Identity fraud reaches law firms by four routes: impersonated conveyancing clients, nominee-fronted company and trust formation, third parties pushing money through the client account, and forged instructions on cross-border matters. The firm's defence is verification before it acts, evidenced source of funds, and screening that covers every party to the retainer.
Key takeaways
- The SRA's sectoral risk assessment, published 6 August 2026, keeps the legal sector's money laundering risk at high, unchanged since 2020, and names residential conveyancing as one of the highest-risk areas of practice.
- In the SRA's 2024 to 2025 review of 5,873 files across 833 firms, 11% of files carried no source of funds check at all and 8% recorded a source of funds the evidence did not support.
- Rule 3.3 of the SRA Accounts Rules bars a client account from being used as a banking facility, which makes unexplained inbound funds a regulatory breach as well as a laundering risk.
- The Economic Crime and Corporate Transparency Act 2023 removed the £25,000 statutory cap on SRA fines for economic crime matters, in force from March 2024.
- Australian lawyers and conveyancers come into scope on 1 July 2026 under table 6 of subsection 6(5B) of the AML/CTF Act 2006.
Which legal services actually attract identity fraud?
Not every retainer carries the same exposure. The work that draws impersonation is the work that moves value or creates a legal person: conveyancing, company and trust formation, holding client money, and equity or debt financing. AUSTRAC's professional designated services guidance lists nine such services under table 6 of subsection 6(5B) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, and that list doubles as a map of where fraud lands.
Item 3 covers receiving, holding, controlling or managing a person's property to help plan or execute a transaction. Item 5 covers selling or transferring a shelf company. Items 7 and 8 cover acting, or arranging for someone else to act, in a named position in a body corporate. Every one of those is a service a fraudster would rather have performed in someone else's name than their own.
The Solicitors Regulation Authority reaches the same conclusion from UK supervisory data. Its sectoral risk assessment rates the legal sector's money laundering risk as high with no significant change since 2020, and singles out residential conveyancing as one of the highest-risk areas of legal practice. Our legal sector page sets out how those services map to screening obligations.
What must a firm verify, and by what point in the matter?
Timing is the part firms get wrong. Under regulation 27 of the Money Laundering Regulations 2017, customer due diligence applies when a business relationship is established or an occasional transaction is carried out. Regulation 28 then requires the firm to identify the client and verify that identity, identify any beneficial owner, and understand the purpose and intended nature of the relationship.
Verification is a precondition of acting, not a file-closing formality. Where the risk is high, regulation 33 adds enhanced due diligence and enhanced ongoing monitoring on top.
| Trigger | What the firm must establish | Source |
|---|---|---|
| New business relationship | Client identity verified before the relationship is established | MLR 2017 reg 27 and 28 |
| Corporate or trust client | Beneficial owners above the 25% test, and control | MLR 2017 reg 28 |
| High-risk client, matter or jurisdiction | Enhanced due diligence and enhanced ongoing monitoring | MLR 2017 reg 33 |
| Australian designated service | Initial customer due diligence before the service is provided | AML/CTF Act 2006, table 6 |
| Any matter involving client money | Origin and legitimacy of funds understood before receipt | SRA Accounts Rules, rule 3 |
Why is the client account the highest-value target?
Because it converts a law firm into a payment channel with a professional name attached to it. The SRA's sectoral risk assessment describes client accounts as capable of transferring funds through a regulated legal services provider in a way that potentially obscures the origin, destination or purpose of those funds. Risk rises where money passes through with no clear connection to the legal service being delivered.
That is why rule 3.3 of the SRA Accounts Rules is written as an absolute: a client account must not be used to provide banking facilities to clients or third parties, and payments in, transfers and withdrawals must all relate to the delivery of regulated services. An unexplained inbound payment is therefore a rule breach before anyone reaches the question of whether the money is criminal.
Two operational consequences follow. Funds should not be accepted into the client account before the origin and legitimacy of those funds are understood. And the paper trail has to survive scrutiny later, since rule 13.1 requires accounting records to be stored securely and retained for at least six years.
How do nominee and shelf structures use a firm as cover?
