We have compiled answers to some of the most frequently asked AML queries to support the legal profession in complying with the regulations.

Remember, there is HM Treasury approved Guidance for the Legal Sector which you should familiarise yourself with if you have any queries on AML, along with lots of information across our own AML webpages, including a handy AML Toolkit.

We intend to update these pages periodically and as necessary with common questions from members.

Regulation 12(1) of the Money Laundering Regulations 2017 details the services which would bring a legal firm in scope for AML Supervision. These are:

(a) the buying and selling of real property or business entities;

(b) the managing of client money, securities or other assets;

(c) the opening or management of bank, savings or securities accounts;

(d) the organisation of contributions necessary for the creation, operation or management of companies; or

(e) the creation, operation or management of trusts, companies, foundations or similar structures, and, for this purpose, a person participates in a transaction by assisting in the planning or execution of the transaction or otherwise acting for or on behalf of a client in the transaction.

While some of these are clear, we are often asked by members who, for example, work in family law, immigration or criminal defence, what constitutes “managing client money, securities or other assets”.

Although the Society does not advise on whether a firm should claim exemption from AML Supervision, we provide the following information in order to help firms come to a decision around what may not be managing client money.

The HMT-approved AML Guidance for the legal sector asserts: “managing client money is more narrowly defined than handling it”.

Further, the guidance goes on to cover activities which are not covered by the regulations and lists:

  • Payment on account of costs
  • Provision of legal advice
  • Participation in litigation or alternative dispute resolution
  • Will writing
  • Work funded by the Legal Services Commission

The view of the Law Society of Scotland is in line with the above. The following is a non-exhaustive list of actions which we do not believe amount to managing client money:

  • Dispersal of funds as ordered by a court
  • When acting in a divorce, dispersal of funds derived from the sale of marital assets when that sale was conducted by another practice, eg dispersal to your client of monies received from a separate practice which arise from the sale by that practice of the family home, most likely in terms of a Minute of Agreement
  • Dispersing to your client an award arising from civil litigation eg a cheque received from an insurance company in connection with a personal injury claim.
  • Dispersing to your client an award from the Criminal Injuries Compensation Board.

It is crucial to keep in mind that not undertaking any of the services in Regulation 12 above does not exempt you from statutory obligations under the Proceeds Of Crime act, particularly sections 327-329. You should always be vigilant to the possibility of money laundering through your business and your obligation to file a Suspicious Activity Report if necessary and therefore you should maintain a basic AML Policy and Procedure which would allow you to pass on basic due diligence to your supervisor or law enforcement.

Please also note, though your firm may be exempt from AML Supervision at a given time, if you should undertake any business in future which does bring you within scope of Regulation 12(1) as detailed above, you must inform us timeously and comply with the AML Registration and AML Certificate processes.

The Association of Certified Anti Money Laundering Specialists (ACAMS) defines crowdfunding as:

“the procedure of raising expansive amounts of cash from numerous people who are interacting via the internet in online consumer communities”

Crowdfunding brings with it various AML considerations, not least around identity and obfuscation.

Here are some quick tips on what to think about when considering business with crowdfunding:

  • Is the crowdfunding platform regulated?  
  • Some crowdfunding in the UK is done through an FCA-regulated platform, which may give a higher degree of comfort.
  • Is the payment service linked to the crowdfunding regulated? 
  • What electronic payment service is being used to transfer funds and is it regulated?
  • What is the purpose of the funding? 
  • If the funding is intended to purchase an asset or could be recoupable in some way (paid into a trust or similar), this makes it inherently higher risk.
  • Why is the funding being sourced in this way? 
  • Are you comfortable about the narrative you are given about why crowdfunding is being used as opposed to other traditional methods?
  • Who can you identify/verify?  
  • If the recipient of the funds is a charity, or if the funds are to be used to inflate a trust, confirm the ownership and control structure of the entity in question.
  • It stands to reason that crowdfunding will make it difficult to carry out due diligence on every source of funding. However, you should still expect to be able to identify and verify  relevant parties. These could be the individual(s) behind the idea, those controlling the funding or those donating over a certain % of the funds (due diligence should be performed where this individual donates significantly more in comparison to other contributors). You should be comfortable that you are able to show you have gathered adequate due diligence,
What other typical AML rules apply?

