SRA Inspections: What to Expect and How to Prepare
A practical guide to SRA inspections and firm reviews — what triggers them, what the SRA looks at, how to prepare, and how to respond to findings effectively.
Obiter Editorial Team
Published 15 February 2025
The SRA inspects law firms. It always has — but the nature, frequency, and sophistication of those inspections has changed significantly since the introduction of the Standards and Regulations in 2019 and the SRA’s ongoing investment in data-driven supervision. Understanding what triggers an inspection, what the SRA looks at when it arrives, and how to present your firm in the best possible light is essential compliance knowledge for every COLP, COFA, and managing partner.
This article walks through the full lifecycle of an SRA inspection: what prompts them, how they are conducted, what happens afterwards, and how to build the kind of firm where an inspection — however unexpected — is an inconvenience rather than a catastrophe.
What Is an SRA Inspection?
The SRA uses several terms for its supervisory visits, including “firm visits,” “targeted reviews,” “thematic reviews,” and — in more serious cases — “investigations.” The terminology matters because the nature of the engagement differs:
- Supervisory visits are routine or risk-based checks. They are not triggered by a specific allegation and do not carry the presumption that something is wrong.
- Targeted reviews focus on a specific area of concern — often identified through data analysis or a complaint — and are more focused in scope.
- Thematic reviews examine a compliance area across a sample of firms (such as the SRA’s reviews of conveyancing practice or AML compliance) and are not targeted at individual firms but at sector-wide patterns.
- Investigations are triggered by credible evidence of a specific breach and are a precursor to formal enforcement action.
Most firms, over the course of their existence, will experience a supervisory or targeted visit. Only a smaller proportion will face a full investigation — though that proportion increases if supervisory visits reveal concerns that are not adequately addressed.
What Triggers an SRA Visit?
The SRA is not resourced to visit every firm every year. It uses a risk-based approach to prioritise its supervisory activity, drawing on several sources of intelligence.
Data Analysis
The SRA holds significant data on every authorised firm, including financial information from annual renewal returns, Accountant’s Reports, and thematic review responses. It uses this data to identify outliers — firms whose profile departs significantly from the norm for their size and practice area. A firm that holds unusually large amounts of client money relative to its fee income, or whose Accountant’s Report is qualified, or that has had a complaint upheld by the Legal Ombudsman, will generate a higher risk score.
In 2024, the SRA published its first detailed account of how it uses data in supervision, confirming that algorithmic risk scoring plays a significant role in targeting visits.
Complaints
A complaint to the Legal Ombudsman that is upheld, or a direct complaint to the SRA about a firm, can trigger a visit. The SRA does not automatically visit every firm that receives a complaint, but patterns of complaints — multiple complaints about the same firm, or complaints that raise systemic concerns rather than individual service failures — attract attention.
Self-Reports
The SRA Standards and Regulations require firms to self-report certain matters promptly. These include material breaches of the Accounts Rules, financial instability, and regulatory matters such as a conviction or adverse finding against a manager. Self-reports are taken seriously: a firm that self-reports promptly and demonstrates a coherent remedial action is treated materially differently from one that conceals a problem until it is discovered.
Thematic Programmes
Each year, the SRA identifies priority compliance themes and selects a sample of firms for targeted visits. Recent themes have included AML compliance, costs transparency, and the supervision of junior fee earners. If your firm falls within the sample for a thematic programme, you will receive advance notice and a list of the documents and information you will need to provide.
Referrals and Whistleblowing
Third parties — other solicitors, former employees, clients, or members of the public — can refer matters to the SRA. Whistleblowing referrals from inside a firm carry particular weight because the informant is likely to have specific, detailed knowledge.
How an SRA Inspection Is Conducted
Desk-Based Reviews
Many SRA reviews begin as desk-based exercises. The SRA sends a written request for information — typically a standard questionnaire covering areas such as governance, AML, financial management, and client care — and asks the firm to respond within a specified period (usually 28 days).
Desk-based reviews are often the precursor to a visit. If the written responses are satisfactory and consistent with the SRA’s other data, the review may conclude without a visit. If the responses raise concerns, or if there are inconsistencies between the questionnaire responses and other information the SRA holds, a visit is likely to follow.
On-Site Visits
An on-site visit typically involves two SRA officers spending one to three days at the firm’s premises. The visit will be pre-notified, usually with a few weeks’ notice, and will come with a list of documents the SRA expects to review.
During the visit, SRA officers will:
- Review a sample of client matter files, usually selected from specified practice areas
- Examine client account records, including reconciliations and ledger entries
- Review AML procedures and a sample of AML checks conducted on clients
- Speak with the COLP, COFA, and potentially other fee earners
- Review governance documentation — terms of business, conflict-checking records, supervision logs
- Check compliance with the Transparency Rules (published pricing information)
The tone of a well-conducted visit is professional and cooperative. SRA officers are not looking to catch the firm out — they are looking to assess whether the firm’s systems and culture are consistent with the regulatory framework. Firms that approach the visit with transparency and can produce documentation promptly create a materially better impression than firms that are disorganised, defensive, or evasive.
