Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

AML compliance officer — AML Compliance Officer Under AMLR: The Essential 2027 Guide

AML Compliance Officer Under AMLR: The Essential 2027 Guide

The AML compliance officer role changes shape under Regulation (EU) 2024/1624, and the change is easy to miss because the job title survives. Article 11 requires two appointments where most national regimes named one, and it allocates specific duties to each. A firm that maps its existing arrangements onto the new text without reading the split will find that some duties have no owner and others sit at the wrong level.

This is what the Regulation actually says about the AML compliance officer, what the second appointment does, and where the old money laundering reporting officer went.

What this guide covers

AML compliance officer explained
AMLR Article 11 splits the old MLRO role in two

What AMLR requires of an AML compliance officer

Article 11(2) requires obliged entities to have a compliance officer, appointed by the management body in its management function, with sufficiently high hierarchical standing. That person is responsible for the policies, procedures and controls in the day-to-day operation of the entity’s anti-money-laundering and counter-terrorist-financing requirements, including in relation to the implementation of targeted financial sanctions, and is a contact point for competent authorities.

The AML compliance officer is also responsible for reporting suspicious transactions to the Financial Intelligence Unit in accordance with Article 69(6). That is the duty least safely diffused: whatever the internal escalation route, the report is made by or under the authority of that role.

The AML compliance officer and the compliance manager are two appointments

Article 11(1) creates the other one. A compliance manager must be a member of the management body in its management function, responsible for ensuring compliance with the Regulation, with Regulation (EU) 2023/1113 and with any administrative act issued by a supervisor.

That is a membership requirement, not a seniority requirement. A senior executive who reports to the board does not satisfy it however senior, and the defect cannot be cured by delegation. It is the single most common appointment error in early AMLR readiness work.

Question Compliance manager AML compliance officer
Must be a member of the management body? Yes No — but must have sufficiently high hierarchical standing
Approves internal procedures and controls? Yes, at least at this level No
Runs the programme day to day? No Yes
Reports suspicions under Article 69(6)? No Yes
Contact point for competent authorities? No Yes
Approves the content of Article 13 integrity assessments? No Yes
Accountable for resourcing the function? Yes No

The four duties of an AML compliance officer under Article 11(2)

Reading the Article closely, the AML compliance officer carries four distinct responsibilities, and each produces different evidence.

  • Day-to-day operation of the policies, procedures and controls — the whole programme, in practice, on any given day.
  • Implementation of targeted financial sanctions, named expressly. It sits with this role rather than a separate sanctions function, unless the firm records how accountability is preserved.
  • Contact point for competent authorities, which means an authority’s first approach should reach a named person rather than a shared mailbox.
  • Reporting suspicions to the Financial Intelligence Unit under Article 69(6), including attempted transactions and suspicions arising from an inability to complete due diligence — the clocks are set out in suspicious transaction report deadline.

The sanctions limb deserves attention because Article 9(1)(b) separately requires the internal policies to address the risks of non-implementation and evasion of targeted financial sanctions, in addition to applying them. Those are different control objectives with different evidence.

MLRO or AML compliance officer: what happened to the old role

The term “money laundering reporting officer” does not appear in Regulation (EU) 2024/1624. It is United Kingdom terminology that spread widely, and mapping it onto the Regulation obscures the split the Regulation is built around.

In practice an MLRO’s duties divide. Making the suspicion report, being the supervisory contact and running the programme day to day map to the AML compliance officer. Owning the adequacy of the framework, ensuring it matches the firm’s risk exposure, ensuring it is implemented and ensuring it is resourced map to the compliance manager on the management body.

Firms in jurisdictions that required a board-level MLRO may find the transition simple. Firms where the MLRO was a senior manager reporting upward will need a second appointment. Either way the mapping should be written down, because a supervisor will ask which named individual holds which Article 11 duty.

Who appoints the AML compliance officer, and the standing test

Two conditions in Article 11(2) are express. The appointment is made by the management body in its management function — not by an executive committee and not by the compliance manager acting alone. And the appointee must have sufficiently high hierarchical standing.

Standing is evidenced by the reporting line, not by the job title. The practical test is whether the AML compliance officer can require action and escalate without needing permission from the business line whose conduct is in question. Record the reporting line in the terms of reference and keep it current.

