Outsourced MLRO and financial crime support
That stands up to scrutiny.
Assess AML, CTF and sanctions risk, test your controls, and evidence a framework that stands up to FCA scrutiny.

Do you need outsourced MLRO support?
You hold the one role in a regulated firm where the individual, not just the firm, can be prosecuted. We help you run it so that never becomes the question.
- You own AML/CTF and sanctions risk for the firm
- You need to test controls against FCA Dear CEO themes
- A financial crime risk assessment is due or overdue
The point where the liability stops being the firm's
What the MLRO is personally liable for
Most obligations land on the firm. These land on the individual holding the function.
SMF17 / MLRs reg. 21
The function is held by you, not by the firm
The nominated officer is a named individual, and the appointment is personal. Where your firm is within SM&CR this is SMF17, approved in your name with a Statement of Responsibilities recording what you answer for. A firm can resource the work; it cannot hold the function on your behalf.
POCA ss.330–332
Failing to disclose is a criminal offence, and it is yours
Where an internal report reaches you and there are reasonable grounds for suspicion, a decision not to report to the NCA can be a criminal offence. Section 331, which applies to nominated officers specifically, carries up to five years' imprisonment. This is personal liability, not a regulatory finding against the firm.
POCA s.333A
Tipping off is separately criminal
Telling the customer, or anyone else, that a report has been made or is contemplated is its own offence — distinct from any failure to disclose, and prosecutable on its own.
POCA s.335
Proceeding before consent exposes the firm
Where suspicion exists, the transaction needs a DAML request and the NCA's consent, or the moratorium period must expire, before it is processed. Processing first means the firm commits a money laundering offence — which is why the moratorium has to be tracked centrally rather than by whoever filed.
MLRs reg. 86
Breaching the Regulations is an offence in its own right
Separately from POCA, contravening the Money Laundering Regulations is itself an offence, carrying an unlimited fine. It runs alongside your disclosure obligations rather than replacing them, and the FCA's own supervisory and enforcement powers sit on top of both.
What the FCA expects from an AML control framework
Having the artefact is rarely the issue. These are the qualities that survive challenge.
Business-wide risk assessmentMLRs reg. 18
It visibly drives something. A supervisor traces your CDD triggers and monitoring thresholds back to the risks this document identifies. An assessment refreshed annually that nothing downstream depends on reads as a formality.
Customer due diligenceMLRs regs. 28–30, 33–35, 37
Risk-based triggers applied consistently, not case by case. The test is whether two similar customers onboarded months apart were treated the same way, and whether the file shows why enhanced diligence was or was not applied.
Transaction monitoring calibrationMLRs reg. 28(11)
Records of how thresholds were set and, more importantly, adjusted — with the reasoning. Back-testing against known cases, and sample testing of transactions that generated no alert at all. The unalerted sample is the part firms skip.
The SAR decision chainPOCA ss.330–332
The complete path from the staff member who raised it to your filing decision — including the cases where you decided not to file. Recording the outcome is not the same as recording the reasoning; what has to be visible is that you weighed the information actually available to you at the time.
Board reporting
At least quarterly, and substantive: SAR volumes and outcomes, typology trends, monitoring effectiveness results, CDD remediation status, training completion. Enough that the board could not later say it was unsighted.
Your own authority
Direct access to the board, access to customer and transaction data without asking permission, and the ability to escalate without interference. Firms that appoint an MLRO and then withhold the data are a recurring FCA finding — and the exposure lands on you.
Financial crime risk assessment and AML controls testing
See the Stay Compliant process- Firm-wide financial crime risk assessment
- AML/CTF framework and controls testing
- Sanctions and transaction-monitoring review
- Remediation planning where gaps are found
Questions MLROs and financial crime leads ask us
Can I outsource the MLRO role to a consultant?
You can appoint an external SMF17, and smaller and newly authorised firms often do. What you cannot outsource is the responsibility: under SYSC 8 the firm stays accountable for the activity and its senior managers keep their SM&CR obligations. A credible arrangement needs a documented agreement, genuine access to systems and management information, enough time allocated to do the job, and board oversight. An application where external support is the firm's only compliance resource will probably be refused.
What is my liability if a SAR is not filed correctly?
Personal and criminal. Under POCA ss.330–332, a nominated officer who receives an internal report and does not report to the NCA where there are reasonable grounds for suspicion commits an offence carrying up to five years' imprisonment. It is one of the few roles in a regulated firm where the individual, not the firm, is in the frame.
How often does the firm-wide risk assessment need refreshing?
The obligation is to keep it current, which in practice means reviewing it at least annually and whenever the business changes materially: a new product, a new market, a new distribution channel, or a shift in customer base. An assessment that has not moved while the business has is the version supervisors find hardest to accept.
Do we have to submit the financial crime data return?
Firms above the revenue threshold submit the FCA's annual financial crime data return, which the regulator uses to benchmark sectors and identify systemic weaknesses. Whether it applies to you depends on your permissions and revenue, and it is worth confirming rather than assuming — the return is also a useful internal check on whether your own MI can answer the questions it asks.
For the full detail, read Financial crime controls: the full explainer.
Talk to a regulatory specialist
Book a scoping call to discuss your situation and the right next step.