What is the difference between the AML Compliance Officer (AMLCO) and the Compliance Manager under EU’s Anti-Money Laundering Regulation (AMLR)? Learn how AMLR’s new governance model reshapes AML/CFT responsibilities, what distinguishes these two key roles, and how financial firms should prepare.
One of the most significant governance reforms introduced by the EU’s Anti-Money Laundering Regulation (EU) 2024/1624 (AMLR) is the clear distinction between the Compliance Manager and the AML Compliance Officer (AMLCO).
While many firms already have individuals responsible for AML/CFT compliance, AMLR introduces a more structured governance model that separates strategic management oversight from day-to-day operational responsibility.
The objective is to strengthen accountability and ensure AML/CFT compliance is embedded throughout the organisation.
As firms prepare for the application of AMLR from 10 July 2027, understanding these roles and assessing existing governance arrangements should be a key priority.
Key Takeaways: AMLCO vs Compliance Manager Under AMLR
- AMLR introduces separate roles for the Compliance Manager and AMLCO, strengthening governance and accountability.
- The Compliance Manager provides strategic oversight at management-body level, while the AMLCO is responsible for the day-to-day operation of the AML/CFT framework.
- The roles may only be combined in limited circumstances, subject to the principle of proportionality.
- Reviewing governance structures should form a key part of every firm's AMLR readiness programme.
AMLR: A Stronger Focus on Governance
One of the key objectives of AMLR is to strengthen AML/CFT governance across the European Union and promote greater consistency in how firms manage financial crime risks.
As highlighted during Complyport’s recent webinar on the EU AML Package, the Regulation introduces enhanced governance requirements, including:
- Strong governance arrangements;
- Independent audit functions;
- Group-wide AML/CFT compliance frameworks;
- Enhanced internal controls;
- Greater emphasis on conflicts of interest management; and
- Clearer accountability for AML/CFT compliance.
These changes reflect a broader regulatory expectation that AML/CFT compliance should be embedded within a firm’s governance framework rather than operating solely as a compliance function.
The introduction of the Compliance Manager role forms part of this wider governance model, helping to ensure that responsibility for AML/CFT compliance is clearly allocated at both management and operational levels.
What Is a Compliance Manager Under AMLR?
Under AMLR, the Compliance Manager must be a member of the management body and is responsible for the firm’s AML/CFT compliance.
The role includes responsibility for:
- Oversight of AML/CFT compliance;
- Ensuring compliance with AML/CFT obligations; and
This requirement reinforces the expectation that AML/CFT compliance should be treated as a strategic governance issue rather than solely an operational responsibility.
What Is an AMLCO Under AMLR?
The AMLCO has a distinct operational role within the organisation.
According to AMLR, the AMLCO should occupy a sufficiently high hierarchical position and is responsible for:
- Day-to-day AML/CFT operations;
- AML/CFT reporting obligations;
- Acting as the firm's AML/CFT contact point.
The AMLCO is therefore responsible for overseeing the practical implementation and day-to-day operation of the firm’s AML/CFT framework.
In many organisations, the AMLCO will continue to be the individual most closely involved with customer due diligence, suspicious activity reporting, transaction monitoring and AML controls.
AMLCO vs Compliance Manager: Key Differences
Having defined both functions, the key distinctions can be summarised as follows:
| Area | Compliance Manager | AMLCO |
|---|---|---|
| Position within the firm | Member of the management body | High Hierarchical Position |
| Primary responsibility | AML/CFT compliance oversight and accountability | Day-to-day AML/CFT operations |
| Primary Focus | Governance and management accountability | Operational implementation |
| Role under AMLR | Responsible for AML/CFT compliance | Responsible for AML/CFT operations, reporting and acting as the firm's AML/CFT contact point |
| Management body involvement | Must be a member of the management body | Not necessarily a member of the management body |
| Reporting responsibilities | Oversight of the compliance framework and submitting report to management body at least once every year in relation to the implementation of firm’s internal policies, procedures and controls | Day-to-day reporting and escalation (i.e.to FIU, Management Body etc.) |
| Regulatory interaction | Responsible for ensuring compliance at management level | Primary AML/CFT contact point |
| Can both roles be performed by the same person? | Yes, in limited circumstances | Yes, in limited circumstances |
Why the AMLCO and Compliance Manager Distinction Matters
The distinction reflects AMLR’s objective of embedding AML/CFT compliance throughout the organisation. While the Compliance Manager provides strategic oversight and accountability at management-body level, the AMLCO is responsible for ensuring the firm’s AML/CFT framework operates effectively on a day-to-day basis.
