Every crypto company operating in Lithuania under the EU MiCA framework needs a named individual who answers for its AML/CFT controls. Lithuanian law calls that individual a senior employee responsible for the prevention of money laundering; the market calls them the money laundering reporting officer, MLRO, AML officer or compliance officer. The appointment is not an internal formality: the person is named in the authorisation file, notified to the regulator and examined again at every inspection.
Is an MLRO mandatory for a crypto company in Lithuania
Yes. The Lithuanian Law on the Prevention of Money Laundering and Terrorist Financing lists crypto-asset service providers among financial institutions, and article 22 of the Act requires every financial institution to designate senior employees to organise its anti-money laundering measures and liaise with the Financial Crime Investigation Service (FNTT, often cited in English as the FCIS). The only carve-out is a provider whose sole service is advice on crypto-assets. For everyone else the duty applies from the first day of operations.
| Requirement | What the Act says | In practice |
|---|---|---|
| Senior employee (MLRO) | Designated to organise anti-money laundering measures and to cooperate with the FNTT | A named person with a managerial position, an employment contract and real authority over onboarding, monitoring and reporting |
| Responsible board member | Where the company is managed by a board, a board member is designated to organise the framework | Owns the policy at management level; a different person from the MLRO once the business has volume |
| Notification | The FNTT is informed in writing within seven working days of the designation or replacement of either person | Missed deadlines surface at the first inspection |
| Staff training | Relevant employees take part in continuous training programmes on recognising money laundering | The MLRO runs the programme and keeps the attendance records |
Since the national transitional period closed, a Lithuanian crypto company operates under a CASP authorisation from the Bank of Lithuania (Lietuvos bankas), which supervises it under MiCA and shares AML/CFT oversight with the FNTT (how the regime changed is covered in our note on the new Lithuanian crypto-asset rules). The compliance officer therefore answers to two regulators: suspicious transaction reports and the appointment notice go to the FNTT; questions about staffing, governance and the design of controls come from the central bank.
Does the MLRO have to be a resident of Lithuania
This is the question founders ask first, and most of the answers still circulating online are out of date. The former registration regime for virtual asset businesses did require a senior manager who was a permanent resident of Lithuania. Those provisions were repealed together with the regime when the transitional period ended, and article 22 of the Act, which now governs the appointment of an AML officer in Lithuania, contains no residency condition.
What replaced the old rule is a substance test. The Bank of Lithuania’s expectations letter to future crypto-asset service providers sets out three things: the applicant must not be an empty shell; key operational and control functions cannot be outsourced to the point where the company no longer controls them; and at least part of the key managers entitled to take decisions should reside in Lithuania, or the company must ensure management and accessibility for the supervisor in another verifiable way. The EU technical standard on CASP applications adds that the location of every head of an internal control function is stated in the file. In practice the compliance officer is expected to sit in the Lithuanian operation centre, see the transaction flow, be able to stop an onboarding and meet an inspector at short notice. An AML officer who lives elsewhere, serves several unrelated firms and visits occasionally fails that test.
Capacity is assessed, not assumed
The central bank reads the staffing table against the business plan. If a platform projects tens of thousands of customers and names one part-time compliance officer, the supervisor will ask how monitoring, screening and reporting will physically be done. Recruit for the volume you plan, not for the minimum you can defend.
Requirements for an AML officer in a Lithuanian crypto company
The Act prescribes no diploma or certificate. It asks for a senior employee, and the Bank of Lithuania asks for qualifications, knowledge and time that match the business, kept current through refresher training. The EU technical standard on the content of a CASP application makes the check concrete: the file must state the identity of the person in charge of anti-money laundering compliance, with evidence of that person’s knowledge, skills and experience, and show that control functions operate independently of what they control. Formal fit-and-proper vetting applies to the management body; the MLRO is judged on the same file. A credible candidate shows:
- education in law, finance, economics or audit, and a work history in an AML or crypto compliance function, ideally in a firm supervised by the Bank of Lithuania;
- working knowledge of the Lithuanian Act, MiCA, the Travel Rule regulation, the EBA risk-factor guidelines and FATF standards, and experience with blockchain analytics;
- a managerial position inside the company with direct access to the board, not a junior analyst with an inflated title;
- an impeccable reputation: no convictions or sanctions in the areas the central bank checks for members of the management body;
- enough working time for the role, with any other positions disclosed in full;
- the ability to work in English and, ideally, Lithuanian, since the programme of activities and customer-facing procedures are filed in Lithuanian.
Can the director be the MLRO
Nothing in the Act prevents a director from being the designated senior employee. Two limits apply. The Bank of Lithuania expects the person who performs a function not to be the one who controls it, so a director who runs sales or onboarding is a poor MLRO. And a director is a member of the management body: any change to that body must be assessed and permitted by the central bank before the person takes up the duties, a supervisory step that a dedicated compliance officer does not trigger.