File Reviews
The file review is the most detailed and time-consuming part of an on-site visit. The SRA will typically review 15 to 30 files across the firm’s main practice areas, looking for evidence of:
- Compliant client care letters (including costs information and complaints procedure)
- Adequate matter planning and supervision
- Proper management of conflicts of interest
- Compliance with specific regulatory obligations (AML checks, LAA requirements, etc.)
- Accurate time recording and billing
- Appropriate communication with clients
Files that are well-organised, properly documented, and demonstrate a clear record of professional advice and client communication will satisfy the SRA officers. Files where there are gaps — no attendance notes, incomplete AML records, unsigned client care letters — will prompt further questions and potentially elevate the review’s risk rating.
Preparing for an SRA Inspection
Build Compliance into Daily Practice
The most effective preparation for an SRA inspection is to run the firm compliantly every day, not to scramble to create documentation when a visit is announced. Retrospectively drafting attendance notes, completing AML records, or reconstructing supervision logs is problematic both ethically (it misrepresents what actually happened) and practically (SRA officers are experienced at spotting documents that have been recently created for a visit).
Conduct a Self-Assessment
Before the visit, the COLP and COFA should conduct a self-assessment against the SRA’s published visit criteria. The SRA publishes worked examples, thematic review outcomes, and guidance notes that give a clear picture of what it expects. A realistic self-assessment will identify gaps that can be addressed in the time available before the visit.
Organise Your Documentation
The SRA will ask for specific documentation. Common requirements include:
- AML policy, risk assessment, and training records
- Client money reconciliations for the most recent 12 months
- Accountant’s Report for the most recent financial year
- Conflict-checking procedure and evidence of checks conducted
- Supervision policy and evidence of its application
- Client complaints log and evidence of resolution
- Transparency Rules compliance (screenshot or URL of pricing information published online)
- Business continuity plan
Having these documents readily available — not scattered across different systems or stored in formats that are difficult to retrieve — saves time and signals good organisation.
Brief Key Staff
The COLP and COFA should brief the partners and senior staff who will be involved in the visit. The brief should cover:
- What the SRA is likely to ask about
- The firm’s approach to specific compliance areas (particularly any recent changes)
- How to respond to questions — honestly and directly, without speculating or guessing
- Who to refer complex questions to if they arise during the visit
Staff should understand that they should not volunteer information beyond what is asked, but must not mislead or withhold information. If an officer asks a question that reveals a compliance gap, the appropriate response is to acknowledge it and explain what the firm is doing to address it — not to deflect or minimise.
After the Visit: Responding to Findings
The Outcome Letter
Following the visit, the SRA will issue an outcome letter setting out its findings. The letter will typically:
- Summarise the scope of the review
- Identify any compliance concerns found
- Rate the firm’s overall compliance as satisfactory, requiring improvement, or of significant concern
- Specify any actions the firm is required to take, with deadlines
An outcome letter is not a formal enforcement action. It is an opportunity to demonstrate that the firm takes compliance seriously and is capable of self-correcting. Firms that respond to outcome letters with a detailed, credible action plan — and then implement it — rarely face formal enforcement proceedings arising from the same issues.
When Enforcement Follows
If the SRA’s findings suggest serious or persistent breaches, the outcome letter may announce that the matter is being referred for investigation. At that point, the firm is moving into the enforcement process, where formal notices, conditions on practising certificates, fines, and SDT referrals become possible.
In that situation, the firm should take immediate legal advice. Responding to a formal investigation without specialist regulatory advice is a significant risk, and there are a number of solicitor regulatory law firms and barristers’ chambers with specific expertise in this area.
Appealing SRA Decisions
Firms and individuals can challenge SRA decisions through the internal process (a waiver or appeal request to the SRA itself) and, ultimately, through the Solicitors Disciplinary Tribunal or the Legal Services Board. The SDT is an independent body and takes a fresh look at the evidence — it does not simply review the SRA’s decision for procedural correctness.
Building Inspection-Ready Compliance
The firms that find SRA visits least disruptive are those that have built compliance into their operational rhythms rather than treating it as a periodic exercise. Key elements of an inspection-ready firm include:
- A genuinely empowered COLP and COFA who have the authority, resources, and information they need to do their jobs
- Documented systems for every compliance-critical process — AML, conflicts, supervision, billing, complaints
- Regular internal audits that identify issues before the SRA does
- A culture of self-reporting where fee earners know that raising a concern early is rewarded, not penalised
- Current, accurate matter files that tell the story of every client relationship clearly and completely
An SRA visit to a firm with these characteristics is typically completed within a day or two, produces a satisfactory outcome letter, and is closed without further action.
Obiter reduces inspection risk by keeping matter files complete, time records accurate, and administrative tasks documented — so when the SRA asks to review a file, there are attendance notes, billing records, and client communications in place. Firms using Obiter spend less time reconstructing their compliance story and more time running their practice. Try Obiter free for 14 days at obiteros.com.
Topics:
Ready to reclaim 12+ hours a week?
See how Obiter handles your legal admin so you can focus on advising clients.