AML risk assessment for law firms comes in two layers, and mixing them up is the most common reason a firm gets criticised for something it thought it had done. One covers the practice as a whole. The other covers a single client on a single matter. You need both, and they do different jobs.
This is a practical guide to the second one, the client and matter assessment, and to what a supervisor is actually looking for when they ask to see it. It is market commentary and a compliance overview, not legal advice.
The two layers, and why the difference matters
The firm-wide assessment looks at your practice: the kinds of client you act for, the countries you deal with, the services you offer, how you take instructions, and how money moves. It is written once and reviewed as the firm changes.
The client and matter assessment applies that thinking to one retainer. It asks whether this client, doing this piece of work, in this way, presents a risk that needs more than your standard checks.
Firms that get into difficulty usually have the first and not the second. They can produce a considered document about the practice, and nothing at all on the individual file. A supervisor asking about a specific matter is asking about the second layer.
What the rules actually require
Three points are worth being precise about, because the common summary is a little stronger than the rule.
The due diligence must match the risk. The money laundering regulations require the checks you apply, and how far you take them, to be appropriate to the risk. That has to reflect both your firm-wide assessment and the risk in the individual case.
Three factors are named. You must consider, among other things, the purpose of the account, transaction or business relationship; the level of assets involved or the size of the transaction; and the regularity and duration of the relationship. Those three are not a suggestion, and a form that never asks about the purpose of the retainer is missing the first of them.
You must be able to demonstrate it. This is the requirement that does the real work. The regulations do not use the word "written". What they say is that you must be able to show your supervisory authority that the measures you took were appropriate. An assessment nobody recorded cannot be shown to anybody, which is why it has to be written down in practice.
That distinction is worth holding onto. The obligation is not paperwork for its own sake. It is being able to prove, later, that what you did followed from what you found.
The mistake that costs firms most
A rating on its own proves nothing.
Plenty of firms complete a form, tick "medium", sign it and file it. If the rating is not visibly connected to what you then did, you have recorded a conclusion without the reasoning, and the requirement is precisely that the due diligence reflects the risk.
The fix is unglamorous: keep the rating and the measures on the same page. If you rated a matter high because a politically exposed person is involved, the same document should show that you obtained source of wealth evidence, that senior management approved acting, and that you set a closer review interval. If the rating suggested a measure you did not take, write down why. An honest note explaining a judgement is worth considerably more than a tidy form that hides one.
What to look for on the file
A few things reliably indicate an assessment that will hold up.
The purpose of the retainer is stated in the client's terms, and somebody has asked whether it makes commercial sense for this client.
The source of funds is recorded and it fits what you know about the person. A mismatch between the money and the client is the single most common indicator, and it is visible early if anybody looks.
Beneficial owners are identified where the client is a company, not merely noted as "director confirmed".
The assessment is dated at or before the start of the work. One written months later, during a file review, cannot have informed the due diligence that was applied, and a supervisor will make that point.
Unrated matters can be listed. This is the one most firms cannot do on demand, and it is the first question an inspection asks.
Unrated is not low risk
That last point deserves its own heading, because it is where the gap usually is.
A matter with no rating has not been assessed as safe. It has not been assessed. Those are entirely different positions, and only one of them is a defence.
Being able to answer "show me every matter with no risk rating" in one go is worth more than any individual form. If that question takes a week of opening files, the honest answer is that nobody knows. Writford's compliance tools treat an unrated matter as exactly that gap rather than folding it in with the low-risk ones, and the risk register lists them.
Practical steps
Set the review triggers rather than the review dates. A matter changes when the scope changes, when funds arrive from somewhere unexpected, or when a new party appears. Those events should prompt a fresh look, not the calendar alone.
Choose intervals you can meet. A published commitment you miss is worse than a longer one you keep.
Keep it with the matter. An assessment in a separate compliance folder, disconnected from the file it concerns, is harder to produce and easier to forget.
Our free legal template library includes a client and matter risk assessment built around the three named factors, which keeps the rating and the measures on the same page. If you would rather start from your own form, the checklist above is the part worth copying.
For the wider picture of what a supervisor asks for, our guide to SRA accounts rules software covers the client money side of the same inspection.