← Back to all articles

Source of funds: still the most common AML failing, and why.

Source of funds remains one of the most common AML failings for UK law firms. What MLR 2017 requires, where firms fall short, and why the gap persists.

Jacob Styles · 1 July 2026 · 7 min read

Year after year, the same failing appears at or near the top of the Solicitors Regulation Authority's list of AML shortcomings: source of funds. It is one of the most heavily scrutinised areas in file reviews, one of the most frequently criticised, and, for a duty so central to the regime, one of the most misunderstood. The persistence of the problem is worth examining, because it tells you something about where firms genuinely go wrong.

What the rules actually require on source of funds.

Source of funds sits within the customer due diligence obligations of the Money Laundering Regulations 2017 (MLR 2017). Regulation 28 sets out what CDD involves: identifying and verifying the client, identifying beneficial owners, and, critically, a duty to "assess, and where appropriate obtain information on, the purpose and intended nature of the business relationship or occasional transaction" (MLR 2017, Reg 28(2)(c)). Where the risk warrants it, that extends to understanding where a client's money has come from.

Two related concepts are often confused, and we cover the distinction in full, with worked examples, in source of funds versus source of wealth:

  • Source of funds: where the specific money used in this transaction originated (for example, the proceeds of a named house sale, a documented inheritance, or a savings account with a traceable history).
  • Source of wealth: how the client accumulated their overall wealth in the first place.

MLR 2017 does not demand a forensic audit on every matter. It demands a risk-based response: the higher the money-laundering risk of the client and matter, the deeper the enquiry and the stronger the evidence required (MLR 2017, Reg 28; LSAG guidance). Enhanced due diligence, including establishing source of funds, is mandatory in higher-risk situations such as dealings involving politically exposed persons or high-risk third countries (MLR 2017, Reg 33).

How often UK firms get source of funds wrong.

The SRA's own figures give a precise picture, and they are worth stating exactly rather than as a vague range. Across the files it reviewed where a source-of-funds check was required, 5,026 files needed one. Of those: 10% had no source-of-funds check at all; among the files where documents had been gathered, 18% were not scrutinised once collected; and 8% contained source-of-funds information that did not match the client's ledger (SRA AML Annual Report 2024/25). Separately, firms received source-of-funds feedback in 41% of the onsite inspections and desk-based reviews the SRA carried out, and 20% of the files rated non-compliant had a source-of-funds issue specifically (SRA AML Annual Report 2024/25). These are five distinct, precisely defined figures, not one blended statistic, and each one describes a different point in the process where the check can fail.

A firm can ask where the money came from, accept the answer, and still fail, because it never tested or evidenced it.

The failings tend to cluster into a few recognisable types.

Asking but not evidencing.

The most common gap is not a total absence of enquiry; it is enquiry that leaves no trace. A fee-earner asks the client where the deposit came from, receives a plausible answer, and moves on. Nothing is recorded, no supporting document is obtained, and the file cannot demonstrate that any check happened at all. Under the SRA's approach, an undocumented check is, for practical purposes, no check.

Collecting documents without interrogating them.

A bank statement in the file is not the same as scrutiny of that statement. This is the specific gap behind the SRA's 18% figure above: documents were gathered, but nobody tested whether the money trail made sense, whether there were unexplained large credits, or whether the stated origin matched the documentary reality. Simply filing a statement, the "collect and forget" approach, does not satisfy the obligation.

Treating identity verification as source of funds.

Electronic identity checks and AML screening tools confirm who the client is. They say nothing about where their money came from. The SRA has been explicit that electronic identity verification is not a substitute for source-of-funds work or for a proper client and matter risk assessment. Conflating the two is a recurring, and penalised, mistake.

Applying the wrong depth of enquiry.

Because the duty is risk-based, some firms under-investigate genuinely high-risk matters while over-documenting low-risk ones, or apply a flat approach that ignores the risk rating entirely. Both miss the point: the level of scrutiny should track the assessed risk of the specific client and matter, as set by the client and matter risk assessment (see our piece on MLR 2017 Reg 28, explained).

Why the source-of-funds failing persists.

If the rule is well known, why does source of funds keep topping the list? Part of the answer is that it is genuinely effortful. Testing the origin of money is slower and more judgement-heavy than ticking an identity box, and it often surfaces at the point of a transaction when the client wants to complete quickly. Commercial pressure and compliance rigour pull in opposite directions.

There is also a stakes problem that firms underestimate. Failing to establish source of funds is not only a regulatory breach. Where funds turn out to be criminal property, a firm that failed to make proper enquiries can find itself exposed under the Proceeds of Crime Act 2002: the offences there do not require the firm to have known, only, in some circumstances, to have had grounds for suspicion it should have acted on. The source-of-funds check is, in effect, the firm's own defensive shield.

Why it matters.

Source of funds is the point where AML compliance stops being about paperwork and starts being about the actual purpose of the regime: keeping dirty money out of the legitimate economy. That is precisely why the SRA scrutinises it so hard, and why it remains the failing most likely to appear in an enforcement summary.

For any firm, the uncomfortable truth is that the checks it believes it performs and the checks it can evidence are often two different things. Closing that gap, recording the enquiry, interrogating the documents, and matching the depth of scrutiny to the risk, is not box-ticking. It is the difference between a defensible file and a finding.

Frequently asked questions.

What counts as evidence of source of funds?

A document that traces the specific money used in the transaction to a plausible, verifiable origin, for example a completion statement from a documented house sale, a probate grant for an inheritance, or account statements showing an accumulated savings history, together with a written note that someone actually checked the document against the client's stated account.

Is a bank statement on file enough to satisfy the source-of-funds duty?

No, on its own. The SRA's own data shows that even where documents were gathered, 18% were never scrutinised once collected. Holding the document is not the same as checking whether the money trail it shows actually makes sense.

Does verifying a client's identity also satisfy the source-of-funds requirement?

No. Identity verification confirms who the client is; it says nothing about where their money came from. The SRA treats conflating the two as a recurring compliance failing, not an acceptable shortcut.

When is enhanced source-of-funds scrutiny mandatory rather than risk-based?

Under Regulation 33 of the MLR 2017, enhanced due diligence, including deeper source-of-funds work, is mandatory in specific higher-risk situations, such as where a politically exposed person is involved or the matter touches a high-risk third country.

Sources.

Written by Jacob Styles. This article is educational and does not constitute legal advice. Regulatory positions should be verified against current SRA guidance and primary legislation.

Book a call.

A free 30-minute call. We'll walk through how Retibo works, what an SRA AML inspection looks for, and whether it fits the way your firm runs. No fee, no obligation, no sales pressure.

Book a callRead our security posture