Quick Answer: A UK firm cannot outsource its Money Laundering Reporting Officer’s accountability, but it can outsource almost all of the work beneath the officer. The MLRO is a named individual holding the SMF17 controlled function who carries personal regulatory accountability, and Regulation 21(3) of the Money Laundering Regulations 2017 requires them to be a member of the board or senior management. Alert triage, know-your-customer file build, screening adjudication and even SAR drafting can sit with a third party. SAR decisioning, board reporting, risk assessment ownership and regulatory liaison cannot.
Key Takeaways
- Outsourcing the officer and outsourcing the team beneath the officer are entirely different arrangements with different regulatory answers. Confusing them is the most common error.
- A fractional or third-party MLRO is permitted in principle for FCA-regulated firms where the individual is FCA-approved for that specific firm, but the PRA expects deposit-taking banks to employ their MLRO directly.
- SAR decisioning cannot be delegated. As Nominated Officer under the Proceeds of Crime Act 2002, the MLRO must personally decide whether to submit each report.
- SYSC 8 prohibits outsourcing in a way that impairs internal controls or the FCA’s ability to monitor compliance, and requires due diligence, a written agreement with audit rights, and ongoing oversight.
- The FCA’s 2026 thematic review criticised inadequate MLRO resource, including part-time or shared MLROs where inappropriate for the firm’s size and nature. Fractional is not objected to in principle, thin capacity is.
- Offshore teams must be firewalled from SAR information because of the tipping-off offence, and South Africa holds no UK adequacy decision, so transfers need contractual safeguards plus a documented assessment.
What the MLRO Role Legally Is
Three roles get conflated in conversation and they arise under different instruments.
The MLRO is required by Regulation 21(3) of the Money Laundering Regulations 2017, which obliges a relevant person to appoint an individual who is a member of the board of directors or senior management as the money laundering reporting officer, responsible for oversight of the development and maintenance of policies, controls and procedures to mitigate money laundering and terrorist financing risks. Three qualities follow from that wording: the individual must be genuinely senior enough to direct staff and access all relevant information, independent enough not to be subject to inappropriate commercial pressure, and in practice UK-based and contactable.
The Nominated Officer arises under the Proceeds of Crime Act 2002, sections 330 to 332. Staff in the regulated sector must disclose internally where they know or suspect money laundering, and the Nominated Officer decides whether to submit a Suspicious Activity Report to the UK Financial Intelligence Unit at the National Crime Agency. For FCA-regulated firms the MLRO and Nominated Officer are normally the same person, but they are separate statutory functions.
The Money Laundering Compliance Principal is used mainly in the investment firm context, sitting alongside or overlapping the MLRO where the FCA distinguishes general compliance oversight from AML-specific oversight. For most payments, e-money, crypto and investment firms, SMF17 is the function that matters.
SMF17 approval is not a formality. The individual must be approved by the FCA, and the PRA too for dual-regulated firms, before performing the function. That means a Form A submission with detail on role, experience and responsibilities, a Statement of Responsibilities setting out precisely what the MLRO is accountable for, ongoing fit and proper certification covering honesty, integrity, competence and financial soundness, and personal exposure to the Senior Manager Conduct Rules and the Duty of Responsibility.
What Cannot Be Outsourced
The governing principle is simple and the FCA states it plainly: regulatory accountability cannot be outsourced. Operational tasks can move. Accountability does not.
| Responsibility | Why it stays with the named officer |
| SAR decisioning and submission to the NCA | As Nominated Officer under POCA, the MLRO must personally decide whether to submit each report. It is a statutory function that cannot be delegated |
| Overall oversight of AML and CTF systems and controls | Regulation 21(3) requires a senior manager responsible for oversight. Outsourcing this would breach the regulation itself |
| Annual MLRO report to the board | A core governance duty. The MLRO must personally report on control effectiveness |
| Regulatory liaison with the FCA, NCA and OFSI | The SMF17 holder is the FCA’s named contact for AML matters |
| Risk assessment ownership and sign-off | The MLRO must own the methodology and approve risk appetite, or accountability becomes fictional |
What Can Be Outsourced
Almost everything beneath those five, which in practice is where the headcount and cost sit.
