Source of funds: proportionality in practice
Proportionality is not a synonym for less. It means the evidence you hold matches the risk you have recorded — and that you can show the link. Here are four worked examples from our independent file reviews, including the high-value case where a bank statement alone was accepted, and the one where it should never have been.
Two firms, two files, one bank statement in each. In the first, the statement is exactly the right evidence and the file is sound. In the second, the same document is the whole of the source-of-funds file and it is a High-severity finding. Nothing about the paper differs. What differs is the risk the firm recorded, and whether anyone wrote down why this evidence was enough.1
§ 01What the regulations actually require
The Money Laundering Regulations 2017 do not contain a list of documents you must hold for source of funds. They require you to assess and, where appropriate, obtain information on the purpose and intended nature of the relationship; to identify and verify the client and any beneficial owner; and, where the risk is higher, to apply enhanced measures, including enhanced ongoing monitoring.2
Proportionality is the join between those two halves. Low risk does not remove the requirement, it shapes the evidence. High risk does not require every document you can think of — it requires evidence that speaks to the specific risk you recorded: an offshore counterparty, a third-party payer, a source of wealth that does not match the client's known profile.3
The second half is ongoing: regulation 33 puts the same duty on the relationship after onboarding. Source of funds is not a form you complete once. It is a position you keep up to date, and the file should show when it was last looked at.
A bank statement is evidence of money moving past an account. On its own it is not evidence of where the money came from — and it is only proportionate when the file explains why the question was never a hard one. — from our file review findings
§ 02Four files, worked through
These are anonymised composites from reviews we have run, not any single real file. Names, amounts and dates are changed. What is preserved is the reasoning.
- The high-value purchase where a statement was enough. A long-standing UK client, known to the firm for years, buying a residential property at a level the firm's risk assessment treats as higher risk. Funds arrived from the client's own account at a UK high-street bank, held in the client's name for over a decade, and the statement showed the money accumulating from a salary and a prior property sale corroborated by the earlier matter file. Here a statement was proportionate — because the source, the journey and the parties were all consistent and checkable, and the fee-earner wrote three lines saying so. The finding we did not make matters as much as the ones we did.
- The third-party payer. A company client's invoice settled by an unrelated individual, with no explanation on file. The fee-earner's note recorded "funds received, cleared". That is a cashiering fact, not an AML record. On review we could not tell who the payer was, what relationship they had to the client, or whether the firm had considered a refund path. The gap was not the money; it was the explanation, which is the one thing a third-party payment always requires.
- The statement-alone file. A purchase where everything pointed the same way: an offshore seller, a short timescale, a recent change in the client's circumstances, an introduction from a party the firm had not dealt with before. Against that, the source-of-funds section contained a single statement, undated, with no note linking the balance to the purchase. Nothing engaged with the recorded risk, because nothing on file engaged with the recorded risk at all.
- The relationship that changed. A retainer client whose payment pattern shifted — a new counterparty, round figures arriving from an account that had not funded the matter before. The source-of-funds section was completed at onboarding two years earlier and never revisited. This is a regulation 33 finding, and in our reviews it is the most commonly missed.
1. The recorded risk level and the reason for it. 2. That the evidence held matches that level. 3. Who the parties are to one another, in writing, especially in any third-party payment. 4. What the firm ruled out, not only what it collected. 5. A named person and a date. 6. Evidence that the position was revisited when the relationship changed. A file that answers all six rarely attracts a finding, whatever the answer was.
§ 03Where proportionality goes wrong
The failure is almost never a fee-earner reaching the wrong conclusion. It is the file failing to show that any conclusion was reached. Three habits cause most of it.
Treating the risk assessment as an onboarding artefact. The risk level is set, filed, and never re-read. But recording risk is precisely how you tell the next person what evidence was expected. If the assessment says higher risk and the evidence section is one statement, the file contradicts itself.
Confusing wealth with funds. Source of funds answers "where did the money for this transaction come from". Source of wealth answers how the client accumulates. Firms frequently collect evidence of one and label it the other, leaving the actual question unanswered when the transaction is unusual. Say which question you are answering.
Delegating without a record. Intake staff, an introducer, a platform — someone else gathered the evidence and the firm inherited a tick. The file needs the underlying evidence, dated and retrievable, plus the firm's own view of it. An inherited tick is not a decision.4
§ 04How to test your own files in an afternoon
Take five live files you would expect to be clean, including at least one where money came from somewhere other than the client's own account. For each, answer in writing: what risk did we record, what evidence does the file hold, does it match the recorded risk, who explained the parties, and when did we last look. Three of five failing on the last question is common — a fixable backlog rather than a crisis.
Where the pattern surprises you, two routes. The independent AML file review is the twenty-file version, against the framework we use in every review; for the DIY version first, the resources page carries our free self-check. Firms that need the whole team consistent usually pair it with the policy and training pack, because a finding is cheap to fix once and expensive to repeat.
- Probative Co is an independent compliance practice, not a law firm, and nothing here is legal advice. The worked examples are anonymised composites, not any real client file. ↩
- Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, SI 2017/692: legislation.gov.uk/uksi/2017/692 — see in particular reg 28 (customer due diligence) and reg 33 (obligation to apply enhanced customer due diligence and enhanced ongoing monitoring). ↩
- The SRA's guidance sets out expectations for client and matter risk assessments, including calibration of measures to assessed risk: sra.org.uk — client and matter risk assessments. General AML guidance for the sector is at sra.org.uk — money laundering and terrorist financing. ↩
- reg 33(1) requires enhanced measures and enhanced ongoing monitoring where risk is high, including where a transaction is unusually large or complex for its nature, or forms part of an unusual pattern. It is a continuing obligation, not an onboarding step. ↩
Send three files.
We'll tell you what a reviewer would flag.
- No charge and no obligation — you keep the findings either way
- Turned around in ~48 hours, encrypted transfer only
- Most firms find at least one issue they did not know they had