

Lauren Watson

Fraud is evolving faster than most compliance frameworks can keep up with. AI-generated deepfakes can now convincingly impersonate a client. Synthetic identities blend real and fabricated data to get through basic verification checks. And the numbers are stark: the UK government predicted 8 million deepfakes would be shared in 2025, up from just 500,000 in 2023.
For UK law firms, this is not an abstract threat. Legal practices sit at the intersection of large financial transactions, sensitive client data, and strict AML obligations. They are, by definition, a target. The question is whether compliance programmes are keeping pace - and that is exactly where the UK Digital Identity and Attributes Trust Framework (DIATF) enters the picture.
What Is DIATF and Why Does It Matter?
The Digital Identity and Attributes Trust Framework is the UK government's statutory framework for digital identity verification services. Established under the Data (Use and Access) Act 2025 and coming into force on 1 December 2025, DIATF sets the rules, standards, and governance requirements for organisations that provide digital identity and attribute verification services in the UK.
Providers that meet the framework's requirements can apply for certification and appear on the government's statutory register of digital identity and attribute services. This gives regulated businesses a clear, government-backed signal of which identity verification services can be trusted.
Crucially, in February 2026, HM Treasury and the Department for Science, Innovation and Technology confirmed something the legal sector had been waiting for: digital verification services certified under DIATF can satisfy identity verification obligations under the Money Laundering Regulations 2017 (MLRs). For the first time, there is an officially recognised digital pathway for AML-compliant identity checks.
The latest version of the framework, version 1.0, was published in March 2026. It introduces the UK CertifID trust mark for certified providers and aligns with updated GPG 45 1.0 identity verification standards, building on the earlier Gamma 0.4 baseline. Legl has been audited against the Gamma 0.4 version framework and has passed this audit. Certification is expected within the next couple of weeks.
What Has the SRA Said?
The Solicitors Regulation Authority has been direct about the implications. In SRA Update 148, published in March 2026, the regulator highlighted the new HM Treasury and DSIT guidance, pointing all regulated firms toward it and confirming its status as official government guidance for AML compliance purposes.
The SRA's message is clear: DIATF-certified digital verification services offer a credible, regulatory-recognised route for fulfilling identity verification duties under the MLRs. For COLPs and MLROs trying to modernise their CDD processes, this removes a significant layer of uncertainty. Firms can now deploy digital identity solutions with confidence that they are operating within a framework the regulator itself endorses.
It is critical to note that the SRA has not mandated DIATF-certified workflows as the only route available to law firms. That would be inconsistent with the risk-based approach that underpins the entire AML framework. What it has done is establish that DIATF-certified services constitute a robust, compliant pathway for firms who want one.
The Risk-Based Approach Hasn't Changed
The risk-based approach to AML compliance remains the governing principle for UK law firms. Firms must assess risk at the client and matter level, apply standard CDD where appropriate, and escalate to enhanced due diligence (EDD) where the risk profile demands it. DIATF does not change that architecture, it enhances the toolkit available within it.
What has changed is the sophistication of the threats that risk-based assessment must now account for.
The Financial Action Task Force's December 2025 Horizon Scan on AI and Deepfakes made the point with some force: AI deepfakes break trust at the exact points where CDD measures and digital identity verification are supposed to work. The types of basic identity verification checks that would have been considered as fairly robust a few years ago (like enabling end-clients to take a photo of themselves rather than using liveness or biometric checks) are no longer considered robust in the new era of threats where fraudsters have new technology at their disposal.
For law firms handling high-value conveyancing transactions, cross-border corporate work, or matters involving politically exposed persons, the risk calculus has shifted. Standard identity checks may no longer be adequate for high-risk matters. Enhanced CDD processes that incorporate dedicated anti-fraud measures are becoming a sensible addition to any serious compliance programme.
DIATF-Enhanced Flows: A New Layer of Anti-Fraud Protection
This is where the evolution of DIATF-compliant workflows becomes particularly relevant for law firms. Legl, which works with law firms across the UK to manage AML and risk obligations across the client lifecycle, has developed enhanced CDD flows that sit within the DIATF framework and incorporate dedicated anti-fraud checks.
These enhanced flows go beyond conventional identity verification. They are designed specifically to address the kind of sophisticated fraud that standard processes were never built to catch including deepfake-driven impersonation and synthetic identity attacks. Legl has completed the DIATF audit process and is awaiting formal certification, giving firms access to workflows built to the framework's standards.
Legl’s certification comes as another layer of trust for its 500+ UK law firm customers - Legl’s suppliers including Mitek and Entrust are already DIATF-registered. This means the supply chain behind Legl's verification infrastructure already meets the government's trust framework requirements.
For law firms, this matters. When selecting a technology partner for AML compliance, the provenance of the verification technology is not a secondary consideration - it is central to the defensibility of your compliance position.
Not Just ID Verification: Compliance Across the Client Lifecycle
There is a risk that the DIATF conversation becomes too narrowly focused on onboarding and identity checks. In practice, AML compliance for law firms is a lifecycle challenge, not a point-in-time one.
Onboarding is the front door. But the regulatory obligation continues throughout the matter and beyond. Source of funds verification, ongoing monitoring, client risk reassessments, and matter-level risk assessments all form part of a robust compliance posture. The SRA's own thematic reviews have consistently found that weaknesses in areas like source of funds or ongoing monitoring are as common as weaknesses at onboarding.
Legl's platform is uniquely tailored to the requirements of law firms. The platform supports the full arc of client lifecycle compliance: ID verification and enhanced CDD at onboarding; source of funds collection and analysis; ongoing monitoring to flag changes in client risk profile; and matter-level risk assessments that give fee earners and compliance teams a coherent, auditable picture of risk.
The flexibility of that approach matters too. Different departments within a firm face different risk profiles. A conveyancing team handling high-volume, lower-risk transactions may have a different need to a corporate team advising on complex cross-border deals. Legl is built to support full service law firms, giving these teams the ability to configure processes that reflect their specific risk appetite, matter types, and client base, rather than forcing a one-size-fits-all approach.
Choosing the Right Processes for Your Firm
The arrival of DIATF is not a signal to overhaul every compliance process. For lower-risk matters, existing CDD processes may remain entirely appropriate. The risk-based approach means firms retain and exercise judgement about where enhanced measures are warranted.
But for firms dealing with high-risk clients, high-value transactions, or sectors particularly exposed to synthetic fraud, the DIATF-enhanced flows now available in Legl represent a more robust, anti-fraud-equipped verification process that operates within the government's recognised framework.
The threat landscape is not standing still. Deepfakes will get better. Synthetic identity fraud will become more sophisticated. The FATF, the SRA, and HM Treasury are all signalling that identity verification needs to evolve.
DIATF is not a silver bullet. But it is a meaningful step toward a more trustworthy, fraud-resistant digital identity ecosystem. And for law firms thinking seriously about how they manage emerging risks, it belongs in the conversation.

