Section 1

Two jobs in one title

Most explanations of the MLRO role collapse it into a single function. It isn't one. The role sits across two distinct legal frameworks that happen to be held by the same person.

The nominated officer function comes from the Money Laundering Regulations 2017 and the Proceeds of Crime Act 2002. This is the reactive half of the job: receiving internal disclosures from staff who suspect money laundering, deciding whether each one warrants an external Suspicious Activity Report to the National Crime Agency, and acting as the firm's registered point of contact with the NCA.

The compliance stewardship function comes from SM&CR itself. This is the preventative half: owning the firm's AML risk assessment, its policies and controls, its training programme, and its overall posture toward financial crime risk.

Treating these as one undifferentiated job, or worse, treating the role as purely reactive SAR processing with no strategic ownership, is a structural weakness FCA supervisory teams are specifically trained to spot. If your firm's MLRO can describe last quarter's SAR volume in detail but can't articulate the firm's current AML risk assessment, that gap is visible from the outside.

Reactive
Nominated Officer
+
  • Receiving internal disclosures from staff who suspect money laundering
  • Deciding whether each disclosure warrants an external SAR to the NCA
  • Acting as the firm's registered point of contact with the NCA
  • Deciding whether a DAML request is needed before a transaction proceeds
Legal source: Money Laundering Regulations 2017; Proceeds of Crime Act 2002
Preventative
Compliance Steward
+
  • Owning the firm's AML risk assessment
  • Owning the firm's AML policies and controls
  • Owning the firm's AML training programme
  • Owning the firm's overall posture toward financial crime risk
Legal source: Senior Managers and Certification Regime (SM&CR)
Section 2

The SAR decision, step by step

Click any stage below to see the detail that applies at that step.

1
A member of staff forms a suspicion
+
Under POCA, this can be knowledge or suspicion. A genuine, honestly held suspicion is enough, certainty is not required, and waiting for certainty is itself a risk.
2
An internal disclosure is made to the MLRO
+
This has to reach the MLRO directly, not get absorbed into a general compliance inbox or handled informally by a line manager.
3
The MLRO assesses whether external disclosure is warranted
+
And, if the underlying transaction needs to proceed before a response is received, whether a Defence Against Money Laundering request is needed to obtain consent from the NCA.
4
The SAR is filed, or the decision not to file is documented
+
The SAR is filed with the NCA, or the MLRO documents, specifically and in writing, why it was not. "We decided not to file" with no rationale on file is one of the more common findings in a poor supervisory review.
5
Tipping off risk is managed throughout
+
Telling, or carelessly signalling to, the subject of a SAR that a disclosure has been made or is being considered is a criminal offence under POCA section 333A, and it's a risk that spreads easily through account managers, relationship teams, or anyone outside the compliance function who becomes aware a review is underway.
Section 3

The dual liability nobody explains clearly enough

Ask most compliance professionals what SMF17 exposes them to and they'll describe FCA enforcement, financial penalties, prohibition, public censure. That's correct, but it's only half the exposure. SMF17 holders sit under two separate liability regimes simultaneously, and the second one is criminal, not regulatory.

โš–๏ธ Regulatory: SM&CR

Under sections 66 and 56 of the Financial Services and Markets Act, the FCA can fine, censure, or prohibit an individual. That's a regulatory sanction, serious, career ending in practice, but not a criminal record.

๐Ÿšจ Criminal: MLR 2017 & POCA

Personal and criminal exposure, running in parallel to the regulatory route:

  • MLR 2017, Regulation 86: failure to comply with the regulations, up to two years' imprisonment and an unlimited fine
  • POCA section 330: failure to disclose suspected money laundering when a SAR should have been filed, up to five years' imprisonment
  • POCA section 333A: tipping off, criminal sanctions for improperly disclosing that a SAR has been made or is being considered

These two frameworks run in parallel, not as alternatives. A single failure, not filing a SAR that should have been filed, can trigger an FCA enforcement action under SM&CR and expose the individual to prosecution under POCA at the same time.

