Role guide · ADGM and the UAE

Fractional MLRO for ADGM and UAE-regulated firms

Your Money Laundering Reporting Officer is the person the regulator and the UAE Financial Intelligence Unit hold responsible for your anti-money laundering controls. Here is what the role involves, why it is required and how a senior, fractional MLRO works in practice.

goAMLSuspicious activity reports
ApprovedIndividual role
OngoingFractional cover
A senior MLRO reviewing a report at an oak desk in a bright Dubai office
At a glance

The MLRO in brief

The senior individual who owns your anti-money laundering framework, decides what is reported to the authorities and answers for it to the regulator.

Also searched as: Outsourced MLRO, interim MLRO
Regulatory status
A regulator-approved role: a Licensed Function (DFSA) or Controlled Function (FSRA), and fit and proper under VARA’s rules. Onshore, the Compliance Officer at management level carries the reporting duty.
Reports to
The board and senior management, with direct access to both.
Works closely with
The Compliance Officer, Deputy MLRO, Head of Financial Crime and client-facing teams.
Where it sits
Second line: independent oversight of the first-line teams who onboard and serve clients.[1]
Typical commitment
Agreed days each month, sized to your client base and volumes, with more around licensing, audits and inspections.

What the rules say

  • In DIFC, the MLRO is a Licensed Function the DFSA must approve, held by an Authorised Individual who is a director, partner or senior manager. Every Authorised Firm must have one at all times.[2]
  • In ADGM, the MLRO is a Controlled Function held by an FSRA Approved Person, and every Authorised Person must have one at all times.[3],[4]
  • In both, the MLRO must be resident in the UAE unless the regulator grants a waiver, and the role can be outsourced to a suitable individual with real seniority and the capacity to do it.[5],[4]
  • VARA requires every virtual asset service provider to appoint a fit and proper MLRO with at least two years of AML/CFT experience, who reports to the board every quarter. VARA allows the MLRO role to be outsourced.[6],[7]
  • Onshore, the federal AML regulations require a Compliance Officer at management level who assesses suspicious transactions and decides what is reported to the Financial Intelligence Unit.[8]
What they do

Running the AML/CFT cycle

Most anti-money laundering frameworks follow the same logic, set out in the FATF Recommendations that UAE law implements: understand your risks, apply controls in proportion to them, watch for anything unusual and report it. The MLRO owns that cycle end to end.[9],[10]

What they own

  • AML/CFT framework
  • Enterprise-wide risk assessment (EWRA)
  • Transaction monitoring
  • SAR and STR filing via goAML
  • Sanctions screening and escalation
  • MLRO reporting to the board
01

Assess the risk

Keep the enterprise-wide risk assessment current: which customers, products, countries and channels expose the firm to money laundering, terrorist financing and sanctions risk.

02

Know the customer

Set the due diligence standard, including enhanced checks for higher-risk clients and politically exposed persons, and sign off the difficult cases.

03

Monitor

Oversee transaction monitoring and sanctions screening, and make sure alerts are reviewed properly and on time.

04

Report

Investigate internal reports and decide, independently, whether to file a suspicious transaction report with the Financial Intelligence Unit through goAML.

05

Train and review

Train staff, report to the board on how the framework is performing, and fix what reviews and audits find.

Why it matters

Why a UAE firm needs an MLRO

It is a legal requirement for regulated firms. A good MLRO is also what keeps a licence safe as the business grows.

  1. 01

    It is a condition of the licence

    The DFSA and the FSRA both require an approved MLRO in place at all times, and VARA requires one for every virtual asset service provider. A gap is a breach in its own right.[2],[3],[6]

  2. 02

    Someone must decide what gets reported

    UAE law requires regulated firms to report suspicions to the Financial Intelligence Unit without delay, through its goAML system. The MLRO makes that call independently. Warning a customer that a report has been made is a criminal offence.[10],[11]

  3. 03

    Sanctions apply immediately

    When a name is added to a sanctions list, UAE firms must apply the Executive Office’s instructions without delay: screen, freeze and report. That needs an owner who is always reachable.[12],[10]

  4. 04

    Senior management must see how it is working

    The MLRO reports on the AML framework every six months in ADGM and every quarter under VARA. In DIFC, senior management gets regular management information and the firm files an annual AML return.[4],[6],[5]

How it works

How a fractional MLRO works with us

One brief, one accountable appointment. The person you meet is the person named on the appointment and doing the work.

01

Brief

Tell us where you are regulated, what stage you are at and why the role is needed. We screen the firm and any open regulatory matters before recommending an appointment.

02

Shortlist

We put forward senior candidates with relevant tenure in your role, sector and jurisdiction. You meet the person who will do the work, not a sales lead.

03

Approval

Where the role needs regulatory approval, we help prepare the application and the candidate for the fit and proper assessment. The regulator holds final acceptance.

04

Ongoing

Your appointee works agreed days each month, reports to your board and steps up around licensing, inspections and remediation.

The first 90 days

Days 1 to 30

Take ownership

  • Review the AML policy, risk assessment and a sample of customer files
  • Check screening and monitoring work, and that alerts are being cleared
  • Confirm goAML registration and internal reporting lines
  • Agree how and when the regulator is updated

Days 31 to 60

Fix what matters most

  • Rank the gaps by risk and agree a remediation plan with the board
  • Refresh the enterprise-wide risk assessment and customer risk-rating
  • Tune screening and monitoring rules to the real client base
  • Run targeted training for client-facing staff

Days 61 to 90

Run and report

  • Set monthly management information on alerts, cases and reports
  • Deliver the first MLRO report to senior management
  • Test a sample of files against the new standard
  • Agree the annual AML plan and training calendar
Choosing the model

Fractional, full-time or outsourced?

