Reglo in practice

How compliance work runs on Reglo

Six situations SRA-regulated firms handle every year, followed step by step: what sets each one off, what Reglo does, what your compliance officers decide, and what stays on the record afterwards.

A rule the firm relies on changes

SRA Standards and Regulations, and the legislation and guidance the firm subscribes to

The firm
An 18 fee-earner firm across private client, conveyancing and litigation. The COLP is also head of private client and has no dedicated compliance staff.
The trigger
A piece of guidance the firm's Anti-Money Laundering Policy relies on is revised. Nobody in the firm is watching the regulator's site on a Tuesday afternoon, and the consultant's next visit is nine weeks away.

What happens

  1. Reglo

    The change is picked up from the subscribed source and assessed for materiality. It appears on the dashboard against the policies it touches, the AML policy and the client onboarding procedure, down to the paragraphs that cite the superseded wording.

  2. COLP

    Opens the affected policy and asks for a suggested update. Nothing is published, and nothing is drafted until someone asks for it.

  3. Reglo

    Drafts a redlined update with citations back to the revised source, so every proposed sentence can be traced to the reason for it.

  4. COLP

    Reviews the redline side by side with the current version, edits two paragraphs, and approves. A new version is created, the approval is recorded, and the people the policy applies to are asked to attest to it again.

On the record afterwards

  • The source change, with the date it was detected and how it was assessed
  • Which policies were assessed and which were affected
  • The redline, the edits made to it, and who approved the final version
  • The full version history, with the superseded version retained
  • Attestations against the new version, by name and time

Further reading: Policy version control for COLPs and MLROs

A desk-based review document request arrives

SRA anti-money laundering supervision; desk-based review

The firm
A six fee-earner conveyancing firm. The MLRO is a partner with a full caseload, and the request lands with a return date around two weeks out.
The trigger
The request asks for the firm-wide risk assessment, the AML policies and procedures, training records for the last year and a sample of files. What the SRA is testing is consistency: whether the documents agree with each other, and with what happens on the files.

What happens

  1. MLRO

    Opens the Evidence Centre and selects what the request asks for: the approved firm-wide risk assessment, the current AML policy set, and the training and attestation records for the period.

  2. Reglo

    Assembles each item as a sealed pack: the approved versions as PDF, attestations and completions as CSV, the underlying audit events as JSON, with a SHA-256 manifest so the SRA can verify nothing was altered after export.

  3. COLP and MLRO

    Sense-check the set for consistency before anything is sent. The risk the assessment names, the control the policy describes and the training that covered it should tell one story. Where they do not, the gap is fixed and versioned first.

  4. MLRO

    Submits. Follow-up questions are answered from the same record, so the answers match the submission, version for version.

On the record afterwards

  • Exactly what was sent, with the manifest hash of each pack
  • Which version of every document was current on the day
  • Who exported the packs, and when
  • The audit events behind each document, exportable on request
  • Answers to follow-up questions tied to the same versions

Further reading: What documents the SRA may request in an AML review

The firm's risk profile changes and the assessment has to follow

Money Laundering Regulations 2017, regulation 18

The firm
A 30 fee-earner firm opening a second office and beginning to act for corporate clients with overseas beneficial owners.
The trigger
Regulation 18 expects the firm-wide risk assessment to reflect the firm's customers, the countries it deals with, its services, its transactions and its delivery channels. Two of those have just changed, and the assessment approved last spring mentions neither.

What happens

  1. MLRO

    Records the change in the firm-wide risk assessment workspace: the new office, the new client type and the jurisdictions involved.

  2. Reglo

    Shows which risk areas the change touches and which policies and controls are linked to them. It drafts the updated risk narrative from the firm's own policies and flags the controls now out of step, such as a customer due diligence procedure with no enhanced due diligence steps for the new jurisdictions.

  3. MLRO

    Sets the risk ratings and the mitigations. The judgement about how risky the new work is, and what the firm will do about it, stays with the MLRO.

  4. Partners

    Approve the revised assessment. Reglo creates the new version and records the approval, and the linked policy updates go through the same redline, approval and attestation flow as any other change.

On the record afterwards

  • The assessment before and after, with the reason for the change
  • The link from each identified risk to the control that mitigates it
  • Who approved the revision, and when
  • The downstream policy changes and the attestations that followed
  • The next review date and the reminders that lead up to it

Further reading: Why generic firm-wide risk assessments create SRA risk

Checking that the files match the policy

Money Laundering Regulations 2017, Part 3 (customer due diligence)

The firm
A 12 fee-earner firm running its matters in Clio. Supervising partners review files by hand, a handful a quarter, when they can.
The trigger
The gaps a review finds are rarely in the policy folder. They are on the files: identification taken but not verified, source of funds discussed but not evidenced, a matter risk assessment started and never signed off.

