The MLRO Role in the UAE: Who Can Hold It, What Authority It Needs

At Ontrax Risk and Compliance Ltd., we deliver tailored Anti-Money Laundering (AML) compliance solutions that protect your business, ensure regulatory alignment, and foster long-term credibility. Whether you’re a financial institution, a crypto business, or part of a DNFBP sector, our specialized services are built to meet your unique compliance challenges.

MLRO UAE

Ask most UAE firms who their MLRO is and you get a name. Ask what happens when that person wants to decline a transaction the sales director has been chasing for six months, and the answer gets vaguer.

That gap is the whole subject. The MLRO UAE regulators expect is not a job title on an org chart. It is a person with the seniority, access, independence and resources to stop something — and in 2026, eight supervisory authorities put their names to a single document saying exactly that.

Short answer:  Every financial institution, DNFBP and virtual asset service provider in the UAE must appoint a Compliance Officer or MLRO under Article 22 of Cabinet Resolution No. 134 of 2025. The person must sit at management level, hold independence in decision-making, and have appropriate competence and experience. In the DIFC and ADGM the role is a regulated function requiring personal approval and UAE residency. It can be outsourced — but accountability still attaches to the individual.

The 2026 joint guidance changed the baseline

MLRO UAE

This is the development most firms have not caught up with, and it is worth leading on.

In 2026, the UAE’s supervisory authorities issued Notice No. 247/2026, a joint guidance on the AML/CFT/CPF Compliance Officer and Money Laundering Reporting Officer. The signatories are the Central Bank, the Securities and Commodities Authority, the Ministry of Justice, the Ministry of Economy and Tourism, the DFSA, the ADGM FSRA, VARA and the GCGRA.

Eight regulators, one document. The purpose is to establish a unified framework for the appointment, authority and responsibilities of the role across licensed financial institutions, DNFBPs and virtual asset service providers, aligned to Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.

What it does and does not do: the guidance harmonises supervisory expectations. It does not constitute new legislation and does not replace or supersede your own regulator’s rulebook. So it sits alongside the DFSA or FSRA rules rather than instead of them — you comply with both.

The practical significance is that a firm can no longer argue its sector is different. The expectations on seniority, board access, operational independence and adequate resourcing are now stated in common terms across every regulated sector in the country.

Compliance Officer or MLRO? Both, and the difference matters

MLRO UAE

A genuine source of confusion, and one that produces badly drafted appointment letters.

UAE federal law uses the term Compliance Officer. Article 22 of Cabinet Resolution No. 134 of 2025 requires every FI, DNFBP and VASP to appoint one, at management level, with independence in decision-making and appropriate competence and experience.

The DIFC, ADGM, VARA and most group-level policies use MLRO. In the DFSA rulebook it is a Licensed Function; under the FSRA it is a Controlled Function. Either way the individual is approved personally by the regulator, not merely notified to it.

The substantive obligation is identical: one accountable, independent person at management level who owns AML decisions and goAML reporting. Where firms get into trouble is treating them as two separate roles with split responsibilities, or appointing a Compliance Officer federally and assuming no MLRO designation is needed in a financial free zone.

For smaller firms the two functions are routinely combined in one person, and both the DFSA and FSRA permit this provided the individual has sufficient knowledge, experience and seniority. Our MLRO services for DIFC and ADGM are usually structured that way.

What makes an MLRO appointment real

MLRO UAE

Four tests, drawn straight from the joint guidance and from how supervisors actually examine the role.

TestWhat a supervisor is looking for
SeniorityManagement level, with enough standing that the board takes the person seriously. A junior analyst with the title fails immediately
Board accessA direct reporting line to the board or equivalent governing body, not one filtered through the CEO or the finance director
IndependenceNo conflicting commercial targets, and nobody in the line able to overrule an AML decision on revenue grounds
ResourcesTime, budget, systems and support proportionate to the size and risk of the business

The resources test is the one firms most often fail unintentionally. Appointing a capable person and then giving them four hours a month, no screening tool and no analyst support is not an MLRO appointment. It is a name on a form.

