Compliance team signing documents in a meeting, the crypto MLRO role explained in 2026
Guides: AML & Compliance

What Does a Crypto MLRO Do? Compliance Officer Role & Requirements in 2026

The crypto MLRO, or Money Laundering Reporting Officer, is the named individual who owns a licensed firm's AML programme, files Suspicious Activity Reports, and answers to the regulator. This guide explains the role, the difference between an MLRO and a compliance officer, the fit and proper test, why MiCA CASPs and VASPs must appoint one, and the personal liability that comes with the job in 2026.

Reading time~9 minutes
Last updatedJune 2026
CategoryAML & Compliance

Meet Dr. Marcus Hartmann

Dr. Marcus Hartmann, Senior Crypto Licensing Advisor
Dr. Marcus Hartmann
Senior Licensing Advisor · Zug, Switzerland
LL.M. International Financial Law · Dr. iur. · Zurich Bar

Dr. Marcus Hartmann has spent over two decades at the intersection of financial law and emerging technology. Based in Zug, Switzerland's Crypto Valley, he has guided exchanges, custodians, and institutional investors through the full spectrum of VASP and CASP licensing, where naming a credible MLRO is now a standard condition of authorisation.

He has built and staffed AML governance structures for clients operating under MiCA in the EU, FCA registration in the UK, and FATF-aligned regimes across the Gulf and Asia, and advises on fit and proper assessments, compliance-team design, and MLRO appointments across more than 60 jurisdictions.

22 years in financial services regulation
400+ crypto licensing mandates across 60+ jurisdictions
Certified AML Officer (ACAMS), FINMA-registered
Fluent in English, German, and French
View Full Profile →
Definition · MLRO

An MLRO is a Money Laundering Reporting Officer: the named individual a regulated crypto firm appoints to own its anti-money laundering programme. The MLRO receives internal suspicion reports from staff, decides whether to file a Suspicious Activity Report with the national authority, and ensures the firm complies with money laundering regulations.

Key Takeaways
  • An MLRO is the named officer accountable for a crypto firm's AML and CFT programme, including the legal duty to file Suspicious Activity Reports to the national authority
  • FATF Recommendation 18 requires obliged entities to appoint a compliance officer at management level, and MiCA, FCA registration, and VASP regimes make the appointment a licensing precondition
  • The post-holder must pass a fit and proper or approved-person test; in the UK the role is the FCA's SMF17 Senior Management Function
  • An MLRO carries personal accountability and can face individual enforcement, fines, or a prohibition order for failures in the firm's controls
  • Regulators increasingly expect a genuinely resident, on-payroll MLRO with real authority, not a nominal name on the application

What an MLRO Actually Is

The MLRO, or Money Laundering Reporting Officer, is the single most important compliance appointment a crypto business makes. It is the named individual who carries personal responsibility for the firm's anti-money laundering and counter-terrorist financing programme. The role is not unique to crypto: it has existed in banking and professional services for decades. What is new is that licensed and registered crypto firms now sit squarely within the same obligation.

The MLRO has two distinct legal responsibilities. The first is the duty to report suspicion of money laundering to the national financial intelligence unit, for example the National Crime Agency in the United Kingdom. The second is to ensure the firm as a whole complies with the applicable money laundering regulations. Everything an MLRO does flows from those two pillars: the reporting line and the ownership of the control framework.

For a crypto firm specifically, the MLRO must understand more than traditional AML. They need a working grasp of FATF crypto guidance, blockchain analytics, wallet tracing, and the Travel Rule that attaches sender and recipient data to virtual asset transfers. If you are new to the underlying obligations, our companion guide on AML and KYC explained sets out the framework the MLRO is appointed to run.

R.18
FATF Compliance-Officer Rule
SMF17
UK FCA MLRO Function
2
Core Legal Duties
€1,000
EU Travel Rule Threshold
5 yrs
CASP Record Retention
Mandatory
For VASP & CASP Licences

Sources: FATF Recommendation 18; FCA Handbook (SMF17 / SUP 10C.6); Regulation (EU) 2023/1114 (MiCA) and the EU AML framework.

What the Crypto MLRO Does Day to Day

The MLRO sits at the centre of the firm's financial crime defences. The most visible duty is handling suspicious activity. Staff who notice something unusual raise an internal report to the MLRO, who investigates, gathers context, and decides whether the suspicion warrants a formal Suspicious Activity Report to the authorities. That decision is the MLRO's alone, and it is the point at which a firm's internal concern becomes a legal disclosure.

