Image related to What will FCA supervision mean for law firms?

What will FCA supervision mean for law firms?

By Bobby Hussain, 28 September 2026

In October 2025 it was announced that the UK government was moving anti money laundering (AML) supervision for the legal sector away from the Solicitor’s Regulation Authority (SRA). Instead, it would be added to the remit of the Financial Conduct Authority (FCA).

The SRA Chief Executive at the time, Paul Philip, had only found this out the week it was announced by the UK government, but was quick to state that the FCA would not have the same relationship with law firms. The same week, my article was published [1] showcasing that many of the law firms that have been fined are failing to meet the Money Laundering Regulations 2017.

Whilst there is an argument that the SRA hasn’t been the most supportive,[2] the proposed transfer of AML supervision to the FCA is not simply a change of regulator. It represents the possible introduction of an entirely different supervisory philosophy, one in which governance, challenge and demonstrable oversight may become just as important as the underlying compliance framework.

Moving from the SRA to the FCA

The supervisory approach adopted by the FCA differs markedly from that traditionally experienced by law firms. Whilst it’s not possible to cover all aspects here, for the purpose of this short article I will focus on the following three areas, illustrating potential differences of approach under the FCA:

  1. Compliance Officer for Legal Practice (COLP)/Money Laundering Reporting Officer (MLRO)
  2. Veto power
  3. Presumption of responsibility

1) COLP/MLRO

Those already working under FCA supervision will know it requires formal approval of individuals performing compliance (SMF16) and MLRO (SMF17) functions, even within relatively small firms.

However, under the SRA Authorisation of Firms Rules,[3] a solicitor is automatically “deemed approved” as a COLP, or Compliance Officer for Finance and Administration (COFA), if:

  • They hold a current practising certificate.
  • The firm's annual turnover is under £600,000.
  • They are not already a compliance officer for another firm.
  • They have no active regulatory investigations or historical adverse findings against them.

At time of writing, no additional investigations or verifications are completed for that role. In comparison, under the FCA, even the smallest firms will have to meet their legal requirements. For Heads of Compliance and MLROs, the FCA will assess relevant training, experience, first-hand knowledge (not reliance on external providers) and capacity.[4]

What this means for those currently appointed as COLPs and MLROs within law firms remains unclear.

Especially concerning is the view most recently put forward by law firms that the FCA will not penalise smaller firms for technical breaches.[5] Currently, for law firms with a turnover of less than £600,000, it was acceptable to appoint anyone to the MLRO role without ‘standing in front of’ the SRA. This is highly unlikely to continue under the FCA.

2) Veto power

The “veto” power: In a small law firm, you notify the SRA and start work. In a bank, the FCA/Prudential Regulation Authority (PRA) can effectively veto your appointment. Not only do you have to ‘stand’ in front of the FCA, but it also decides on the capability. You cannot legally perform a Senior Management Function (SMF) until the FCA gives the green light, which can take up to 90 days.

This includes having meetings and an interview with the FCA and/or the PRA.

Your views, thoughts and culture are checked.[6] How will law firms and compliance employees react to this?

3) Presumption of responsibility

As illustrated by the following case study on Kennedys Law LLP, in appropriate circumstances, the SRA disciplinary framework has accepted that a compliance officer may reasonably rely on assurances provided by colleagues.

Case study 1: Kennedys

Kennedys Law LLP was fined £18,000 because it was ultimately responsible for the systems that allowed its client account to be misused as a “banking facility”. This is a “strict liability” issue for the entity, regardless of who specifically messed up.

Whilst Kennedys Law LLP and former partner Dennis Ko were sanctioned, the Solicitors Disciplinary Tribunal (SDT) cleared Andrew Coates, the firm’s Chief Risk Officer and COLP, of all allegations.[7]

In November 2024, the SDT dismissed the case against Coates, concluding that there was:

Reasonable action: Once Coates became aware of potential issues, the steps he took were deemed “reasonable and adequate” based on what he knew at the time.

