What is an MLRO?
What does an MLRO actually do all day? If your answer is “AML checks”, you're not wrong, but there is quite a bit more to it than that.
MLRO stands for Money Laundering Reporting Officer.
In simple terms, the MLRO has an important role in helping a business identify and deal with money laundering and other financial crime risks.
That can mean looking into unusual activity, investigating a possible sanctions or PEP match, reviewing customer risk and making sure there is a clear record of the decisions that have been made. They can also be responsible for reviewing concerns raised by colleagues and deciding whether something needs to be reported through a Suspicious Activity Report, usually known as a SAR.
The exact responsibilities can vary between organisations, but judgement and understanding risk sit right at the heart of the role.
So what does an MLRO actually do?
There probably isn't really a standard day.
Priorities can change pretty quickly depending on the business, its customers and what comes up.
A day could look something like this:
8:30am - Reviewing alerts
Checking new alerts, internal concerns and any cases that might need looking at straight away.
9:15am - Looking into a potential match
A new customer has triggered a possible sanctions or Politically Exposed Person, or PEP, match.
That does not automatically mean there is a problem. The MLRO or compliance team needs to work out whether it is genuinely the same person or simply somebody with a similar name.
10:30am - Reviewing customer information
Looking at the information available to get a better understanding of who the customer is and whether anything needs further investigation.
If the customer is a company, this could also involve looking at directors, beneficial owners and the people behind the business.
12:00pm - An urgent query
A colleague has spotted something that does not quite look right and wants some guidance. Is more information needed? Can the customer proceed? Does something need to be escalated?
Sometimes the difficult bit is not finding the information. It is deciding what that information actually means.
2:00pm - Existing customer reviews
Not everything happens at onboarding.
An existing customer's circumstances, ownership or risk profile may have changed and need looking at again.
4:00pm - Keeping the records straight
Making sure the checks, decisions and supporting evidence have actually been recorded properly. That can become pretty important if somebody needs to understand six months later why a decision was made.
And that is only one possible day.
If that sounds like a lot of information, systems and decisions to keep on top of, it can be. And that is really one of the problems we are trying to help with through Goidentity. Not replacing the MLRO or their judgement but making it easier to get the right information in front of them.
The check is often the easy bit
A potential sanctions or PEP match does not automatically mean someone is high risk.
It still needs to be understood.
Is it actually the same person? Does the date of birth match? Does the location make sense? Is the information current? Is there anything else about the customer that changes the picture?
This is where a lot of the work can come in.
The information needed to make that decision might be sitting across different systems, emails, documents and screening tools. Someone then has to pull it together, understand it and record what they decided. That can turn what looks like a simple check into quite a time-consuming process.
Good KYC information makes a difference
KYC simply means Know Your Customer.
At a basic level, it is about understanding who you are dealing with.
That means having good identity information, checking the relevant documents and, where needed, understanding the people behind a business.
The better the information at the start, the easier it is for an MLRO or compliance team to spot the things that genuinely need a closer look.
It can also mean less time chasing missing information later.
Where technology can help
Technology is not going to replace the judgement of an MLRO, and I don't think it should try to. What it can do is make some of the work around that judgement much easier. Digital identity checks can help collect and verify customer information. Screening can help identify possible sanctions or PEP matches. Digital questionnaires can collect additional information at the same time.
Done well, that means less moving between different systems, less copying information around and less manual chasing.
This is where Goidentity comes in.
Goidentity brings identity and biometric verification, sanctions and PEP screening, location checks and customer questionnaires together into one verification journey.
The point is not to turn every customer into a simple green tick or red cross. A possible match still needs somebody to look at it and make a decision. What we can do is make sure they have clearer information in front of them when they make that decision.
It still comes back to judgement
Technology can flag something unusual.
It can find a possible match.
It can help collect the information.
But somebody still has to ask the questions and decide what happens next. That is why the MLRO role remains so important. For me, the opportunity is to remove some of the admin around that role so compliance teams can spend more time on the bits that actually need their experience and judgement.
That is really what we are trying to do with Goidentity. Bring more of the KYC and AML journey together, reduce some of the manual work and give compliance teams clearer information to work with.
If that sounds useful, take a look at Goidentity or book a Demo and we'll show you how it works.