HomeInsightsMLRO, DMLRO and Compliance Officer
AML/CFT · Governance
MLRO, DMLRO and Compliance Officer: roles, responsibilities and independence
The three compliance roles distinguished, the independence test regulators apply, and the board reporting standard they expect.
Published 13 June 2022 · 8 min read
Three compliance roles appear in every Mauritius regulated firm’s organigram: Money Laundering Reporting Officer (MLRO), Deputy MLRO (DMLRO) and Compliance Officer. Most firms conflate them. Most board packs confuse them. And most audit findings start with the observation that one or more of the three is not meaningfully independent from the functions they are meant to oversee.
This article sets out what each role actually does, where the statutory hooks sit, what the independence test looks like in practice, and the board reporting standard that inspectors expect to see.
The three roles, distinguished
The Money Laundering Reporting Officer (MLRO)
The MLRO is a statutory appointment under FIAMLA and the FIAML Regulations 2018. The role has three core functions:
- Receiving and assessing internal suspicion reports from staff.
- Deciding, in each case, whether to file a Suspicious Transaction Report (STR) with the FIU.
- Serving as the firm’s point of contact with the FIU, and as the senior owner of the AML/CFT framework.
The MLRO must have sufficient seniority, authority and independence to discharge the role without interference from the business. In practice, this means a direct reporting line to the board (or a board committee), unfettered access to client files and systems, and protection from reprisal for legitimate compliance decisions.
The Deputy MLRO (DMLRO)
The DMLRO is the MLRO’s statutory backup — covering annual leave, illness, travel, and any situation where the MLRO is conflicted out of a specific decision. The DMLRO exercises the full authority of the MLRO when acting in that capacity: receiving internal suspicion reports, deciding on STR filing, and engaging with the FIU.
The common mistake is to treat the DMLRO role as a formality. It is not. A firm whose MLRO is unavailable for two weeks without a functioning DMLRO has, during that period, no AML reporting function at all — an enforcement-grade failure.
The Compliance Officer
The Compliance Officer oversees the broader compliance framework — regulatory adherence, policy maintenance, staff training, regulatory reporting, internal controls testing. In smaller firms the Compliance Officer and MLRO may be the same person (where regulatory permissions allow), but the roles are functionally distinct: the MLRO’s focus is ML/TF-specific; the Compliance Officer’s mandate is wider.
In larger firms — banks, mid-sized FSC licensees — the roles should be separate. In smaller DNFBPs, role-combining is permissible but must be documented, risk-assessed, and reviewed if the firm grows.
The independence test
Independence is the most commonly-tested, and most commonly-failed, aspect of the MLRO function. Inspectors look for functional independence, not just the title on the org chart:
- Reporting line. Does the MLRO report directly to the board or a board committee, or does the MLRO report to a business-line head who can pressure their decisions?
- Remuneration. Is the MLRO’s compensation determined independently, or linked to business-generation KPIs that create a conflict?
- Role combinations. Does the MLRO also run operations, sales, or onboarding? If yes, can they realistically escalate their own function’s failings?
- Decision record. Are MLRO decisions documented, timestamped, and retained outside the reach of the business?
- Escalation history. Has the MLRO ever escalated a concern to the board? If never, is that because there was nothing to escalate — or because the culture discourages it?
A common failure pattern
Firm X appoints its Chief Operating Officer as MLRO, with the Financial Controller as DMLRO. The COO reports to the CEO and has revenue responsibilities. When the regulator tests independence, the file shows that every MLRO decision of the last 12 months aligned with the preferred commercial outcome. The finding writes itself: independence compromised, function ineffective, framework inadequate.
Statutory responsibilities at a glance
- Appointment, notification to the regulator where required, and disclosure in regulatory returns.
- Receipt of internal suspicion reports from staff through a defined, confidential channel.
- Assessment and decisioning on each internal report — file an STR, do not file, or seek further information — with documented reasoning.
- Filing STRs with the FIU where the statutory test is met.
- Liaison with the FIU on any follow-up requests.
- Periodic reporting to the board on the state of the AML/CFT framework.
- Oversight of training, screening, monitoring and CDD/EDD processes.
- Participation in or sign-off on the Business-Wide Risk Assessment and other governance documents.
The board reporting standard
A board-level MLRO report is not a one-page summary. It should, at minimum, include:
- Number of internal suspicion reports received and how they were resolved.
- Number of STRs filed and themes.
- Sanctions screening hits, PEP identifications, adverse-media alerts and their disposition.
- Completion rates for staff training, including overdue refreshers by role.
- Open audit findings, their status, and target remediation dates.
- Changes in the regulatory environment and their operational impact.
- Resource requests — headcount, technology, training budget — where the function is under-resourced.
Inspectors read board packs. A board pack that does not contain this content is a finding. A board that receives this content and does not act on it is a bigger one.
Where Audacia can help
We support clients in three related ways on the MLRO function:
- MLRO / DMLRO outsourcing for firms that cannot fill the role in-house — with full statutory responsibility, reporting-line independence, and board engagement.
- MLRO function reviews as part of our AML/CFT audits — testing independence, reporting, decisioning and escalation against the current regulatory standard.
- Training for existing MLROs, DMLROs and Compliance Officers through Audacia Training — covering role-specific scenarios, STR decisioning, and board reporting.
Reviewing your MLRO function?
Book a 30-minute conversation. We’ll walk through your current structure, the independence pressures, and what a defensible function looks like for your firm.
Related
AML/CFT · Audit
Is your AML/CFT framework ready for an independent audit?
What regulators actually expect from an independent AML/CFT audit, how to scope it, and the common gaps we see across Mauritius licensees.
Read article →AML/CFT · CDD & EDD
Enhanced Due Diligence: when, how and what to evidence
When EDD is triggered, what it must cover, the evidence pack regulators expect, and the six failures cited most often in audit reports.
Read article →AML/CFT · Training
Building an audit-ready AML/CFT training programme
The four properties of a training programme that survives FSC and FIU inspection — scalable, role-specific, auditable and current.
Read article →