The MLRO Role: Duties, Liability, Outsourcing
The UAE names the person who owns AML/CFT/CPF controls. Federal Decree by Law No. 10 of 2025 Article 19 requires financial institutions, designated non-financial businesses and professions, and virtual asset service providers to keep senior-management-approved internal policies.
Cabinet Resolution No. 134 of 2025 Article 21(3) puts a compliance officer at management level inside those policies. Article 22 then lists the work: monitor transactions related to the Crime, decide whether to notify the Financial Intelligence Unit or to retain the file with reasons, test internal systems, train staff, and cooperate with the supervisor and the Unit. Supervisors print “compliance officer” and “money laundering reporting officer” on the same seat, then add residency, experience and outsourcing limits for the licence in front of you.
A founder appointing the first officer and a licensed firm reviewing the seat both start from that stack. AML/CFT policy work builds the pack and the officer support around it. UAE company formation and licensing produces the entity. The named officer is a separate appointment. A licence file that names a friend in another time zone, with no access to alerts and no authority to file, fails the statute before it fails the interview.
Who is the MLRO or compliance officer under UAE law?
The federal English texts use “Compliance Officer”. DIFC, ADGM and most bank job specs use “Money Laundering Reporting Officer”. CBUAE procedures for licensed financial institutions treat the compliance officer as the MLRO charged with reviewing, scrutinising and reporting suspicious transaction reports. The 2026 Joint Guidance of the Supervisory Sub-committee uses both labels for one function: a senior, independent officer with board access, resources, and the authority to file with the Unit. Title shopping does not change Article 22.
FATF Recommendation 18 sits underneath as overlay, not as UAE law. The interpretative note requires a compliance officer at management level, with internal controls, screening, training, an independent audit, and group-wide programmes. Decree-Law Article 19(d) already sends those policies to majority branches and subsidiaries. Cabinet Article 21(3) is the appointment line.
Independence is a statutory quality. Cabinet Article 22 requires independence in decision-making. The Joint Guidance adds that the officer must be free to challenge ill-suited decisions, must not hold day-to-day sales responsibility, and must receive systems, data and headcount from the board. CBUAE Licensed Persons go further in Rulebook 16.4.8: the compliance officer reports to the Board or owners, and acts without interference from the Manager in Charge. A founder who keeps the STR button on their own phone while the “MLRO” drafts policies in another company has appointed a ghostwriter.
The firm remains responsible for the appointment. Article 22 says the officer sits “under their responsibility”.
What must the officer do under Cabinet Article 22?
Cabinet Resolution 134 of 2025 Article 22 binds financial institutions, designated non-financial businesses and professions, and virtual asset service providers. The firm appoints a compliance officer at management level, under the firm’s responsibility. That officer has independence in decision-making and appropriate competence and experience. Five statutory duties follow. The 2026 Joint Guidance repeats those five and expands them into day-to-day work: monitoring design, the STR retain-or-file decision, the programme and risk assessment, training, the contact point for the supervisor and the Unit, and the bi-annual report. A job description that reprints the five bullets and stops there still misses the STR clock and the board pack.
Monitor, decide, and keep the file
Article 22(1) requires monitoring of transactions related to the Crime. Article 22(2) requires the officer to receive, examine and assess suspicious-transaction data, then decide whether to notify the Unit or to retain the matter, stating the reasons, in full confidentiality. Decree-Law Article 18 is the firm’s filing duty: where it suspects, or has reasonable grounds to suspect, that a transaction or funds represent proceeds or relate to the Crime, it notifies the Unit without delay, regardless of value, through the Unit’s electronic system. Cabinet Articles 17 and 18 add indicators and the same clock. The officer makes the retain-or-file call.
Decree-Law Article 24 and Cabinet Article 19 forbid tipping-off. Staff who warn the customer walk into Decree-Law Article 29. A good-faith filing sits under Article 37: no criminal, civil or administrative liability unless the report was made mala fide to harm someone. The Joint Guidance tells the officer to understand the monitoring scenarios and to prioritise high-risk internal reports. After a filing, the same person sees the subject on an internal watchlist and the risk rating move. A vendor that “runs alerts” while the named officer never sees the queue has not discharged Article 22(1) or 22(2).