Apart from “crowdfunding specific” considerations, you shouldn’t lose sight of the normal checks undertaken for AML, what the client’s background is, and including other factors such as high risk jurisdictions, PEPs, layering, value of transaction etc.

There is no panacea regarding due diligence where crowd funding is concerned - however you should clearly articulate and record the factors you have taken into consideration regarding your risk assessment, the due diligence performed and why you have performed it on specific individuals involved. EDD should be considered in cases where high value assets or recoupable payments are involved.

Regulation 4 (3) states:-

“For the purposes of these Regulations, an estate agent is to be treated as entering into a business relationship with a purchaser (as well as with a seller), at the point when the purchaser’s offer is accepted by the seller.”

On the face of it, this might mean that a selling solicitor has to, as part of their estate agency service, AML check the purchaser as well as their client.


Estate agent is defined in Regulation 3, General Interpretation:-

“estate agent” has the meaning given by regulation 13(1);”


Regulation 13(1) states:-

“In these Regulations, “estate agent” means a firm or a sole practitioner, who, or whose employees, carry out estate agency work, when the work is being carried out.”


Estate agency work is defined in Regulation 13(2). The relevant part is underlined.

For the purposes of paragraph (1) “estate agency work” is to be read in accordance with section 1 of the Estate Agents Act 1979(a) (estate agency work), but for those purposes references in that section to disposing of or acquiring an interest in land are (despite anything in section 2 of that Act) to be taken to include references to disposing of or acquiring an estate or interest in land outside the United Kingdom where that estate or interest is capable of being owned or held as a separate interest.”


Section 1(2)(a) of the Estate Agency Act 1979 is immediately below. The relevant part is underlined.

This Act does not apply to things done

(a)in the course of his profession by a practicing solicitor or a person employed by him or by an incorporated practice (within the meaning of the Solicitors (Scotland) Act 1980) or a person employed by it;”

  • The 2017 Regulations define estate agency work in terms of an Act which does not apply to our members.
  • For that reason, it is our view that solicitors are exempted from the definition of ‘Estate Agents’ in the 2017 Regulations.

Therefore, Regulation 4(3) does not apply to our members.


A fundamental element of client due diligence is understanding the nature, background and circumstances of the client, including their financial position – and making an assessment as to whether the legal services provided to the client are in keeping with your understanding of that background and circumstances.

The financial circumstances of a client can broadly be categorised into Source of Funds (SoF), and Source of Wealth (SoW).

As per LSAG Guidance, you must take adequate measures to check SoF and SoW as a part of EDD when applied to PEPs. You should also consider doing so as a part of ongoing monitoring of any business relationship (whether high risk or otherwise). You should also apply a source of wealth check in other applications of EDD on a risk-based approach.


Source of Funds

LSAG Guidance states "Source of Funds refers to the funds that are being used to fund the specific transaction in hand – i.e., the origin of the funds used for the transactions or activities that occur within the business relationship or occasional transaction. The question you are seeking to answer should not simply be, "where did the money for the transaction come from," but also "how and from where did the client get the money for this transaction or business relationship." It is not enough to know the money came from a UK bank account".

Thus, Source of Funds means establishing the provenance of the particular funds for use in a transaction - this includes the remitting account details but also an understanding of the activity which generated those specific funds, for example savings from employment or inheritance

You may already be obtaining bank statements to show the client’s possession of the funds in question, and you should continue to do this on the understanding that these statements are also intended to evidence possession and transit of the funds i.e. what account they are coming from and is that in the name of the client

Example: A client is purchasing a flat for £400,000. The client, a teacher at a local high school, has obtained a mortgage but has a deposit of £25,000 to put down. The client explains that the deposit is a mix of employment savings and a gift from parents. The risk assessment is Medium (Standard CDD).

