Skip to content
EBA · EU-wide

AMLR governance — the compliance manager and officer split

Fintech Passport
August 19, 2026 · 10-min read
AMLR governance — the compliance manager and officer split

The AMLR does not have an MLRO. It has two roles — one of them a named member of your board — and it makes removing the other one a reportable event. Regulation (EU) 2024/1624 replaces the single-officer model most firms run today with a split between a compliance manager drawn from the management body and a compliance officer who runs the day-to-day framework. It also decides who signs off the internal policies, who drafts the business-wide risk assessment and who approves it. For a compliance director, this is the article of the AML package that changes the org chart.

1. Two roles, and only one of them is on the board

Article 11 creates both. The compliance manager is one member of the management body in its management function, appointed to be responsible for ensuring compliance with the AMLR, with Regulation (EU) 2023/1113 and with any administrative act issued by a supervisor. Their duties are stated as outcomes rather than tasks: ensure the internal policies, procedures and controls are consistent with the entity’s risk exposure and that they are implemented; ensure sufficient human and material resources are allocated; and receive information on significant or material weaknesses. Where the management body decides collectively, the compliance manager assists and advises it and prepares the decisions.

The compliance officer is appointed by the management body in its management function, must have sufficiently high hierarchical standing, and is responsible for the policies, procedures and controls in day-to-day operation — including the implementation of targeted financial sanctions. They are the contact point for competent authorities and they are responsible for reporting suspicious transactions to the FIU under Article 69(6).

Compliance managerCompliance officer
WhoA member of the management body in its management functionAppointed by that body; sufficiently high hierarchical standing
HorizonConsistency with risk exposure, implementation, resourcingDay-to-day operation, including targeted financial sanctions
External roleContact point for competent authorities; files STRs under Article 69(6)
Business-wide risk assessmentApproves (as part of the management body)Draws up
Annual reportSubmits it to the management bodyDraws it up
RemovalPrior notification to the management body; supervisor must be notified

Article 11(7) allows one natural person to perform both functions where the nature of the business, its risks and complexity, and its size justify it, and allows those functions to be cumulated with others. Where the obliged entity is a natural person, or a legal person whose activities are carried out by one natural person only, that person performs the tasks. So the two-role structure is a default with a proportionality release — not an unconditional headcount requirement.

2. The compliance officer gets statutory protection — and an exit route to the supervisor

This is the part with no real equivalent in most national regimes today, and it deserves reading closely.

  • Article 11(4): obliged entities must take measures to ensure the compliance officer is protected against retaliation, discrimination and any other unfair treatment, and that their decisions are not undermined or unduly influenced by the commercial interests of the entity.
  • Article 11(5): the compliance officer and the person responsible for the audit function must be able to report directly and independently to the management body in its management function, and to the supervisory function where one exists — and to raise concerns and warn that body where specific risk developments affect or may affect the entity.
  • Article 11(2): the compliance officer may only be removed after prior notification to the management body in its management function. The entity must then notify the supervisor of the removal, specifying whether the decision relates to the carrying out of the tasks assigned under the Regulation. And the compliance officer may — on their own initiative or on request — give the supervisor information concerning their removal.

Facts: an EMI runs a single MLRO who reports to the COO, sits two levels below the board, and whose objectives include onboarding conversion targets.

What the rule says: three separate provisions bite. The officer needs sufficiently high hierarchical standing; must be able to report directly to the management body; and their decisions must not be unduly influenced by commercial interests — which a conversion-linked objective plainly is. Separately, a board member has to be designated as compliance manager.

What the practitioner does: moves the reporting line to the management body, strips commercial metrics out of the officer’s objectives, and puts the compliance-manager designation to the board as a named appointment with a minuted acceptance — because the role is personal, not departmental.

Outcome: the org-chart work is done before the framework work, which is the right order given that the framework has to be approved by people who must first exist in these roles.

3. Who approves what — the sign-off map

Article 9 requires internal policies, procedures and controls proportionate to the nature, risks, complexity and size of the business, covering all in-scope activities, and directed at two things: mitigating and managing ML/TF risks identified at Union, member-state and entity level, and — in addition to actually applying targeted financial sanctions — mitigating the risks of non-implementation and evasion of those sanctions. That second limb is easy to miss and is a distinct control objective.

The prescribed content runs from the business-wide risk assessment and the risk-management framework through customer due diligence and PEP determination, suspicious-transaction reporting, outsourcing and reliance, record retention and personal-data processing, monitoring of compliance with the policies themselves and remediation of deficiencies, good-repute verification when recruiting and assigning staff and when appointing agents and distributors, internal communication of the policies to agents, distributors and service providers, and a training policy. Alongside them sit internal controls and an independent audit function to test the policies — and where there is no independent audit function, an external expert may perform that test.

Then the sign-off rule, which is more granular than most firms’ current practice: everything must be recorded in writing; internal policies are approved by the management body in its management function; and internal procedures and controls are approved at least at the level of the compliance manager. Two different approval altitudes, and a firm that runs one omnibus “AML Policy” approved once a year by the board will find it does not map cleanly onto either.