Beyond reporting, the MLRO owns the AML control framework. That means designing and maintaining the firm's written policies, overseeing customer due diligence and enhanced due diligence, running transaction monitoring, managing sanctions and watchlist screening, and ensuring the Travel Rule data process works for covered transfers. The MLRO also drives staff training so that the people raising internal reports know what to look for.

Crucially, the MLRO is a reporting line to the top of the firm. They are expected to brief the board or senior management on financial crime risk, escalate systemic weaknesses, and act as the firm's main point of contact with the supervisor. Where a firm operates a no-questions-asked model, those defences collapse, which is exactly the failure pattern we examine in our analysis of the risks of no-KYC exchanges.

MLRO vs Compliance Officer

The terms MLRO, AML compliance officer, and compliance officer are often used loosely, but regulators draw real distinctions. A compliance officer has the broad mandate of keeping the firm within all of its regulatory obligations, including conduct, governance, reporting, and the design of AML policy. The MLRO is the narrower, statutory role focused on suspicious activity reporting and the operational AML function. In larger firms the two are separate people; in smaller firms one person may lawfully hold both, subject to the regulator's approval.

The table below sets out where the responsibilities differ. Getting this structure right is a governance decision that regulators scrutinise closely during licensing, and our compliance advisory service helps firms design a defensible split before they apply.

Dimension MLRO Compliance Officer
Primary focus Suspicious activity reporting and AML operations All regulatory compliance and conduct
Files SARs externally Yes, the named filer No, unless also the MLRO
Statutory appointment Required by AML law / FATF R.18 Often required, role scope varies
UK function SMF17 (MLRO) SMF16 (Compliance Oversight)
Can be combined Yes, in smaller firms with approval Yes, with the MLRO role in smaller firms

Based on FATF Recommendation 18 and the FCA Senior Managers and Certification Regime (SMF16 / SMF17). National rules vary.

"Founders think the MLRO is a box to tick. It is not. The regulator reads the appointment as a statement about how seriously the firm takes financial crime. We have seen otherwise strong applications stall purely because the proposed MLRO could not evidence real authority or relevant crypto AML experience."

Dr. Marcus Hartmann, Senior Licensing Advisor

Why Crypto Firms Must Appoint One

The obligation to appoint an MLRO is not optional for a regulated crypto business. It flows from international standards down into national law. At the global level, FATF Recommendation 18 requires obliged entities, including virtual asset service providers, to run an internal AML and CFT programme that includes the appointment of a compliance officer at management level, alongside internal policies, employee screening, and an independent audit function.

In the European Union, crypto-asset service providers authorised under MiCA, Regulation (EU) 2023/1114, are designated obliged entities under the EU anti-money laundering framework. That means the full AML and CFT regime applies, not a lighter version: customer due diligence, the Travel Rule for transfers of EUR 1,000 or more, transaction monitoring, five-year record retention, and a named, qualified MLRO. National competent authorities expect to see a clear three-lines-of-defence model and fit and proper key function holders before they authorise a CASP. Our AML and KYC compliance service builds this structure into the licensing engagement.

The same logic applies under legacy national VASP regimes and standalone registrations such as the FCA cryptoasset register in the UK. As the MiCA transitional period for grandfathered VASPs winds down across the EU through 2026, firms moving from a national VASP registration to a full CASP authorisation are finding that the MLRO appointment is examined more rigorously than before, not less.

Why this matters for licensing: the MLRO is not a hire you make after the licence is granted. Most regulators want to assess the named individual as part of the application itself. A weak or absent MLRO appointment is one of the most common reasons a crypto licence application is delayed or refused. See our compliance service for how we structure the function before submission.

◆ Need Help?

Need a fit and proper MLRO for your licence application? Get a free 30-minute consultation. We will assess your compliance structure and help you appoint and document the MLRO regulators expect to see.

Get Free Consultation →

The Fit and Proper Test

An MLRO cannot simply be appointed by the firm. The candidate must satisfy the regulator's fit and proper assessment, the test of whether an individual has the honesty, integrity, competence, and financial soundness to hold a key function. The regulator examines AML experience, professional qualifications, criminal and disciplinary history, and the candidate's capacity to actually do the job given other commitments.