Source of Funds may be assessed and evidenced by, for example, obtaining bank statements to check for sufficient and regular credits from the expected employer and obtaining bank statements to check for gifted funds matching the amount detailed by client. Should remitter details be available, it may also be possible to check any connection/related names to the client’s details)

Where risks are assessed as higher (for example all the funding is being provided by the client)actions might also include more investigation to confirm the source of any gifted funds and/or evidence of employment, though there may also be reasons particular to any transaction (low, medium or high risk) where further investigation or evidence should be sought.


Source of Funds - Things to Consider
  • Source of Funds should be evidenced in line with risk grading (and may have an effect on your risk grading!)
  • It is not just about collecting documents; you should consider what you have been given e.g. Is the client’s explanation and evidence sensible/feasible? Do the bank statements show what you’d expect to see? How many months of statements should you collect in line with the risk profile?
  • Document your rationale and decision-making - if the LSS asked you what you had done to satisfy Source of Funds, would you be comfortable explaining and evidencing the decisions you had made, why you made them, what you had done to satisfy requirements?


Source of Wealth

LSAG Guidance states "The source of wealth refers to the origin of a client’s entire body of wealth (i.e., total assets). SoW describes the economic, business and/or commercial activities that generated, or significantly contributed to, the client’s overall net worth/entire body of wealth. This should recognise that the composition of wealth generating activities may change over time, as new activities are identified, and additional wealth is accumulated. You should seek to answer the question: "why and how does the individual have the amount of overall assets they do – and how did they accumulate/generate these?"

When addressing SoW, you should consider whether the SoW is commensurate to your client in general i.e., does it make sense that the client in front of you obtained their wealth in the way that they have advised you?

SoW information will usually give an indication as to the volume of wealth the client would be expected to have, and a picture of how the person acquired such wealth. It does not however require you to account for all of a client’s assets, but to build a rationale and reasoning as to why they have such wealth and to provide assurance that it was obtained through legal means. This will help you to establish whether the transaction makes sense.

Aside from the bank statements you might collect as part of Source of Funds (which remains an obligation even when Source of Wealth checks are engaged), you should collect and assess documents which account for the wider wealth of your client. Depending on the client, this evidence may include audited accounts, share registers, property portfolios or other reliable documents that give you comfort as to the level of wealth of the client, and where it came from.

Example: A non-face to face client instructs your firm in the purchase of an £800,000 home. The client is using her own funds with no mortgage or lending, and during your screening it is confirmed that she is an entrepreneur with a high net worth. She explains that the funds for this purchase are coming from a single property sale, but you know from public sources she generates income from a well-known private equity fund, as well as having a wider property portfolio. Her husband is a senior cabinet minister.

Obtaining bank statements to show the proceeds of the property sale she mentioned would go some way to covering Source of Funds (although in this high-risk situation you may want to check later that the funds arrive from that same account etc.), but the client is a PEP by her association with her PEP husband.

In this situation, you must also establish and evidence the client’s SoW. This may include obtaining documentation regarding drawdowns/income streams from the private equity fund, and the value/ any income derived from the property portfolio.

Source of Wealth - Things to consider
  • Does the matter involve high risk or a PEP?
  • Along with the specific funds being used in the business relationship/transaction at hand, what is the value of the client’s overall body of wealth and where/what activity is it generated/derived from?
  • What types of information, evidence or documentation would help you gain comfort that the client’s wealth is not derived from criminal activities (including the proceeds of corruption) extent do you feel you need to go to satisfy the risk?

Is the client’s explanation and evidence sensible/feasible?

  • Document your rationale and decision-making - if the LSS asked you what you had done to satisfy Source of Wealth, would you be comfortable explaining and evidencing the decisions you had made, why you made them, what you had done to satisfy requirements?


Source of Funds and Source of Wealth - Why do they exist separately?

