people working at desks in open office

MLRO and AML Compliance Officer Recruitment for Regulated Companies

A named person answerable for anti-money laundering controls is a licensing condition for banks, payment institutions, crypto-asset service providers and other obliged entities across Europe. We recruit and train that specialist.

Every licensed financial business in the European Union needs a named individual who answers for its anti-money laundering and counter-terrorist financing (AML/CFT) controls. National statutes call that individual a contact person, a senior employee or a compliance officer; the market calls them the MLRO or the AML officer. Whatever the label, the appointment is a licensing condition rather than an internal formality, and the regulator reviews the person behind it.

This page explains what the role involves, what EU law requires of it, what a candidate has to satisfy, and how Eesti Firma helps regulated companies across Europe find, hire and train the right specialist.

MLRO, AML officer, compliance officer: one role, many names

The function is the same everywhere in the EU; only the vocabulary changes. International practice prefers money laundering reporting officer, shortened to MLRO. The EU Anti-Money Laundering Regulation speaks of a compliance officer. National statutes use their own labels: a contact person for the financial intelligence unit, a senior employee responsible for organising anti-money laundering measures, a money laundering officer with a mandatory deputy, a nominated officer. In everyday use the role is simply the AML officer, the AML compliance officer or the anti-money laundering officer.

Is an MLRO the same as a compliance officer? In a large institution, no: the compliance officer holds the broad regulatory mandate and the MLRO owns the statutory duty to review and file suspicious activity reports (SARs or STRs, depending on the jurisdiction). In most fintech and crypto companies one person holds both, and the licence names that person. This page uses the terms interchangeably for that reason.

Two features of the role recur in every regime and are now fixed by EU law. The compliance officer reports straight to the management body, not to a line manager, and the company must give them the competence, means and access to information they need across every business unit. An MLRO who cannot see the transaction data or cannot stop an onboarding does not meet the legal definition.

MLRO responsibilities: what a money laundering reporting officer does

National acts list the core duties; the company’s internal rules and its licence conditions add to them. In practice the MLRO carries the following:

  • organises the collection and analysis of information about unusual or suspicious transactions and circumstances in the company’s activity;
  • files suspicious transaction reports and other notifications with the national financial intelligence unit (FIU) and serves as the contact point for the competent authority;
  • requires business units to remedy deficiencies in anti-money laundering procedures within a reasonable time;
  • reports periodically to the management body on compliance with the law;
  • runs the day-to-day AML programme: KYC and customer due diligence at onboarding, transaction monitoring, sanctions screening, record keeping, staff training and the upkeep of internal rules and the business-wide risk assessment.

The weight of each duty depends on the business model; two sectors deserve a separate word.

AML officer for a crypto-asset service provider (CASP)

A company holding or applying for a crypto licence in Europe operates under the MiCA framework and answers to a financial supervisor, not to an FIU alone. The AML officer of a crypto company must read blockchain analytics, apply the Travel Rule that attaches originator and beneficiary data to every crypto transfer, and satisfy a competent authority that assesses the whole management body for repute and knowledge. MiCA applications list the MLRO among the key function holders whose CVs and repute declarations go into the dossier, so the candidate is chosen before the application is filed, not after. One who knows the statute but has never traced a transaction on-chain will struggle.

MLRO for a payment institution, EMI or fintech

Payment institutions, e-money institutions (EMIs), creditors and other holders of a financial institution licence process high volumes in real time. The MLRO of a payment company is judged on monitoring design: the rules that flag a transaction, the thresholds that trigger enhanced due diligence, the escalation path to a report. Correspondent banks and acquiring partners run their own checks on the fintech’s AML function, which adds a commercial dimension to the role.

The EU baseline: compliance manager and compliance officer

The EU Anti-Money Laundering Regulation replaces the national transpositions of the AML directives with a single rulebook that applies directly in every member state. On the compliance function it prescribes a two-tier structure that most national regimes already reflect: a compliance manager drawn from the management body, who owns the policy and its resourcing, and a compliance officer appointed by that body, who runs day-to-day controls, files reports with the FIU and acts as the contact point for supervisors.

Four details matter for hiring. The compliance officer must have sufficiently high hierarchical standing, report to the management body directly and be free to raise concerns on their own initiative; the Regulation shields them from retaliation and commercial pressure. The company must supply the function with staff and technology proportionate to its size and risk. Where senior management is subject to fit and proper checks, the compliance officer is assessed against the same standard. And removing a compliance officer requires prior notice to the management body and a report to the supervisor, so a poor appointment is hard to undo quietly.

Member states keep their own appointment mechanics on top of this floor: residency expectations, notification to the FIU or supervisor, prior approval of the candidate. We verify those rules for each jurisdiction before a name is proposed.

Two roles, not one

Under the Regulation, and in the national regimes that mirror it, the board-level manager and the operational officer are distinct functions. The first owns the policy and answers for resourcing; the second runs the controls and signs the reports. One person may hold both only where the nature, risks, complexity and size of the business justify it.

