Your duty is to take all reasonable steps — to keep the firm compliant with the Accounts Rules, and to make sure a prompt report reaches the SRA when something is capable of amounting to a serious breach. Not to be perfect, and not to be a lawyer or an accountant.
Guide · Updated August 2026
A COFA takes all reasonable steps to ensure the firm and its managers and employees comply with the SRA Accounts Rules, to ensure a prompt report is made to the SRA of anything reasonably believed capable of amounting to a serious breach of those rules, and to ensure the SRA is informed promptly of anything it should know about so that it can investigate or exercise its regulatory powers. That is paragraph 9.2 of the SRA Code of Conduct for Firms, and it is the whole of the formal job description.
Two things follow that firm owners consistently get wrong. The standard is all reasonable steps, not a guarantee of compliance — a COFA who has designed sensible controls, checked they run, and acted on what they found is doing the job even in a year when something goes wrong. And the role is not about being technically expert in bookkeeping; it is about knowing what is happening in the firm and being willing to act on it.
The SRA regulates law firms in England and Wales only. There is no COFA role in Scotland or Northern Ireland, where the Law Societies operate their own compliance regimes.
Under Rule 8.1 of the SRA Authorisation of Firms Rules, an authorised body must at all times have an individual designated as its COLP and an individual designated as its COFA, whose designations the SRA has approved. Rule 8.2 sets the conditions. The individual must:
That last point cuts both ways and is worth stating plainly: there is no requirement that a COFA is a lawyer, and no requirement that a COFA is an accountant either. A practice manager, a finance director or a senior legal cashier can hold the role, provided they are a manager or employee, they consent, and the SRA approves. Rule 8.3 relaxes the manager-or-employee requirement where the individual is already an approved compliance officer at a related authorised body with a manager or owner in common.
Approval is not a formality to be sorted out later. The firm must have an approved COFA at all times, which means a departure needs a replacement designated and approved, not just a name written on a policy.
The Code of Conduct for Firms in force from 11 April 2025 requires the COFA to take all reasonable steps to:
Limb (c) is broader than limb (b) and catches things that are not Accounts Rules breaches at all. It is the sweeper, and it is the one people forget exists.
Paragraph 9.1 gives the COLP the equivalent duties for everything except Accounts Rules matters — it ends with the words "save in relation to the matters which are the responsibility of the COFA as set out in paragraph 9.2". The COLP additionally covers compliance with the terms and conditions of authorisation, compliance by the firm, its managers, employees and interest holders with the SRA's regulatory arrangements, and ensuring that managers, interest holders and those they employ or contract with do not cause or substantially contribute to a breach.
The boundary matters because it decides who reports what. Money goes to the COFA; everything else goes to the COLP. Where the two overlap — a client account shortfall caused by dishonesty, say — both duties are engaged, and the sensible answer is a single report that both officers have seen.
The current test is a serious breach. The "material" and "non-material" breach language belonged to the pre-November-2019 rules and has not been the test since the SRA Standards and Regulations took effect on 25 November 2019. If a policy document, a template or an internal register in your firm still says "material breach", it was written against the old regime and should be updated — it is the quickest available signal of compliance material that has not been reviewed.
It means promptly. The rules set no number of days — there is no seven-day, no fourteen-day and no twenty-eight-day rule, and any source telling you otherwise is wrong. The SRA's guidance says a report should be made as soon as possible, because delay is likely to impede an effective investigation.
In practice that means you do not wait for the next partners' meeting, and you do not wait until the investigation is complete. The test is whether you reasonably believe the facts are capable of amounting to a serious breach — a lower bar than establishing that one occurred. Report what you know, say what you are still finding out, and update the SRA as the picture firms up.
Your paragraph 9.2 duty does not replace the firm's own obligations, and a COFA who knows these is far harder to leave in the dark:
Read 3.11 and 3.12 together and they are a protection written for you. A COFA being leaned on not to report is itself a reportable matter.
Separate from breach reports, paragraph 3.6 requires the firm to notify the SRA promptly of: any indicators of serious financial difficulty; a relevant insolvency event; an intention, or awareness, that the firm will cease operating as a legal business; and any change to information recorded in the register. Paragraph 3.7 requires the annual information report in the prescribed form by the prescribed date, and paragraph 3.8 requires prompt notification of material changes to information previously supplied about the firm, its managers, owners or compliance officers — or if that information may be false, misleading, incomplete or inaccurate.
Paragraph 3.6(a) is the one most firm owners have never read. "Indicators of serious financial difficulty" is a notification trigger in its own right, and a COFA with sight of the firm's cash position is usually the first person in the building to see one coming. That is a good reason for the COFA to receive management figures monthly rather than annually — the point of our accounts and management reporting work.