4. The business-wide risk assessment, and the pre-launch duty inside it

Article 10 requires obliged entities to identify and assess their ML/TF risks and the risks of non-implementation and evasion of targeted financial sanctions, taking into account at least six named inputs: the risk variables in Annex I and the risk factors in Annexes II and III; the findings of the Union-level risk assessment under Article 7 of Directive (EU) 2024/1640; the findings of the national risk assessments under Article 8 of that Directive and any relevant sector-specific assessment; relevant publications by international standard setters, the Commission or AMLA; information on risks provided by competent authorities; and information on the customer base.

The assessment must be documented, kept up to date and regularly reviewed — including where internal or external events significantly affect the risks — and made available to supervisors on request. It is drawn up by the compliance officer and approved by the management body in its management function, and communicated to the supervisory function where one exists.

The provision most likely to catch a product team is in the second subparagraph of Article 10(1). Before launching new products, services or business practices — including new delivery channels and new or developing technologies — and before starting to provide an existing service or product to a new customer segment or in a new geographical area, the entity must identify and assess the related ML/TF risks and take measures to manage and mitigate them. That is a gate on the product lifecycle, not an annual document.

Facts: a payment institution authorised in one member state plans to open its existing product to customers in two further markets under freedom of services, with no change to the product itself.

What the rule says: providing an existing service in a new geographical area triggers the pre-launch assessment in its own right. The product being unchanged is not the test.

What the practitioner does: builds the geography assessment into the passporting workstream rather than the product workstream, and has the compliance officer document it as an update to the business-wide risk assessment with a dated management-body approval — because the approval, not the analysis, is what a supervisor will ask to see.

One exemption exists and it will not help most readers of this site: under Article 10(3) supervisors may decide that individual documented assessments are not required where the sector’s inherent risks are clear and understood — but the provision expressly excludes credit institutions and financial institutions, which is where payment institutions and e-money institutions sit.

5. What is still being written

Three AMLA mandates in this part of the Regulation matter for planning, because they determine how much of the detail is knowable today. By 10 July 2026 AMLA is to issue guidelines on the elements determining the extent of internal policies, procedures and controls — in particular the staff allocated to the compliance functions — and to identify situations where, given nature and size, internal controls should be organised at the level of the commercial function, the compliance function and the audit function, and where the independent audit function may be carried out by an external expert. By the same date it is to issue guidelines on the minimum content of the business-wide risk assessment and the additional information sources to be taken into account.

The practical consequence is that the *structure* is fixed now and the *calibration* is not. Designing the org chart and the approval map can proceed; sizing the compliance team against a supervisory expectation cannot, until the guidelines land. See our note on the AML package timeline for how these dates sit against the rest of the runway.

6. FAQ

Does the AMLR still have an MLRO?

Not by that name. Article 11 creates a compliance manager — a member of the management body in its management function — and a compliance officer responsible for day-to-day operation and for reporting suspicious transactions to the FIU under Article 69(6). Most existing MLRO roles map onto the compliance officer.

Can one person hold both roles?

Yes, where the nature of the business, including its risks and complexity, and its size justify it, under Article 11(7); the functions may also be cumulated with others. Where the obliged entity is a natural person or is run by a single natural person, that person performs the tasks.

Who approves the business-wide risk assessment?

The compliance officer draws it up; the management body in its management function approves it; and it is communicated to the management body in its supervisory function where such a body exists.

Do we have to tell the supervisor if we dismiss the compliance officer?

Yes. Removal requires prior notification to the management body, and the entity must notify the supervisor, specifying whether the decision relates to the carrying out of tasks assigned under the Regulation. The compliance officer may also provide the supervisor with information about the removal on their own initiative.

Can a group appoint one compliance officer for several entities?

Where justified by the size of the obliged entity and the low risk of its activities, an entity that is part of a group may appoint as its compliance officer an individual who performs that function in another entity within the group.

Does a new market need a fresh risk assessment if the product is unchanged?

Yes. Article 10(1) requires identification and assessment of the risks before providing an existing service or product to a new customer segment or in a new geographical area, as well as before launching new products, services, practices, delivery channels or technologies.

7. What to do, today

  • Name the compliance manager before you touch the framework. It is a personal appointment from the management body in its management function, and several approvals in Articles 9 and 10 run through that person or that body.
  • Split your policy stack in two. Internal policies need management-body approval; internal procedures and controls need approval at least at compliance-manager level. One omnibus document approved once a year satisfies neither cleanly.
  • Audit the compliance officer’s independence now — reporting line, hierarchical standing, and whether any objective is tied to commercial performance. Article 11(4) makes commercial influence over their decisions a compliance defect.
  • Put the pre-launch assessment into the product and passporting gates, not into the annual cycle. New geography and new customer segment are triggers on their own.
  • Do not size the team yet. The AMLA guidelines on staffing and on the minimum content of the risk assessment are due by 10 July 2026; design the structure now and calibrate after.

Related: the EU AML package timeline · the AML representative across the EU · AMLA’s entity risk-scoring method · ANIFI, Spain’s new AML authority

Related reads.