Systems, training, and the supervisor
Article 22(3) requires the officer to review internal AML/CFT/CPF systems, test consistency with the Decree-Law and the Resolution, evaluate compliance, propose updates, and submit periodic reports directly to Senior Management, with a copy to the supervisor on request, including management observations. Article 22(4) requires documented ongoing training. Article 22(5) requires cooperation with the supervisor and the Unit: data on request, and access to records.
Reporting clocks then stack by perimeter. CBUAE Licensed Persons give the Board or owners AML issues quarterly at a minimum (16.4.3(j)) and prepare bi-annual compliance reports under 16.25. VARA’s MLRO reports quarterly to the Board, including anonymity-enhanced transactions. FSRA AML 12.4 requires a semi-annual MLRO report to the Governing Body or Senior Management, copied to the Regulator. The Joint Guidance reads Article 22 as a bi-annual CO/MLRO report. Align the calendar to the licence.
The officer consults before senior management onboards or keeps a high-risk customer. If senior management overrules that advice, the Joint Guidance requires a recorded rationale. Silence in the minute book is an examination finding.
How do CBUAE, VARA, DFSA and FSRA change the seat?
Your supervisor adds tests on top of the federal floor. Copy a residency rule, an experience floor or an outsourcing ban from the wrong perimeter and you will fail a fit-and-proper file. CBUAE Licensed Persons that carry out exchange business sit under Rulebook Chapter 16. Dubai VASPs sit under VARA’s Compliance and Risk Management Rulebook and the Company Rulebook. DIFC Relevant Persons sit under the DFSA AML module. ADGM Relevant Persons sit under the FSRA AML Rulebook. Federal Decree-Law 10/2025 and Cabinet 134/2025 still apply in all four. The Joint Guidance says that where guidance and a binding rulebook diverge, the legal and regulatory framework prevails. Name the licence before you hire.
CBUAE Licensed Persons and the wider LFI desk
Rulebook 16.3 is the policy chapter for Licensed Persons that carry out exchange business, not every CBUAE-supervised bank by default. The policy must define the roles of the Manager in Charge, Compliance Officers, the Compliance Committee and employees, and must provide regular reporting to the Board or Owner/Partners on ML/FT risks (16.3.2). The Manager in Charge, the Compliance Officer and the Board or owners approve it (16.3.6). Review is annual at a minimum (16.3.7). Copies sit in every licensed premises (16.3.8).
Appointment sits in 16.4. The compliance officer is a member of Senior Management, reports to the Board or owners, holds a dedicated AML/CFT role that must not be combined with other functions (16.4.7), is a full-time UAE resident (16.4.6), and needs a Letter of No Objection after a fit-and-proper test. Experience floors split by licence category under 16.4.4 (three years for Category A; eight years, or five plus an accepted certification, for Category B or C). Vacancy notice is five working days; a permanent replacement is due within 180 calendar days, with the Alternate covering the gap (16.4.10). Paragraph 16.4.11 forbids outsourcing the CO role and the entire compliance function. Specific tasks may be outsourced after a No Objection.
CBUAE’s wider LFI procedures (2.2.1) treat the compliance officer as the MLRO for STR work. Read 16.3/16.4 for an exchange Licensed Person. Do not paste 16.4.4’s eight-year floor onto a VARA MLRO.
VARA splits Compliance Officer from MLRO
VARA’s Compliance and Risk Management Rulebook (file VARA_EN_123_VER20250519, mirrored on the live rulebook) requires two seats. The Compliance Officer needs at least five years in a compliance function, must be Fit and Proper as approved by VARA, must be a UAE resident or hold a UAE passport, must be a full-time employee, and must report directly to the Board. The appointment is reviewed annually. The CO owns the compliance management system: training, policies, Board reporting and corrective action.
The MLRO needs at least two years handling AML/CFT matters and must be Fit and Proper, reviewed annually. The MLRO trains the Board and staff on VA AML/CFT, implements AML/CFT policies, runs the risk assessment, monitors and reports suspicious transactions, and reports quarterly to the Board, including anonymity-enhanced transactions. AML/CFT activities may be delegated. The MLRO remains accountable under the Company Rulebook.
The CO or the MLRO may hold more than one non-client-facing role, including each other’s seat and the head of risk, if duties do not conflict. VARA weighs the combination in Fit and Proper. The CISO is a separate technology owner. Company Rulebook Part IV lets a VASP outsource the MLRO, the CISO and the data-protection officer. The Compliance Officer is not on that list. VARA may still require a full-time employee at licensing or later. A file that names one junior as “CO/MLRO/CISO” on a four-hour week fails this split.
