Table of contents
- An MLRO, or Money Laundering Reporting Officer, is the named individual in a regulated firm responsible for receiving internal reports of suspicion and deciding whether to file a suspicious activity report with the authorities.
- It is a legally required role for regulated firms in the UK and much of the EU, and the equivalent function in the US sits with the BSA compliance officer.
- The MLRO is usually the firm's nominated officer under proceeds-of-crime law, the single point through which the firm discharges its reporting duty.
- The role carries personal statutory liability: failing to report suspicion can be a criminal offence for the individual, not just the firm.
- Beyond reporting, the MLRO oversees the AML programme: policies, controls, customer due diligence, training and staying current with the law.
- An MLRO must have the authority and independence to report to law enforcement without needing anyone else's permission.
A Money Laundering Reporting Officer, or MLRO, is the individual a regulated firm appoints to take responsibility for its anti-money-laundering reporting: receiving internal disclosures of suspicious activity, deciding whether a suspicious activity report must be filed, and submitting it to the national authorities. Usually the firm's nominated officer under proceeds-of-crime law, the MLRO holds personal statutory responsibility.
TL;DR
An MLRO is the named person in a regulated firm responsible for suspicious activity reporting: they receive internal reports of suspicion, decide whether to file a suspicious activity report, and submit it to the authorities. It is a legally required role in the UK and much of the EU, usually combined with being the firm's nominated officer under proceeds-of-crime law; the US equivalent is the BSA compliance officer. The role carries personal statutory liability, so failing to report can be a criminal offence for the individual. Beyond reporting, the MLRO owns the AML programme and must be able to report to law enforcement independently.
What is an MLRO?
An MLRO, short for Money Laundering Reporting Officer, is the specific person a regulated firm puts in charge of its anti-money-laundering reporting obligations. When any member of staff suspects that a transaction or customer may involve money laundering or terrorist financing, they report it internally to the MLRO, who then decides whether that suspicion must be escalated to the national authorities as a formal report.
The role exists because anti-money-laundering law does not just require firms to have controls; it requires a named, accountable individual to sit at the centre of the reporting chain. That person is the bridge between what staff notice on the ground and what the state's financial intelligence unit receives. The title is most associated with the UK and EU frameworks, while the equivalent function in the United States is typically the BSA compliance officer. Whatever the label, the MLRO is the human anchor of a firm's AML compliance programme.
What does a Money Laundering Reporting Officer do?
The defining duty of a Money Laundering Reporting Officer is reporting, but the role is broader than that single act. At its core, the MLRO receives internal suspicious activity reports from staff, assesses each one, and decides whether it meets the threshold to file an external suspicious activity report with the authorities. That decision is theirs to make, and making it correctly and promptly is the heart of the job.
Around that sit the wider responsibilities. The MLRO oversees the firm's AML systems, policies and controls, checks that customer due diligence and know-your-customer procedures are being followed, runs staff training, keeps up with changes in AML legislation, and typically produces an annual report to senior management on the effectiveness of the programme. In effect, the MLRO both operates the reporting mechanism and owns the framework that feeds it, connecting front-line checks, enhanced due diligence and monitoring into a coherent whole.
Is an MLRO a legal requirement?
For regulated firms, yes. In the UK, the Money Laundering Regulations 2017 require relevant firms to appoint a nominated officer, and the FCA's rules require an MLRO, so the reporting function must be assigned to a named individual. Across the EU, anti-money-laundering directives, now consolidated under the AML package and the new Anti-Money Laundering Authority, impose the same obligation to designate a person responsible for compliance and reporting.
In the United States, the Bank Secrecy Act requires covered institutions to designate a BSA compliance officer who performs the equivalent function, overseeing the AML programme and the filing of suspicious activity reports to FinCEN. So while the exact title and statutory basis differ by jurisdiction, the underlying requirement is universal among regulated firms: there must be a specific, accountable person responsible for anti-money-laundering reporting. Operating without one is itself a compliance failure that supervisors treat seriously.
