Brief
MLRO Resourcing: Balancing In-house Expertise with External Support
A decision guide to employed, external-support and co-sourced MLRO models, focused on SMF17 capacity, authority and retained senior-management accountability.
Michaela Clarke
Operations & Compliance Coordinator

At a Glance
External specialists can strengthen an MLRO function, but the resourcing model still needs an accountable person with sufficient knowledge, capacity and authority. The decision should be based on the firm's financial-crime risk and operating reality, not on an assumption that accountability can be transferred by contract.
As firms grow and their financial crime risks evolve, revisiting the structure and resourcing of the MLRO function becomes critical. This often involves considering whether to rely solely on an employed MLRO, integrate external specialist support, or adopt a co-sourced model. The FCA's guidance underscores that any resourcing decision must prioritise the MLRO's ability to effectively oversee financial crime risks, ensuring they have the necessary knowledge, capacity, and decision-making authority to fulfil their Senior Management Function (SMF17) responsibilities.
The FCA says an application will probably be refused where external support is the firm's only compliance resource. That does not prohibit external or co-sourced support; it means the application and operating model must demonstrate suitable knowledge, experience, capacity and decision-making authority for the approved individual.
What the Evidence Shows
FCA Expectations for MLRO Knowledge and Capacity
The FCA's guidance for Heads of Compliance and MLROs indicates that individuals applying for the MLRO function (SMF17) must possess suitable knowledge, experience, capacity, and decision-making authority. This means that while external advisers can provide support, they cannot be the firm's sole compliance resource for an approved individual role, as such an application would likely be refused. Firms should assess their MLRO's current capabilities against these expectations, ensuring that any resourcing model chosen enhances, rather than diminishes, the MLRO's ability to perform their duties effectively.
Senior Management Responsibility for Financial Crime Risk
The FCA's Financial Crime Guide (FCG 2) explicitly states that senior management must take clear responsibility for managing financial crime risk and provide evidence of active engagement. While the MLRO serves as the focal point for oversight, the broader governance responsibility for financial crime remains with senior management.
Decision Criteria and Dependencies
MEMA recommends that firms considering external MLRO support first assess the proposed SMF17 holder's knowledge, capacity and authority against the actual business. The assessment should consider workload, expertise gaps, access to customer and transaction information, ability to influence senior-management decisions and resilience during absence or peak demand. The resulting options paper should compare an employed model, external specialist support and co-sourcing against the same risk criteria, then identify which tasks external input would genuinely strengthen and which decisions remain with the approved individual.
The operating record should show how external advice is commissioned, challenged and translated into decisions; which matters remain with the approved individual; and how senior management stays actively engaged. It should define information access, conflicts, escalation times, absence cover, service-failure response and the management information used to test capacity. The MLRO should remain the focal point for oversight without being described as the sole owner of every financial-crime decision. Assurance can then sample live alerts, escalations and board challenge to test whether the model works in practice.
Who Needs to Choose
This includes founders, boards, financial crime leaders, and compliance officers responsible for the SMF17 role. Firms experiencing growth, expanding into new products or geographies, or those with evolving risk profiles will find this guidance particularly pertinent as they review their MLRO resourcing strategies and governance arrangements.
The precise approved-person requirement depends on the firm's permissions and regulatory status. Where SMF17 applies, external support should not be presented as a substitute for a capable accountable person or for active senior-management responsibility. Smaller firms can still design a proportionate arrangement, provided the evidence matches their risk and operating model.
MEMA Perspective
This involves asking for evidence that the MLRO possesses sufficient knowledge, experience, and capacity, and crucially, has the authority to make independent decisions without undue influence. The board should also seek assurance that external support, if used, is genuinely augmenting the internal function rather than creating a dependency that could compromise the MLRO's accountability.
FCG 2 says senior management should take clear responsibility for financial-crime risk and evidence active engagement. In practice, the board or governing body can challenge the MLRO on control effectiveness, resources, material incidents and the firm's risk assessment rather than treating receipt of an external provider report as sufficient oversight.
