Meet Dr. Marcus Hartmann
Dr. Marcus Hartmann has spent over two decades at the intersection of financial law and emerging technology. Based in Zug, Switzerland's Crypto Valley, he has guided exchanges, custodians, and institutional investors through the full spectrum of VASP and CASP licensing, where naming a credible MLRO is now a standard condition of authorisation.
He has built and staffed AML governance structures for clients operating under MiCA in the EU, FCA registration in the UK, and FATF-aligned regimes across the Gulf and Asia, and advises on fit and proper assessments, compliance-team design, and MLRO appointments across more than 60 jurisdictions.
An MLRO is a Money Laundering Reporting Officer: the named individual a regulated crypto firm appoints to own its anti-money laundering programme. The MLRO receives internal suspicion reports from staff, decides whether to file a Suspicious Activity Report with the national authority, and ensures the firm complies with money laundering regulations.
- An MLRO is the named officer accountable for a crypto firm's AML and CFT programme, including the legal duty to file Suspicious Activity Reports to the national authority
- FATF Recommendation 18 requires obliged entities to appoint a compliance officer at management level, and MiCA, FCA registration, and VASP regimes make the appointment a licensing precondition
- The post-holder must pass a fit and proper or approved-person test; in the UK the role is the FCA's SMF17 Senior Management Function
- An MLRO carries personal accountability and can face individual enforcement, fines, or a prohibition order for failures in the firm's controls
- Regulators increasingly expect a genuinely resident, on-payroll MLRO with real authority, not a nominal name on the application
What an MLRO Actually Is
The MLRO, or Money Laundering Reporting Officer, is the single most important compliance appointment a crypto business makes. It is the named individual who carries personal responsibility for the firm's anti-money laundering and counter-terrorist financing programme. The role is not unique to crypto: it has existed in banking and professional services for decades. What is new is that licensed and registered crypto firms now sit squarely within the same obligation.
The MLRO has two distinct legal responsibilities. The first is the duty to report suspicion of money laundering to the national financial intelligence unit, for example the National Crime Agency in the United Kingdom. The second is to ensure the firm as a whole complies with the applicable money laundering regulations. Everything an MLRO does flows from those two pillars: the reporting line and the ownership of the control framework.
For a crypto firm specifically, the MLRO must understand more than traditional AML. They need a working grasp of FATF crypto guidance, blockchain analytics, wallet tracing, and the Travel Rule that attaches sender and recipient data to virtual asset transfers. If you are new to the underlying obligations, our companion guide on AML and KYC explained sets out the framework the MLRO is appointed to run.
Sources: FATF Recommendation 18; FCA Handbook (SMF17 / SUP 10C.6); Regulation (EU) 2023/1114 (MiCA) and the EU AML framework.
What the Crypto MLRO Does Day to Day
The MLRO sits at the centre of the firm's financial crime defences. The most visible duty is handling suspicious activity. Staff who notice something unusual raise an internal report to the MLRO, who investigates, gathers context, and decides whether the suspicion warrants a formal Suspicious Activity Report to the authorities. That decision is the MLRO's alone, and it is the point at which a firm's internal concern becomes a legal disclosure.
Beyond reporting, the MLRO owns the AML control framework. That means designing and maintaining the firm's written policies, overseeing customer due diligence and enhanced due diligence, running transaction monitoring, managing sanctions and watchlist screening, and ensuring the Travel Rule data process works for covered transfers. The MLRO also drives staff training so that the people raising internal reports know what to look for.
Crucially, the MLRO is a reporting line to the top of the firm. They are expected to brief the board or senior management on financial crime risk, escalate systemic weaknesses, and act as the firm's main point of contact with the supervisor. Where a firm operates a no-questions-asked model, those defences collapse, which is exactly the failure pattern we examine in our analysis of the risks of no-KYC exchanges.
MLRO vs Compliance Officer
The terms MLRO, AML compliance officer, and compliance officer are often used loosely, but regulators draw real distinctions. A compliance officer has the broad mandate of keeping the firm within all of its regulatory obligations, including conduct, governance, reporting, and the design of AML policy. The MLRO is the narrower, statutory role focused on suspicious activity reporting and the operational AML function. In larger firms the two are separate people; in smaller firms one person may lawfully hold both, subject to the regulator's approval.
The table below sets out where the responsibilities differ. Getting this structure right is a governance decision that regulators scrutinise closely during licensing, and our compliance advisory service helps firms design a defensible split before they apply.
| Dimension | MLRO | Compliance Officer |
|---|---|---|
| Primary focus | Suspicious activity reporting and AML operations | All regulatory compliance and conduct |
| Files SARs externally | Yes, the named filer | No, unless also the MLRO |
| Statutory appointment | Required by AML law / FATF R.18 | Often required, role scope varies |
| UK function | SMF17 (MLRO) | SMF16 (Compliance Oversight) |
| Can be combined | Yes, in smaller firms with approval | Yes, with the MLRO role in smaller firms |
Based on FATF Recommendation 18 and the FCA Senior Managers and Certification Regime (SMF16 / SMF17). National rules vary.
"Founders think the MLRO is a box to tick. It is not. The regulator reads the appointment as a statement about how seriously the firm takes financial crime. We have seen otherwise strong applications stall purely because the proposed MLRO could not evidence real authority or relevant crypto AML experience."
Dr. Marcus Hartmann, Senior Licensing Advisor
Why Crypto Firms Must Appoint One
The obligation to appoint an MLRO is not optional for a regulated crypto business. It flows from international standards down into national law. At the global level, FATF Recommendation 18 requires obliged entities, including virtual asset service providers, to run an internal AML and CFT programme that includes the appointment of a compliance officer at management level, alongside internal policies, employee screening, and an independent audit function.