As the inherent risk increases, so does the need to be surer that the funds in use in a matter are not derived from criminal activities (including the proceeds of corruption) by understanding the funds proffered for use in a particular transaction (SoF) and the client’s funds more generally (SoW).

In higher risk situations, it is important to evidence both, in order to ensure that the SoF evidence collated to fund one transaction is not then used again to fund another.

For example, a client is able to demonstrate to your firm that they possess £1m in order to fund a house purchase, and those funds have been derived legitimately (source of funds). The client could then go to another department in your firm, or to another firm and (in the absence of SoW checks being undertaken) potentially use the same SoF information to then buy another £1m property or use for another investment/business activity.

Evidencing Source of Wealth would help prevent or mitigate the risk of this scenario occurring and may also mitigates the risk of commingling funds from another part of the client’s total wealth, which may include the proceeds of crime particularly in PEP/higher risk scenarios.


Summary Table


Source of Funds

Source of Wealth

Relationship to risk

Should be satisfied in all risk scenarios, with evidence dependent on risk (see below)

Higher risk and PEP scenarios

What to ask/evidence

How and from where did the client get the money for this transaction or business relationship?

(N.B. It is not enough to know the money came from a UK bank account")

How and from where did the client obtain their overall body of wealth?

What were the economic, business and/or commercial activities that generated, or significantly contributed to this body of wealth?

Evidence/Documentation Required

You should collect and assess documentation commensurate with the risk assessment, which sufficiently evidences the provenance of the funds to be used in the transaction.

You should obtain the remitting account details as well as evidence of the activity which generated those specific funds.

You should collect documentation which allows you to sufficiently document and assess the broader wealth-generating activities of the client.


What to do with the information

For both Source of Funds (SoF) and Source of Wealth (SoW) it is important that this is not treated as a simple collection of documents.

Commensurate with the risk you should take time to assess the evidence you collect, and evidence collated should be used to build a rationale and reasoning as to how the client can fund the transaction and to provide assurance that these funds were obtained through legal means.

As with all CDD/KYC activities, you should label and store the documentation clearly and keep notes of the deliberations and decisions you make based on the evidence.


Further information:

LSAG Guidance

Wolfsberg Guidance on Source of Funds and Source of Wealth

Source of Funds and Source of Wealth: What you need to know 

There are certain jurisdictions around the world which have been deemed as presenting various risks in terms of the funds you may receive from them (for example increased risks of money laundering, corruption, bribery, tax evasion etc).

Risk profiling countries is a difficult task and there is no single global arbitrator on this. For example, the US State Department's Money Laundering Assessment is separate from Transparency International's Corruption Index.

We have some useful links in our Jurisdictions and Sanctions section found on our Additional Support page.

In light of the information in these resources, should you deem the client or transaction to be of higher risk, based on jurisdictional risk and/or other factors, Enhanced Due Diligence should be applied. This would include verification of the source of wealth involved in the transaction, as per the previous FAQ.


Remember, certain jurisdictions, entities and individuals are sanctioned. This is different from the client/transaction or jurisdiction simply being of higher risk and it may preclude you from acting without applying for a licence to do so from the Office of Financial Sanctions Implementation (OFSI).

You should consult the UK government website for further information before progressing any such business. You may also wish to speak to our Professional Practice helpdesk.

A method for screening clients for Sanctions, Politically Exposed Persons (PEPs) and adverse media should be part of your usual procedures. You should implement a procedure relative to the size and nature of your business i.e. you may wish to carry out manual public sources checks or you may wish to employ a third party electronic platform to carry out these searches for you. See our later FAQ on electronic providers.

You will find helpful information in the Financial Sanctions Guidance provided by The Office of Financial Sanctions Implementation (OFSI), (which is part of HM Treasury) and the UK Sanctions List on the UK Government website.


If your client cannot attend your office at any point in the transaction, you may first wish to consider why. A client who avoids much interaction with you may be a red flag, especially if that client is local to you. You should also consider any compounding risk factors.

