The short answer
Recent SRA enforcement suggests that SRA compliance in 2026 increasingly turns on evidence. The regulator is consulting on advance notification before firms hold client money, has fined firms whose anti-money laundering risk assessments did not reflect their actual practice, and continues to scrutinise cyber incidents where controls were inadequate. For COLPs and managing partners, the focus has shifted from having written policies to demonstrating that their SRA compliance systems operate effectively in practice.
SRA Compliance in 2026: Where the SRA’s Attention Is
Three threads run through the SRA’s current activity: client money, AML evidence standards, and the systems firms use to protect both. The regulator is consulting on strengthening notification requirements so it can identify risk in firms earlier, including proposals for advance notice of mergers and new client accounts, which we covered when the plans were announced in June. Its fining decisions keep landing on firms whose compliance documentation could not survive contact with an inspection.
None of these proposals change the current rules unless adopted following consultation. What recent enforcement does show is an increasing expectation that firms can demonstrate how their compliance systems operate in practice, supported by clear records and evidence.
AML: evidence over paperwork
Anti-money laundering remains one of the SRA’s busiest enforcement areas, and recent decisions demonstrate an increasingly evidence-based approach to compliance. A client file that holds documents without a coherent account of where the money came from will not pass. Firms need to distinguish source of funds, the money in the specific transaction, from source of wealth, how the client came to have it, and record how each was checked and why the answer satisfied the fee earner.
Firm-wide risk assessments face the same test. This week the SRA fined KTP Solicitors after finding its firm-wide AML risk assessment was not adequate and did not properly reflect the firm’s practice, one in a steady line of fines where the assessment existed but did not reflect the firm’s actual work. A template completed once and filed is the pattern these decisions punish. The assessment should change when the firm’s client base, practice areas or sanctions exposure changes, and the review dates should prove it.
Sanctions compliance is also receiving greater regulatory attention alongside AML. Firms should ensure sanctions screening, escalation procedures and related risks are reflected within their firm-wide risk assessment rather than treated as a separate exercise.
Cyber risk and AI oversight
Email compromise attacks on client account payments increasingly involve cloned voices and AI-generated content, making verbal instructions alone a weaker form of verification than they once were. The Code of Conduct for Firms requires effective systems and controls, and the SRA has repeatedly emphasised that firms remain responsible for protecting client money through appropriate safeguards. Being the victim of cybercrime does not automatically prevent regulatory scrutiny where payment verification or other controls were inadequate.
The controls that hold up are unglamorous. Multi-factor authentication across all systems with access to client information or client money. Out-of-band verification of any change to payment details, using contact details sourced independently of the request. Appropriate monitoring of client account transactions. A written procedure staff actually follow under time pressure, which is when these frauds are timed to land.
AI use inside the firm needs the same discipline. Where drafting or research relies on AI tools, supervision has to catch what the tool gets wrong, because professional responsibility remains with the solicitor. If an AI system produces inaccurate research or citations, the solicitor—not the technology provider—remains accountable for the work submitted.
Transparency and vulnerable clients
The SRA Transparency Rules remain an active area of regulatory attention, particularly in conveyancing and probate, where disbursement structures confuse clients and cost estimates drift without warning. Publishing prices is the floor. The expectation is that costs information is accurate, that estimates are realistic, and that clients hear early when the figure moves.
Alongside pricing sits the treatment of vulnerable clients: staff who can recognise vulnerability, an escalation route that is written down, and communication that adapts rather than defaults to standard letters. Firms get asked for this evidence during thematic work, and “we would handle it sensitively” is not a document.
Culture, and how to evidence it
The SRA increasingly considers firm culture when assessing governance and compliance. When something goes wrong, the SRA looks at whether people inside the firm could raise concerns and whether leadership acted on them. That assessment is often supported by records such as: board minutes that show compliance was discussed, training logs, internal audit findings and what was done about them, and the breach register the firm is required to keep under paragraph 2.2 of the Code of Conduct for Firms.
The same records cut both ways. A firm that can show it found a problem, fixed it and documented the fix presents a different enforcement picture from a firm with a clean-looking file and no evidence anyone ever looked.
What this means for the COLP
All of the above lands on one desk. The COLP’s duty under paragraph 9.1 of the Code of Conduct for Firms is to take all reasonable steps to ensure compliance and to report serious breaches promptly, and the evidence trail above is what “reasonable steps” looks like when the SRA asks. For the role itself, who can hold it, how approval works and what happens when an officer leaves, read our guide to what a COLP is and who can hold the role.
Two practical points for the year. First, if the client money notification proposals are adopted, opening a client account or completing a merger will carry an advance-notice step; COLPs in firms planning either should watch the consultation outcome. Second, treat the breach register as a working risk tool rather than a filing obligation, because it is the first document that shows whether the firm’s compliance is real.
Frequently asked questions
What is the SRA focusing on in 2026?
Client money protections, including a live consultation on advance notification requirements, AML risk assessments and source of funds evidence, cyber controls around client account payments, and pricing transparency in conveyancing and probate. Across all of them, recent enforcement increasingly focuses on documentary evidence showing that controls operate effectively in practice, not just that policies exist.
Do firms have to notify the SRA before opening a client account?
Not yet. The SRA is consulting on strengthening notification requirements, including advance notice of mergers and new client accounts, so it can identify risk earlier. Until the consultation concludes and any rule change takes effect, the current notification rules apply.
What AML evidence does the SRA expect on a client file?
A record showing what source of funds and, where relevant, source of wealth checks were done, what the evidence was, and why it satisfied the firm. Recent fines, including the KTP Solicitors decision, show that a firm-wide risk assessment must also reflect the firm’s actual practice and be kept under review.
Does being a victim of cybercrime excuse a client money breach?
No. The SRA assesses whether the firm had effective safeguards in place. Where verification and payment controls were inadequate, the firm can face regulatory consequences for the loss even though the immediate cause was criminal fraud by a third party.
What to do this quarter
Reread the firm-wide risk assessment against the work the firm actually did in the last twelve months and record the review. Test the payment-change procedure with a live drill rather than a policy circulation. Check the breach register is current and that someone senior reads it. And put the client money consultation outcome on the compliance agenda for the next partner meeting, because if the notification proposals proceed, the timetable for mergers and new client accounts changes with them.