| Function | Conditions and retained decision rights |
| Transaction monitoring alert triage | Outsourceable, but the MLRO sets alert thresholds and discounting criteria and reviews escalations |
| KYC and CDD file build | Outsourceable, but the firm remains responsible for adequacy of due diligence under Regulation 28 |
| Enhanced due diligence file preparation | Outsourceable, but the MLRO or designated senior UK staff must approve conclusions for high-risk customers |
| Sanctions and PEP screening, first pass | Outsourceable, but the MLRO must ensure screening coverage and calibration and approve true matches |
| SAR drafting and quality assurance | Drafting is outsourceable. The MLRO must personally review and approve before submission |
| Periodic review remediation | Outsourceable, but the MLRO oversees scope, sampling and reports remediation progress to the board |
Four mechanisms keep the decision rights genuinely with the officer rather than nominally. Written escalation protocols specifying exactly which alerts, matches and files must reach the MLRO or UK senior staff. A four-eyes principle requiring UK-based senior approval on high-risk decisions such as onboarding a politically exposed person or submitting a SAR. A complete audit trail logging all offshore work with the rationale for discounting alerts or closing files, available for FCA inspection. And tipping-off constraints, discussed below.

Outsourcing the Officer Versus Outsourcing the Team
These are different products and the regulatory answers differ.
Outsourcing the officer means engaging a third-party individual, typically a consultant, to hold SMF17 for your firm. This is permitted in principle for FCA-regulated firms provided the individual is FCA-approved as SMF17 for that specific firm and meets fit and proper standards. It is not acceptable for dual-regulated deposit-taking banks, where the PRA expects the MLRO to be an employee. Wherever it is used, the FCA expects the holder to have genuine authority, unfettered access to data, and real-time contactability.
Outsourcing the team beneath the officer means engaging a provider, onshore or offshore, to perform operational financial crime tasks while the named MLRO retains decision rights and oversight. This is common, well understood and acceptable, provided the firm complies with SYSC 8 and maintains operational resilience.
Most firms asking about an “outsourced MLRO” actually need the second arrangement. The officer is rarely the binding constraint; the analyst capacity beneath them almost always is.
The Outsourcing Rules You Must Satisfy
SYSC 8 prohibits outsourcing operational functions in a way that impairs the quality of internal controls, the FCA’s ability to monitor compliance, or the firm’s ability to meet its regulatory obligations. Practically, that requires due diligence on the provider, a written outsourcing agreement specifying roles, responsibilities, audit rights, data protection and exit arrangements, and ongoing oversight and monitoring of performance.
Operational resilience adds a second layer. Firms must identify important business services, set impact tolerances, and test their ability to remain within tolerance under severe but plausible disruption. Financial crime controls such as transaction monitoring and sanctions screening may well form part of an important business service, particularly for payments and e-money firms, which means a provider failure is a resilience event and not merely a service problem.
There is also a reporting change coming. Under the FCA’s rules on reporting material third-party arrangements, firms will need to report material arrangements annually. An arrangement is material where its disruption or failure could cause intolerable harm to clients, pose systemic risk, or cast doubt on the firm’s ability to meet threshold conditions. For most firms no formal FCA pre-approval is required for outsourcing itself, but the PRA requires prior notification for material outsourcing by banks, and the position for any given firm should be confirmed rather than assumed.
Where a Fractional MLRO Works, and Where It Does Not
The FCA does not object to fractional MLROs in principle. It objects to inadequate ones.
| Firm profile | Viability | Regulatory stance |
| Small e-money or payment firm, under 20 staff, low volumes | Viable and common, often 2 to 5 days a month with outsourced operational support | Accepted where capacity is credible and the individual is contactable and genuinely performing the function |
| Mid-sized cryptoasset firm, under 50 staff | Viable, widely used to meet Regulation 21(3) while controlling cost | Acceptable where the individual has real oversight and decision rights |
| Established investment firm, 50 to 200 staff, complex products | Possible but scrutinised, and needs a strong deputy and financial crime team beneath the officer | Concerns flagged where MLROs are part-time or shared inappropriately for the size and nature of the business |
| Deposit-taking bank or large lender | Not viable | PRA expects a full-time employee; outsourcing SMF17 is not acceptable |
The FCA’s 2026 thematic review of financial crime controls at asset management and alternative firms identified inadequate MLRO resource, specifically including MLROs acting part-time or with shared responsibilities where inappropriate for the size and nature of the firm’s business, alongside inadequate board-level oversight of financial crime risk. Read that as a capacity test rather than a prohibition. The arrangements that get challenged are those where the MLRO lacks the time to perform the function, is shared across firms without clear governance and conflict management, or sits over a risk profile that demands fuller oversight.
What the Enforcement Record Shows
The pattern across recent FCA actions is consistent: financial crime capability that failed to scale with the business.
