority where appropriate.
Cascade is a workflow platform and does not provide legal or compliance advice. Use of Cascade does not guarantee compliance with any regulation or law. Errors and omissions may exist in this article; Cascade is not liable for their use or consequences.






