Where the MLRO sits on the org chart

MLRO UAE

If you want to know in thirty seconds whether a firm’s AML governance is genuine, look at the reporting line.

An MLRO reporting into the head of finance, or into a chief executive who owns the revenue number, can be overruled by the person whose business they are policing. That is a structural conflict, and no amount of personal competence fixes it. A supervisor will see it on the organisation chart before they read a single policy.

The correct structure gives the MLRO a direct line to the board or a board committee. That does not mean the MLRO never speaks to management — it means the escalation path cannot be closed off below board level.

This is also why the annual MLRO report matters. Under the DFSA regime the MLRO submits an annual report to the board, which forces a documented conversation at the right level once a year. Even where your regulator does not mandate it, we recommend producing one — it is among the cheapest pieces of evidence you can create, and its absence is conspicuous during an independent AML audit.

Can an MLRO be outsourced in the UAE?

Direct answer:  Yes. Outsourced and provisioned MLRO arrangements are well established and widely used across the UAE, particularly by smaller firms and new entrants. The individual normally needs to be UAE resident, must be approved by the relevant regulator where the role is a licensed or controlled function, and must have enough engagement time to genuinely understand the business. Accountability attaches to the individual regardless of employment status.

MLRO UAE

Notice how much of that table is identical on both sides. Regulatory approval, residency, fit and proper assessment and personal accountability do not change based on who signs the paycheque. What changes is cost structure, breadth of experience and how absence is covered.

The honest case for outsourcing is that the role requires seniority and specific regulatory experience but, at a smaller firm, does not require a full-time person. Paying a senior salary for a part-time job is poor capital allocation in the early years, and the alternative — promoting someone junior into the title — fails the seniority test.

The honest case against is that an external MLRO who is not genuinely embedded will miss things a full-time insider would catch. That risk is real and it is managed through engagement time, not through contract wording.

One constraint to plan around, and we would rather say it before you engage us than after: whoever provides your outsourced AML function or MLRO cannot then independently audit the programme they operate. Independence rules out reviewing your own work. If you use us for MLRO provision, you will need a separate firm for the audit, and we will tell you that at the outset.

Appoint first, register second, onboard third

MLRO UAE

A short section, because it is a single point that saves real time.

DNFBPs supervised by the Ministry of Economy and Tourism must appoint the Compliance Officer or MLRO before completing goAML registration, and before onboarding any customer subject to AML risk. The appointment is not a post-licence tidying exercise. It is a gating step.

Firms that discover this late end up either delaying onboarding or, worse, taking on customers before the reporting infrastructure exists — which creates a population of files that were never subject to a functioning AML process. That is expensive to remediate and impossible to hide.

The same logic applies to newly regulated sectors. A virtual asset business or a commercial gaming licensee needs the appointment in place during licensing, not after approval, because the regulator assesses the person as part of the application.

What the MLRO is actually responsible for

The job description, stripped of rulebook language.

  • Owning the AML/CFT/CPF framework — policies, procedures and their upkeep
  • Overseeing the enterprise-wide risk assessment and ensuring it reflects the business
  • Deciding on internal escalations and determining whether a report is filed
  • Filing suspicious transaction reports with the UAE Financial Intelligence Unit through goAML
  • Acting as the primary point of contact for the FIU and the supervisory authority
  • Overseeing sanctions screening and targeted financial sanctions obligations
  • Ensuring staff are trained and that training is evidenced
  • Reporting to the board, at least annually and on exception
  • Monitoring the adequacy of the compliance function and addressing deficiencies

Two of these deserve emphasis. The decision not to file is as consequential as the decision to file, and it must be documented with reasoning — an undocumented decision not to report looks identical to an oversight. And the risk assessment is the MLRO’s document, not the board’s; the board approves it, but the MLRO owns whether it is accurate.

