Welcome to our EU site – choose your Jurisdiction

AMLCO vs Compliance Manager: Understanding AMLR’s New Governance Model

What is the difference between the AML Compliance Officer (AMLCO) and the Compliance Manager under EU’s Anti-Money Laundering Regulation (AMLR)? Learn how AMLR’s new governance model reshapes AML/CFT responsibilities, what distinguishes these two key roles, and how financial firms should prepare.

 

One of the most significant governance reforms introduced by the EU’s Anti-Money Laundering Regulation (EU) 2024/1624 (AMLR) is the clear distinction between the Compliance Manager and the AML Compliance Officer (AMLCO).

While many firms already have individuals responsible for AML/CFT compliance, AMLR introduces a more structured governance model that separates strategic management oversight from day-to-day operational responsibility.

The objective is to strengthen accountability and ensure AML/CFT compliance is embedded throughout the organisation.

As firms prepare for the application of AMLR from 10 July 2027, understanding these roles and assessing existing governance arrangements should be a key priority.

Key Takeaways: AMLCO vs Compliance Manager Under AMLR
AMLR: A Stronger Focus on Governance

One of the key objectives of AMLR is to strengthen AML/CFT governance across the European Union and promote greater consistency in how firms manage financial crime risks.

As highlighted during Complyport’s recent webinar on the EU AML Package, the Regulation introduces enhanced governance requirements, including:

These changes reflect a broader regulatory expectation that AML/CFT compliance should be embedded within a firm’s governance framework rather than operating solely as a compliance function.

The introduction of the Compliance Manager role forms part of this wider governance model, helping to ensure that responsibility for AML/CFT compliance is clearly allocated at both management and operational levels.

What Is a Compliance Manager Under AMLR?

Under AMLR, the Compliance Manager must be a member of the management body and is responsible for the firm’s AML/CFT compliance.

The role includes responsibility for:

This requirement reinforces the expectation that AML/CFT compliance should be treated as a strategic governance issue rather than solely an operational responsibility.

What Is an AMLCO Under AMLR?

The AMLCO has a distinct operational role within the organisation.

According to AMLR, the AMLCO should occupy a sufficiently high hierarchical position and is responsible for:

The AMLCO is therefore responsible for overseeing the practical implementation and day-to-day operation of the firm’s AML/CFT framework.

In many organisations, the AMLCO will continue to be the individual most closely involved with customer due diligence, suspicious activity reporting, transaction monitoring and AML controls.

AMLCO vs Compliance Manager: Key Differences

Having defined both functions, the key distinctions can be summarised as follows:

Area Compliance Manager AMLCO
Position within the firm Member of the management body High Hierarchical Position
Primary responsibility AML/CFT compliance oversight and accountability Day-to-day AML/CFT operations
Primary Focus Governance and management accountability Operational implementation
Role under AMLR Responsible for AML/CFT compliance Responsible for AML/CFT operations, reporting and acting as the firm's AML/CFT contact point
Management body involvement Must be a member of the management body Not necessarily a member of the management body
Reporting responsibilities Oversight of the compliance framework and submitting report to management body at least once every year in relation to the implementation of firm’s internal policies, procedures and controls Day-to-day reporting and escalation (i.e.to FIU, Management Body etc.)
Regulatory interaction Responsible for ensuring compliance at management level Primary AML/CFT contact point
Can both roles be performed by the same person? Yes, in limited circumstances Yes, in limited circumstances
Why the AMLCO and Compliance Manager Distinction Matters

The distinction reflects AMLR’s objective of embedding AML/CFT compliance throughout the organisation. While the Compliance Manager provides strategic oversight and accountability at management-body level, the AMLCO is responsible for ensuring the firm’s AML/CFT framework operates effectively on a day-to-day basis.

Although AMLR allows both functions to be performed by the same individual in limited circumstances, firms should carefully assess whether their governance arrangements remain appropriate given their size, complexity and risk profile.

Can One Person Perform Both Roles?

This is one of the most frequently asked questions arising from AMLR.

AMLR recognises the principle of proportionality and allows, in limited circumstances, the Compliance Manager and AMLCO functions to be performed by the same individual.

However, firms should not assume this will always be appropriate.

Factors that should be considered include:

Firms should be able to demonstrate that their governance arrangements remain effective and proportionate to the risks they face. The decision should be documented and supported by the firm’s governance framework and risk assessment.

Preparing Your Governance Framework for AMLR

The introduction of the Compliance Manager and AMLCO roles is only one aspect of AMLR’s wider governance reforms. Firms should use the transition period to assess whether their governance framework, reporting lines and compliance structures remain fit for purpose.

As part of a wider AMLR readiness programme, firms should consider the following actions:

  1. Review Existing Governance Structures

Assess whether AML/CFT responsibilities are clearly allocated and appropriately documented.