There will, of course, be times where a client legitimately cannot attend. In this instance you should obtain a copy of their ID which should be certified by an appropriate person. The UK Government website lists these persons. You should be satisfied that the person certifying the document genuinely holds the position they claim to.

Alternatively, you may wish to use R.39 "Reliance" to obtain relevant Customer Due Diligence (CDD) information (including ID and verification) on your client from another regulated professional. This is different to simply obtaining an appropriate certified document. For further information on using this regulation please see the Legal Sector AML Guidance. Please note that at all times the relying firm will remain responsible for the adequacy of the due diligence you obtain under the terms of R.39.

If your client is not attending and someone else claims to be acting on behalf of this person, this is a separate issue and you must (under Regulation 28.10) verify that that person acts on behalf of your client as well as verifying the representative's identity.


There may be legitimate requests to send payments to a third party (e.g. pay Registers of Scotland or similar providers necessary to the smooth running of the underlying transaction) and therefore there is no Accounts Rule permitting or disallowing this, however, you should keep in mind that there are risks associated with undertaking this, especially if the request is unusual or there appears to be no normal business rationale for doing so. This may represent a risk as these payments can circumvent all the good CDD work you have carried out on the parties in a transaction. We therefore do not recommend paying money to a third party, other than in the normal course of business.

Generally, we recommend paying funds back to the client, who can transfer it on from there.

There are various commercial providers of electronic identification/verification (including Sanctions, PEPs, Adverse Media Checkers, Company Registry Information Providers, and verification of Identification Providers), which collate information from sources such as electoral rolls and other governmental records, credit agencies etc.

These may be acceptable as part of Identification and verification however the onus is on you to take appropriate steps to understand how the tool works, where it derives its data from, how it searches and be satisfied as to the validity and reliability of the information the tool is reporting. Further, you should consider the GDPR/Data Protection implications for incorporating one of these systems into your procedures.

Please note, we do not endorse any particular provider of these services, nor can we make any statement regarding the quality of the underlying data they use or how they collect/use/store this, or your client's data.

Your AML policy statement is the organisation-level document which sets out your approach to AML within your business. You can find an outline policy here, which outlines all necessary sections. Please tailor this to the individual circumstances of your business.

Where you conduct any business on an ongoing basis or which has a recurring element, you must conduct ongoing monitoring. This allows you to ensure you remain compliant. The Money Laundering Regulations stipulate that ongoing monitoring must include;

  • Scrutiny of transactions to ensure that the transactions are consistent with your knowledge of your customers business and risk profile
  • Undertaking reviews of existing records and keeping the documents or information obtained for the purpose of applying customer due diligence measures up to date.

For long-term business/clients, you should have a clear policy and procedures around how often, and in what way, your AML checks are to be refreshed. At a minimum you should assess the service provision, any changes in ownership and Identification and verification documents for anything which may represent a material change to the risk profile or the validity of your records. These refreshes should be recorded by your business.

If a transaction/matter is undertaken over a more significant timeframe (where significant factors may change such as those involved in the transaction, the amounts involved or even the underlying assets) it may be necessary to undertake interim risk assessments to ensure the risk profile of the transaction has not changed. These interim assessments should also be recorded.

The 2017 Money Laundering Regulations dictate that where “there is more than one supervisory authority for a relevant person, the supervisory authorities may agree that one of them will act as the supervisory authority for that person.” 

We have agreed a memorandum of understanding with the Solicitors Regulation Authority, which assigns responsibility for AML supervision, based on the location of law firms’ registered offices.

For clarity, firms whose registered offices are in Scotland will be supervised for AML compliance by the Law Society of Scotland and the Solicitors Regulation Authority will supervise firms whose registered offices are in England or Wales for AML compliance.

Read more here.

When verifying the identity of a Client, pursuant to Regulation 28 of the Money Laundering Regulations 2017, it is generally understood that you will request to see an identification document, such as a passport, and an original proof of address for a natural person as a minimum.