DFSA and FSRA: MLRO language, UAE residence, dual sources
DFSA AML Rule 11.2.1 (current from 1 May 2024 on the DFSA rulebook, with the DFSA AML/CTF framework page as the second source) requires a Relevant Person to appoint an individual as MLRO, suitable, senior and independent, resident in the UAE except for a Registered Auditor or a Representative Office. The MLRO implements the firm’s AML systems and oversees the AML module and other AML legislation applicable in the DIFC. DFSA guidance on an outsourced MLRO asks whether that person has real seniority and the hours if they act for more than one Relevant Person.
FSRA AML 12.1 (appointment pages amended 21 May 2026 on the ADGM rulebook) requires an MLRO of seniority, experience and independence, resident in the UAE, plus a deputy. AML 12.1.6 allows outsourcing the role to an individual outside the firm if that person remains suitable; the Relevant Person stays responsible. AML 12.3.1 covers day-to-day operations, internal suspicion notifications, STRs under federal AML legislation, the contact point for UAE authorities, training and policy review. AML 12.4 is the semi-annual report. Confirm the live module before you file.
What personal liability attaches to the officer and to actual management?
Administrative penalties and criminal fines live in different articles of Decree-Law 10/2025. Do not add them together into one “UAE AML fine”.
Article 17 is the supervisory toolkit. It reaches people. The authority may warn; impose an administrative fine of AED 10,000 to AED 5,000,000 for each violation; prohibit the violator from the sector; restrict the powers of board members, executives, managers or owners proven responsible, including by appointing a temporary supervisor; suspend those directors or executives or request their replacement; suspend the activity; or revoke the licence. Recurrence within a year can bring an incremental fine. The authority may publish the penalty. A hollow MLRO appointment, a missing STR or a refused examination usually arrives here: against the firm, with named managers in the same notice.
Article 27 is a criminal fine on the legal person after a court finds that representatives, directors or agents committed money laundering, financing of terrorism or proliferation financing on its behalf or in its name. The band is AED 5 million to AED 100 million, or the value of the Criminal Property, whichever is greater. Article 27(2) sets AED 200,000 to AED 10 million for listed lesser offences, including STR failure (Article 28) and tipping-off (Article 29). Conviction for financing of terrorism or proliferation financing brings mandatory dissolution. For money laundering the court may order dissolution. Article 4 already makes the legal person criminally liable where a crime in the Decree-Law is intentionally committed in its name or for its account, without prejudice to the personal liability of the perpetrator.
Article 27(5) is the manager limb. Where the crimes in Article 27(1) or (2) are committed, the person responsible for actual management is punished by imprisonment and a fine, or either, if they knew and the crime followed a breach of the duties of their position. White & Case’s 6 November 2025 alert flagged that exposure.
Article 28 hits the STR duty: whoever deliberately or through gross negligence violates Article 18 faces imprisonment and a fine of AED 100,000 to AED 1,000,000, or either. An officer who sits on an internal report, or a manager who instructs delay, is in that frame. Article 37 shields a good-faith filing.
When is outsourcing lawful, and when does it become theatre?
An outsource contract buys capacity. The statutory seat stays with the named officer. The 2026 Joint Guidance states that an LFI, DNFBP or VASP must not outsource the role of the CO/MLRO nor the entire compliance function. Specific tasks such as enhanced due diligence, training delivery and system support may be bought in after a letter of no objection from the relevant supervisor. CBUAE Licensed Persons repeat that ban in Rulebook 16.4.11. VARA then lists the MLRO as a specified officer a VASP may outsource, with the VASP still accountable and VARA able to force the role in-house. DFSA and FSRA allow an external MLRO if seniority and access are real. Read your own perimeter before you sign.
What you may buy in
Lawful support looks like labour under the officer’s instruction. A vendor may collect CDD files, run list screening, host a monitoring engine, deliver training the officer has signed, or draft a policy the officer then owns. Cabinet Article 20 lets the firm rely on a third party for some CDD identification steps, while remaining responsible for accuracy. Clause 20(3) distinguishes that reliance from outsourcing done under the firm’s own policies. Neither clause moves the Article 22(2) decision.