A single failure can trigger FCA enforcement and criminal prosecution at the same time.

This is the detail that separates SMF17 from almost every other Senior Management Function, and it's worth being explicit about with anyone being asked to take the role, particularly at a small firm where the appointment can otherwise be framed as a title change rather than a genuine shift in personal exposure.

Section 4

The Annual MLRO Report

There's no single prescribed format, but the FCA and industry practice converge on the same expectations. At minimum, annually, the report should cover the items below.

โœ… What your Annual MLRO Report should cover
Click an item to mark it covered. This is illustrative only, it is not a template that substitutes for firm-specific legal advice.
โœ“
SAR volume, themes, and outcomes over the reporting period
โœ“
The current state of the firm's AML risk assessment and any material changes to it
โœ“
Training completed across the firm, and any gaps identified
โœ“
Resourcing: whether the compliance function has had sufficient capacity for the period
โœ“
Any regulatory contact, thematic reviews, or supervisory visits during the period
0 of 5 covered
Illustrative checklist only, based on FCA and industry practice. It is not a template and does not substitute for firm-specific legal advice.

Waiting a full year to surface material issues to the board is a common failure pattern in itself. Quarterly management information to senior leadership, even informally, is considered good practice precisely because it means the annual report becomes a formal record of things the board already knew about, not the first time anyone heard them.

Section 5

Where personal MLRO liability has actually been tested

Most AML enforcement headlines are about firms, not individuals. Nationwide, Barclays, and Monzo were all fined in 2025 for AML control failures, ยฃ44 million, ยฃ39 million, and ยฃ21 million respectively, but those penalties landed on the firms, not on named MLROs personally. Personal enforcement against a named SMF17 holder is comparatively rare. When it happens, the reasoning in the FCA's decision notice is worth reading closely, because it tells you exactly what the regulator considers unacceptable in practice, not in theory.

Sonali Bank (UK), 2016

The firm's MLRO was personally fined for a pattern that's still instructive: no functioning AML monitoring arrangement in place, failure to identify serious weaknesses in operational controls, failure to address known training deficiencies, failure to escalate internal auditors' concerns, and failure to make the case to senior management for more resource. None of these individually sound dramatic. Together, they describe an MLRO who knew about the gaps and didn't force the issue upward, which is precisely the behaviour SM&CR was designed to make personally costly.

CFP Management Ltd, 2023

A more unusual and arguably more important case for anyone holding SMF17 alongside another role. The former MLRO here was fined over ยฃ630,000, prohibited from any regulated function, and had both his compliance oversight (SMF16) and MLRO (SMF17) approvals withdrawn, not primarily for an AML failure, but for a conflict of interest. He held a second controlled function, benefitted financially from a flawed advice model he was simultaneously supposed to be overseeing, and the FCA found he'd failed to act with integrity as a result. The lesson generalises well beyond pensions advice: holding SMF17 alongside a role with a direct financial stake in the outcomes you're meant to be independently scrutinising is exactly the structural conflict the FCA is trained to look for, and it doesn't need a money laundering failure attached to still end a career.

It isn't one dramatic missed SAR that ends an MLRO's career, it's a sustained failure to escalate, to resource, or to remain independent.

The pattern across both cases is the same. It isn't one dramatic missed SAR that ends an MLRO's career, it's a sustained failure to escalate, to resource, or to remain independent, that becomes visible only once something else forces the FCA to look closely.

๐Ÿ“˜
This closes the handbook, for now
Together, the two parts cover who can hold the role, how approval works, what the job actually involves day to day, and what the regulator has done when it goes wrong. A future addition to this series will look at MLRO resourcing benchmarks by firm size, and how the FCA's shift toward becoming the AML supervisor for professional services firms changes the picture from late 2026.