In order to evidence the date received and, indeed, that you have seen the individual and the documentation at the same time, we recommend that you certify with copies with a statement similar to the following.

For the ID document

Having seen the individual and the identification document at the same time, I certify that this is a true copy and the photograph bears a reasonable likeness of the individual.”


For other documentation, such as a proof of address:

Having seen the original and the photocopy at the same time, I certify that this is a true copy of the same.”

For both of the above, the certifier should include the following–

  • Name
  • Position
  • Name of Firm / Organisation
  • Contact details, namely their physical address and / or email address plus a contact number
  • Signature
  • Date


The same applies to certifying the due diligence documentation for any legal entity or arrangement such as a Trust and the connected Principals.

Furthermore, when requesting due diligence from a Third Party such as another regulated entity / relevant person, you should ensure that you receive the original copies of the documentation with a similar statement to those suggested above, signed and dated.

If applicable, the certifier should include the relevant professional body of which they are a member as well as their membership number.

A cryptocurrency, crypto currency or crypto are digital assets designed to work as a medium of exchange. They exist electronically and use a peer-to-peer system, where individual coin ownership records are stored in a computerized database with strong cryptography to secure transaction records.

There are many crypto currency providers and you may have heard of some in the news, such as Bitcoin, Litecoin and Ethereum.

Since 10 January 2020, all UK crypto service providers have been in-scope of the Money Laundering Regulations 2017 and are regulated for AML purposes by the Financial Conduct Authority (FCA). 

Dealing with crypto currencies/assets

There are no reasons why you should not engage with clients wishing to deal in crypto currency. However, the use of crypto may be indicative of higher risk (as per LSAG Guidance s and therefore you may wish to conduct Enhanced Due Diligence (EDD) and consider/document the following:

  • What is the value of the deposit coming from crypto currency?
  • Can you establish and evidence how the client funded the original acquisition of the crypto currency (i.e. their Source of Funds/Wealth)
  • Is the explanation in line with your knowledge of the client, and can this be supported?
  • Can the client provide evidence of the crypto currency portfolio? Such as:
    • When was it created?
    • Evidence of deposits from the client?
    • How has the asset performed and over what period?
  • Has the client used a reputable crypto service provider? Is it regulated by the FCA? (Some wallet providers remain unregulated outside the UK)

There is no one-size-fits-all when it comes to diligence for crypto currency. Commensurate with the risk you should take time to assess all available evidence before deciding as to whether you should proceed with the matter. Should you decide to go ahead you should clearly articulate and record the factors you have taken into consideration regarding your risk assessment and the due diligence performed.

Further information

The Joint Money Laundering Steering Group (JMLSG) has released new draft guidance for banks and other financial institutions regarding the treatment of ‘Pooled Client Accounts’ (PCA) for Anti-Money Laundering (AML) purposes. Broadly speaking, this guidance means that practice units can now expect more contact from their client account holder about potential Anti-money Laundering (AML) risks arising from the operation of that account.


The JMLSG is a private sector body made up of leading financial services sector trade associations.

Compliance with JMLSG guidance is considered closely by the Financial Services Authority (FCA) in the context of any disciplinary action or criminal prosecution they may take against banks or financial institutions, during the course of their AML supervisory work. Departure by banks from the guidance may need to be justified to the FCA.

This guidance may have significant implications for legal firms, many of which use client accounts to administer clients’ funds, co-mingling them and transferring them as appropriate.

The key features of the JMLSG guidance are summarised below – Money Laundering Reporting Officers, cash-room managers and compliance officers are advised to read the full guidance and carefully consider how their businesses may be impacted.

