SRA compliance software: what the categories actually do
“Compliance software” covers everything from firm-wide governance suites to single-purpose checkers. Choosing well starts with which obligation you're trying to manage — most tools manage records about compliance; very few look at the thing the SRA's web sweeps look at.
The three categories
Practice-wide GRC and policy management suites
Registers of risks, policies, breaches, file reviews, training records, AML checks — the whole compliance function in one system. Think of them as the COLP's filing cabinet and workflow engine.
Best for: Firms that want one system of record for every regulatory obligation, with the admin overhead that implies.
The catch: They track what you say you do. Most do not go and look at your public website to see whether the SRA badge still renders or the VAT wording survived the last edit.
Client onboarding, AML and risk tools
Identity verification, source-of-funds checks, conflict searches, matter risk scoring — compliance at the point a client arrives.
Best for: High-volume firms automating intake obligations under the money-laundering regulations.
The catch: A different obligation entirely — these tools never touch the Transparency Rules.
Website-specific compliance monitoring
Automated checks of your firm's public web pages against published website obligations — for SRA firms, the Transparency Rules: price information, complaints procedure, SRA number and digital badge — re-run on a schedule with evidence kept.
Best for: Any firm whose website is in scope of the Transparency Rules (that is, any SRA firm with a website) and that would rather hear about drift from a monitor than from the regulator's next web sweep.
The catch: Deliberately narrow. It checks the website, not your files, your policies or your people — and its results are monitoring findings, not certification.
Where FirmProof deliberately fits
FirmProof is in the third category on purpose, and stays there. It monitors exactly one surface — your firm's public website — against exactly one published rule set: the SRA Transparency Rules. That narrowness is a design decision with three consequences worth knowing before you buy anything:
- No client data, ever. The scanner reads the same public pages any visitor (or the SRA) can. There is no integration with your practice-management system, no matter files, no personal data of your clients in our systems.
- Evidence, not verdicts. Every check produces Action needed, Review needed, or Clear — where “Clear” means no issue detected by that check, never “compliant”. Findings carry the page, the excerpt and the SRA source they were tested against, so a human can verify each one.
- It complements, not replaces. If you run a GRC suite, FirmProof's monthly monitoring statement becomes one dated line of evidence in it. If you don't, the 12-month history stands on its own as your record of website oversight.
If what you need is policy workflow, file-review scheduling or AML onboarding, buy a tool from those categories — this one won't do it. If what you need is to know, every week, that the pages the SRA can see still show what the rules require, that is the entire job.
See what website monitoring finds on your site
Three checks, one minute, no account. The paid monitor extends the same engine to the full supported rule set, weekly, with a dated evidence history — £39/month.
Run the free scan