Hirra

Hiring guide

How to hire an MLRO

Why MLRO hiring sits on the critical path to launch, why regulatory approval is not portable between jurisdictions, and how to screen for judgement rather than framework recall.

14 August 2026 · 5 min read

The MLRO hire has a property that almost no other role in a fintech shares: the regulator can reject your choice. That single fact should change how you plan it, and it is the reason MLRO searches so often end up on the critical path to launch.

Start earlier than feels reasonable

The sequence teams expect is: build the product, apply for the licence, hire the compliance team. The sequence that works is closer to the reverse. Your MLRO is frequently a named individual in the licence application itself, which means they need to be identified, hired and often approved before you can complete the submission.

Teams that leave it late end up choosing between two bad options: appointing whoever is available and approvable, or delaying launch. Both are more expensive than starting the search a quarter earlier.

Approval is not portable

This is the most common and most costly misunderstanding we see.

An MLRO approval is granted by a specific regulator, for a specific regulated entity, in respect of a specific individual. Someone approved by the FCA in the UK is not thereby approved by the DFSA in the DIFC, the FSRA in ADGM, or MAS in Singapore. Nor does an approval at their previous employer transfer to yours.

What prior approval does give you is a materially lower-risk application: the individual has demonstrated fitness and propriety before, understands what the process demands, and will not be surprised by the questions. That is genuinely valuable. It is just not a shortcut past the process.

The practical implication: when you assess candidates, establish which regimes they have actually held an approved role in, not which regimes they have “worked with”. These are different claims and candidates do not always distinguish them.

Builder or maintainer?

The second question that determines fit. Running an established AML programme at a bank and standing one up at a pre-licence fintech are different jobs requiring different people.

The maintainer has inherited a mature framework, a team of analysts, established tooling and a defined escalation path. Their skill is running that machine well and defending it under scrutiny.

The builder has a blank page, a licence condition, a small budget and no analysts. They have to write the risk assessment, choose and tune the monitoring tooling, define the escalation route, and do the alert review themselves for the first year.

Both are legitimate careers. A maintainer dropped into a builder role frequently struggles, not through lack of knowledge but because the job is 70% hands-on work they have not personally done in a decade. Screen for it directly: ask what existed when they arrived and what they personally built.

Screening for judgement

An MLRO hire is ultimately a judgement hire. Framework recall is easy to test and predicts very little — anyone can name the elements of a risk-based approach.

Ask about a decision made under commercial pressure.

“Tell me about a time you made a call that the commercial side of the business did not want. What happened, and what did you do when they pushed back?”

You are listening for a specific decision, an understanding of the commercial cost, and evidence they held the line without being obstructive. Candidates who cannot produce an example have either never had real authority or never used it.

Ask about a false positive problem.

“Your transaction monitoring is generating far more alerts than your team can clear. Walk me through the next ninety days.”

Strong answers cover triage, rule tuning against actual outcomes, tooling and headcount as trade-offs, and the governance around changing thresholds. Weak answers jump straight to buying a new system.

Ask about a SAR they decided not to file.

Carefully, and respecting confidentiality. The reasoning matters more than the outcome. You want someone who can articulate why a suspicion did not meet the threshold — the judgement is symmetrical, and an MLRO who files everything is as much a problem as one who files nothing.

Ask what they would need from you.

The best candidates interview you back. They will ask about board access, reporting lines, budget, headcount and whether they can say no. A candidate who does not ask these things has either not held real accountability or is not planning to exercise it.

The mistakes

Hiring a title rather than authority. Appointing a compliance officer to satisfy a licence condition, then giving them no seniority, no budget and no board access, produces a person who cannot do the job and a regulatory exposure that surfaces later.

Assuming approvals transfer. Covered above, and worth repeating because it reliably costs weeks.

Underpaying against a small market. The pool of approvable, genuinely experienced MLROs in any given jurisdiction is small, and they know it. Compensation benchmarking against generic compliance roles will not work.

Treating monitoring as a tooling problem. Teams buy a platform and consider financial crime handled. The binding constraint is almost always analyst capacity and rule tuning, both of which are people problems.

Not planning for the deputy. Regulators expect coverage. A single MLRO with no deputy is a continuity risk, and it is a question you will be asked.

What to do first

If you are pre-licence, work backwards from your target submission date and start the search at least a quarter before you need the name. If you are already regulated and replacing an incumbent, treat it as a confidential search — the market is small enough that news travels, and an unmanaged departure creates both a regulatory and a commercial problem.


Hiring an MLRO or building a compliance function? Send us the brief, or read more about our compliance and financial crime recruitment.

FAQ

Frequently asked

How long does it take to hire an MLRO?

The search is usually not the constraint — regulatory approval is. Approval timelines vary substantially by regulator and by how complete the application is, so the honest answer is that you should plan the approval as a workstream from the start rather than assume a generic number of weeks.

Can an MLRO approved in one country move to another?

Not automatically. Approval is granted by a specific regulator for a specific entity, and an approval held with the FCA, the DFSA, the FSRA or MAS does not carry across. Someone who has been approved before is usually a lower-risk application, but they still have to be approved again.

Can the MLRO role be outsourced or part-time?

In some jurisdictions and for some licence types, yes — and it can be a reasonable bridge. But regulators increasingly expect the role to have genuine authority, sufficient time and real proximity to the business, so treat outsourcing as a stopgap rather than a permanent answer.

The question

Who are you missing?