AML Governance for MLROs, MLCOs and Compliance Partners
What it actually means to hold the MLRO or MLCO role at a law firm: the distinct duties Regulation 21 creates, day-to-day oversight, SRA assurance and the personal exposure that comes with the title.
Being named as a firm's Money Laundering Reporting Officer or Money Laundering Compliance Officer is not the same as being good at anti-money laundering compliance. Plenty of solicitors are handed the title, added to a policy document, and left to work out what it actually requires of them week to week. That gap between the title and the job is where firms run into trouble with the SRA, and where individual MLROs and MLCOs run into trouble personally.
This guide is about the role itself, not the mechanics underneath it. For how to build and document a compliant risk assessment, see our companion piece on firm-wide AML risk assessment for law firms, which covers Regulation 18 in depth; for fee-earner basics like client due diligence and red flags, see our AML training requirements for solicitors guide. Here, we're focused on governance: what the MLRO and MLCO roles legally are, what oversight looks like day to day, how these officers demonstrate assurance to the SRA, and the practical tensions - resourcing, independence, personal exposure - of holding either title.
Two roles, one regulation: MLRO and MLCO under Regulation 21
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017, as amended) create two distinct officer roles under Regulation 21, and it matters that they are legally separate, even though most firms fill both with the same person.
- The nominated officer (MLRO). Regulation 21 requires firms to appoint an individual to receive internal disclosures of suspected money laundering or terrorist financing and to decide whether those suspicions meet the threshold for a Suspicious Activity Report (SAR) to the National Crime Agency. This is the role most people mean when they say "MLRO". Failing to report a genuine suspicion is a criminal offence under the Proceeds of Crime Act 2002 and the Terrorism Act 2000, and that liability attaches to the individual who held the decision, not just the firm.
- The Money Laundering Compliance Officer (MLCO). Regulation 21 separately requires a member of the board, or of the firm's senior management where there is no board, to be responsible for the firm's overall compliance with the regulations. The MLCO's job is broader than SAR decisions: it is ownership of the whole AML framework - policies, controls, procedures, training, and whether the firm's practice actually matches what its documents say it does.
The SRA's own guidance for new MLCOs and MLROs notes that the large majority of firms combine both roles in one person, and for small and medium practices that is often the only realistic option. But combining the roles doesn't collapse the duties into one. An MLRO who never steps back to ask whether the firm's controls are actually working is not discharging the MLCO function, and an MLCO who never engages with how SAR decisions are actually being made is not discharging the MLRO function. Firms should be able to say, in writing, who is answerable for which duty - even where both sit with the same partner.
What oversight actually means day to day
"Oversight" is the word used constantly in AML policy documents and rarely defined in practical terms. For an MLRO or MLCO, it breaks down into a handful of concrete, recurring activities.
SAR decision-making and internal reporting lines
Every member of staff who forms a suspicion has an obligation to disclose it internally, and the firm's policy needs a clear, well-publicised route for that disclosure to reach the MLRO - not a vague instruction to "raise it with compliance". Once a disclosure lands, the MLRO assesses it against the legal threshold for suspicion, decides whether it needs to go to the NCA as a SAR, and does so without tipping off the client. We cover that decision-making process, and the tipping-off offences around it, in full in our guide to suspicious activity reports and tipping-off. From a governance perspective, the MLRO needs a defensible, documented reason for every internal report received - including the ones not escalated to a SAR, since the SRA will ask to see that reasoning too.
Escalation that actually works
Oversight also means having a route for problems that are not, individually, SAR-worthy but point to something systemic: a fee earner repeatedly missing source-of-funds checks, a practice area rubber-stamping risk assessments, a client relationship generating unusual instructions. A functioning escalation process lets staff flag these patterns to the MLCO without relying on someone informally deciding it's worth mentioning - through regular file reviews, a genuine open door for questions, and treating near-misses as information rather than embarrassments to bury.
Reporting to the board or partnership
Both MLR 2017 and the SRA expect the MLCO to report upward on the health of the firm's AML controls, not just downward to staff - typically at least an annual report to the board or partnership covering training completion, the volume and outcome of internal disclosures, audit findings, and any change in the firm's risk profile. The SRA's 2021 thematic review, "Money Laundering Governance: Three Pillars of Success," found that most effective AML officers held equity partner status or its equivalent, giving them direct access to the people who make resourcing and policy decisions. Where the MLRO or MLCO sits several rungs below partner level, oversight becomes slower and weaker by design, whatever the policy document says.
The independent audit function
Regulation 21 also requires firms, where appropriate to their size and nature, to arrange an independent audit of their AML policies, controls and procedures - testing whether they are adequate and actually followed, not just present on paper. The SRA has been clear that only the very smallest practices fall outside this expectation. Two points matter for MLROs and MLCOs specifically:
- The audit cannot be carried out by the MLRO, the MLCO, or anyone reporting to them on AML matters - it needs a genuinely independent reviewer: a separate partner with no AML responsibilities, an external consultant, or an internal audit function with clear separation from compliance.