  1. Identify Who Will Perform Each Function

Determine whether separate individuals should perform the Compliance Manager and AMLCO roles.

  1. Update Governance Documentation

Review organisational charts, terms of reference, reporting lines, policies and procedures.

  1. Assess Group-Wide Compliance Arrangements

AMLR introduces enhanced group-wide requirements, including group compliance functions and group-wide policies.

  1. Include Governance Within AMLR Gap Analysis Projects

Governance should form part of wider AMLR readiness assessments, alongside customer due diligence, monitoring systems, business-wide risk assessments and internal controls.

  1. Train Senior Management

Management bodies should understand the new governance expectations and their role within the AML/CFT framework.

Frequently Asked Questions

No. AMLR distinguishes between the two functions. The Compliance Manager is responsible for AML/CFT compliance at management-body level, while the AMLCO is responsible for day-to-day AML/CFT operations.

AMLR allows both functions to be performed by the same person in limited circumstances, depending on the firm's size, nature and risk profile.

The objective is to strengthen governance and accountability by ensuring that AML/CFT compliance receives oversight at management-body level.

The AML Regulation is expected to apply from 10 July 2027.

How Complyport Can Support AMLR Readiness 

Preparing for AMLR requires more than updating policies. Firms should review governance structures, reporting lines, compliance functions and operating models to ensure they remain aligned with the Regulation’s enhanced governance requirements.

Complyport supports investment firms, payment institutions, electronic money institutions, crypto-asset service providers, fund managers and other regulated firms with:

Our specialists work with firms to assess existing governance arrangements, identify areas requiring enhancement and develop practical implementation plans aligned with AMLR requirements.

To discuss how AMLR may affect your governance framework and compliance function, contact Complyport’s regulatory compliance team.

Table of Contents

Watch our Recent AMLR Webinar on Demand

Blog image

EU’s Latest AML/CFT Package: The Changes Financial Firms Need to Prepare for Now

Presented by Alexandros Constantinou, Senior Managing Director, Complyport EU, the webinar explores the key regulatory changes and the practical steps firms should be taking ahead of the 2027 implementation deadline.

White outline of an envelope centered on a red circle/badge image area is red with a white envelope icon in the middle.

Subscribe for Exclusive Regulatory News and Updates

Receive the latest regulatory developments, expert insights, practical compliance guidance and invitations to Complyport webinars and events.

With over 25 years of experience, Complyport brings together former regulators, industry practitioners, and legally qualified experts, supported by scalable RegTech solutions and SaaS technology, to help clients meet regulatory obligations efficiently and with confidence. Subscribe for Exclusive Regulatory News and Updates

Share this Article

Found this article useful? Share it with your colleagues and network.

Refresh icon indicating reload or update

Analyze your
Business

We have a complete understanding of our clients’ risk management framework, capital planning and reporting obligations.

Why Choose Complyport?

Red line drawing of a hand with three stars above, symbolizing rewards or achievement.

Extensive Regulatory Expertise

With over 25 years of experience in the financial services industry, Complyport offers unparalleled expertise in regulatory compliance, ensuring your firm stays ahead of evolving regulations.

Icon: gear with circular arrows around it and a checkmark, symbolizing a completed automated process or successful system update

Comprehensive Service Offering

From AML audits to risk management and regulatory reporting, Complyport provides a full spectrum of compliance services, allowing you to streamline your compliance processes and focus on your core business activities.

Red outline light bulb icon with rays, signaling a bright idea or insight.

Tailored Compliance Solutions

We provide bespoke compliance solutions that are specifically designed to meet the unique needs of your business, ensuring that all regulatory requirements are met efficiently and effectively.

Three red outlined people with three arrows pointing toward the central figure, emphasizing the focal person in a team.

Client-Centric Approach

We prioritise open and transparent communication, building strong relationships with our clients based on trust and mutual respect. Our commitment to excellence ensures that we deliver high-quality services with courtesy, patience, and flexibility.

Red outline of a person standing beside a multi-arrow signpost, indicating directions (icon-style illustration).

Senior-Level Guidance

Our team of seasoned professionals, including former regulators and industry experts, leads all engagements, offering deep insights and practical advice to help you manage compliance risks effectively.

Red line illustration of a brain fused with a lightbulb and gear, symbolizing ideas and thinking for innovation and problem solving.

Innovative Fintech, Regtech and AI Solutions

Leveraging cutting-edge fintech, regtech and AI tools, Complyport enhances your compliance processes with advanced technology, ensuring accuracy, efficiency and real-time regulatory updates. Our innovative solutions empower your firm to stay compliant while maximising operational efficiency.

Key Figures

Over 25 Years

Providing Compliance Excellence

Over 1,500

Successful FCA, EU and UAE Authorisations

Over 1,000

Active Firms Receiving
Regulatory Support

8 Lots

FCA/PRA Skilled Person
& Consultancy Panel

Speak to an Expert