SRA Regulatory Sandbox: What Law Firms Need to Know

Originally published 11 November 2015. Updated 8 October 2026.

The idea of an SRA regulatory sandbox raised an important question in 2015: could law firms test new services and technologies with regulatory support while protecting clients?

The original article welcomed the prospect of clearer support for innovation. That remains relevant as firms introduce artificial intelligence, automated processes and new ways of delivering legal services. For COLPs and managing partners, the challenge is to assess the benefits alongside the responsibilities that accompany them.

What prompted the original sandbox question?

In November 2015, this blog reported a new SRA initiative intended to support firms exploring innovative ways to serve clients and grow their businesses.

The article drew a comparison with the Financial Conduct Authority’s developing regulatory sandbox approach. It asked whether a supported testing environment could help legal services providers understand potential regulatory barriers before committing to a new model.

That was a question about the direction of regulation, rather than an announcement that the SRA had already established a particular sandbox with defined terms of participation.

What is a regulatory sandbox?

A regulatory sandbox provides a structured environment in which selected organisations can test ideas and explore regulatory questions. Its scope, safeguards and permissions depend on the particular programme.

Some arrangements provide regulatory guidance. Others may involve specific permissions or waivers. Firms should establish exactly what support is available and what any written decision covers before relying on it.

For a law firm, a useful testing process should help answer practical questions about the service, its risks, the people affected and the controls needed before wider deployment.

How did the SRA’s approach develop?

The SRA subsequently tested an Innovation Space during 2016. Its published account of innovation and waiver decisions explains the historical approach.

Today, SRA Innovate provides resources on innovation, technology and associated regulatory questions, together with routes to contact the Innovation Policy and Professional Ethics teams.

Firms considering a new service should use current information. An earlier description of an innovation programme does not establish that the same support or permissions remain available.

The Advisory AI Growth Lab: a 2026 development

On 8 June 2026, the SRA announced its involvement in the government’s Advisory AI Growth Lab. Legal services was identified as the first sector to participate.

The initiative involves collaboration with the Council for Licensed Conveyancers, Information Commissioner’s Office and Legal Services Board to help organisations navigate regulatory questions surrounding AI.

The SRA expressly states that participation does not constitute regulatory approval, endorsement or authorisation. Legal and regulatory requirements remain unchanged.

Read the SRA’s announcement about the Advisory AI Growth Lab for the stated scope. Check current programme information for participation arrangements.

Start with the problem the technology should solve

Before adopting a tool, define the problem and the intended improvement. Examples might include reducing repetitive administration, improving document accessibility or helping staff identify matters requiring further review.

Then decide how the firm will assess the result. Faster processing is useful, but the evaluation should also consider accuracy, client understanding, exceptions and the work needed to correct errors.

A limited pilot can provide evidence before a wider rollout. Set clear boundaries, allocate responsibility and specify the circumstances in which use should stop or require additional review.

Questions for COLPs and managing partners

A proportionate review of a proposed technology or service should consider:

  • Purpose: what will the tool do, and where will it be used?
  • Responsibility: who approves its use and remains accountable for the work?
  • Information: what client data will be shared, stored or processed?
  • Quality: how will outputs be checked and errors identified?
  • Supervision: when must staff refer an output or decision for review?
  • Client communication: what explanation is needed about the service and its limitations?
  • Resilience: what happens if the provider fails or the tool becomes unavailable?
  • Review: who monitors performance and decides whether continued use is appropriate?

Record the assessment and the reasons for proceeding. Revisit it when the product, its use or the firm’s experience changes.

Connect innovation with risk management

A technology project should connect with the firm’s existing supervision, information security and risk management arrangements. A separate procurement decision may overlook how the tool changes everyday legal work.

Our article on integrating risk management and SRA compliance explains the value of coordinating those decisions.

Material risks and corrective actions should also feed into the firm’s review process. See our guide to maintaining a living and breathing risk register.

Train staff and document permitted use

Staff need to understand what an approved tool can do, its limitations and the checks required before relying on its output. Training should include examples relevant to their work and a clear process for reporting problems.

Our guide to continuing competence for solicitors and COLPs explains how learning needs can be identified and reviewed as roles develop.

For CQS firms considering policy wording, Lexsure’s suggested paragraph on AI and technology partners provides a starting point for addressing third-party technology within the risk management framework. Adapt it to the actual tools and controls used by the practice.

Review your firm’s technology risk arrangements

Lexsure’s CQS Risk Management Policy template includes responsibilities, operational and regulatory risks, the risk register and AI and technology partners.

Designed for CQS-accredited conveyancing firms, it provides a starting point to tailor to the practice’s services, technology and supervision arrangements.

View the CQS Risk Management Policy

The opportunity identified in 2015 remains valuable: regulatory engagement can help firms explore new ways of working. A successful project also needs clear responsibility, suitable safeguards and evidence that the service works for its intended users.

Leave a Reply

Discover more from Colp & Cofa

Subscribe now to keep reading and get access to the full archive.

Continue reading