MLROs & financial crime leads

Outsourced MLRO and financial crime support
That stands up to scrutiny.

Assess AML, CTF and sanctions risk, test your controls, and evidence a framework that stands up to FCA scrutiny.

Do you need outsourced MLRO support?

You hold the one role in a regulated firm where the individual, not just the firm, can be prosecuted. We help you run it so that never becomes the question.

  • You own AML/CTF and sanctions risk for the firm
  • You need to test controls against FCA Dear CEO themes
  • A financial crime risk assessment is due or overdue

The point where the liability stops being the firm's

What the MLRO is personally liable for

Most obligations land on the firm. These land on the individual holding the function.

SMF17 / MLRs reg. 21

The function is held by you, not by the firm

The nominated officer is a named individual, and the appointment is personal. Where your firm is within SM&CR this is SMF17, approved in your name with a Statement of Responsibilities recording what you answer for. A firm can resource the work; it cannot hold the function on your behalf.

What the FCA expects from an AML control framework

Having the artefact is rarely the issue. These are the qualities that survive challenge.

Business-wide risk assessmentMLRs reg. 18

It visibly drives something. A supervisor traces your CDD triggers and monitoring thresholds back to the risks this document identifies. An assessment refreshed annually that nothing downstream depends on reads as a formality.

Customer due diligenceMLRs regs. 28–30, 33–35, 37

Risk-based triggers applied consistently, not case by case. The test is whether two similar customers onboarded months apart were treated the same way, and whether the file shows why enhanced diligence was or was not applied.

Transaction monitoring calibrationMLRs reg. 28(11)

Records of how thresholds were set and, more importantly, adjusted — with the reasoning. Back-testing against known cases, and sample testing of transactions that generated no alert at all. The unalerted sample is the part firms skip.

The SAR decision chainPOCA ss.330–332

The complete path from the staff member who raised it to your filing decision — including the cases where you decided not to file. Recording the outcome is not the same as recording the reasoning; what has to be visible is that you weighed the information actually available to you at the time.

Board reporting

At least quarterly, and substantive: SAR volumes and outcomes, typology trends, monitoring effectiveness results, CDD remediation status, training completion. Enough that the board could not later say it was unsighted.

Your own authority

Direct access to the board, access to customer and transaction data without asking permission, and the ability to escalate without interference. Firms that appoint an MLRO and then withhold the data are a recurring FCA finding — and the exposure lands on you.

Financial crime risk assessment and AML controls testing

See the Stay Compliant process
  • Firm-wide financial crime risk assessment
  • AML/CTF framework and controls testing
  • Sanctions and transaction-monitoring review
  • Remediation planning where gaps are found
100+
Firms authorised
11
FCA sectors covered
10+
Years regulatory experience
Since 2019
Led by ex-FCA regulators

Questions MLROs and financial crime leads ask us

Can I outsource the MLRO role to a consultant?

You can appoint an external SMF17, and smaller and newly authorised firms often do. What you cannot outsource is the responsibility: under SYSC 8 the firm stays accountable for the activity and its senior managers keep their SM&CR obligations. A credible arrangement needs a documented agreement, genuine access to systems and management information, enough time allocated to do the job, and board oversight. An application where external support is the firm's only compliance resource will probably be refused.

What is my liability if a SAR is not filed correctly?

Personal and criminal. Under POCA ss.330–332, a nominated officer who receives an internal report and does not report to the NCA where there are reasonable grounds for suspicion commits an offence carrying up to five years' imprisonment. It is one of the few roles in a regulated firm where the individual, not the firm, is in the frame.

How often does the firm-wide risk assessment need refreshing?

The obligation is to keep it current, which in practice means reviewing it at least annually and whenever the business changes materially: a new product, a new market, a new distribution channel, or a shift in customer base. An assessment that has not moved while the business has is the version supervisors find hardest to accept.

Do we have to submit the financial crime data return?

Firms above the revenue threshold submit the FCA's annual financial crime data return, which the regulator uses to benchmark sectors and identify systemic weaknesses. Whether it applies to you depends on your permissions and revenue, and it is worth confirming rather than assuming — the return is also a useful internal check on whether your own MI can answer the questions it asks.

For the full detail, read Financial crime controls: the full explainer.

Talk to a regulatory specialist

Book a scoping call to discuss your situation and the right next step.