Where the entity is subject to checks on its senior management or beneficial owners under Article 6 of Directive (EU) 2024/1640 or other Union law, Article 11(2) requires the compliance officer to be verified as complying with those requirements too.

Sharing an AML compliance officer across a group

Article 11(2) permits a group entity to appoint as its compliance officer an individual who performs that function in another entity within the group — but only where justified by the size of the obliged entity and the low risk of its activities.

Both conditions must hold, and both are findings about this entity rather than about the group. A justification resting on the group’s low risk profile does not meet the test. Record the size basis, the low-risk basis by reference to the entity’s own business-wide risk assessment, and how the shared officer maintains sight of the entity’s business.

Separately, Article 16(2) requires compliance functions at group level, including a compliance manager at group level and, where justified by the activities carried out at group level, a compliance officer. The decision on the extent of those functions must be documented.

Resourcing the AML compliance officer function

Article 11(1) puts an express duty on the compliance manager to ensure that sufficient human and material resources are allocated. That allocation of accountability has a useful consequence: whether the AML compliance officer is adequately resourced becomes a question the management body must answer with evidence, rather than a complaint the officer raises and is told to manage.

Size the demand from the risk assessment and the customer base — relationships by risk band, enhanced cases per period, alerts requiring review, suspicion assessments, periodic reviews falling due, Member States of operation, agents to oversee. Then state the conclusion explicitly. An assessment that always concludes “sufficient” and never produces an action is not evidence of adequacy.

Awareness, training and the integrity checks that sit behind the role

Two Articles put work into the compliance function that firms often assign elsewhere and then cannot evidence.

Article 12 requires measures to ensure that employees and persons in comparable positions whose function so requires — including agents and distributors — are aware of the requirements arising from the Regulation, from Regulation (EU) 2023/1113 and from any supervisory administrative act, and of the entity’s own business-wide risk assessment, policies, procedures and controls. Awareness expressly extends to the processing of personal data for the purposes of the Regulation, which a generic module rarely covers.

The Article then requires participation in specific, ongoing training programmes appropriate to function and to the entity’s risk exposure, and states that those programmes must be duly documented. Documentation is part of the obligation, not administration around it: content and its version, audience, date and attendance by named individual all have to be producible. Attendance recorded as a headcount does not show that a particular person was trained.

Article 13 then requires an assessment of skills, knowledge and expertise, and of good repute, honesty and integrity, for anyone directly participating in compliance — again including agents and distributors. It must be performed before activities are taken up and repeated, with the intensity set by the tasks and the risks of the function.

Two details govern how this interacts with the role. The content of that assessment must be approved by the compliance officer, and Article 13(2) requires anyone entrusted with compliance tasks to inform the compliance officer of any close private or professional relationship with a customer or prospective customer, and to be prevented from performing compliance tasks for those customers. Disclosure without a reassignment control does not satisfy it. Article 13(4) disapplies the whole Article where the entity is a natural person, or a legal person whose activities are performed by one natural person only.

Frequently asked questions

Can one person be both the compliance manager and the AML compliance officer?

In a small entity the same individual may in practice carry both, but the Article 11(1) requirement that the compliance manager sit on the management body still applies, and the split of duties should still be recorded so it is clear which hat was worn for which decision.

Does the AML compliance officer have to be an employee?

The Regulation requires the appointment, the appointing body and the standing. Where a group arrangement is used, Article 11(2) sets the size and low-risk conditions. Outsourcing the role wholesale is a different question: Article 18(3) makes the suspicion report itself non-delegable except to another obliged entity in the same group and the same Member State.

Who approves the staff integrity assessments?

The compliance officer. Article 13(1) requires the content of the assessment of skills and of good repute to be approved by them, which means a human-resources screening standard adopted without that approval does not satisfy the Article.

What happens if the conflict involves the compliance officer personally?

It cannot be handled by that role. Article 13(2) requires disclosures of close private or professional relationships to be made to the compliance officer, so the firm needs a defined route to the compliance manager for the case where the officer is the subject.

Getting the appointments documented

Both appointments need terms of reference, a dated decision of the management body, and a resourcing assessment behind them. Our EU AMLR Toolkit carries separate terms of reference for each role and the proportionality assessment Article 11(1) implies. The wider set of changes is in AMLR vs AMLD, the deadline is in the AMLR 2027 timeline, and Article 11 itself is on EUR-Lex.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.