Key features of the guidance
  • Your bank should be satisfied as to the purpose and nature of the client account, including likely deposit sizes and transaction sizes and types, as well as your exposure to industries and geographies of known AML risk.
  • Your bank should consider the risk profile of the account, for example, whether the account will be used for a limited, domestic purpose, whether your law firm is supervised for AML Compliance by a body such as the Law Society of Scotland or the Solicitors Regulation Authority, and what services the account opener will provide while using the account. The bank must also take reasonable measures to satisfy itself that the firm it provides the client account to, applies robust and risk sensitive customer due diligence (CDD) measures to its clients, in line with its obligations under the Money Laundering Regulations (MLRs).
  • Your bank must enter into a written agreement with your firm, in which you agree to provide, upon request, information on the identity (including verification documents/data) of the owners of the funds held in the account(s). The timescale associated with such requests must be reasonable in the context of the business relationship, but must allow the bank to comply with the terms of any court order should one arise relating to the client account it holds on behalf of your firm.
  • Your bank may require you to provide the identification and verification information you hold on your clients. If your bank assesses your firm as having a low AML risk, it may choose to apply Simplified Due Diligence. However, where the bank assesses the risk to be anything other than low and Simplified Due Diligence cannot be applied, the guidance details that the bank must either take reasonable measures to identify and verify the identity of the owners of the funds held in the PCA (e.g. by entering into a formal reliance agreement allowed under the MLRs), or take measures to decrease the money-laundering /terrorist financing risk until simplified due diligence measures can be applied.” Examples of measures the bank could apply are listed in the guidance.
What this might mean for your firm

It is important that you consider what this draft guidance might mean for your business. It could be that some of the following actions may be taken by your bank in the future.

  • You may be asked to enter into a written agreement with your banking provider, as described above
  • The terms of business between you and your bank may be amended and/or you may be asked by your bank to amend your own terms of business for your clients, allowing for GDPR-compliant transfer of information. You may be asked to provide a firm level risk assessment, AML policy and procedural documents and/or other documentation to satisfy the bank as to the level of AML risk in your business, and the strength of your AML controls.
  • You may be asked to enhance your AML procedures to a level that satisfies your bank. The bank may otherwise impose restrictions on the use of your client account or the types of client whose funds you can accept, conduct further/enhanced due diligence on your firm or, in extreme circumstances, the bank may demand that you enhance AML controls as a condition of the continued operation of your client account.
  • The guidance states that banks should allow firms reasonable time to implement any improvements or measures requested, taking into account the level of AML risk, the complexity of the relationship, compliance with regulatory obligations as assessed by their supervisor, legal privacy issues and the perceived level of co-operation by the firm.
Next steps

The guidance is live and effective now.  We are aware that banks have already started reviewing and updating their policies and procedures to align to it, and therefore you should be prepared to hear from your client account provider relatively shortly regarding any changes they will make to comply with the guidance.

The more robust your AML measures, the better placed your firm will be to respond.  We would therefore strongly suggest your firm familiarises  itself with the guidance and reviews its AML policies and procedures to ensure they can meet the requirements therein.

When providing regulated AML services, you may wish to place reliance (Regulation 39) on another licensed and regulated service provider (third party) to conduct appropriate and effective Customer Due Diligence CDD checks on your behalf.

The benefits of placing reliance on a third party can save time and expedite the delivery of your services to the client. However, there are factors that you must consider and document -

1. your policies, controls, and procedures (PCPs) must address the associated risks when placing reliance on a third party
2. detail when reliance is permitted, the conditions precedent and the necessary controls you have in place to satisfy your firm that you are indeed meeting your statutory obligations to comply with Regulation 28 of the MLR17
3. obtain the agreement of the third party
4. establish and document that the third party has appropriate and effective PCPs in place to ensure they are robust and executed
5. ensure that the third party can make the CDD information available to you immediately on request
6. ensure that the third party retains the documentation pursuant to Regulation 40 and
7. Periodically test that the arrangements are adequate

Conversely, should your firm be relied upon you must ensure that you have the factors listed above in place and, importantly, that you have the consent of the parties involved in the matter to share the CDD information and documentation that you hold on file.

Please note: You cannot outsource your responsibility to ensure that your firm complies with the Regulations and will remain liable for any failures.

