AMLR's compliance officer requirement, precisely explained: what Article 9 actually asks of a football club or agency

Ask most people in football compliance what AMLR requires on personnel, and the answer comes back as some version of "a compliance officer and an MLRO." It is a reasonable shorthand, and it is not quite what the Regulation actually says. AMLR does not use the term MLRO anywhere in its own text. Getting this precisely right -- what Article 9 actually requires, what role sits alongside it, and what genuinely counts as "designated" rather than a title on a business card -- is the difference between a compliance structure that would survive scrutiny and one that only looks right on paper.

Lagom Article Header CTA
Lagom Sports Compliance

This article is brought to you by Lagom Sports Compliance -- the leading governance, risk, compliance and anti-financial crime consultancy built exclusively for professional football. We help clubs, agents and leagues navigate the IFR, UEFA licensing and EU AML obligations with proportionate, practitioner-led support.

Want to talk through what this means for your club?

What Article 9 of the AMLR actually says

Article 9(2) of the AMLR is precise, and worth reading closely rather than paraphrased. It requires that obliged entities "shall have a compliance officer, to be appointed by the management body in its management function and with sufficiently high hierarchical standing, who shall be responsible for the policies, procedures and controls in the day-to-day operation of the obliged entity's AML/CFT requirements, including in relation to the implementation of targeted financial sanctions, and shall be a contact point for competent authorities."

The same subsection continues: "The compliance officer shall also be responsible for reporting suspicious transactions to the FIU in accordance with Article 69(6)." That final sentence is the one worth pausing on, because it is where the popular "compliance officer and MLRO" shorthand actually comes from -- and where it starts to mislead.

No Separate MLRO Role Callout

AMLR does not create a separate MLRO role. It builds the function that title traditionally refers to directly into the compliance officer's own statutory job description.

Why 'MLRO' is not actually AMLR's own term

MLRO, Money Laundering Reporting Officer, is a term with real pedigree in AML compliance, including in the UK's own Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017, and in earlier EU AML directives. It refers, specifically, to the individual responsible for receiving internal suspicious activity reports and deciding whether to escalate them externally to the relevant Financial Intelligence Unit. It is a genuinely important, well-understood function in AML compliance history.

It is simply not the label AMLR itself uses. Read Article 9(2) again: the compliance officer, not a separately titled MLRO, is the person Article 9 makes "responsible for reporting suspicious transactions to the FIU." AMLR has folded what the industry has traditionally called the MLRO function directly into the statutory job description of the Article 9 compliance officer, rather than creating two named statutory roles that map neatly onto "compliance officer" and "MLRO" as separate titles. A club or agency that appoints "a compliance officer and an MLRO" as two distinctly titled positions has not done anything wrong -- but it has organised itself around a structure the Regulation's own text does not actually require, and may be missing the role AMLR does explicitly require alongside the Article 9 compliance officer. 

The role that genuinely sits alongside it: the Compliance Manager

AMLR does create a second, distinct role. It is simply not called MLRO.

Article 11 of the Regulation establishes a Compliance Manager: a member of the entity's own management body, given specific responsibility for AML/CFT and targeted financial sanctions compliance at board level. The Compliance Manager's role is different in character from the Article 9 compliance officer's: the Compliance Manager sits on the management body itself and is responsible for ensuring the entity's AML/CFT policies align with its actual risk exposure and are properly resourced, with the entity's internal policies formally approved at management-body level, while the Article 9 compliance officer -- appointed by the management body rather than sitting on it -- runs the operational, day-to-day implementation of those policies, procedures and controls, and personally carries the FIU reporting responsibility.

In practical terms: the Compliance Manager is accountability at board level. The Article 9 compliance officer is execution and operational ownership, including the specific statutory duty to report suspicious transactions -- the function most people are actually thinking of when they say MLRO. Both roles are required to have direct access to the entity's management body and the ability to raise concerns independently, without needing permission or facing retaliation for doing so.

Compliance Officer MLRO Same Person Box

Can the compliance officer and 'MLRO' function be the same person?

This is the question most clubs and agencies actually want answered, and the precise answer is: the question itself is slightly the wrong shape, but the underlying practical answer is yes, in the right circumstances.

Because AMLR does not create a separate MLRO role, there is no question of combining a compliance officer with a distinct MLRO -- the suspicious-transaction-reporting function is already, by default, part of the Article 9 compliance officer\'s own job. The genuine combination question under AMLR is whether the Compliance Manager and the Compliance Officer roles can be held by the same individual -- and the Regulation is explicit that, where justified by the size of the entity and the level of risk involved, they can. For a small agency with a handful of staff and a modest transaction volume, one appropriately senior individual holding both the board-level Compliance Manager responsibility and the operational Article 9 compliance officer function, including its FIU reporting duty, is a legitimate, proportionate structure. For a large multi-client agency or a club with genuinely material transaction volume and risk exposure, separating the two is likely to be the more defensible approach -- precisely because the size-and-risk justification that permits combination becomes harder to sustain as the entity itself grows.

What 'designated' actually means in practice

The word "designated" does a lot of quiet work in AML compliance commentary, and it is worth being precise about what Article 9 actually requires beyond simply naming someone to a role.