Where personal liability begins

This is the part that changes how founders think about the appointment, and it is under-discussed.

Under the 2025 framework, accountability attaches personally to the MLRO as well as institutionally to the firm. Article 17 of Federal Decree-Law No. 10 of 2025 provides for administrative penalties from AED 10,000 to AED 5,000,000 per violation, and supervisory action can extend to individuals as well as entities.

In the DIFC and ADGM the personal dimension is sharper still, because the role is an approved function. The regulator assesses the individual as fit and proper, interviews them, and approves them by name. Withdrawal of that approval follows the person, not the firm, and it surfaces in every future application they make in any jurisdiction that asks.

Why this matters commercially: a credible candidate will ask about authority, resourcing and reporting line before accepting the role, because their own regulatory record is on the line. If a firm cannot answer those questions, good candidates decline — and the firm ends up appointing someone who did not think to ask.

Enforcement is not theoretical. Between July and October 2024, the licences of 32 local gold refineries were suspended and the businesses charged with 256 violations relating to money laundering control failures, including failure to notify the FIU of suspicious transactions and inadequate systems and controls.

What happens when the MLRO is away

A small point that produces findings out of proportion to its difficulty.

The obligation does not pause for annual leave. ADGM rules expect firms to make adequate arrangements to remain compliant when the MLRO is absent, which in practice means appointing a temporary MLRO for the period or ensuring systems and controls allow continued compliance.

Most firms have no documented deputy. If a suspicious transaction arises during a two-week absence and nobody has authority to file, the firm has a gap it cannot explain. Name a deputy, document the delegation, and make sure the deputy has goAML access before it is needed rather than during a crisis.

Common findings on the MLRO function

  • An MLRO appointed in title with no authority to decline a transaction or relationship
  • Reporting line running through the CEO or finance rather than to the board
  • No annual MLRO report, or one that records no issues at all
  • goAML registration completed in the firm’s name but the MLRO lacking access
  • Decisions not to file left undocumented
  • No deputy or absence arrangement
  • Engagement time so limited that the MLRO cannot describe the customer base
  • The same firm providing MLRO services and the independent audit
  • An appointment made after goAML registration or after customer onboarding began

Most of these are governance design problems rather than personnel problems. They are fixed by restructuring the role, not by replacing the person — and usually alongside a refresh of AML policies and staff training.

MLRO UAE: frequently asked questions

What is an MLRO?

An MLRO, or Money Laundering Reporting Officer, is the individual accountable for a firm’s anti-money laundering framework and for reporting suspicious activity to the authorities. In UAE federal law the equivalent term is Compliance Officer, required under Article 22 of Cabinet Resolution No. 134 of 2025.

Is an MLRO mandatory in the UAE?

Yes. Every financial institution, DNFBP and virtual asset service provider must appoint a Compliance Officer or MLRO at management level, with independence in decision-making and appropriate competence and experience. There is no exemption based on firm size, though the role may be combined with other compliance duties at smaller entities.

What is the difference between a Compliance Officer and an MLRO?

They are labels for the same substantive obligation. UAE federal law says Compliance Officer; the DIFC, ADGM, VARA and most group policies say MLRO. In smaller firms one individual holds both, which the DFSA and FSRA permit where the person has sufficient knowledge, experience and seniority.

Does the MLRO have to be resident in the UAE?

Generally yes. Both the DFSA and the ADGM FSRA require the MLRO to be UAE resident, and the FSRA sets out limited grounds on which a residency waiver may be granted. Practically, residency is treated as a precondition of the appointment.

Can an MLRO be outsourced?

Yes, and it is common, particularly among smaller firms and new market entrants. The individual still needs regulatory approval where the role is a licensed or controlled function, still needs UAE residency, and still carries personal accountability. What outsourcing changes is cost structure and breadth of experience, not the substance of the obligation.

What authority does an MLRO need?