- The audit tests the MLRO and MLCO's own work as much as anyone else's: whether SAR decisions were properly reasoned, escalations followed through, and board reporting reflected what was actually found.
There's no fixed legal frequency, but firms handling higher-risk work such as conveyancing commonly run one every twelve to twenty-four months. An MLCO who can't say when the last audit took place, or what it found, will struggle to demonstrate effective oversight if the SRA asks.
Demonstrating assurance to the SRA
The SRA does not expect perfection; it expects evidence that the firm knows where its risks lie and is actively managing them. For an MLRO or MLCO, being ready for an SRA visit, desk-based review or thematic review generally means being able to produce, without a scramble:
- Up-to-date notification of who holds the MLRO and MLCO roles, since firms must tell the SRA within 14 days of any change, along with a current Disclosure and Barring Service check for each officer, no more than three months old.
- A record of internal disclosures received, decisions made on each, and the reasoning behind SARs filed and SARs not filed.
- Evidence of training delivered across the firm, tailored to role and risk exposure rather than a single generic session repeated every year.
- Minutes or reports showing the MLCO has reported to the board or partnership, and that the firm-wide risk assessment and policies have been reviewed and, where necessary, revised as a result.
- Findings from the independent audit function, and evidence that any issues it raised were actually acted on.
The common thread is that assurance is built from a paper trail generated continuously, not assembled retrospectively when a review is announced. Treat these records as ongoing evidence of a working system, not as paperwork, and you're in a far stronger position when the SRA comes calling.
The practical reality: resourcing, independence and personal exposure
The SRA's own research into what separates effective AML officers from struggling ones points to three consistent factors: authority, independence and resources. In practice, all three are harder to secure than the guidance documents suggest.
Resourcing. The 2021 SRA thematic review found that most AML officers still carried a substantial fee-earning caseload alongside their MLRO or MLCO duties, with only a small minority having had billing targets reduced to reflect the role, and fewer than half had a designated deputy for cover or a second opinion on difficult decisions. An MLRO squeezed between chargeable hours and compliance duties will, under pressure, deprioritise the work that doesn't generate an invoice - which is precisely the work the regulations require.
Independence. An MLCO needs the standing to override a senior partner's preferred course of action on an AML matter, and that only works if it is genuinely backed by the firm's governance structure - not merely asserted in the policy manual. Where the MLRO or MLCO is junior to the partners whose client relationships they are sometimes required to question, independence exists on paper only.
Personal exposure. This is the sharpest edge of the role. The MLRO carries potential criminal liability for failing to report a genuine suspicion, and the MLCO carries accountability, in the SRA's eyes, for the adequacy of the firm's whole AML regime. Both risks sit with named individuals, not an abstract "the firm". That is why the role needs to come with real authority and real resource behind it - a title without either is exposure without protection.
None of this is a reason to avoid the role; it's a reason to insist, on appointment, that the firm's governance actually matches what Regulation 21 assumes it will look like: a genuinely senior officer, with a deputy, a reduced caseload where the firm's size warrants it, and a direct line to the partnership.
Frequently asked questions
Can the same person be both MLRO and MLCO?
Yes, and most firms combine the roles in one individual. Regulation 21 doesn't require separate people, but it does require both sets of duties to be fulfilled - SAR decision-making on one side, overall responsibility for the compliance framework on the other. Firms should record clearly which duties the combined role covers.
Does every law firm need an MLRO and MLCO?
Any SRA-regulated firm doing work within scope of the MLR 2017 needs a nominated officer, and firms of any meaningful size need a designated MLCO at board or senior management level. Only the very smallest practices, doing occasional in-scope work, might fall outside the expectation for a formal, separately resourced role - and even then, someone still has to hold the underlying responsibility.
What happens if the MLRO decides not to file a SAR and turns out to be wrong?
The legal test is whether the officer had reasonable grounds for suspicion and exercised proper judgement based on the information available, not whether the outcome later proves to have involved money laundering. This is why a documented decision-making process matters: an MLRO who can show how a decision was reached, and that it was reasoned rather than reflexive, is in a materially stronger position than one who cannot.
How does the MLCO role relate to the firm-wide risk assessment?
The MLCO typically owns the firm-wide risk assessment required under Regulation 18, working with the MLRO and compliance staff to keep it current. Oversight of that document - ensuring it is genuinely reviewed, not just re-dated - is one of the clearest, most checkable signs of effective MLCO governance. See our companion guide on firm-wide AML risk assessment for law firms for the detail.
Building the capability the role demands
Regulation 21 puts a specific, personal set of duties on named individuals, and neither the MLRO nor the MLCO role can be learned purely from a policy manual - it requires an understanding of the legal thresholds for suspicion, the audit and assurance expectations the SRA applies, and the governance structures that make independence real rather than nominal. Learnsignal's CPD courses for legal professionals include dedicated AML governance training for MLROs, MLCOs and compliance partners, built around exactly these responsibilities. If you're stepping into the role for the first time, or want to be confident your firm's governance would stand up to an SRA review, our legal CPD catalogue is the place to start.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