MLRO salary in Lithuania
A qualified compliance officer in Lithuania is a mid-to-senior hire on the Vilnius market. Budget a monthly gross salary in the low thousands of euros, employer social contributions on top, and a premium for crypto experience or Lithuanian-English fluency; that is the real cost of an in-house MLRO. One offered for a fraction of it is a name on a form, which is exactly what the substance test is designed to catch.
What the compliance officer of a Lithuanian CASP does
The statutory description is short: organise anti-money laundering measures and maintain contact with the Financial Crime Investigation Service. In a crypto-asset service provider that unpacks into:
- customer due diligence (KYC) at onboarding, including beneficial ownership, politically exposed persons and the higher-risk categories in the EBA risk-factor guidelines for crypto businesses;
- transaction monitoring on-chain and off-chain, with blockchain analytics as a standard tool;
- the Travel Rule: making sure originator and beneficiary data accompanies crypto-asset transfers and handling transfers where it is missing;
- sanctions screening and the internal procedures for international financial sanctions that the law requires of every obliged entity;
- suspicious transaction reports (STRs) to the Financial Crime Investigation Service, suspension of suspicious operations, and answers to requests for information;
- the business-wide ML/TF risk assessment, reviewed at least once a year, the internal control review at least once every two years, AML training for staff and the upkeep of internal rules;
- preparation for and follow-up of Bank of Lithuania inspections.
When the MLRO enters the picture
The money laundering reporting officer is not a post-authorisation hire. The role appears at four points in the life of a CASP in Lithuania, each with its own paperwork:
| Stage | What happens with the MLRO |
|---|---|
| Company formation | The candidate is recruited in parallel with registering the Lithuanian company so that the compliance function exists on paper and in person before anything is filed |
| Authorisation file | Identity, CV and location of the officer, the description of the function and its reporting line, the internal rules and the business-wide risk assessment go to the Bank of Lithuania with the MiCA application |
| Designation | Board resolution naming the compliance officer, employment contract, registration with the tax authority and Sodra, written notification to the FNTT within seven working days |
| Replacement | The same notification to the FNTT; if the officer sits on the management body, the central bank assesses and permits the successor before they start |
How Eesti Firma recruits and trains an MLRO for Lithuanian crypto companies
Eesti Firma has supported crypto projects in Lithuania since the first registrations under the anti-money laundering law. Our MLRO services in Lithuania cover the search, vetting, employment and training of AML specialists, from a first compliance officer to a head of compliance. We work with crypto exchanges, custodians and other crypto-asset service providers, and with applicants for a MiCA licence. Outsourced, fractional and interim models, where a licence permits them, are described on our MLRO and compliance officer services across the EU page; this page is about the in-house appointment a Lithuanian CASP is expected to make.
Search and selection
We screen candidates against the criteria above and the client’s own conditions on language, sector experience and start date. Education and employment history are checked against documents, reputation is verified before a name is put forward, and availability to work from the Lithuanian office is confirmed rather than assumed. The client meets a shortlist, and once a candidate is chosen we prepare the designation package and the description of the compliance function for the file.
Training and ongoing support
A newly appointed compliance officer rarely arrives fitted to the specific business. We provide onboarding training built around the client’s risk assessment and internal rules, refresher courses when the law or supervisory guidance changes, and the documented training programme for front-line staff that the Act requires. Beyond that, our lawyers support the AML officer in practice: revising internal rules, the risk assessment and the sanctions procedure, reviewing monitoring scenarios, and preparing correspondence with the FNTT or the Bank of Lithuania. Where an officer leaves at short notice, we bridge the gap and notify both regulators.
Who this service is for
Crypto-asset service providers authorised in Lithuania, applicants preparing an authorisation file for the Bank of Lithuania, EU financial institutions adding crypto-asset services to a Lithuanian entity, and groups that need a deputy MLRO for continuity.
If your Lithuanian crypto business needs to hire an MLRO, an AML officer or a full compliance team, describe the business model and the services you provide or seek authorisation for, and we will come back with candidate profiles and a plan.
Frequently asked questions
External advisers can draft rules, train staff and support the officer, but the Bank of Lithuania treats anti-money laundering as a key control function that cannot be outsourced to the point where the company no longer controls it, and the application must name the person in charge of it. That is why we recruit an in-house specialist for Lithuanian CASPs rather than lend a name.
The Act does not forbid it, and within a group with a shared compliance function it can work. Across unrelated companies it rarely survives the capacity test, and each company still needs its own designated compliance officer with a contract and a notification on file.
No certificate is prescribed by the Lithuanian AML law. Recognised anti-money laundering certifications strengthen a candidate’s file and shorten the supervisor’s questions, but they do not replace experience in a supervised business and knowledge of the Lithuanian framework.
The company is in breach of the Act and of its conditions of authorisation. The consequences range from a supervisory instruction to remedy the gap to fines under the anti-money laundering law; MiCA also requires the Bank of Lithuania to withdraw the authorisation of a provider that fails to keep effective AML/CFT systems and procedures in place.