  • Appointed by the management body itself, not delegated downward informally. Article 9(2) specifies the compliance officer is "to be appointed by the management body in its management function." This is a formal, board-level appointment decision, evidenced as such -- not a job title an operations manager assigns to a junior colleague as an additional duty without the board itself having made and recorded that decision.

  • Sufficiently high hierarchical standing. This is a specific, deliberately imprecise-sounding phrase that nonetheless carries real weight: the compliance officer needs genuine seniority and standing within the organisation to be effective in the role -- able to be heard, to challenge commercial decisions on compliance grounds, and to be taken seriously by the people whose activity they are responsible for monitoring. A compliance officer appointed at a level too junior to credibly challenge senior colleagues or ownership does not meet this standard, regardless of the title on their contract.

  • Direct access to the management body, and the ability to raise concerns independently. Both the compliance officer and the Compliance Manager must be able to reach the entity's management body directly, and to raise concerns about AML/CFT risk without needing to route that concern through a chain of command that could suppress or delay it. A structure where the compliance officer reports only to a commercial director, with no independent line to the board, does not satisfy this requirement even if the individual formally holds the title.

  • A genuine contact point for competent authorities. Article 9(2) specifies the compliance officer "shall be a contact point for competent authorities" -- meaning the role has to function as a real, reachable, informed point of contact for a regulator, not a name on an organisational chart that has never actually engaged with a regulatory body or does not know what such an engagement would require.

The pattern across all four elements is the same: "designated" means the role is genuinely embedded in the organisation's governance -- formally appointed, properly senior, structurally independent, and operationally real -- rather than a job title assigned informally to satisfy a compliance checklist. A regulator assessing whether an obliged entity has genuinely met Article 9 is very unlikely to accept a title alone as evidence; the appointment record, the individual's actual seniority and access, and evidence of the role functioning in practice are all likely to matter.

Proportionality: what changes between a small agency and a large one

The size-and-risk justification for combining the Compliance Manager and compliance officer roles is the clearest proportionality mechanism in Article 9 and Article 11, but it is not the only place proportionality shows up in practice, and it is worth being specific about what actually scales and what does not.

What scales down for a small agency: the formality and resourcing of the role. A sole practitioner or small agency combining both roles in one appropriately senior individual, supported by proportionately simple policies, procedures and controls appropriate to a modest transaction volume, is a legitimate reading of the Regulation's own size-and-risk test. What does not scale down, for any entity regardless of size: the substance of the obligations themselves. A small agency's compliance officer still needs sufficiently high hierarchical standing, still needs direct and independent access to the entity's management body, and is still personally responsible for FIU suspicious-transaction reporting under Article 69(6). Proportionality changes the shape and scale of the compliance structure. It does not remove any of the underlying obligations Article 9 actually sets out.

For a large, multi-client agency or a club with material transaction volume, the practical expectation moves in the opposite direction: separating the Compliance Manager and compliance officer roles becomes progressively harder to avoid as size and risk increase, and the day-to-day compliance officer role itself is likely to require genuine capacity -- not a single individual holding the title alongside a full caseload of unrelated commercial responsibilities, but a role with the time, resource and organisational standing actually required to run the day-to-day AML/CFT function Article 9 describes.

For the broader picture of how football's obligations under AMLR fit within the wider EU AML reform architecture, including AMLA's role in ensuring national supervisors apply these requirements consistently, see Lagom's companion article on AMLA and football. 

A job title is not a compliance structure. Article 9 asks for something more specific than that, and more specific than most existing commentary describes.

Lagom Sports Compliance is the leading specialist governance, risk, compliance and anti-financial crime consultancy built exclusively for professional football, globally. We help clubs and agents, in the EU and UK, build genuine, tested AMLR readiness on a realistic timeline. If you want to discuss what a genuinely compliant Article 9 structure looks like for your club or agency, get in touch.

Start with our free compliance checker. It maps your club's current position against EU AML 2024/1624 requirements in minutes and gives you an immediate read on your exposure. No obligation. No cost. 

For agents and agencies ready to begin formal preparation, the Lagom Sports Compliance EU AML 2024/1624 Readiness Assessment delivers a fixed-scope diagnostic for a fixed fee: an enterprise risk assessment, football-specific risk mapping, sanctions exposure review and a prioritised remediation roadmap. The fee is credited in full against any subsequent framework implementation.

Agents and agencies requiring full framework design can explore our AML Framework Development support, and those seeking a fully outsourced AML function can review what we can provided through outsourcing and resourcing. We have a dedicated page on AMLR support for football agents that you can view as well.

Lagom Article Header CTA
Lagom Sports Compliance

This article is brought to you by Lagom Sports Compliance -- the leading governance, risk, compliance and anti-financial crime consultancy built exclusively for professional football. We help clubs, agents and leagues navigate the IFR, UEFA licensing and EU AML obligations with proportionate, practitioner-led support.

Want to talk through what this means for your club?

Frequently asked questions: AMLR's Article 9 compliance officer requirement

Previous
Previous

Beneficial ownership and football: what AMLR actually requires, the exemption most clubs have not read, and why it is about to get harder

Next
Next

AMLR for football agents: the full compliance guide