Lack of direct involvement: Coates was not involved in the day-to-day running of the Grosvenor Hotel matter (which was led by Ko), and there was no evidence he was personally aware of the specific “serious concerns” or the misappropriation of funds.

The SDT concluded that the lead partner, Ko, had day-to-day responsibility for customer due diligence. His failure to spot “hallmarks of fraud” was a direct personal breach, resulting in his £27,500 fine.

The outcome strengthened the defence of entitlement to rely on colleagues. The tribunal found Coates was entitled to rely on assurances from Ko that matters were “on track”, and had no reason to believe there was evidence of fraud or misappropriation at that stage.

The distinction in responsibility

The FCA operates under the Senior Managers and Certification Regime (SM&CR). This regime was specifically designed after the 2008 financial crisis to prevent senior bankers from “getting away with it” by claiming they didn't know what was happening.

Under the UK's SM&CR, a high-ranking officer can be fined for the failures of their subordinates if they did not take “reasonable steps” to prevent the breach.

In a legal context, a COLP is not automatically responsible for every mistake a firm makes. To be fined personally, usually they must be shown to have failed in their own duties. Coates took steps to investigate and was effectively kept in the dark by the partner on the ground. As a result, the tribunal found the allegations against him “not proved”. Most importantly, he was allowed to rely on others despite being the COLP. If Coates had investigated but looked the other way, then the result may have been different.

In the banking sector, the “reliance on others” defence is much harder to sustain because the FCA applies a “should have known” standard that the SRA does not.

Case study 2: Sir Christopher Gent

The case of Sir Christopher Gent (ConvaTec Group Plc) provides a direct example of where a senior manager relied on the silence and expertise of others, but the FCA rejected this as a valid defence.

In 2022, the FCA fined Gent £80,000 for the unlawful disclosure of inside information.[8]

The defence: Gent argued that his breach was “inadvertent” because he had consulted with a board-level executive and a broker before making the disclosures. Since neither of these experts with specific compliance responsibilities warned him against the calls, he argued he had reasonably relied on their implied assurance. 

The reasoning: The FCA determined that Gent’s own training and considerable experience meant he should have independently realised the information was sensitive. He could not use the silence or “implied assurance” of others to escape his personal responsibility to verify the situation himself. 

Under the SRA, Coates was ‘entitled to rely’ on his colleague’s word. Under the FCA, Gent’s defence was rejected as he had a duty to independently investigate regardless of ‘compliance experts’ not raising red flags.

Compliance and culture change

Although the three areas investigated here do not paint the complete picture of what life will be like for law firms under the FCA, we can see that this is a huge compliance and cultural shift for them. Indeed, therein might lie the reason why the shift has occurred in the first place.

The FCA's supervisory approach places greater emphasis on personal accountability and evidencing reasonable steps than has traditionally been seen in SRA disciplinary proceedings. Whilst the SRA tribunal allowed Coates to rely on a partner's word, the FCA's Senior Manager Conduct Rules explicitly list failures that would make that same defence fail in a banking context.

In short, whereas the SRA accepted that Coates followed a “reasonable” process, the FCA's rules are designed to ensure that “not knowing” is itself a failure if a competent manager in that position should have found out.

Overall, adhering to the rules under the FCA will look very different to what law firms have been used to. 

 

About the author

Bobby Hussain

Bobby Hussain LL.B, LL.M, LPC, Adv. Paralegal (CILEX) is a strategic regulatory advisor with deep expertise in UK and international sanctions, AML/KYC frameworks, and PRA/FCA implementation. He has led high-impact compliance initiatives across Tier 1 banks and specialist consultancies, with a publishing portfolio that includes ICA inCOMPLIANCE and Trinity Law Review. As founder of BSAH Consultancy Ltd, Bobby is architecting phased legal, financial, and strategic advisory services designed for institutional resilience and legacy impact.

You may also be interested in: