Deepfake identity checks are now a named risk in the regulator's own assessment of your sector. The Solicitors Regulation Authority published a substantially revised sectoral risk assessment on 6 August 2026, and its summary of changes records that technology risk has been updated to focus on recent AI risks. For a firm that identifies most of its clients through a screen, that line changes what a file has to show.
What the assessment now says
The technology section opens with the Financial Action Task Force, which has identified AI-enabled fraud as an emerging threat, and the SRA's own wording follows closely behind it. AI-enabled impersonation techniques, including deepfakes, may increase the risk of identity fraud and misrepresentation during client onboarding and throughout the life of a matter. The risk may be greater, the assessment adds, where firms rely on remote verification methods or digital onboarding processes.
Two parts of that deserve your attention. The risk runs throughout the life of a matter rather than stopping once the file opens, so the voice that calls in week nine to change the account for completion money sits inside the same warning as the person who first instructed you. The assessment also treats the assurance given by a digital identification service as a relevant consideration when you weigh the risk, and points to the government's Digital Identity and Attributes Trust Framework register as the place to check which providers take part.
Where a smaller firm is exposed
Under delivery channel risk the document is blunter still. Remote onboarding and non-face-to-face interaction can increase exposure to impersonation, synthetic identity and deepfake-enabled fraud, it says, particularly where verification relies heavily on digital information or video-based interaction. The firms this describes are the ones that moved client meetings onto video in 2020, found it worked, and never went back to look at the process again.
Conveyancing carries the sharpest version of the problem. The same assessment keeps vendor impersonation fraud as a live risk in property and other asset transactions and notes that weaknesses in verification make that activity more likely. Your practice has guarded against the fake seller for years. What has changed is that the seller can now hold a convincing conversation with your assistant on video while the documents behind them come out of the same toolkit.
What to change before the next file opens
Write down how your firm establishes who a client is and at what points it does so. Most practices keep that knowledge in the heads of two or three experienced people, which works until one of them is on holiday and a junior takes the call. A written process gives you something to test against the regulator's wording and something to hand a supervisor.
Then put a question to whoever runs your electronic verification. Ask what its liveness detection does about generated video and about a stream injected between the camera and the software, and ask for the answer in writing. Check the same supplier against the government register the assessment cites. Where the answers are thin, the honest conclusion is that a video call alone no longer carries the weight you have been putting on it, and a face-to-face meeting or a document check through an independent route has to carry some of the load.
Keep a second channel for anything that moves money. Where an instruction changes a bank account, a completion date or the destination of client funds, confirm it on a number your firm held before that instruction arrived, and record who confirmed it. Tell reception and your fee earners what to do when a call feels wrong, because the person who first senses something is off is rarely the partner.
The responsibility does not move when you buy a service. Client due diligence under the Money Laundering Regulations 2017 stays with the firm whether the check runs in your office or in a supplier's software. A regulator reading your file after a loss will ask what you knew about the tool you relied on.
The revised document, including the technology section and the delivery channel risks quoted here, is published free to read by the regulator as its sectoral risk assessment for anti-money laundering, terrorist financing, proliferation financing and sanctions, updated on 6 August 2026.
If nobody has looked at your onboarding process since it went remote, that review is the sort of work we do with firms before a fraud tests it: talk it through with us.
