What this is
The compliance programme a supervisor will actually test, and the registration that has to be in place before it does.
Why the template fails
A downloaded AML policy describes a business that does not exist. A supervisor reads the risk assessment first, and if it does not reflect the actual customer base, products and geographies, everything built on it is discounted.
We write the risk assessment against the business, then the policy against the risk assessment and the applicable rulebook.
What the work involves
Registering the entity and the officer on goAML. Drafting the enterprise-wide risk assessment and the policy suite. Designing the customer due diligence and enhanced due diligence flows. Building the sanctions screening process against the Executive Office lists, including what happens in the hours after a match — the obligation with the shortest clock and the least tolerance for a manual process. Designing the reporting workflow for each report type. Preparing and supporting the MLRO. Running training. Arranging the independent audit.
The MLRO
The appointment is the part most often treated as a formality and most often tested. The role needs seniority, independence and enough knowledge of the business to recognise what is unusual about it.
Regulators
Common questions
Can the MLRO be outsourced?
In some structures, yes. Responsibility for making a fit appointment does not move, and an outsourced officer who cannot get the business on the phone is not a control.
Sources
- Scope of work described here reflects our practice, not a regulatory requirement — Regulatory statements on these pages carry the same review status as elsewhere on the site