The MLRO & AML governance
The MLRO (also called the nominated officer) is the firm's central point for money-laundering concerns: staff report suspicions to them, and they decide whether to escalate to the national FIU. Around that role sits an AML governance framework - a documented risk assessment, policies and controls, staff training, and clear board and senior-management accountability. In the UK these duties are set by the Money Laundering Regulations 2017, and the role carries personal responsibility.
The nominated officer/MLRO receives internal suspicious activity disclosures and must be able to report to the NCA without seeking anyone else's permission.
The Money Laundering Regulations 2017 require appointment of both a nominated officer (MLRO) and, where appropriate to size/nature, an officer responsible for compliance (MLCO) (reg 21); the supervisor must be notified within 14 days.
The regime requires a documented business-wide money-laundering/terrorist-financing risk assessment (reg 18) and ongoing staff training (reg 24), with independent audit of controls where proportionate.
AML is a board and senior-management responsibility - governance, tone from the top and resourcing sit above the MLRO, who cannot carry the firm's obligations alone.
For FCA-regulated firms the MLRO is a Senior Management Function (SMF17) under the Senior Managers and Certification Regime (SMCR), attaching personal accountability.
Gambling operators are supervised for AML by their gambling regulator (in the UK, the Gambling Commission), not by the FCA/SMCR, but face equivalent expectations for a named, empowered MLRO.
Under the Malta Gaming Authority framework, AML/CFT responsibility is a designated 'key function', and Malta operators report suspicious transactions to the FIAU.
UK gambling operators must appoint an MLRO/nominated officer as part of their licensed governance, and the person holding that AML responsibility is typically required to hold a personal management licence from the Gambling Commission. Malta (MGA) treats AML/CFT as a designated key function, with suspicious transaction reports going to the Financial Intelligence Analysis Unit (FIAU). In both cases the operator's board retains ultimate accountability for the AML programme.
Reference, not advice. This is a teaching summary of the AML framework — not legal advice, and not an operational compliance procedure. Confirm requirements against the primary regulator and your own counsel.