What happens

  1. Reglo

    Pulls the selected matters from the case management system and reviews each one against the checklist the firm's own policy sets out: client identification and verification, source of funds evidence, the matter risk assessment, the engagement letter.

  2. Reglo

    Flags what is missing or inconsistent on each file, with the reason. A file with identification on record but no verification is flagged as exactly that, not as a generic fail.

  3. Supervising partner

    Reads each finding, assigns the fix to the fee-earner, and marks it resolved or records why it does not apply.

  4. Reglo

    Records the outcome of every finding, so the review is a record of what was checked, what was found and what was done about it, rather than a note in a partner's drawer.

On the record afterwards

  • Which files were reviewed, when, and against which version of the checklist
  • Every finding and its resolution, with who closed it
  • The files where nothing was found, which matter as much
  • A record that can be read across files to see what keeps recurring
  • Evidence that reviews happen, not only that a procedure says they should

Further reading: How to build an AML audit trail before the SRA asks

Proving staff have read, understood and been trained

Money Laundering Regulations 2017, regulation 24; SRA continuing competence

The firm
A 70 fee-earner firm across three offices, with a compliance manager who runs the programme and a COLP who signs it off. Fee-earners, support staff and a finance team each need different things.
The trigger
Regulation 24 asks the firm to make relevant employees aware of the law on money laundering, train them to recognise it, and keep a written record. What the SRA tends to ask is simpler: who was trained, on what, when, and can you show it.

What happens

  1. Compliance manager

    Assigns policies and training by group and by office: fee-earners, support staff, finance. New joiners inherit their group's assignments on their first day.

  2. Reglo

    Delivers the training, runs the comprehension check at the end, and asks each person to attest to the exact version of each policy that applies to them.

  3. Staff

    Read, attest and complete the check. Every event is timestamped against the version it relates to.

  4. Compliance manager

    Sees completion by group and by office on the dashboard, chases only the people who are outstanding, and exports the register when the COLP or an inspector asks for it.

On the record afterwards

  • Who was assigned what, and when
  • Completion and comprehension results, by person and by module
  • Attestations tied to the specific policy version, not just the policy
  • New joiners' onboarding evidence from day one
  • Coverage by role, so a gap in one group is visible before an inspection finds it

Further reading: How to evidence AML training and staff attestations

Working alongside the firm's compliance consultant

SRA Code of Conduct for Firms, section 9 (compliance officers)

The firm
An eight fee-earner firm with an outsourced compliance consultant who visits each quarter and is on call in between.
The trigger
Between visits, guidance changes, people join and files accumulate. The consultant arrives to a quarter's worth of catching up before any advice can be given. Reglo is built to sit behind the adviser, not in front of them.

What happens

  1. The firm

    Gives the consultant access to the workspace, with their own login and a role that fits the engagement.

  2. Reglo

    Carries the upkeep between visits: watching the sources, listing affected policies, holding drafts for review, tracking attestations and keeping the audit trail current.

  3. Consultant

    Reviews what changed since the last visit from the record rather than reconstructing it from emails, and brings their own methodology and judgement to the drafts and the risk assessment.

  4. COLP

    Approves. The adviser owns the judgement, the firm's compliance officers own the decisions, and Reglo owns nothing except the record.

On the record afterwards

  • What the consultant reviewed, and when
  • Advice given against a specific version of a specific document
  • Approvals with the compliance officer's name on them
  • One record shared by the firm and its adviser, instead of two sets of notes

Further reading: What does a COLP need to evidence?

Judgement stays with people. The upkeep goes to Reglo.

The same split holds in every situation above. Nothing becomes a version, a submission or a piece of advice without a named person deciding it should.

Reglo

  • Watches the subscribed sources and maps changes to the policies they affect.
  • Drafts redlines with citations when asked.
  • Reviews files against the firm's own checklist.
  • Tracks attestations and training.
  • Keeps an append-only audit trail and seals evidence packs.

Your compliance officers

  • Decide what changes and what does not.
  • Approve every draft before it becomes a version.
  • Own the risk judgement in the firm-wide risk assessment.
  • Sign off what goes to the SRA.

Your consultant

  • Keeps the advisory relationship and the methodology.
  • Works from the same record as the firm.
  • Advises on the judgement calls, not on what changed last Tuesday.
  • Reglo carries the upkeep between visits and never replaces the adviser.

See the full product

See the situation that matches your firm

Book a demo and we run it on one of your own policies, with your COLP or MLRO in the room. Nothing changes without their approval.

30-min callNo commitment