The MLRO in brief
The senior individual who owns your anti-money laundering framework, decides what is reported to the authorities and answers for it to the regulator.
Also searched as: Outsourced MLRO, interim MLRO- Regulatory status
- A regulator-approved role: a Licensed Function (DFSA) or Controlled Function (FSRA), and fit and proper under VARA’s rules. Onshore, the Compliance Officer at management level carries the reporting duty.
- Reports to
- The board and senior management, with direct access to both.
- Works closely with
- The Compliance Officer, Deputy MLRO, Head of Financial Crime and client-facing teams.
- Where it sits
- Second line: independent oversight of the first-line teams who onboard and serve clients.[1]
- Typical commitment
- Agreed days each month, sized to your client base and volumes, with more around licensing, audits and inspections.
What the rules say
- In DIFC, the MLRO is a Licensed Function the DFSA must approve, held by an Authorised Individual who is a director, partner or senior manager. Every Authorised Firm must have one at all times.[2]
- In ADGM, the MLRO is a Controlled Function held by an FSRA Approved Person, and every Authorised Person must have one at all times.[3],[4]
- In both, the MLRO must be resident in the UAE unless the regulator grants a waiver, and the role can be outsourced to a suitable individual with real seniority and the capacity to do it.[5],[4]
- VARA requires every virtual asset service provider to appoint a fit and proper MLRO with at least two years of AML/CFT experience, who reports to the board every quarter. VARA allows the MLRO role to be outsourced.[6],[7]
- Onshore, the federal AML regulations require a Compliance Officer at management level who assesses suspicious transactions and decides what is reported to the Financial Intelligence Unit.[8]
Running the AML/CFT cycle
Most anti-money laundering frameworks follow the same logic, set out in the FATF Recommendations that UAE law implements: understand your risks, apply controls in proportion to them, watch for anything unusual and report it. The MLRO owns that cycle end to end.[9],[10]
What they own
- AML/CFT framework
- Enterprise-wide risk assessment (EWRA)
- Transaction monitoring
- SAR and STR filing via goAML
- Sanctions screening and escalation
- MLRO reporting to the board
Assess the risk
Keep the enterprise-wide risk assessment current: which customers, products, countries and channels expose the firm to money laundering, terrorist financing and sanctions risk.
Know the customer
Set the due diligence standard, including enhanced checks for higher-risk clients and politically exposed persons, and sign off the difficult cases.
Monitor
Oversee transaction monitoring and sanctions screening, and make sure alerts are reviewed properly and on time.
Report
Investigate internal reports and decide, independently, whether to file a suspicious transaction report with the Financial Intelligence Unit through goAML.
Train and review
Train staff, report to the board on how the framework is performing, and fix what reviews and audits find.

Why a UAE firm needs an MLRO
It is a legal requirement for regulated firms. A good MLRO is also what keeps a licence safe as the business grows.
- 01
- 02
- 03
- 04
How a fractional MLRO works with us
One brief, one accountable appointment. The person you meet is the person named on the appointment and doing the work.
Brief
Tell us where you are regulated, what stage you are at and why the role is needed. We screen the firm and any open regulatory matters before recommending an appointment.
Shortlist
We put forward senior candidates with relevant tenure in your role, sector and jurisdiction. You meet the person who will do the work, not a sales lead.
Approval
Where the role needs regulatory approval, we help prepare the application and the candidate for the fit and proper assessment. The regulator holds final acceptance.
Ongoing
Your appointee works agreed days each month, reports to your board and steps up around licensing, inspections and remediation.
The first 90 days
Days 1 to 30
Take ownership
- Review the AML policy, risk assessment and a sample of customer files
- Check screening and monitoring work, and that alerts are being cleared
- Confirm goAML registration and internal reporting lines
- Agree how and when the regulator is updated
Days 31 to 60
Fix what matters most
- Rank the gaps by risk and agree a remediation plan with the board
- Refresh the enterprise-wide risk assessment and customer risk-rating
- Tune screening and monitoring rules to the real client base
- Run targeted training for client-facing staff
Days 61 to 90
Run and report
- Set monthly management information on alerts, cases and reports
- Deliver the first MLRO report to senior management
- Test a sample of files against the new standard
- Agree the annual AML plan and training calendar
Fractional, full-time or outsourced?
All three can work. What matters to the regulator is that the person named on the appointment has the seniority, independence and time to hold it.
Signs it is time
- A licence application needs a named MLRO
- Your MLRO is leaving, or the current arrangement is not working
- Post-licence obligations have outgrown the team
- An inspection or thematic review is coming up
- You are adding higher-risk clients, products or countries
What good looks like
Relevant tenure and experience as an MLRO or in senior AML and financial crime roles.
- Prior MLRO or Deputy MLRO experience in a regulated firm
- Hands-on goAML reporting and sanctions screening
- Experience with your regulator and your sector
- The judgement to decline business, and the confidence to explain why to the board
Often appointed alongside
Most regulated firms need more than one of these roles. Each has its own guide.
- Deputy MLROThe MLRO’s second in command: shares the anti-money laundering workload and takes over the role, with its responsibilities, whenever the MLRO is unavailable.
- Compliance OfficerThe approved individual who makes sure the firm meets its regulatory obligations day to day, and tells senior management when it does not.
- Head of Financial CrimeThe senior specialist who owns the firm’s defences against money laundering, sanctions breaches, fraud and bribery, and proves they work.
MLRO, answered
Sources
- [1]The Institute of Internal Auditors, Three Lines Model: Assurance and Advice in Support of Effective Governance (2026).
- [2]Dubai Financial Services Authority, DFSA Rulebook, General Module (GEN), GEN 7.4 to 7.5, Licensed Functions and mandatory appointments.
- [3]ADGM Financial Services Regulatory Authority, General Rulebook (GEN), GEN 5.3 and 5.5, Controlled Functions and Approved Persons.
- [4]ADGM Financial Services Regulatory Authority, Anti-Money Laundering and Sanctions Rules and Guidance (AML), Chapter 12, the Money Laundering Reporting Officer.
- [5]Dubai Financial Services Authority, DFSA Rulebook, Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Module (AML), Chapter 11, the Money Laundering Reporting Officer.
- [6]Virtual Assets Regulatory Authority, Compliance and Risk Management Rulebook, Part I (Compliance Officer, risk management) and Part III (MLRO).
- [7]Virtual Assets Regulatory Authority, Company Rulebook, Part I.C (Responsible Individuals) and Part IV.A (outsourcing).
- [8]United Arab Emirates, Cabinet Resolution No. 134 of 2025, Executive Regulations of Federal Decree-Law No. 10 of 2025, Articles 21 and 22, the Compliance Officer.
- [9]Financial Action Task Force, The FATF Recommendations, Recommendations 1, 6, 10, 18 and 20.
- [10]United Arab Emirates, Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and Proliferation Financing, Articles 18, 19, 29 and 37.
- [11]UAE Financial Intelligence Unit, goAML reporting.
- [12]Executive Office for Control and Non-Proliferation, Cabinet Resolution No. 74 of 2020 on the UAE list of terrorists and targeted financial sanctions.
Plain-English summaries, reviewed September 2026. Rulebooks change, so always check the current text. Fractional places qualified executives into regulated appointments. We do not provide legal advice, and final acceptance of any appointment rests with the relevant regulator; we work alongside your appointed legal and compliance advisers. Appointments to roles requiring regulatory approval are subject to the relevant authority’s requirements.
