Insights

The SRA Sectoral Risk Assessment and the confidence gap I see

Four questions to test whether your firm could actually prove it is on top of its risk, and what the pause before you answer says.

Eloise Butterworth · 8 September 2026 · a five-minute read

In August 2026, the SRA published its updated sectoral risk assessment. If your firm's response was to open the firm-wide risk assessment, change the date on the front page, tweak the emerging risks and file it away again - you've just told me something important. Not about your risk. About your confidence.

That's the real story here. Not what the SRA has flagged this time round – or what they’ve removed. The gap between firms who think they're on top of their risk, and firms who could actually prove it if I sat down opposite them and asked.

I'd like to put that gap to the test. Four questions. See how confidently you can answer them.

1. What do you actually mean by "updated"?

When a policy, control or procedure gets "updated," what happened? Be honest.

Was it properly scrutinised against the standard the regulator expects? Or was it redated, lightly tweaked, and reuploaded.

Those are not the same exercise, and the difference matters more than most firms admit. A review that isn't rigorous doesn't just fail to improve the document - it can quietly dilute it. Each pass softens something, drops a line that felt awkward, waters down a commitment that was inconvenient to keep, misses out granular data because you don’t have it at your fingertips. Nobody intends that. It happens anyway, review after review, until the document says less than it did the first time you wrote it.

For most policies, that's a bad habit. For your firm-wide risk assessment, it's a legal requirement being slowly hollowed out. If your last review can't tell you what changed and why, it wasn't a review. It was a formality.

2. Would a stranger understand your firm from it?

Hand your firm-wide risk assessment to someone who knows nothing about your firm. Not a fellow partner, not your COLP - an outsider. Me, say.

Could they read it and understand your firm? Your clients. The work you take on, and just as importantly, the work you turn away. Where your risk appetite actually sits, not where the policy claims it sits. Can your position be backed up by data, by evidence.

Would it tell me what controls you have - clearly, not implied? Who owns each one? How effective they are? And how you know that, on an ongoing basis, rather than asserting it once a year and hoping?

Most firm-wide risk assessments I read fail this test. They're accurate as far as they go. And many scrape through an SRA audit. They're just not honest about what they don't say. If yours needs you in the room to explain what it really means - it isn't doing its job.

3. Does it actually earn its keep?

Here's the harder question. Not "do you have a firm-wide risk assessment" - everyone has one if they are regulated for AML purposes. Does yours do anything? Does it serve you?

Does the data in it inform decisions your firm actually makes? New service lines, new jurisdictions, new client types - does the risk assessment shape those conversations, or does someone update it afterwards to reflect what the Board already decided?

And does it run the other way too? When the board makes a call with risk implications, does that thinking feed back into the framework, or does the risk assessment sit in its own lane, disconnected from the strategic conversations happening one floor up?

If the honest answer is that your FWRA is a compliance artefact rather than a strategic one, you're carrying the cost of maintaining it without getting any of the value back. That's not a small inefficiency. That's a live risk tool sitting unused while the decisions that actually shape your risk profile get made somewhere else.

4. Are you leading, or just keeping up?

The SRA's update names some current and emerging risks: technology and the misuse of AI, passporting, cash intensive businesses and high street crime, global instability and uncertainty and company registration.

If you work in this space, and understand money laundering risk properly, none of these are new. I wouldn’t call them emerging either. They’ve well and truly emerged. These are risks firms have been wrestling with for a while. The SRA naming them isn't the moment they became real.

So here's the uncomfortable part. If your firm's risk posture moves only when the SRA publishes something, you're not keeping pace. You're behind, and the update just made that visible. Being reactive to a sectoral risk assessment doesn't put you on the front foot. It's usually proof you were already on the back one - that your own risk identification wasn't picking these things up before the regulator had to spell them out.

Agile risk management doesn't wait for an update. It's already looking at the risks your firm is actually exposed to, updating as the picture changes, regardless of the SRA's publishing calendar.

Where the gap shows up

It shows up in the pause before you answer one of these four questions. In the glance across the table to see who's going to field it. In the answer that starts confidently and trails off somewhere around "well, it depends what you mean by…"

That pause is the confidence gap. It's the space between a firm that's compliant on paper and a firm that could stand behind its risk framework if someone genuinely tested it.

The SRA's update is not the risk. It's the prompt. What you do with these four questions - properly, not as a box-ticking exercise - is the actual work.

So: could you answer all four, right now, without checking with anyone first?

If the honest answer is no, that's useful information. It tells you exactly where to start.

Could you answer all four? If the honest answer is no, the Confidence Snapshot was built for exactly this: a one-day read that turns unease into a list. Let's talk.
Eloise Butterworth
Get in touch

Let's talk about where you're trying to get to.

No pitch, no jargon, nothing open-ended. Email eloise@itsallthingsrisk.com, find All Things Risk on LinkedIn, or start with a fifteen-minute call.

Let's talk