The MLRO: the one role UK law almost never lets you automate away.
Of every role in the minimum viable org structure, the Money Laundering Reporting Officer sits closest to an absolute floor. A named, individually accountable human is a direct requirement of the Money Laundering Regulations 2017[13]. Not a judgement call this investigation is making.
Last reviewed: 2026-07-24
Receiving, evaluating, and (if needed) reporting suspicion.
The MLRO (SMF17) is the named point of accountability for the firm's anti-money-laundering systems and controls. Internally, staff and monitoring systems escalate suspicious activity to the MLRO as internal reports; the MLRO personally evaluates each one and decides whether it meets the threshold to file an external Suspicious Activity Report (SAR) with the National Crime Agency. That decision (and the "consent" question of whether a suspicious transaction can proceed) is the one action in this entire investigation with direct personal criminal liability attached if it's handled negligently.
Everything before the decision, not the decision itself.
This is exactly the shape of the Financial Crime Detection & Threat-to-Control Latency blocker on the hub page: network-based, agentic monitoring (in the pattern piloted by Napier AI's Theseus) handles first-pass detection across the entire transaction base, assembles the evidence package, and drafts the internal report. None of that requires the MLRO personally. What can't move is the evaluation of genuinely ambiguous cases and the external filing decision itself.
The artefacts that prove "reasonable steps."
- Every external Suspicious Activity Report filed with the National Crime Agency.
- Any "consent" decision on whether a flagged transaction may proceed while under review.
- The firm's annual MLRO report to the Board on the effectiveness of AML systems and controls.
Sources
[13] The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, legislation.gov.uk. Not independently re-confirmed by Axiom Verity this session. See the hub's What's Still Open section.
This is one of seven role perspectives.
CEO, CRO, COO, Head of Internal Audit, Compliance Oversight, and the NEDs each get the same treatment as research progresses.