Compliance Officer for Finance and Administration COFA: Role Guide
A complete guide to the COFA role in law firms — covering SRA duties, client account obligations, reporting requirements, and best practices for compliance officers in 2025.
Obiter Editorial Team
Published 15 February 2025
The Compliance Officer for Finance and Administration is the person in a law firm who is accountable — personally, to the SRA — for the firm’s financial compliance. In an environment where mishandling client money remains the primary cause of SRA interventions, and where the financial health of a firm can deteriorate rapidly if warning signs are missed, the COFA carries one of the most consequential compliance responsibilities in legal services.
This guide covers everything you need to know about the COFA role: the regulatory basis, the specific duties, the overlap with the COLP, common challenges, and practical guidance for discharging the role effectively.
The Regulatory Foundation
Where the COFA Role Comes From
Every SRA-authorised firm must designate a COFA under the SRA Authorisation of Firms Rules. The requirement was introduced as part of the 2011 regulatory reforms that also introduced alternative business structures, and was carried through into the 2019 Standards and Regulations framework.
The COFA’s obligation is set out in Rule 8.6 of the Code of Conduct for Firms: the firm must ensure that its COFA takes all reasonable steps to record and report to the SRA any failure to comply with the SRA Accounts Rules.
The Accounts Rules obligation is the COFA’s primary focus, but it sits within the broader context of the firm’s financial health. A COFA who is alert to Accounts Rules compliance but oblivious to cashflow problems, unreconciled differences, or unexplained transactions is not doing the full job.
Approval by the SRA
Like the COLP, the COFA must be approved by the SRA before they can take up the role. The nominated individual must be a manager or employee of the firm. Unlike the COLP, the COFA does not need to be an authorised person — a qualified accountant who is a manager or employee of the firm can serve as COFA.
In practice, the COFA in a smaller firm is often a solicitor partner who also holds fee-earning responsibilities. In a larger firm, the COFA is more likely to be the firm’s finance director, head of accounts, or a senior accounts manager. In either case, the individual must have a thorough understanding of the SRA Accounts Rules and the authority to enforce them.
The COFA Cannot Be the COLP
It is worth noting that while the COLP and COFA roles can be held by the same person in very small firms (subject to the SRA agreeing this is appropriate given the firm’s size and risk profile), the SRA generally expects them to be separate individuals. The separation creates an independent check — the COLP overseeing general regulatory compliance while the COFA focuses on financial compliance — and reduces the concentration of regulatory responsibility in a single person.
Core Duties of the COFA
Monitoring Accounts Rules Compliance
The COFA’s day-to-day function is to monitor the firm’s compliance with the SRA Accounts Rules and to identify any failures. This requires:
- Reviewing reconciliations: the COFA should review every client account reconciliation, not simply sign off on it. This means looking at the underlying figures, understanding how any differences arose, and satisfying themselves that the reconciliation is accurate.
- Reviewing the Accountant’s Report: the annual Accountant’s Report is the external check on the firm’s Accounts Rules compliance. The COFA should review the report carefully, discuss any findings with the reporting accountant, and — where the report is qualified — take prompt action to address the issues identified.
- Reviewing unusual transactions: large, unusual, or unexplained transactions in the client account should trigger scrutiny. The COFA should have a process for identifying and reviewing such transactions, particularly where they involve amounts significantly above the firm’s normal transaction sizes.
- Monitoring residual balances: the COFA should maintain oversight of unspent client balances on closed matters and ensure that the firm has a documented process for returning or (where necessary) paying residual balances to the SRA.
Reporting to the SRA
The COFA must report to the SRA any failure to comply with the Accounts Rules that falls within the scope of the reporting obligation. The key question is whether the failure is material — whether it is the kind of breach that the SRA would expect to be told about.
Material failures that typically require reporting include:
- Misappropriation of client funds (however discovered)
- Significant shortfalls in the client account — meaning the aggregate of individual client ledger balances exceeds the actual client account balance
- Systematic failure to reconcile the client account
- A qualified Accountant’s Report disclosing unremedied breaches
- Failure to bank client money promptly (if it is a pattern rather than an isolated incident)
- Drawing costs from client account without a bill having been delivered (again, if systemic)
Minor, isolated, promptly-remedied technical breaches — a payment banked a day late, a trivial ledger error — generally do not require reporting, but should still be recorded on the compliance issues log.
Ensuring Adequate Accounts Procedures
Beyond monitoring and reporting, the COFA is responsible for ensuring that the firm has adequate financial procedures to support Accounts Rules compliance. This includes:
- A documented accounts procedure manual that all relevant staff are trained on
- Clear processes for receiving and banking client money
- Segregation of duties between those who authorise payments and those who maintain ledgers
- Procedures for identifying and handling mixed payments
- A written interest policy
- A procedure for handling residual client balances
The procedure manual does not need to be lengthy, but it does need to be current, accurate, and actually used. A COFA who can produce a well-drafted accounts manual but cannot demonstrate that staff follow it is unlikely to satisfy an SRA reviewer.
The COFA and the Reporting Accountant
The Annual Accountant’s Report
The reporting accountant’s annual examination is the external counterpart to the COFA’s internal oversight. The accountant examines the firm’s client account records for the period and prepares an Accountant’s Report confirming whether the firm has complied with the Accounts Rules.