The point of a nominee is that the verified person is not the interested person. A firm can complete a technically correct identity check on a director, a settlor or a signatory and still have no idea who benefits. Under the Money Laundering Regulations 2017, a beneficial owner of a body corporate is an individual who directly or indirectly owns more than 25% of the shares or voting rights, or who otherwise controls the entity, and the same 25% test applies to a partnership's capital, profits or voting rights.
Shelf companies compress the problem further. A company sold with an existing incorporation date inherits an apparent history it never lived, which is precisely why AUSTRAC lists the sale or transfer of a shelf company as a designated service in its own right. Registered office and nominee director services, items 7 to 9 of the same table, complete the set.
Resolving this needs ownership data rather than document checks, which is the gap know your business screening fills. Our explainer on shell companies covers the structures themselves in more detail.
What does an evidenced source of funds check look like?
It looks like scrutiny, not collection. The SRA's thematic review of source of funds and source of wealth compliance, published on 5 November 2025, reviewed 5,873 files across 833 firms in the 2024 to 2025 period. The findings describe a sector that gathers paperwork and then does not read it.
| Finding, 2024 to 2025 file review | Share of files |
|---|---|
| No source of funds check at all | 11% (648 files) |
| Source of funds documentation held but inadequately scrutinised | 18% |
| Source of funds on the ledger not supported by the evidence collected | 8% |
| Firms given feedback on deficiencies | 41% of firms |
That last 8% is the finding a compliance officer should worry about, because it means the ledger and the evidence tell different stories about the same money. The SRA also reported 42 suspicious activity reports submitted to the National Crime Agency between April 2023 and April 2025, of which 73% related to conveyancing transactions. Late or unexplained changes to how a transaction is funded are treated as a red flag in their own right.
Which client identity red flags should a fee earner escalate?
Escalation triggers work better when they are tied to observed behaviour rather than to a risk score. The recurring patterns in legal practice are consistent across supervisors.
- The client resists giving beneficial ownership detail, or supplies it only after repeated requests.
- The structure is more complex than the transaction needs, with no commercial explanation for the extra layers.
- Identity documents are inconsistent between matters, or between the client and the entity they claim to represent.
- Funds arrive from a party who is not the client, or from a jurisdiction with no connection to the matter.
- The funding route changes late in the transaction, particularly close to completion.
- Instructions arrive with pressure to skip onboarding steps, often justified by a deadline.
- The entity was created or restructured shortly before the instruction.
None of these is proof of fraud. Each is a reason to pause and verify rather than proceed and hope.
What happens to a firm whose identity checks fail?
The financial exposure changed in 2024. The Economic Crime and Corporate Transparency Act 2023 removed the statutory cap on the Law Society's fining power as delegated to the SRA, for disciplinary matters relating to economic crime. Before that change the SRA's own limit was £25,000.
Recent settlements show what the enforcement pattern rewards and punishes. In a regulatory settlement agreement dated 24 September 2025, Vine Orchards LLP was fined £20,234 plus £600 in costs. The findings included failing to hold an appropriate firm-wide risk assessment under regulation 18(2) between 1 October 2017 and 8 May 2025, and, in three of six files reviewed, failing to conduct ongoing monitoring including scrutiny of the client's source of funds under regulation 28(11)(a).
That last finding is the important one for identity fraud. The firm was not accused of missing a forged passport. It was penalised for not looking again after onboarding.
How should identity verification fit into matter opening?
Sequence it so that nothing irreversible happens before the checks clear. Verify the individual against authoritative sources rather than a document image alone, then resolve the entity behind them, then screen every party the retainer touches. That means the client, the beneficial owners, the directors and any third party funding the transaction, not just the name on the engagement letter.
Screening is not a one-off event either. Ownership changes, sanctions listings and adverse media all move after onboarding, which is what makes ongoing monitoring and periodic rescreening part of the control rather than an optional extra. For higher-risk matters, enhanced due diligence adds the source of wealth work that regulation 33 expects. MemberCheck combines identity verification with PEP and sanctions screening so the same party is checked once against both.
Two boundaries are worth naming. Fraud that sits in the transaction rather than in the retainer, principally seller and title impersonation, is covered in our companion piece on identity fraud in real estate. Australian firms preparing for 1 July 2026 should read the Tranche 2 material for lawyers, and definitions sit in the glossary of AML terms.