VARA Rule III.A.3 allows AML/CFT activities to be delegated if the MLRO stays accountable and Company Rulebook Part IV is met. The named MLRO still agrees individual responsibility to VARA. A DIFC or ADGM firm that appoints an external MLRO still owes that person Board access, data, and the authority to file without a sales countersignature. DFSA guidance asks whether a multi-firm MLRO has the hours. FSRA guidance says the Relevant Person remains responsible even when the individual sits in the group.
What must stay with the appointed officer
Theatre is a regional AML team that files UAE STRs, a founder who holds the goAML credentials while a consultant uses the title, a VARA Compliance Officer who is not a full-time employee, or a CBUAE Licensed Person that outsources the CO seat itself. The Joint Guidance appendix already lists the findings: limited oversight of UAE operations, the officer shut out of monitoring, no seniority, no board reporting. A contract that sells “outsourced MLRO” as a signature on a licence form, with no alert queue, is that list in commercial clothing.
The practical evaluation of an outsourced compliance retainer is a step that comes after the legal duties are clear. This section stops at the legal line: the named officer keeps the STR decision, the Senior Management report, the Unit relationship, and the Fit and Proper file. Allocation as of August 2026. Confirm the live rulebook for your licence before you sign.
STR / SAR decision (Cabinet 22(2); Decree-Law 18)
Named CO/MLRO owns it in-house. The officer keeps sole authority to notify the Unit or retain with written reasons. A vendor may assemble the file.
Transaction monitoring related to the Crime (Cabinet 22(1))
Named officer, with operations support. Sign-off on scenarios, thresholds and alert disposition stays with the officer. A vendor may run the engine.
Internal systems review and periodic report (Cabinet 22(3))
Named officer. Drafting and submitting the report to Senior Management, and sending a copy to the supervisor on request with management observations, stay with the officer.
Staff training (Cabinet 22(4))
Named officer. Curriculum, attendance records, and training of Senior Management and the Board stay with the officer. A vendor may deliver sessions the officer has approved.
Cooperation with supervisor and Unit (Cabinet 22(5))
Named officer. Appear, produce records, and answer goAML / IEMS follow-ups in the officer’s own name.
Board / Senior Management reporting clocks
Named officer. CBUAE Licensed Person: quarterly AML issues (16.4.3(j)). VARA MLRO: quarterly effectiveness pack. FSRA: semi-annual report to Governing Body or Senior Management. Joint Guidance: bi-annual CO/MLRO report.
Fit-and-proper and vacancy
Board or owners. Nomination, evidence, supervisor notification. CBUAE Licensed Person: five working days on vacancy; 180 days to replace. VARA: annual Fit and Proper review.
High-risk onboarding advice (Joint Guidance)
Named officer. Written advice. If Senior Management overrules, the rationale and mitigation sit on the file.
Sanctions programme oversight (Joint Guidance; Cabinet Decision 74/2020)
Named officer. Freeze / unfreeze execution sign-off. A vendor may run list screening. Screening operations sit in a separate process article.
Record-keeping (Decree-Law 19(f); Cabinet 25)
Named officer with operations. Statutory retention clock (federal floor five years from the latest listed trigger). A vendor SLA cannot shorten it. VARA books and AML records: at least eight years.
Independence and reporting line (Cabinet 22; CBUAE 16.4.7–16.4.8)
Board or owners. No sales dual-hat. Direct line to Board or owners. Unrestricted data access. The contract cannot put the officer under the sales director.
goAML / Unit filing identity
Named officer. Credentials and filing identity. A vendor submitting under the officer’s login is theatre.
How should a founder appoint the first officer?
Start with the licence you want, then map the federal floor. A DNFBP still needs a management-level compliance officer under Cabinet Articles 21(3) and 22. A CBUAE exchange Licensed Person needs a full-time UAE-resident CO with a Letter of No Objection. A Dubai VASP needs a full-time CO who meets the five-year test and an MLRO who meets the two-year AML/CFT test; one person may hold both non-client-facing seats if VARA accepts Fit and Proper. A DIFC or ADGM firm needs a UAE-resident MLRO, with the DFSA auditor and representative-office exceptions, and, in ADGM, a deputy.
Write the appointment before you file. The board minute should name the individual, the reporting line, the STR authority, and the budget for systems. Attach a role description that reprints Article 22 and the extra duties of your supervisor. Complete a documented Fit and Proper assessment. Notify the supervisor in the form that perimeter requires.