If the accountant identifies unremedied breaches, they are obliged to report them to the SRA — not just to the firm. This means that a COFA who conceals a breach from the reporting accountant faces a double risk: the breach is likely to be discovered anyway, and the concealment will be treated as an aggravating factor.
The COFA should work constructively with the reporting accountant, providing full access to records and responding promptly to any queries. If the accountant identifies an issue during the examination, addressing it before the report is finalised is far preferable to having it disclosed in a qualified report.
Choosing the Right Accountant
The reporting accountant must be independent of the firm. They cannot be a current employee or a person who has had a significant involvement in the firm’s accounts during the period under review. Beyond independence, COLPs and COFAs should look for an accountant who has specific experience of solicitors’ accounts — the Accounts Rules are technical, and a generalist accountant may miss issues that a specialist would catch.
Many firms use the same reporting accountant year after year. Continuity has value — an accountant who knows the firm’s systems and history is better placed to identify changes — but over time there is a risk that familiarity reduces scrutiny. A periodic change of reporting accountant, or a second-opinion review of the Accountant’s Report by an independent specialist, can be a useful safeguard.
The COFA and Anti-Money Laundering
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 impose specific obligations on law firms and their senior management. The COFA’s responsibilities intersect with AML compliance in several ways.
Unusual Financial Patterns as AML Red Flags
The COFA’s oversight of the client account puts them in a position to identify financial patterns that might indicate money laundering or fraud — unusual large deposits, complex chains of transactions, payments to unusual jurisdictions, or client funds that appear to exceed the apparent value of the underlying transaction.
Where the COFA identifies transactions or patterns that give rise to suspicion, they should report their concerns to the firm’s MLRO, who will assess whether an external suspicious activity report (SAR) is required.
Record-Keeping Under the MLR 2017
The MLR 2017 require firms to retain records of client due diligence and transactions for five years. The COFA should ensure that the firm’s financial records — client account ledgers, bank statements, transaction records — are retained in a format and for a period that satisfies both the Accounts Rules (six years) and the MLR 2017 (five years).
Practical Challenges in the COFA Role
The Fee-Earning COFA
In many smaller firms, the COFA is a solicitor who also carries a full caseload. The tension between fee-earning responsibilities and compliance oversight is real and persistent. A COFA who is under pressure to meet billing targets will struggle to give compliance the attention it deserves.
Firms that appoint fee-earning COLPs and COFAs need to be realistic about the time required for the compliance function and should provide protected time — not simply expect the individual to absorb the compliance work on top of their existing responsibilities.
Dealing with Non-Compliant Partners
The COFA will sometimes identify Accounts Rules failures that involve a partner or senior fee earner. This is one of the most challenging situations the COFA faces, because the consequences of raising the concern — potential reputational damage, personal conflict — can feel greater than the consequences of overlooking it.
The COFA must not overlook material breaches, regardless of who is involved. If a partner is drawing costs from client account without issuing bills, or if there are unexplained movements in client funds associated with a particular matter, the COFA must investigate and, if the concern is well-founded, report it. A COFA who fails to act because the breach involves a partner is exposed to personal enforcement action from the SRA.
Keeping Up with Regulatory Change
The SRA Accounts Rules are relatively stable, but the broader financial regulatory environment — including AML, economic crime, and financial crime prevention — changes regularly. The COFA needs to stay current with regulatory developments and ensure that the firm’s procedures are updated accordingly.
Key sources of regulatory updates include the SRA’s own website, the Law Society’s compliance updates, and specialist compliance publications such as those produced by the SRA’s Practice Finance team.
Interplay with the COLP
The COFA focuses on financial compliance; the COLP focuses on broader regulatory compliance. In practice, the two roles overlap significantly, and the COFA and COLP need to work closely together.
Matters that typically involve both roles include:
- Decisions about whether to report a breach to the SRA (the COFA may identify the financial dimension while the COLP assesses the broader regulatory context)
- AML compliance, where financial monitoring by the COFA and regulatory oversight by the COLP both contribute
- Preparing for SRA visits, where both the accounts records (COFA’s domain) and the regulatory systems (COLP’s domain) will be reviewed
- Reviewing the annual Accountant’s Report and deciding on any required remedial action
Many firms formalise the working relationship between the COLP and COFA by establishing a regular compliance committee — a monthly or quarterly meeting where both roles can review open issues, discuss upcoming regulatory changes, and agree on priorities.
Building an Effective Compliance Framework Around the COFA
The COFA role does not exist in isolation. It is most effective when it sits within a broader financial compliance framework that includes:
- Capable accounts staff who understand the Accounts Rules and apply them consistently
- Practice management software that supports Accounts Rules compliance — with features such as matter ledgers, automated reconciliation prompts, and alerts for residual balances
- Regular training for fee earners and accounts staff on Accounts Rules obligations
- A culture where compliance is valued — where fee earners raise concerns rather than hoping problems will go away, and where the COFA has the authority to investigate without interference
Obiter helps COFAs maintain oversight of client money by keeping matter records accurate and billing workflows orderly — reducing the risk of the ledger errors, underbilled matters, and cost transfer irregularities that lead to Accounts Rules breaches. With Obiter handling routine financial administration, COFAs can focus on the oversight and analysis that the role genuinely requires. Explore Obiter at obiteros.com.
Topics:
Ready to reclaim 12+ hours a week?
See how Obiter handles your legal admin so you can focus on advising clients.