In the European Union, crypto-asset service providers authorised under MiCA, Regulation (EU) 2023/1114, are designated obliged entities under the EU anti-money laundering framework. That means the full AML and CFT regime applies, not a lighter version: customer due diligence, the Travel Rule for transfers of EUR 1,000 or more, transaction monitoring, five-year record retention, and a named, qualified MLRO. National competent authorities expect to see a clear three-lines-of-defence model and fit and proper key function holders before they authorise a CASP. Our AML and KYC compliance service builds this structure into the licensing engagement.
The same logic applies under legacy national VASP regimes and standalone registrations such as the FCA cryptoasset register in the UK. As the MiCA transitional period for grandfathered VASPs winds down across the EU through 2026, firms moving from a national VASP registration to a full CASP authorisation are finding that the MLRO appointment is examined more rigorously than before, not less.
Why this matters for licensing: the MLRO is not a hire you make after the licence is granted. Most regulators want to assess the named individual as part of the application itself. A weak or absent MLRO appointment is one of the most common reasons a crypto licence application is delayed or refused. See our compliance service for how we structure the function before submission.
Need a fit and proper MLRO for your licence application? Get a free 30-minute consultation. We will assess your compliance structure and help you appoint and document the MLRO regulators expect to see.
Get Free Consultation →The Fit and Proper Test
An MLRO cannot simply be appointed by the firm. The candidate must satisfy the regulator's fit and proper assessment, the test of whether an individual has the honesty, integrity, competence, and financial soundness to hold a key function. The regulator examines AML experience, professional qualifications, criminal and disciplinary history, and the candidate's capacity to actually do the job given other commitments.
In the United Kingdom the role is formalised as SMF17, the Money Laundering Reporting Officer Senior Management Function under the FCA's Senior Managers and Certification Regime. A firm in scope must have an FCA-approved SMF17 holder, and the FCA states that it pays particular attention to the competence and capability of SMF17 candidates, expecting their skills and knowledge to be proportionate to the firm's size and its risk of harm.
For a crypto MLRO, regulators increasingly look for more than a generic AML background. Recognised credentials such as an ACAMS certification, a legal or finance education, and demonstrable knowledge of FATF crypto guidance, the Travel Rule, and blockchain analytics all strengthen the case. Substance matters too: a growing number of supervisors expect the MLRO to be locally resident, genuinely available, and on the firm's own payroll rather than a remote name on the application.
| Fit and Proper Factor | What the Regulator Looks For |
|---|---|
| Honesty & integrity | Clean criminal and regulatory record, no disqualifications |
| Competence & capability | AML experience and qualifications proportionate to firm size and risk |
| Crypto knowledge | FATF crypto guidance, Travel Rule, blockchain analytics, wallet tracing |
| Capacity | Genuine availability; not spread thin across unrelated mandates |
| Substance | Local residence, on payroll, real authority within the firm |
Indicative; based on the FCA approach to SMF17 and common national competent authority practice. Exact criteria vary by jurisdiction.
In our VASP and CASP licensing work across more than 60 jurisdictions, the MLRO appointment is where applications most often come unstuck. Founders frequently propose a director who already wears three other hats, or a remote consultant with no local footprint. Supervisors read both as a signal that the firm sees AML as a formality, and the file slows immediately.
The applications that move fastest are the ones where the MLRO is identified early, has documented crypto AML experience, and sits inside a clearly drawn three-lines-of-defence structure. We routinely advise clients to lock the MLRO appointment down before drafting the rest of the licensing pack, because almost every other AML document, from the risk assessment to the policy manual, has to be owned by that named individual to carry credibility.
Personal Liability of the MLRO
The flip side of holding a key function is personal accountability. The MLRO is not a passive title; it carries individual exposure for the firm's AML failures. Under accountability regimes such as the FCA's Senior Managers and Certification Regime, an approved MLRO can face individual enforcement action, financial penalties, or a prohibition order that bars them from working in regulated financial services.
The exposure also runs to the reporting duty itself. Where an MLRO knows or suspects money laundering and fails to make the required disclosure, that omission can carry personal criminal liability in many jurisdictions, separate from any action against the firm. This is precisely why the role demands genuine authority and resources: an MLRO who is denied the information or independence to do the job is being set up to carry a risk they cannot manage.
For founders, the practical lesson is that the MLRO must be empowered, not just named. A credible candidate will ask hard questions about reporting lines, budget, and board access before accepting the role, because their own licence to operate in the industry is on the line alongside the firm's.
How the MLRO Files a SAR
The Suspicious Activity Report workflow is the operational heart of the MLRO role. The five steps below describe the path from an employee's first concern to a filed disclosure and the records that evidence it. The detail varies by jurisdiction, but the sequence is consistent across regimes.
Crypto MLRO: Common Questions
Sources & Official References
- FATF: The FATF Recommendations (including Recommendation 18 on internal controls)
- FATF: Explanatory Materials on Recommendations 18 and 23
- FCA: Heads of Compliance and MLROs (SMF16 / SMF17)
- FCA Handbook: SUP 10C.6 FCA-required Senior Management Functions
- EBA: Anti-Money Laundering and Countering the Financing of Terrorism
- EUR-Lex: Regulation (EU) 2023/1114 (Markets in Crypto-Assets, MiCA)
- FATF: Virtual Assets (guidance for VASPs)