Do not use the licence file as a costume change. Nataly Medici puts the same point on sloppy filings: a licence rejected for sloppy documentation is harder to recover from than one that was never filed. A named officer who cannot explain the product flows or the last STR decision is sloppy documentation with a human face. Crypto compliance in 2026 is the wider operating context; this appointment is the named seat inside it.
If the business is small, the Joint Guidance allows the CO/MLRO to carry the whole function unless a sector rule says otherwise. Small is not a waiver of independence. A one-principal DNFBP still needs a written STR path that does not wait for a sales conversation.
How should a licensed firm review the seat?
Pull the last two periodic reports, the STR retain-or-file log, the training register, the high-risk onboarding overrides, the vacancy file, and the outsource contract. Read them against Article 22 and your supervisor’s clock. The Joint Guidance appendix is a gap list: UAE operations run from a regional office; the officer shut out of monitoring; no dedicated senior officer; no board reporting; no UAE statutory literacy.
Check conflicts. CBUAE Licensed Persons cannot combine the CO role with other functions. VARA allows a non-client-facing combination if duties do not conflict. DFSA and FSRA care about seniority and the ability to act on the officer’s own authority. If the same human is Head of Sales, Article 22’s independence sentence is already broken.
Check presence. Full-time and UAE-resident mean what the rulebook says for that licence. A “UAE MLRO” who spends three days a month in the country, with alerts closed in another group entity, matches the first Joint Guidance finding. CBUAE Licensed Persons must notify a vacancy within five working days. FSRA requires immediate cover when the MLRO leaves.
Check the contract last. Confirm any No Objection your supervisor requires, confirm that STR credentials stay with the named officer, and confirm that the vendor cannot file or tip off. If you are a VARA VASP with an outsourced MLRO, confirm individual responsibility to VARA and whether VARA has told you to bring the role in-house. The legal question is whether the appointed officer can still do Article 22 on a surprise afternoon.
FAQ
What is the difference between an MLRO and a compliance officer in the UAE?
Federal Cabinet 134/2025 Article 22 appoints a “Compliance Officer”. CBUAE LFI procedures, DFSA and FSRA use “MLRO” for the same function: the senior person who decides STRs, tests systems, trains staff and deals with the Unit. VARA splits the seats: a full-time Compliance Officer (five years, UAE resident or passport, Board report) and an MLRO (two years AML/CFT). One human may hold both VARA seats if duties do not conflict and VARA accepts Fit and Proper.
Can a UAE firm outsource the MLRO role?
It depends on the perimeter. The 2026 Joint Guidance and CBUAE Rulebook 16.4.11 forbid outsourcing the CO/MLRO role and the entire compliance function; specific tasks may be bought in with a No Objection. VARA lets a VASP outsource the MLRO, not the Compliance Officer, while both remain accountable. DFSA and FSRA allow an external MLRO if seniority and access are real. The STR decision stays with the appointed individual.
Does the MLRO face personal liability in the UAE?
Yes. Decree-Law Article 17 lets the supervisor restrict or suspend managers proven responsible, alongside firm-level administrative fines of AED 10,000 to AED 5,000,000 per violation. Article 28 punishes deliberate or grossly negligent STR failure. Article 27(5) punishes actual management if they knew of listed crimes and those crimes followed a breach of their duties. Article 37 shields good-faith reporting.
Must the MLRO live in the UAE?
For CBUAE Licensed Persons, yes: full-time employee and UAE resident (16.4.6). For VARA, the Compliance Officer must be a UAE resident or hold a UAE passport. DFSA requires a UAE-resident MLRO except for a Registered Auditor or Representative Office. FSRA requires a UAE-resident MLRO, with a limited waiver possible. Confirm the live module.
What experience does VARA require?
The Compliance Officer needs at least five years in a compliance function. The MLRO needs at least two years handling AML/CFT. Both remain Fit and Proper on an annual review. Those floors sit on top of Cabinet Article 22. They do not replace the federal duties.
How often must the officer report to the board?
Cabinet Article 22 requires periodic reports to Senior Management, copied to the supervisor on request. CBUAE Licensed Persons add quarterly AML issues. VARA’s MLRO reports quarterly. FSRA requires a semi-annual report, copied to the Regulator. The Joint Guidance treats a bi-annual CO/MLRO report as the federal working rhythm. Use the strictest clock that applies to you.