Another factor to consider is the geographical location of the third party. You can only place reliance on the following regulated entities in the UK:
a credit or financial institution as defined in Regulation 10
auditors, insolvency practitioners, external accountants and tax advisers as defined in Regulation 1

  • independent legal professionals as defined in Regulation 12
  • trust or company service providers as defined in Regulation 12(2)
  • estate agents as defined in Regulation 13
  • high value dealers as defined in Regulation 14(1) and
  • casinos as defined in Regulation 14(2)

    Further detail can be found on Reliance within the LSAG Guidance, Section 6.23 (Reliance and Outsourcing)

You must report breaches of the regulations to your AML Supervisor, where you have not complied with the requirements of the regulations and where the result of a breach has been serious.

Non-exhaustive examples of serious breaches include:
Intentional or willfully negligent breaches of legal requirements in relation to applicable anti-money laundering legislation or regulation

  • repeated unintentional or repeated accidental breaches of legal requirements in relation to applicable anti-money laundering legislation or regulation
  • systemic breaches associated with a failure of AML-related policies, controls or procedures
  • the facilitation of business activities which bear the hallmarks of money laundering activity (this does not replace the legal requirement to file a SAR where appropriate)

You must also report breaches of related legislation for which AML supervisors don’t have a direct regulatory responsibility but is still relevant to your ability to prevent financial crime (for example breaches of Financial Sanctions legislation).
You do not need to report one-off or non-systematic breaches of the regulations which are limited in scope and impact.

How do I report these?:

Should you wish to make a breach report you can do so by submitting the MLR Breach Reporting Form and send to AML@Lawscot.org.uk with the subject line: “AML Regulations Breach”

What happens next?

Following receipt of any breach reporting forms, the AML team will review these and contact the reporter directly for follow up discussions.

Further information or documentation can be passed through secure/encrypted channels.

If you have concerns about data protection you can find information about how we use your personal data in our privacy policy

Read the LSAG Breach Reporting Note

LSAG Guidance Section 12.6 states;

"Before establishing a business relationship with a:

• Company (registered or unregistered as defined in the Unregistered Companies Regulations 2009(1));
• Limited Liability Partnership; or
• Scottish Partnership;

- a practice must collect proof of registration (e.g., via the client) or an excerpt from the relevant register.

If the firm finds a discrepancy between information relating to the beneficial ownership of the company which it collects as above, and information which becomes available to it
whilst carrying out its duties under the ML Regulations (during its onboarding process), the
discrepancy must be reported to Companies House (R30A(3))

Practices that encounter such discrepancies while fulfilling their AML duties, must report them, but it is not a requirement for practices to actively seek out such discrepancies."

In order to report identified discrepancies to Companies House you can access the register HERE:

Further information on People with significant control (PSC) discrepancy reporting in the form of a recorded webinar can also be found HERE: 

Further information is also available on our AML Toolkit under Guidance

We recently published an updated Scottish sectoral AML risk assessment, which included information on clients and business matters with links to higher risk jurisdictions. It is vital to ensure there continues to be close scrutiny of sources of funds and potential exploitation of legal services by organised crime and in the assessment, we stated our view that the inherent money-laundering risks associated with Chinese individual direct investment activity, capital flight and high value goods trading are significant in the Scottish legal sectoral context and more can be found on this subject through the following Supervisory Advice Note and associated webinar: Chinese underground banking – Money laundering risks, and potential exploitation of legal services by organised crime

Two women sat at a desk in an office, both looking at a laptop screen

Anti-money laundering

The fight against money laundering and counter terrorist financing - the role of the legal profession.

Law Society of Scotland website shown on tablet screen with hands holding tablet

AML Toolkit

Useful tools, resources and templates to help your practice unit with anti-money laundering.

Close up view of woman's hand typing on a laptop with a coffee cup

Additional support

Information on SARs reporting procedures, international sanctions, high risk jurisdictions and PEPs.