On 29 June 2018 the Law Society launched version 6.1 of the 
Lexcel Standard. This implemented major changes to version 6 made necessary by recent developments in the fields of data protection and money laundering. To give firms time to get their houses in order, assessments against the new version will start on 1 November 2018. This article will consider the main changes for legal practices in relation to money laundering.
The changes were necessitated by the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations (AML) 2017 which repealed the 2007 regulations and implemented the 4th Money Laundering Directive. These should be read in conjunction with the Legal Sector Affinity Group AML guidance that was finalised in March 2018.
If you are familiar with the 2017 regulations and have updated your procedures to meet the additional requirements, then the changes to Lexcel should not cause you any concern. However, because some of the 2007 requirements have been retained, a significant number of firms (and their MLROs) have not seen any need to attend training on the new regulations.
Those adopting such an approach tend to keep an AML folder to demonstrate that they are on top of their obligations in this area. The folder may include a copy of the Legal Sector Affinity Group guidance, and perhaps the regulations themselves. What is missing is any evidence that this folder is a useful source of reference: no flagged pages, no highlighter pen, no well-thumbed pages, no underlining. There is nothing to indicate that these are working documents, referred to when tricky points arise, as they are bound to, from time to time, in a regulated practice. For example, it is always reassuring if the MLRO understands the requirements imposed by regulations 18 and 21.
Lexcel 6.1 introduces changes to sections three and six, but those are outside the scope of this article which will focus on the changes in section 5.13. Version 6 required firms to have a policy to ensure AML compliance. The new wording is more comprehensive and requires firms to have a policy “approved by senior management, to mitigate and manage money laundering and terrorist financing risks” before reverting to the old wording “and to ensure compliance with AML legislation”.
Although the requirement for senior management approval must be documented, the key change is the need ‘to mitigate and manage’ which sounds like a requirement for duly documented monitoring. This might include periodic reviews of the percentage of clients seen in the office and, for those not seen, the nature of additional ID checks completed. Or reviewing the nature of queries passed to the MLRO and how many resulted in Suspicious Activity Reports.
Bearing in mind how the definition of a Politically Exposed Person (PEP) has changed to include domestic PEPs and the different definition used in the Criminal Finance Act 2017, consider how well your potential exposure is identified and escalated to ensure that potential red flags are not overlooked.
Your file audit regime can play an important part. When auditing files, if you don’t do so already, check that the names on ID documents match the file name and that names on documents match those on the file and client ledger. Surprisingly they don’t always. In a recent fraud case, Pemberton Greenish v Henry, the very experienced fee earner opened a file in the name of one of two clients because she knew that opening up the file in joint names would flag up the missing ID for the other client.
Where funds are coming from third parties, such as the bank of mum and dad, do check that relevant evidence has been obtained. It is often requested once and then conveniently overlooked. On one matter, nearly £600,000 was being sent by the client’s father from Dubai. The fee earner obtained a bank statement showing where the funds were held but the name, address and account number had all been redacted, making the document completely useless. But the fee earner had still ticked the Source of Funds box!
At 5.13(a) another new requirement is the inclusion in your AML policy of “a documented practice-wide risk assessment (PWRA) that identifies and assesses the risks of money laundering and terrorist financing to which the practice is subject.” This has been taken almost word for word from regulation 18(1) of the AML regulations 2017.
Regulation 18(2) warns firms to take into account information made available to them by their supervisory authority. The SRA’s AML review of March 2018 found that only one-third of the 50 practices visited had a practice-wide risk assessment in place or in preparation. Over one year on from the introduction of the regulations, this risk assessment really should be in place.
Regulation 18(2) (b) lists the risk factors that should be taken into account. Following this, it is suggested that your PWRA should cover, inter alia, your client demographic and how well you know your clients; the risks inherent in the services you offer and the way they are delivered; the number and location of your offices; an analysis of payments into and out of client account (including cash payments); any SARs; and the results of the AML monitoring referred to above.
You must keep an up to date record of all steps taken to produce the PWRA which should be collated in a form that you would be happy to share with the SRA (as they might ask for it). See regulations 18(4) and (6). Of course, your Lexcel assessor might also be interested in seeing this evidence and may ask whether any risks identified have made it into your risk register or list of generic risks.
The requirements in the new section 5.13(h) in Lexcel closely mirror the obligations in section 21.1 (a) to (c) of the AML 2017. Whether they apply to your firm will depend on the size and nature of your practice. This, in turn, is likely to depend on the result of your PWRA but will be influenced by the number and location of your offices, the nature of your work and the number of staff employed. Guidance on these regulations can be found in the Affinity Group guidance. If you don’t think section 5.13(h) applies to your firm, you must document your reasoning.
When facing your next assessment, expect your Lexcel assessor to ask staff how money laundering risks are managed. They may also wish to interview those responsible for making Suspicious Activity Reports and to establish why your MLRO was the right person for the job.
Finally, do note the new requirement in section 5.18(i) which concerns the annual review of risk data. Your analysis must now include the risk of non-compliance with your policy to manage personal data. Although this ties in with the revised data protection requirements, there will be some overlap with your AML compliance procedures given the consequential personal data held.
The Standard has been amended to reflect changes in the law. While the well-managed practice will have nothing to fear, the SRA’s recent AML review showed that many firms still have much to do. It is to be hoped that the changes made to Lexcel in version 6.1 will help to drive compliance in this respect.
For more information on this article, please contact:
Grahame Davidson, Director, Aon UK Limited
On 0117 9485117
Whilst care has been taken in the production of this article and the information contained within it has been obtained from sources that Aon UK Limited believes to be reliable, Aon UK Limited does not warrant, represent or guarantee the accuracy, adequacy, completeness or fitness for any purpose of the article or any part of it and can accept no liability for any loss incurred in any way whatsoever by any person who may rely on it. In any case any recipient shall be entirely responsible for the use to which it puts this article.
This article has been compiled using information available to us up to 01 September 2018.