Challenges and opportunities for MLROs and subject persons
The expectations placed on Subject Persons are evolving rapidly as regulators place increasing emphasis on the effectiveness, transparency and accountability of anti-money laundering and countering the financing of terrorism (AML/CFT) frameworks.
The new Anti-Money Laundering Regulation (AMLR), which will apply from 10 July 2027, together with the establishment of the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), are key drivers of this change. However, the more significant challenge for many organisations may be ensuring that governance arrangements, operating models and control environments can meet these heightened expectations.
For Money Laundering Reporting Officers (MLROs), compliance teams and senior management, these developments represent more than regulatory change. They signal a shift towards greater accountability, enhanced governance, increased transparency and higher expectations regarding the effectiveness of AML/CFT controls.
While these changes present new challenges, they also provide Subject Persons with an opportunity to strengthen their anti-financial crime frameworks, improve operational resilience and build greater confidence among regulators, customers, investors and other stakeholders.
Rising expectations for subject persons across europe
The introduction of the AMLR and the establishment of AMLA signal a significant shift in the way AML/CFT compliance will be approached across the European Union.
Rather than navigating an environment shaped by varying national interpretations and supervisory practices, Subject Persons are moving towards a framework characterised by greater consistency, increased transparency and closer regulatory alignment.
Perhaps the most significant shift is that AML/CFT compliance is increasingly being assessed through an effectiveness lens rather than a purely technical one. Supervisors are seeking evidence that controls can identify, manage and mitigate financial crime risks in practice, rather than simply existing on paper.
This represents a notable change for organisations that have historically approached regulatory compliance as a standalone objective rather than as part of a broader financial crime risk management strategy.
This transition will require Subject Persons to review policies, procedures, risk assessment methodologies, customer due diligence frameworks and governance structures to ensure that they remain aligned with evolving expectations.
Data, reporting and supervisory expectations
Regulators are increasingly using data and regulatory reporting to support more targeted and risk-based supervision.
Through common reporting exercises and enhanced data collection initiatives, competent authorities are gaining deeper insight into Subject Persons’ risk profiles, customer bases, governance arrangements and control environments.
As supervisory authorities gain access to increasingly granular information, regulatory reporting is becoming more than a compliance exercise. The quality of information submitted may increasingly influence supervisory perceptions of an organisation’s governance, risk management maturity and overall control environment.
In this context, data quality is emerging as a strategic consideration rather than simply an operational challenge.
As reporting obligations expand and supervisory expectations continue to evolve, Subject Persons will need to strengthen their data governance frameworks, implement robust quality assurance processes and regularly assess the effectiveness of their AML/CFT controls.
Organisations that invest in reliable data, meaningful management information and demonstrable control effectiveness will be better positioned to meet regulatory expectations and respond confidently to supervisory engagement.
The evolving role of the MLRO
The role of the MLRO continues to evolve, with MLROs increasingly expected to act as strategic advisers to senior management and boards, providing insight into emerging financial crime risks and helping shape organisational responses.
MLROs are operating at the intersection of regulatory compliance, risk management, governance and strategic decision-making. This raises an important question for many organisations: whether the traditional structure and resourcing of the MLRO function remain sufficient for the demands of the emerging AML/CFT landscape.
In response to these increasing demands, Subject Persons should ensure that MLROs are supported by adequate resources, appropriate technology, access to specialist expertise and strong engagement from senior management and governing bodies.
Such support is essential to enable MLROs to fulfil their responsibilities effectively and provide meaningful oversight of financial crime risks.
Turning challenges into opportunities
While many Subject Persons are understandably focused on meeting upcoming regulatory requirements, organisations should also view these developments as an opportunity to strengthen the overall maturity of their anti-financial crime frameworks.
Those that act early may not only reduce regulatory risk but also improve operational efficiency, support better decision-making and enhance stakeholder confidence.
Key actions that Subject Persons should consider include:
- Conducting gap assessments against forthcoming AMLR requirements and emerging regulatory expectations
- Reviewing governance arrangements to ensure clear accountability for AML/CFT compliance
- Enhancing customer due diligence, transaction monitoring and sanctions screening frameworks
- Investing in data governance and regulatory reporting capabilities
- Performing independent reviews and effectiveness testing of AML/CFT controls
- Providing ongoing training and awareness programmes for staff, management and boards
- Establishing robust regulatory change management processes to monitor and respond to new developments
Looking ahead
The combined impact of AMLA, the AMLR, enhanced reporting obligations and increasingly data-driven supervision marks a significant evolution in the European AML/CFT landscape.
For Subject Persons, success will depend not only on achieving compliance but also on demonstrating that AML/CFT frameworks are effective, sustainable and embedded within broader governance and risk management arrangements.
Those that take a proactive approach to strengthening governance, improving data quality and enhancing control effectiveness will be better positioned to respond to regulatory expectations, support organisational resilience and maintain stakeholder confidence.
RSM Malta supports Subject Persons in assessing and strengthening their AML/CFT frameworks, from governance and risk assessments to control effectiveness, regulatory readiness and independent reviews.
To discuss how your organisation can prepare for the evolving AML/CFT landscape and strengthen its financial crime risk framework, contact RSM Malta’s Governance, Risk and Compliance team.