Keep one. Just do not cite an Accounts Rule for it, because there is not one. The 2011 rules had a breaches register requirement; the rules in force since 25 November 2019 do not. The obligation comes from paragraph 2.2 of the Code of Conduct for Firms — you keep and maintain records to demonstrate compliance with your obligations under the SRA's regulatory arrangements — read with the SRA's guidance on the Responsibilities of COLPs and COFAs, published 25 November 2019, which says the SRA expects compliance officers to keep a record of all breaches that occur while not prescribing a method of recording them.
Because the method is not prescribed, make yours useful. For each entry record what happened, the date it occurred, the date it was discovered, the rule engaged, the amount if there is one, what was done to correct it and when, whether it was reported and why or why not, and what changed so it does not recur. That last column is the one that shows a pattern — three separate rule 4.3 transfers without a bill is not three small entries, it is one systemic problem with billing sequence, and recognising it early is the difference between an internal fix and a qualified report. Our Accounts Rules guide sets out the rules the register is recording against.
On 2 June 2026 the SRA announced that it has submitted a package of client money rule changes to the Legal Services Board for final approval, following its December 2025 to February 2026 consultation. The SRA's own words are that, subject to LSB approval, the new rules are expected to come into force early in 2027. Until the LSB approves them, none of this applies. Two elements land directly on the COFA:
If you are a managing partner holding both hats at a firm near either threshold, that is a succession question to start thinking about now rather than in the quarter the rules land. Our Accountant's Report guide covers the rest of the package.
Most COFAs we meet are doing the job alongside a full caseload, which is why we do the work that produces the evidence: reconciliations tied three ways and ready to sign, debit balances flagged as they arise, transfers evidenced against bills, and a breach record kept as it happens. That is what our COFA support service is. Our free client account health check is a quick way to see where you stand first — it is information, not advice, and it takes about ten minutes.
What has changed in the Accounts Rules, the dates coming up, and one number worth checking in your firm. No spam, unsubscribe any time.
Neither. Rule 8.2 of the SRA Authorisation of Firms Rules requires only that the individual is a manager or employee of the body, consents to the designation, and is not disqualified under section 99 of the Legal Services Act 2007. The requirement to be authorised to carry on reserved legal activities applies to the COLP alone, not to the COFA. So a practice manager, finance director or senior legal cashier can hold the role, provided they meet those conditions and the SRA approves the designation. What the job needs is sight of what is actually happening with client money and the standing to act on it, which is a different thing from a legal or an accountancy qualification.
The Code of Conduct for Firms does not define it exhaustively, which is deliberate: the reporting test at paragraph 9.2(b) is whether you reasonably believe facts are capable of amounting to a serious breach, which is a lower bar than proving one happened. The SRA's own steer, in the context of qualified accountant's reports, is that seriousness turns on whether money belonging to clients or third parties is, has been or may be placed at risk. Shortfalls on client account, systematic improper billing, evidence of fraud, missing records and reconciliations that were never done or resolved sit at the serious end. Note that material breach is dead terminology from the 2011 rules and should not be used.
Promptly. The rules set no number of days, and there is no seven, fourteen or twenty-eight day rule — if a source gives you one, it is wrong. The SRA's guidance says reports should be made as soon as possible because delay is likely to impede effective investigation. In practice that means not waiting for the next partners' meeting and not waiting until your internal investigation has finished, because the test at paragraph 9.2(b) is a reasonable belief that the facts are capable of amounting to a serious breach rather than a conclusion that one occurred. Report what you know, say what you are still establishing, and update the SRA as the position becomes clear.
The COFA owns the money. Paragraph 9.2 of the Code of Conduct for Firms requires the COFA to take all reasonable steps to ensure compliance with the SRA Accounts Rules, to ensure prompt reporting of anything capable of amounting to a serious breach of those rules, and to ensure the SRA is informed of anything it should investigate. The COLP has the equivalent duties under paragraph 9.1 for everything else, expressly excluding the matters that are the COFA's responsibility, plus compliance with the terms of authorisation and with the regulatory arrangements by the firm, its managers, employees and interest holders. Where a problem engages both, one report seen by both officers is the sensible approach.
Not by a numbered Accounts Rule. The 2011 rules contained one; the rules in force since 25 November 2019 do not. The obligation is built from paragraph 2.2 of the Code of Conduct for Firms, which requires you to keep and maintain records demonstrating compliance with your obligations under the SRA's regulatory arrangements, together with the SRA's guidance on the responsibilities of COLPs and COFAs, which states that the SRA expects compliance officers to keep a record of all breaches while not prescribing a method. Keep the register, record what happened, when it was found, what was done and what changed — and describe its authority correctly if anyone asks.
A free, no-obligation conversation about where your client account and your firm's numbers actually stand. If we cannot add anything, we will say so.
One short email: what has changed in the Accounts Rules, the dates coming up, and one number worth checking in your firm. No spam, unsubscribe any time.