Four things: seniority at management level, a direct reporting line to the board, operational independence with no conflicting commercial targets, and resources proportionate to the firm’s risk. These are set out in the 2026 joint guidance issued by the UAE supervisory authorities and are what examiners test.

Who does the MLRO report to?

The board or an equivalent governing body, directly. An MLRO reporting through the CEO or the finance function can be overruled by the person whose revenue they police, which is a structural conflict a supervisor will identify from the organisation chart.

Is the MLRO personally liable?

Accountability attaches personally to the MLRO as well as institutionally to the firm. In the DIFC and ADGM the role is an approved function, so the regulator assesses and approves the individual by name, and withdrawal of that approval follows the person rather than the firm.

What is Notice No. 247/2026?

It is a joint guidance on the AML/CFT/CPF Compliance Officer and MLRO issued by eight UAE supervisory authorities — the Central Bank, SCA, Ministry of Justice, Ministry of Economy and Tourism, DFSA, ADGM FSRA, VARA and GCGRA. It establishes a unified framework for appointment, authority and responsibilities, and harmonises expectations without replacing individual rulebooks.

When must the MLRO be appointed?

Before completing goAML registration and before onboarding any customer subject to AML risk. DNFBPs supervised by the Ministry of Economy and Tourism are explicitly held to this sequence, and in the DIFC and ADGM the individual forms part of the authorisation application itself.

Can the MLRO also be the CEO or owner?

In very small entities this is sometimes permitted with prior regulatory approval — for example, a DNFBP comprising a single officer, partner or principal. It is an exception rather than a norm, and it weakens the independence test, so expect closer supervisory scrutiny where it applies.

What does the MLRO annual report cover?

Typically the state of the AML framework, reporting volumes and trends, screening outcomes, training delivery, findings and remediation status, and any matters requiring board attention. A report recording no issues at all tends to attract more scrutiny than one that identifies real gaps with a plan.

Can our MLRO provider also do our AML audit?

No. Independence rules out reviewing your own work, so the firm operating your AML function or providing your MLRO cannot perform the independent audit of that same programme. You need a second, separate firm.

What happens if the MLRO is on leave?

Firms are expected to make adequate arrangements so the obligation continues during any absence — typically a named deputy with delegated authority and goAML access, documented in advance. An absence with no cover is a gap that is difficult to explain after the fact.

Where this leaves you

The MLRO is the only control in an AML framework that is a person rather than a document. That makes it the easiest to appoint badly and the hardest to fix quietly.

What changed in 2026 is that eight regulators agreed a common description of what the role requires. The expectations on seniority, board access, independence and resourcing are no longer a matter of interpretation by sector. If your appointment was made before that guidance, it is worth testing against it — not because the rules are new in principle, but because the standard is now written down in one place and every supervisor in the country has signed it.

Ontrax provides MLRO provision from DIFC, Dubai, for financial institutions, DNFBPs and virtual asset businesses — including MLRO services for DIFC and ADGM entities where the role is a licensed or controlled function requiring regulatory approval. We take the role with the authority it needs, or we tell you why the structure you are proposing will not work.

If you want a quick test of your current arrangement, ask three questions: can the MLRO decline a transaction without asking anyone, do they have a direct line to the board, and when did they last write a report the board actually read. If any answer is uncomfortable, get in touch.

Leave a Reply

Your email address will not be published. Required fields are marked *

OntraxAML
OntraxAML

At Ontrax Risk and Compliance Ltd., we deliver tailored Anti-Money Laundering (AML) compliance solutions that protect your business, ensure regulatory alignment, and foster long-term credibility. we ensure your business stays compliant with evolving AML regulations. Our expert-driven AML solutions help you mitigate risks, prevent financial crime, and meet global compliance standards.

NEWSLETTER

    © 2026 Ontrax Risk and Compliance Ltd. | All Rights Reserved. Designed & Developed by Inspia Technologies