MEMA helps firms apply regulatory developments through its financial crime compliance support.
Further reading: SMCR accountability and evidence.
Implementation Priorities
| Action | Owner | Status | Timing | Evidence |
|---|---|---|---|---|
| MEMA recommended action: document the proposed MLRO's authority, time capacity, access to customer and transaction information, escalation route and direct access to the governing body. | Board Chair / Chief Executive | MEMA recommended action | MEMA planning point: before selecting or changing the resourcing model | KNOWLEDGE, CAPACITY AND OUTSOURCING SECTIONS - Heads of compliance and MLROs |
| MEMA recommended action: separate accountable SMF17 decisions from research, monitoring and advisory tasks that an external specialist may perform. | MLRO / Financial Crime Lead | MEMA recommended action | MEMA planning point: in the role profile, service schedule and responsibility map | SENIOR MANAGEMENT RESPONSIBILITY AND MLRO GOVERNANCE - Heads of compliance and MLROs |
| MEMA recommended action: test whether the arrangement still provides sufficient knowledge, capacity and influence as products, volumes, customers and geographic exposure change. | Independent Assurance Lead | MEMA recommended action | MEMA planning point: at least annually and after a material business-model change | KNOWLEDGE, CAPACITY AND OUTSOURCING SECTIONS - Heads of compliance and MLROs |
Source Evidence
| Source | Document type | Published | Why it matters |
|---|---|---|---|
| Heads of compliance and MLROs | FCA firm guidance (Knowledge, capacity and outsourcing sections) | Current | Explains the FCA's expectations for SMF16 and SMF17 applicants, including knowledge, capacity, authority and limits on relying solely on external compliance support. |
| FCA Handbook | FCA Handbook guide (Senior management responsibility and MLRO governance) | Current | Confirms that senior management should take clear responsibility for financial-crime risk and demonstrate active engagement with the control framework. |
Plain English Glossary
- SMCR - Senior Managers and Certification Regime. Accountability framework requiring named senior managers, certified individuals, and conduct rules training.
Disclaimer
This article is for general information only and does not constitute legal or regulatory advice. Firms should assess the application of regulatory requirements by reference to their permissions, products, customers and operating model.
How MEMA Can Help
MEMA can help firms translate regulatory change into practical controls, policies, monitoring activity and board evidence. Book a free scoping call to discuss what this development means for your firm.
Frequently asked questions
Can a firm outsource the accountability of its MLRO?
External specialists can support the firm, but the proposed SMF17 holder still needs suitable knowledge, experience, capacity and decision-making authority. The FCA says an application will probably be refused where external support is the firm's only compliance resource. The exact approved-person requirement depends on the firm's permissions and status, so the arrangement should be assessed against the live FCA guidance and the firm's facts.
When can external MLRO support add value?
External MLRO support can add specialist knowledge, independent challenge, surge capacity or monitoring capability around the SMF17 function. It is most defensible when the division of work is explicit, the accountable person remains close to the business and management information, and the governing body can show active engagement. Cost saving alone does not demonstrate that the arrangement is proportionate to the firm's financial-crime risk.
What should the oversight file contain?
MEMA recommends retaining the SMF17 role and responsibility map, service scope, conflicts assessment, access rights, escalation rules, meeting and challenge record, management information, capacity review, service failures and remedial action. That evidence should show how the accountable person reaches decisions and how senior management remains engaged, consistent with Heads of compliance and MLROs and FCG 2 in the Financial Crime Guide.
Need expert regulatory guidance?
Our ex-regulator team helps firms navigate complex requirements and evidence compliance with confidence.
Book a Free Scoping CallRelated insights
View all insights →
Agentic AI in Retail Finance: Governance Decisions for Boards Now
The Mills Review is not a new AI rulebook. It gives retail-finance boards a practical prompt to define delegated authority, human intervention and outcome testing.

Navigating Section 166 Skilled Person Reviews: A Guide for Boards and Compliance Leaders
A practical guide to FCA Section 166 skilled-person reviews, covering appointment routes, scope control, evidence quality and remediation governance.

SIPP reform: due diligence and asset controls under FCA CP26/20
CP26/20 proposes explicit SIPP due-diligence rules and a Pension Scheme Money and Assets regime. We examine the evidence and operating-model decisions.