Take a firm whose firm wide risk assessment carries a date two and a half years old and names private client, employment, a little commercial and a modest amount of residential conveyancing. On illustrative figures, conveyancing has grown since then from around one new matter in ten to well over a third of everything the firm opens. Two introducers now send a steady flow of work and neither existed when the document was written. Close to half the clients taken on last year were never met by anyone at the firm, and a handful of them live abroad.

None of that is wrong in itself. The difficulty is that the firm's own document describes a practice that stopped existing some time ago, and an inspector measures your assessment against your caseload rather than against an ideal firm. What fails an inspection is rarely the absence of a document, since most firms produced one when the regulations came in. What fails is the distance between what the document claims the firm does and what the matter files show it doing.

The assessment has to describe the firm as it is

A firm in the regulated sector must keep a written assessment of the risks of money laundering and terrorist financing that it faces. That assessment has to take account of matters including its clients, the countries and geographic areas it deals with, the products and services it offers, the transactions it handles and the channels through which it delivers its work. It must be kept up to date, so the duty runs continuously rather than being discharged once. The policies, controls and procedures sitting beneath it have to be proportionate to the risks identified and approved by senior management, and where it is appropriate to the size and nature of the business there must be an independent audit function that examines and evaluates how well those policies, controls and procedures work in practice.

Read that back against the firm described above. Its delivery channels have changed, because clients are taken on without attending the office, and its geographic reach has changed, because instructions arrive from abroad. Conveyancing brings exposure that private client work does not. Each of those sits squarely within what the assessment must address, and the version sitting in the compliance folder addresses none of them.

The evidence is already on your matter files

The usual response is to book a partners' meeting, talk through what the firm does now and write the assessment from recollection. That produces a document describing the firm as the partners picture it, which is not the firm the files record. Recollection favours the memorable matter and misses the changes that arrived gradually, which is how most of them arrive.

Build it instead from what you already hold. Take the last twelve months of new matters and aggregate the information recorded at opening, being the type of work, the type of client, meaning an individual, a company, a trust or someone acting under a power of attorney, where the client and the money were based, how the client came to the firm and whether anyone met them, how the funds arrived, and the risk rating given on the day the file was opened. Then set that picture beside what your firm wide document asserts.

Where the two disagree, one of two things has happened. Either the document has fallen out of date, or the matter level ratings are being applied loosely, with fee earners reaching for standard risk because the work felt familiar. Both are findings worth having, and you want to know which one you are looking at before you rewrite anything.

The same aggregation answers a second question that weighs more at inspection than the wording of the assessment, which is whether your controls operate. If the policy promises enhanced due diligence on high risk matters, the file data tells you how many high risk matters there were and how many of them carry the enhanced checks. An independent audit function is looking for that answer, tested across the whole caseload rather than on a handful of sampled files.

This is the work Bracton was built to take off a compliance officer. It connects to the case management system your firm already runs, whether LEAP, Clio, Proclaim or another, and reads every live matter overnight. The Bracton AI Assistant gathers what the files already hold into the firm wide picture, keeps that picture current as new matters open rather than once a year, marks where the practice has drifted away from the written document, and shows you where a control the policy promises was never applied. Nothing it produces is a finished assessment. Your money laundering reporting officer reads it, tests it and signs it off, because the judgement stays with the officer.

Your own last twelve months already hold the answer to whether the document in your compliance folder still describes you, and setting the two pictures beside each other takes an afternoon rather than a project: book a client account review.