In the United Kingdom the role is formalised as SMF17, the Money Laundering Reporting Officer Senior Management Function under the FCA's Senior Managers and Certification Regime. A firm in scope must have an FCA-approved SMF17 holder, and the FCA states that it pays particular attention to the competence and capability of SMF17 candidates, expecting their skills and knowledge to be proportionate to the firm's size and its risk of harm.

For a crypto MLRO, regulators increasingly look for more than a generic AML background. Recognised credentials such as an ACAMS certification, a legal or finance education, and demonstrable knowledge of FATF crypto guidance, the Travel Rule, and blockchain analytics all strengthen the case. Substance matters too: a growing number of supervisors expect the MLRO to be locally resident, genuinely available, and on the firm's own payroll rather than a remote name on the application.

Fit and Proper Factor What the Regulator Looks For
Honesty & integrity Clean criminal and regulatory record, no disqualifications
Competence & capability AML experience and qualifications proportionate to firm size and risk
Crypto knowledge FATF crypto guidance, Travel Rule, blockchain analytics, wallet tracing
Capacity Genuine availability; not spread thin across unrelated mandates
Substance Local residence, on payroll, real authority within the firm

Indicative; based on the FCA approach to SMF17 and common national competent authority practice. Exact criteria vary by jurisdiction.

From Our Practice

In our VASP and CASP licensing work across more than 60 jurisdictions, the MLRO appointment is where applications most often come unstuck. Founders frequently propose a director who already wears three other hats, or a remote consultant with no local footprint. Supervisors read both as a signal that the firm sees AML as a formality, and the file slows immediately.

The applications that move fastest are the ones where the MLRO is identified early, has documented crypto AML experience, and sits inside a clearly drawn three-lines-of-defence structure. We routinely advise clients to lock the MLRO appointment down before drafting the rest of the licensing pack, because almost every other AML document, from the risk assessment to the policy manual, has to be owned by that named individual to carry credibility.

Personal Liability of the MLRO

The flip side of holding a key function is personal accountability. The MLRO is not a passive title; it carries individual exposure for the firm's AML failures. Under accountability regimes such as the FCA's Senior Managers and Certification Regime, an approved MLRO can face individual enforcement action, financial penalties, or a prohibition order that bars them from working in regulated financial services.

The exposure also runs to the reporting duty itself. Where an MLRO knows or suspects money laundering and fails to make the required disclosure, that omission can carry personal criminal liability in many jurisdictions, separate from any action against the firm. This is precisely why the role demands genuine authority and resources: an MLRO who is denied the information or independence to do the job is being set up to carry a risk they cannot manage.

For founders, the practical lesson is that the MLRO must be empowered, not just named. A credible candidate will ask hard questions about reporting lines, budget, and board access before accepting the role, because their own licence to operate in the industry is on the line alongside the firm's.

How the MLRO Files a SAR

The Suspicious Activity Report workflow is the operational heart of the MLRO role. The five steps below describe the path from an employee's first concern to a filed disclosure and the records that evidence it. The detail varies by jurisdiction, but the sequence is consistent across regimes.

1
Detect
Staff identify suspicious activity
An employee or an automated transaction-monitoring alert flags a transaction or customer that looks inconsistent with the expected profile or carries financial crime indicators.
2
Escalate
Raise an internal report to the MLRO
The staff member submits an internal suspicious activity report to the MLRO without tipping off the customer, handing the matter to the one person empowered to decide on external disclosure.
3
Investigate
MLRO reviews and gathers context
The MLRO examines the customer file, transaction history, KYC data, and any blockchain analytics, then forms a reasoned judgment on whether genuine suspicion exists.
4
Decide & file
Submit the SAR to the FIU
If suspicion is confirmed, the MLRO files a formal Suspicious Activity Report with the national financial intelligence unit, and where required seeks consent before proceeding with the transaction.
5
Record & retain
Document the decision and store it
The MLRO records the rationale, whether or not a SAR was filed, and retains the file for the statutory period so the firm can evidence its decision to the supervisor.