What is the difference between an MLRO and a compliance officer?
The two roles overlap but are not identical, and in some firms they are held by different people. The MLRO is specifically responsible for the reporting function: receiving internal disclosures and deciding whether to file suspicious activity reports. A broader compliance officer, sometimes called the money laundering compliance officer or MLCO, is responsible for the firm's overall AML compliance framework, ensuring the policies, controls and systems meet regulatory requirements.
In many smaller firms one person wears both hats, acting as MLRO and compliance officer together. In larger institutions the functions are separated, with the compliance officer owning the programme and the MLRO focused on the reporting decisions within it. The distinction matters because the reporting role carries a particular, personal statutory duty that the general compliance role does not: the MLRO is the individual through whom the firm discharges its legal obligation to report suspicion, which is why that responsibility is defined so precisely.
What is a nominated officer?
A nominated officer is the person a firm formally designates, under proceeds-of-crime and terrorism legislation, to receive internal reports of suspicion and to make disclosures to the authorities on the firm's behalf. In UK practice the nominated officer and the MLRO are usually the same individual: the MLRO is appointed under the money laundering regulations, and the nominated officer role is the mechanism, under the Proceeds of Crime Act, through which that person actually makes the reports.
The concept matters because it locates the reporting duty in a single, identifiable person rather than leaving it diffuse. When staff have a suspicion, they discharge their own legal obligation by reporting internally to the nominated officer; the nominated officer then decides whether the firm must report externally. Getting a report to the nominated officer promptly is how individual staff protect themselves, and getting the external decision right is how the firm and the MLRO meet their own duties. It is the same reporting logic that runs through any audit-ready compliance stack, where suspicion flows to one accountable point.
What authority and skills does an MLRO need?
An MLRO needs a specific and often underappreciated quality: the authority to report to law enforcement without seeking anyone's permission. Because the reporting decision is a personal statutory one, the MLRO must be independent enough that no commercial pressure, and no senior colleague, can override or delay a report. Firms are expected to give the role sufficient seniority, resources and access to information for that to be real rather than nominal.
On skills, the MLRO needs a solid grasp of AML law and typologies, sound judgement to assess whether a suspicion crosses the reporting threshold, and the operational understanding to run the wider programme, from customer due diligence to sanctions and PEP screening and ongoing monitoring. Just as important is access to good information: the quality of an MLRO's decisions depends on the quality of the data reaching them, which is why clean identity data and reliable monitoring, the goal of perpetual verification, directly affect how well the role can be performed.
What is the MLRO's personal liability?
The MLRO role is unusual in carrying personal statutory liability. In the UK, failing to report knowledge or suspicion of money laundering can be a criminal offence under the Proceeds of Crime Act, and that liability can attach to the individual MLRO, not only to the firm. A Money Laundering Reporting Officer who fails to make a report they should have made can face personal consequences, which is precisely why the role demands independence and authority.
This personal exposure shapes how the role is performed. It is why the MLRO must be able to report without permission, why the reporting decision cannot be commercially overridden, and why firms are expected to support the role properly. It also underlines why the quality of a firm's controls matters to the person in the seat: an MLRO relying on weak data and poor monitoring is exposed to missing something they will later be judged on. Strong, well-evidenced controls protect the firm, and they protect the individual carrying the statutory duty.
The bottom line
An MLRO, the Money Laundering Reporting Officer, is the accountable human at the centre of a firm's anti-money-laundering reporting: the person who receives internal suspicion, decides whether to file a suspicious activity report, and answers personally for that decision. It is a legally required role for regulated firms, usually combined with being the nominated officer under proceeds-of-crime law, and its defining features are independence and personal statutory liability. Because the quality of the MLRO's decisions depends entirely on the quality of the information reaching them, strong identity data, screening and monitoring are not just the firm's protection but the individual's.
Related resources
- What is a suspicious activity report (SAR)?
- AML compliance software in 2026
- Enhanced due diligence workflows
- Building an audit-ready compliance stack
- PEP screening in 2026