Staying compliant
Compliance officer and MLRO
Outsourced compliance support for Authorised Firms and DNFBPs
In short
Smaller Authorised Firms and DNFBPs often cannot justify a full-time compliance hire. We provide outsourced compliance officer and MLRO support: the framework, the monitoring, the reporting and the regulatory returns, with named individuals the DFSA will accept.
What you get
- Business risk assessment and annual review
- Compliance monitoring programme and testing
- AML policy, customer due diligence procedures and enhanced due diligence triggers
- goAML registration and suspicious activity reporting
- Annual AML return and DFSA regulatory returns
- Staff training and board reporting
Timeline: Ongoing, with framework build in 4 to 8 weeks
Outsourced does not mean absent
The DFSA accepts outsourced compliance and, for smaller firms, an outsourced MLRO. What it does not accept is a name on a form. The individual needs genuine capacity, real access to the business and enough time to do the work.
Responsibility stays with the firm and its governing body. A written outsourcing agreement setting out scope, service levels and access rights is expected, and the regulator will ask for it.
Questions
Can the compliance officer and MLRO be the same person?
In smaller firms the DFSA will approve one individual for both. It assesses capacity, so as the firm grows or takes on client assets the regulator becomes more likely to want the roles split.
Do DNFBPs need an MLRO?
Yes. DIFC entities falling within the DNFBP categories must appoint an MLRO, carry out a business risk assessment and register on goAML, supervised by the DIFC Registrar rather than the DFSA.
Not sure which DIFC licence you need?
Answer eight questions and we will tell you the licence route, the likely cost and the realistic timeline. It takes about two minutes and there is no obligation.