Policy Pros
Written by Joanne Hughes, Policy & Compliance SpecialistLast reviewed

Policies for Solicitors and Law Firms

This page is for SRA-regulated firms in England and Wales that need their compliance documentation written properly, from a sole practitioner to a multi-office practice. Policy Pros writes bespoke COLP and COFA frameworks, AML documentation, Accounts Rules procedures and the office policies behind them.

Bespoke, audit-ready policies from £65 + VAT per document. Get a quote or call 020 3951 2875 for a free scoping conversation.

Policies Law Firms Need

Required by the Rules

  • Governance, Systems and Controls Documentation - the Code of Conduct for Firms requires effective governance arrangements and records that demonstrate compliance
  • COLP and COFA Frameworks - compliance plans, breach registers and reporting procedures behind the two mandatory officer roles
  • Firm-Wide AML Risk Assessment - a written, up-to-date assessment under regulation 18 for every in-scope firm
  • AML Policies, Controls and Procedures - proportionate, senior-management approved and maintained in writing under regulation 19, with an MLRO appointed
  • Client Money Procedures - separation of client money, three-way reconciliations at least every five weeks with sign-off, and six years of accounting records
  • Health and Safety Policy Statement - required in writing with 5 or more employees

Expected by the SRA, Insurers and Clients

  • Client Care and Complaints Procedure - the front door of every retainer and the first document a dissatisfied client tests
  • Cyber Incident Response Plan - covering both 72-hour ICO breach reporting and prompt SRA reporting where client money or confidentiality is hit
  • Conflicts and Confidentiality Procedures - evidencing how the firm identifies and manages conflicts
  • Fraud Prevention Procedures - built on the government's six principles, and increasingly requested by large clients' supplier due diligence
  • Continuing Competence Records - supporting the annual declaration every solicitor now makes

The Code for Firms Makes Systems a Duty

The SRA Code of Conduct for Firms requires effective governance structures, systems and controls, and, just as importantly, records that demonstrate compliance. Managers are jointly responsible where management is shared, and every authorised firm must have a COLP and a COFA taking all reasonable steps to ensure compliance and reporting serious breaches promptly.

In a small firm those roles often sit with people who also run the practice, which makes the documentation the difference between a role held on paper and a role performed. A compliance plan, a live breach register and a reporting procedure are the working minimum.

AML Is Where the SRA Is Looking

The SRA's AML supervision has scaled up sharply, with hundreds of onsite inspections and desk-based reviews a year and a large share of inspected firms found short of full compliance. The starting points are the scope rules, the written firm-wide risk assessment and the policies, controls and procedures that flow from it, with an appointed MLRO.

Two changes raise the stakes. Since March 2024 the SRA holds unlimited fining powers for economic crime related breaches, and the 2026 amendments to the Money Laundering Regulations, in force since 30 June 2026, reworked enhanced due diligence, converted thresholds to sterling and added pooled client account provisions that speak directly to law firms. Risk assessments and CDD procedures written against the old wording are the obvious review point, and our guide to which businesses need an AML policy covers the wider framework.

Client Money Runs on a Reconciliation Rhythm

The SRA Accounts Rules are short but relentless: client money kept separate, breaches corrected promptly on discovery, client ledgers and cash books maintained, a three-way reconciliation at least every five weeks signed off by the COFA or a manager, records kept six years, and an accountant's report obtained where required.

The SRA's consumer protection review is also consulting on stronger client money safeguards, so documented checks and balances around who can move money are becoming an expectation rather than a distinguishing feature. Written procedures that match how your accounts team actually works are what an inspection tests.

Fraud, Cyber and the Duties Around the Edges

The failure to prevent fraud offence, in force since September 2025, applies to large organisations, but its six prevention principles have become the template large clients use to question every supplier, law firms included; our failure to prevent fraud guide covers the framework. A cyber incident response plan needs to serve two clocks at once: the ICO's 72 hours for reportable personal data breaches, and the SRA's expectation of prompt reports where client money or confidentiality is affected.

Continuing competence rounds out the set: every solicitor declares annually that development needs have been addressed, and the records behind that declaration are the firm's to keep.

What Policy Pros Delivers

Every document is written around your practice areas, your structure and your risk profile, not adapted from a City compliance manual. You get plain-English documents on professionally branded templates, consistent with each other and ready for an SRA inspection or an insurer's proposal form.

  • COLP and COFA compliance plans, breach registers and reporting procedures
  • AML risk assessments, policies, controls and procedures updated for the 2026 amendments
  • Accounts procedures, client care letters, complaints and conflicts documentation
  • Cyber incident response, fraud prevention and office policies

How to Get Started

Tell us your practice areas, your headcount and what has prompted the request, whether that is an SRA visit, an insurer question or a gap you already know about. We will come back with a fixed-price quote and a realistic timescale, usually the same working day.

Get a quote or call 020 3951 2875. Accountancy practices have a parallel page at policies for accountants and professional services.

Frequently Asked Questions

What documents do a COLP and COFA actually need?

A compliance plan mapping the firm's obligations, a live breach register with a severity assessment route, reporting procedures for prompt SRA notification of serious breaches, and the records the Code requires to demonstrate compliance. The COFA additionally relies on the reconciliation and accounts procedures under the Accounts Rules.

Which law firms need an AML risk assessment?

Firms in scope of the Money Laundering Regulations, mainly through work as independent legal professionals on financial or property transactions or as trust and company service providers. In-scope firms need a written firm-wide risk assessment, proportionate policies, controls and procedures, and a nominated officer, all kept current with the June 2026 amendments.

How often must client account reconciliations be done?

At least every five weeks, as a three-way reconciliation of bank statements against the cash book and client ledger total, signed off by the COFA or a manager of the firm. Accounting records must be retained for at least six years, and breaches corrected promptly on discovery.

Does the failure to prevent fraud offence apply to small firms?

The offence itself applies to large organisations meeting two of three thresholds: more than 250 employees, £36 million turnover or £18 million balance sheet. Smaller firms feel it indirectly, because large clients' due diligence now asks suppliers, including law firms, to evidence fraud prevention procedures built on the government's six principles.

Trustpilot Reviews - 5 Stars