MLRO requirements: what regulators expect from a candidate

EU law prescribes no diploma or certificate for the role, and national acts generally ask for education, suitability, experience and reputation rather than a named qualification. The MLRO requirements are qualitative: a fit and proper test applied by the competent authority or the FIU when the appointment is coordinated, or when a licence application names the intended officer. The elements are broadly the same everywhere:

  • education relevant to the duties, typically in law, finance or audit;
  • professional experience in an AML/CFT function, ideally in a supervised institution;
  • personal qualities and the ability to act independently of the commercial side of the business;
  • an impeccable reputation, tested against criminal records and past supervisory history;
  • presence in the jurisdiction where the law requires it, and genuine capacity to do the job.

Continuity is part of the test. Several national regimes require a deputy MLRO, and every supervisor asks what happens when the officer is on leave or resigns. Naming a deputy or arranging interim cover answers that before it is asked.

Capacity is assessed, not assumed

Regulators look at whether the candidate can actually do the job: hours available, other appointments held, distance between the person and the transaction flow. An AML officer who serves several unrelated companies, or who sits abroad and visits occasionally, invites exactly the questions a licence applicant wants to avoid.

In-house, outsourced or fractional MLRO: what regulators accept

Most companies looking for an MLRO are first offered an outsourcing model: a virtual MLRO, a fractional officer shared between several start-ups, a firm that lends a name. Whether any of it works depends on what the licence and the national act require, and the answer differs by model.

Model How it works Where regulators push back
In-house MLRO Employee appointed by the board, named in the licence, reachable by the FIU Only on the individual: education, experience, reputation, capacity
Outsourced MLRO External firm supplies a named individual under an outsourcing agreement Permitted in some states, excluded in others; where allowed, the agreement, the individual’s fitness and the board’s retained responsibility are all reviewed
Fractional MLRO One officer serves several unrelated companies part-time Capacity and conflicts of interest; crypto and payment supervisors increasingly expect one officer per licence
Interim MLRO Temporary officer while a permanent hire is found or during absence Accepted as a bridge if the regulator is told; not accepted as a permanent structure

Eesti Firma works with all four models. We recruit in-house officers, provide outsourced MLRO services or a fractional officer where the jurisdiction and the licence allow it, and arrange an interim MLRO when a company needs a bridge. If you already have a candidate in mind, we vet that person against the regulator’s criteria before the name goes to the authority.

MLRO recruitment and AML officer services from Eesti Firma

Eesti Firma has supported crypto and fintech projects since the first European licensing wave, and the question of whom to hire as MLRO comes up in almost every one of them. We run a dedicated practice for the search, vetting, employment and training of AML compliance officers for regulated companies in any EU jurisdiction, working with local partners where the appointment must be made on the ground.

MLRO search and candidate vetting

We select candidates against the client’s brief and the regulator’s expectations at the same time. In screening we look first at:

  • education and hands-on AML experience, ideally in a regulated institution;
  • working knowledge of the national act, the EU AML/CFT framework and FATF standards;
  • business reputation, checked before a name is put forward;
  • real availability to work in the jurisdiction and to be reachable by the FIU.

The same screening is available as a stand-alone check for a candidate the client has found itself: we review the file the way the regulator will, flag what is likely to draw questions, and say plainly whether the appointment is worth submitting. Once the candidate is chosen we prepare the appointment package: the board resolution, the description of the role and reporting line, the documents the FIU or supervisor sees during coordination, and the employment registration.

AML officer training and refresher courses

A newly appointed compliance officer rarely arrives already fitted to the business. We provide onboarding training for the new AML officer built around the client’s risk assessment and internal rules, refresher courses when the law or supervisory guidance changes, and the staff AML training programme that the law requires for employees who onboard customers or conclude transactions.

Ongoing AML compliance support for the MLRO

Beyond the hire, our lawyers support the compliance officer in practice: drafting and revising internal rules and the risk assessment, reviewing monitoring scenarios, preparing correspondence with the FIU or the financial supervisor, and advising on KYC and transaction monitoring tools. Where an officer leaves at short notice, we help the company bridge the gap without breaching its licence conditions.

Who this service is for

Crypto-asset service providers, payment and e-money institutions, creditors, crowdfunding platforms, trust and company service providers, and any company preparing a licence application in an EU member state that must name its compliance officer before filing.

If your project needs an MLRO, an AML officer or a full compliance team, describe the business model, the jurisdiction and the licence you hold or seek, and we will come back with candidate profiles and a plan.

Frequently asked questions

This guide was prepared by the Eesti Firma team, including Co-founder and Chief Legal Officer Ilja Nikiforov, and is intended solely for informational purposes. None of the provided content constitutes legal, tax, or investment advice. While every effort has been made to ensure accuracy at the time of publication, laws and regulations may change. For personalized legal assistance, please contact Eesti Firma directly.