Although AMLR allows both functions to be performed by the same individual in limited circumstances, firms should carefully assess whether their governance arrangements remain appropriate given their size, complexity and risk profile.
Can One Person Perform Both Roles?
This is one of the most frequently asked questions arising from AMLR.
AMLR recognises the principle of proportionality and allows, in limited circumstances, the Compliance Manager and AMLCO functions to be performed by the same individual.
However, firms should not assume this will always be appropriate.
Factors that should be considered include:
- The size of the organisation;
- The nature and complexity of its activities;
- The firm's customer base;
- Geographic reach;
- Transaction volumes; and
- Overall AML/CFT risk exposure.
Firms should be able to demonstrate that their governance arrangements remain effective and proportionate to the risks they face. The decision should be documented and supported by the firm’s governance framework and risk assessment.
Preparing Your Governance Framework for AMLR
The introduction of the Compliance Manager and AMLCO roles is only one aspect of AMLR’s wider governance reforms. Firms should use the transition period to assess whether their governance framework, reporting lines and compliance structures remain fit for purpose.
As part of a wider AMLR readiness programme, firms should consider the following actions:
- Review Existing Governance Structures
Assess whether AML/CFT responsibilities are clearly allocated and appropriately documented.
- Identify Who Will Perform Each Function
Determine whether separate individuals should perform the Compliance Manager and AMLCO roles.
- Update Governance Documentation
Review organisational charts, terms of reference, reporting lines, policies and procedures.
- Assess Group-Wide Compliance Arrangements
AMLR introduces enhanced group-wide requirements, including group compliance functions and group-wide policies.
- Include Governance Within AMLR Gap Analysis Projects
Governance should form part of wider AMLR readiness assessments, alongside customer due diligence, monitoring systems, business-wide risk assessments and internal controls.
- Train Senior Management
Management bodies should understand the new governance expectations and their role within the AML/CFT framework.
Frequently Asked Questions
No. AMLR distinguishes between the two functions. The Compliance Manager is responsible for AML/CFT compliance at management-body level, while the AMLCO is responsible for day-to-day AML/CFT operations.
AMLR allows both functions to be performed by the same person in limited circumstances, depending on the firm's size, nature and risk profile.
The objective is to strengthen governance and accountability by ensuring that AML/CFT compliance receives oversight at management-body level.
The AML Regulation is expected to apply from 10 July 2027.
How Complyport Can Support AMLR Readiness
Preparing for AMLR requires more than updating policies. Firms should review governance structures, reporting lines, compliance functions and operating models to ensure they remain aligned with the Regulation’s enhanced governance requirements.
Complyport supports investment firms, payment institutions, electronic money institutions, crypto-asset service providers, fund managers and other regulated firms with:
- AMLR readiness assessments and gap analyses;
- AML governance reviews;
- Compliance function effectiveness reviews;
- AML/CFT framework assessments;
- Board and senior management training;
- Policy and procedure redesign; and
- AMLR implementation programmes.
Our specialists work with firms to assess existing governance arrangements, identify areas requiring enhancement and develop practical implementation plans aligned with AMLR requirements.
To discuss how AMLR may affect your governance framework and compliance function, contact Complyport’s regulatory compliance team.
Table of Contents
Watch our Recent AMLR Webinar on Demand
EU’s Latest AML/CFT Package: The Changes Financial Firms Need to Prepare for Now
Presented by Alexandros Constantinou, Senior Managing Director, Complyport EU, the webinar explores the key regulatory changes and the practical steps firms should be taking ahead of the 2027 implementation deadline.
Related Insights

Subscribe for Exclusive Regulatory News and Updates
Receive the latest regulatory developments, expert insights, practical compliance guidance and invitations to Complyport webinars and events.
Share this Article
Found this article useful? Share it with your colleagues and network.