All three can work. What matters to the regulator is that the person named on the appointment has the seniority, independence and time to hold it.

Fractional
Full-time hire
Outsourced provider
Who does the work
FractionalThe named senior individual you appointed
Full-time hireYour own employee
Outsourced providerA provider’s team, under a named lead
Time commitment
FractionalAgreed days each month, flexing with need
Full-time hireFull time, whatever the workload
Outsourced providerSet by the service contract
Cost basis
FractionalA share of a senior salary, for the time you use
Full-time hireFull salary, benefits, visa and hiring costs
Outsourced providerA service fee, often plus ad hoc charges
Getting started
FractionalNo full recruitment cycle
Full-time hireA full search and notice period
Outsourced providerQuick to contract
Continuity
FractionalStays as long as you need; handover planned
Full-time hireDepends on retention
Outsourced providerStaff may rotate across clients
Best when
FractionalYou need senior judgement and accountability, but not five days a week.
Full-time hireVolumes or complexity justify a full-time officer, as at a larger bank or exchange.
Outsourced providerYou want a defined service and are comfortable with how the provider staffs it.
When to engage

Signs it is time

  • A licence application needs a named MLRO
  • Your MLRO is leaving, or the current arrangement is not working
  • Post-licence obligations have outgrown the team
  • An inspection or thematic review is coming up
  • You are adding higher-risk clients, products or countries
Who we place

What good looks like

Relevant tenure and experience as an MLRO or in senior AML and financial crime roles.

  • Prior MLRO or Deputy MLRO experience in a regulated firm
  • Hands-on goAML reporting and sanctions screening
  • Experience with your regulator and your sector
  • The judgement to decline business, and the confidence to explain why to the board
Related roles

Often appointed alongside

Most regulated firms need more than one of these roles. Each has its own guide.

  1. Deputy MLROThe MLRO’s second in command: shares the anti-money laundering workload and takes over the role, with its responsibilities, whenever the MLRO is unavailable.
  2. Compliance OfficerThe approved individual who makes sure the firm meets its regulatory obligations day to day, and tells senior management when it does not.
  3. Head of Financial CrimeThe senior specialist who owns the firm’s defences against money laundering, sanctions breaches, fraud and bribery, and proves they work.
All seven Risk and Compliance roles
Common questions

MLRO, answered

Yes, in many cases. DFSA and FSRA rules allow the MLRO role to be outsourced to a suitable individual, provided they have real seniority and the capacity to do the job, which can include serving more than one firm. VARA also allows the MLRO to be outsourced. We agree and document the time commitment up front, so the regulator can see it is enough.

Often, yes. In DIFC one person can hold both functions if they can do both effectively and conflicts are managed, but not alongside the Senior Executive Officer or Finance Officer roles. ADGM guidance expects independent monitoring where functions are combined, and VARA allows the roles to be combined where duties do not conflict.

In DIFC and ADGM, yes: the MLRO must be resident in the UAE, although the regulator can grant a waiver in some cases.

goAML is the UAE Financial Intelligence Unit’s reporting system. Firms register on it, and the MLRO uses it to file suspicious transaction and activity reports.

No. The regulator holds final acceptance. We put forward candidates with the relevant tenure and experience, and prepare them for the fit and proper assessment.

Brief a compliance search

Need a MLRO? Tell us where you are regulated.

We screen why the role is needed, triage any regulatory action and recommend the appointment your risk profile requires.

Brief a search for this role

Sources

  1. [1]The Institute of Internal Auditors, Three Lines Model: Assurance and Advice in Support of Effective Governance (2026).
  2. [2]Dubai Financial Services Authority, DFSA Rulebook, General Module (GEN), GEN 7.4 to 7.5, Licensed Functions and mandatory appointments.
  3. [3]ADGM Financial Services Regulatory Authority, General Rulebook (GEN), GEN 5.3 and 5.5, Controlled Functions and Approved Persons.
  4. [4]ADGM Financial Services Regulatory Authority, Anti-Money Laundering and Sanctions Rules and Guidance (AML), Chapter 12, the Money Laundering Reporting Officer.
  5. [5]Dubai Financial Services Authority, DFSA Rulebook, Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Module (AML), Chapter 11, the Money Laundering Reporting Officer.
  6. [6]Virtual Assets Regulatory Authority, Compliance and Risk Management Rulebook, Part I (Compliance Officer, risk management) and Part III (MLRO).
  7. [7]Virtual Assets Regulatory Authority, Company Rulebook, Part I.C (Responsible Individuals) and Part IV.A (outsourcing).
  8. [8]United Arab Emirates, Cabinet Resolution No. 134 of 2025, Executive Regulations of Federal Decree-Law No. 10 of 2025, Articles 21 and 22, the Compliance Officer.
  9. [9]Financial Action Task Force, The FATF Recommendations, Recommendations 1, 6, 10, 18 and 20.
  10. [10]United Arab Emirates, Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and Proliferation Financing, Articles 18, 19, 29 and 37.
  11. [11]UAE Financial Intelligence Unit, goAML reporting.
  12. [12]Executive Office for Control and Non-Proliferation, Cabinet Resolution No. 74 of 2020 on the UAE list of terrorists and targeted financial sanctions.

Plain-English summaries, reviewed September 2026. Rulebooks change, so always check the current text. Fractional places qualified executives into regulated appointments. We do not provide legal advice, and final acceptance of any appointment rests with the relevant regulator; we work alongside your appointed legal and compliance advisers. Appointments to roles requiring regulatory approval are subject to the relevant authority’s requirements.