Crypto MLRO: Common Questions

An MLRO is a Money Laundering Reporting Officer, the named individual a regulated firm appoints to own its anti-money laundering programme. The MLRO receives internal suspicion reports from staff, decides whether to file a Suspicious Activity Report with the national financial intelligence unit, and ensures the firm complies with money laundering regulations.
A crypto MLRO owns the firm's AML and CFT framework, receives internal suspicious activity reports, investigates them, and decides whether to file a formal SAR with the national authority. They also oversee transaction monitoring, the Travel Rule process, staff training, sanctions screening, and report on financial crime risk to the board or senior management.
Yes. In almost every regulated market, a licensed or registered crypto firm is an obliged entity that must appoint an MLRO or equivalent compliance officer. FATF Recommendation 18 requires a compliance officer at management level, and MiCA, FCA registration, and national VASP regimes all make the appointment a precondition of authorisation.
A compliance officer oversees the firm's general adherence to regulation, including conduct, governance, and AML policy design. The MLRO is the specific role responsible for receiving internal suspicion reports and deciding whether to file SARs with the authorities. In smaller firms one person may hold both roles, but larger firms separate them.
A SAR, or Suspicious Activity Report, is a disclosure to the national financial intelligence unit about a transaction or customer suspected of money laundering or terrorist financing. Staff raise an internal report to the MLRO, who investigates and decides whether to submit a formal SAR externally. The MLRO is the only person who files the external report.
Fit and proper is a regulatory assessment of whether a candidate has the honesty, integrity, competence, and financial soundness to hold a key function. For an MLRO, the regulator examines AML experience, qualifications, criminal and disciplinary history, and capacity. The FCA assesses the SMF17 candidate's competence in proportion to the firm's size and risk.
SMF17 is the Money Laundering Reporting Officer Senior Management Function under the FCA's Senior Managers and Certification Regime. A UK firm in scope must have an FCA-approved SMF17 holder. The FCA pays particular attention to the competence and capability of SMF17 candidates, expecting skills proportionate to the firm's size and risk of harm.
Yes. Crypto-asset service providers authorised under MiCA are obliged entities under the EU anti-money laundering framework, so the full AML and CFT regime applies. National competent authorities expect a CASP applicant to name a qualified MLRO, evidence a three-lines-of-defence model, and pass fit and proper assessments on all key function holders.
Some operational tasks can be supported by outsourced specialists, but the accountable MLRO must be a named, approved individual with real authority inside the firm. Regulators reject applications where the compliance function is combined with a revenue role or shared across entities, and many expect the MLRO to be on the firm's own payroll.
Increasingly, yes. As substance requirements tighten, many regulators expect the MLRO to be locally resident, available to the supervisor, and genuinely present rather than a name on paper. The exact rule varies by jurisdiction, but a remote or nominal MLRO with no local footprint is a common reason for application delay or refusal.
Yes. The MLRO holds personal accountability for the AML function. Under regimes such as the FCA Senior Managers and Certification Regime, an approved MLRO can face individual enforcement, fines, or a prohibition order for failures in the firm's financial crime controls. Failure to report a known suspicion can also carry personal criminal exposure.
There is no single mandatory licence, but regulators expect relevant AML experience plus recognised credentials such as an ACAMS certification, a legal or finance background, and demonstrable knowledge of FATF crypto guidance, the Travel Rule, blockchain analytics, and wallet tracing. The depth required scales with the firm's size and risk profile.
FATF Recommendation 18 requires financial institutions, including virtual asset service providers, to maintain internal AML and CFT programmes that include the appointment of a compliance officer at management level, plus internal policies, employee screening, training, and an independent audit function to test the system.
Naming a credible, fit and proper MLRO is a baseline condition of most VASP and CASP licence applications. Regulators want to see who the MLRO is, their qualifications, their authority within the firm, and how the AML programme they own is documented before granting authorisation. A weak MLRO appointment is a frequent cause of application failure.

Sources & Official References

MH
Senior Licensing Advisor · LL.M. International Financial Law
22 years in financial services regulation. Advised 400+ crypto licensing mandates across 60+ jurisdictions. Based in Zug, Switzerland.
Free Consultation

Get Your AML Function Right Before You Apply

Share your business model and target markets, and we will help you appoint a fit and proper MLRO, design a defensible compliance structure, and build the AML framework regulators expect to see. No obligation.

  • 🇨🇭 Swiss-registered firm, Zug
  • ⚡ Response within 24 hours
  • 🔒 Strictly confidential
  • ✓ 80+ jurisdictions covered

Confidential · No obligation · No spam