Starling Bank was fined £28.96m in September 2024 over inadequate AML and sanctions controls, a breached voluntary requirement not to onboard high-risk customers, and a sanctions screening system misconfigured for years. The FCA found the financial crime function under-resourced and lacking key AML experience at the relevant time.
Monzo was fined £21.09m in July 2025 for inadequate AML systems and controls between 2018 and 2020, having onboarded more than 34,000 high-risk customers in breach of an FCA restriction, with weaknesses in customer risk assessment, enhanced due diligence and transaction monitoring.
Nationwide Building Society was fined £44.08m in December 2025 over inadequate AML monitoring between 2016 and 2021. Notably for this topic, the firm’s own 2022 MLRO report had described the financial crime control environment as only partially effective, with significant due diligence gaps and no process for periodic reviews.
Further back, NatWest’s £264.8m penalty in December 2021 was the first criminal prosecution of a UK bank under the Money Laundering Regulations, and Santander UK’s £107.7m fine in December 2022 turned on an absence of effective ownership of money laundering risk in business banking.
The lesson for a firm considering outsourcing is not that outsourcing causes enforcement. It is that under-resourcing does. A well-governed outsourced support layer with a properly resourced named officer is a stronger position than a nominally in-house function with two overloaded analysts.

Cost Benchmarks
UK salary data from the Barclay Simpson 2026 Financial Crime Salary Guide sets the in-house baseline. A financial crime analyst runs £40,000 to £50,000 in London and the South East and £30,000 to £40,000 regionally. A financial crime manager runs £50,000 to £80,000, a VP or senior manager £80,000 to £130,000, and a Head of Financial Crime or MLRO £150,000 to £300,000 in London. Interim MLRO day rates run £1,000 to £1,600 in London and £550 to £1,000 regionally.
| Cost component | In-house, London, annual | Outsourced support model, annual |
| MLRO (SMF17) | £150,000 to £300,000 | £60,000 to £150,000 fractional, 2 to 10 days a month |
| Deputy MLRO or financial crime manager | £60,000 to £100,000 | £40,000 to £80,000 |
| Financial crime analysts, 2 to 4 FTE | £80,000 to £200,000 | £50,000 to £120,000 offshore or nearshore |
| Technology: monitoring, sanctions, KYC tools | £100,000 to £300,000 including licences and integration | £50,000 to £150,000 shared platform or per-case |
| Training, recruitment, overheads | £50,000 to £100,000 | £20,000 to £50,000, usually in the provider fee |
| Approximate total | £440,000 to £1.1m | £220,000 to £550,000 |
Treat the outsourced column as indicative rather than benchmarked, since there is no independent published dataset of outsourced financial crime pricing. The saving is real but it is conditional: it holds only where the MLRO retains genuine oversight and decision rights, and a model that saves money by hollowing out the officer’s capacity is the exact arrangement the FCA’s thematic review criticised.
Data Protection, Tipping-Off and Offshore Delivery
Financial crime work processes criminal offence data, including SAR content, sanctions matches and adverse media. Under UK GDPR that category can be processed only under the control of official authority or where specifically authorised by law, which for these purposes means the firm’s obligations under POCA and the Money Laundering Regulations. That framing needs to be documented rather than assumed.
The tipping-off offence under POCA sections 333A and 342 is the constraint that shapes offshore design more than any other. Disclosing information that might prejudice a money laundering investigation is a criminal offence, so offshore staff should not know whether a SAR has been or will be filed. SAR narratives and internal escalation notes should be firewalled from offshore teams wherever possible. Offshore teams can perform alert triage, KYC file build and screening. They cannot perform final SAR decisioning or make disclosures to external parties. Build that boundary into system permissions, not just into policy.
On transfers, South Africa holds no UK adequacy decision. A transfer therefore requires appropriate safeguards such as standard contractual clauses or binding corporate rules, a documented transfer impact assessment considering whether local law undermines those protections, and supplementary measures such as encryption, pseudonymisation or contractual restrictions on onward transfers. The Data (Use and Access) Act 2025 introduced a streamlined test for international transfers, but firms must still ensure adequate safeguards are in place. Our guide to outsourcing data security and compliance covers the certification questions, and BPO compliance in South Africa covers the domestic regime.
If You Are Also Subject to US or EU Rules
Under the US Bank Secrecy Act, every covered financial institution must designate a BSA compliance officer with sufficient authority, independence and resources. Operational tasks may be outsourced, but the officer is expected to be US-based and to retain oversight. The structural logic mirrors the UK position.
In the EU, the Anti-Money Laundering Authority became operational in July 2025 and will directly supervise a group of high-risk institutions from 2028. The AML Regulation applies fully from 10 July 2027 and creates a directly applicable EU-wide rulebook requiring obliged entities to appoint a compliance officer with seniority, board access and adequate resources. Outsourcing is permitted, the firm remains responsible, and critical outsourcing requires supervisor notification. Anyone building a multi-year operating model across both regimes should track that timetable, since the detail is still settling.
Nothing here is legal advice, and the position for any individual firm turns on its permissions, risk profile and supervisor. Where the regulatory position is unsettled or firm-specific, confirm it rather than reasoning from a general rule.
Frequently Asked Questions
Can a UK firm outsource its MLRO? It can outsource the individual holding SMF17 in principle, provided that person is FCA-approved as SMF17 for that specific firm and meets fit and proper standards, but this is not acceptable for dual-regulated deposit-taking banks where the PRA expects an employee. What cannot be outsourced in any case is the accountability: SAR decisioning, overall oversight of systems and controls, board reporting, regulatory liaison and risk assessment ownership stay with the named officer.
What is the difference between an MLRO and a Nominated Officer? They arise under different statutes. The MLRO is required by Regulation 21(3) of the Money Laundering Regulations 2017 and is responsible for oversight of AML and CTF policies, controls and procedures. The Nominated Officer is required under the Proceeds of Crime Act 2002 sections 330 to 332, receives internal disclosures of suspicion and decides on SAR submission. In FCA-regulated firms the same individual normally holds both.
Is a fractional or part-time MLRO acceptable to the FCA? Yes in principle, and it is common for small payment, e-money and cryptoasset firms. The FCA’s 2026 thematic review criticised inadequate MLRO resource including part-time or shared MLROs where inappropriate for the size and nature of the business. So the test is capacity and genuine authority, not hours. Expect challenge where the MLRO lacks time, is shared across firms without conflict management, or sits over a risk profile demanding fuller oversight.
What financial crime work can legally be sent offshore? Transaction monitoring alert triage, KYC and customer due diligence file build, enhanced due diligence preparation, first-pass sanctions and PEP screening, SAR drafting, and periodic review remediation. Each is conditional on the MLRO retaining defined decision rights, and the firm remains responsible for adequacy of due diligence under Regulation 28 regardless of who performs the work.
How does the tipping-off offence constrain an offshore team? POCA sections 333A and 342 make it an offence to disclose information that might prejudice a money laundering investigation. Offshore staff should therefore not know whether a SAR has been or will be filed, and SAR narratives and internal escalation notes should be firewalled from them wherever possible. Offshore teams can triage alerts and build files but cannot make final SAR decisions or disclosures to external parties. Enforce this through system permissions, not policy alone.
What does an outsourced financial crime support model cost against an in-house team? An in-house London function covering an MLRO, deputy, two to four analysts, technology and overheads runs roughly £440,000 to £1.1m a year. An outsourced support model with a fractional MLRO and an offshore analyst team runs roughly £220,000 to £550,000. The saving is conditional on the MLRO retaining genuine oversight; a model that saves money by thinning the officer’s capacity is the arrangement the FCA has criticised.
Do I need FCA approval before outsourcing financial crime operations? For most firms there is no formal pre-approval requirement for outsourcing itself, but the arrangement must satisfy SYSC 8 and operational resilience rules, and material third-party arrangements become annually reportable to the FCA. The PRA requires prior notification for material outsourcing by banks. Confirm the position for your specific permissions rather than assuming the general rule applies.
Can financial crime work be performed in South Africa under UK GDPR? Yes, but not automatically. South Africa holds no UK adequacy decision, so the transfer needs appropriate safeguards such as standard contractual clauses, a documented transfer impact assessment considering whether local law undermines those protections, and supplementary measures such as encryption or pseudonymisation. Criminal offence data handling must also be justified under the firm’s POCA and Money Laundering Regulations obligations.
Afrishore BPO builds financial crime support teams from Johannesburg for UK-regulated firms, covering alert triage, KYC and EDD file build, screening adjudication and periodic review remediation, with UK-side decision rights, audit trails and SAR firewalling designed in. Our financial services outsourcing division also covers AML as an outsourced function and banking and financial services BPO, and our guides to BPO contracts and SLAs and outsourcing finance and operations to South Africa for UK companies cover the commercial structure.
Talk to us about your financial crime operating model at https://afrishorebpo.com/financial-services-outsourcing/.



