← All articlesAll firms7 July 2026 · 6 min read

The AMLR’s compliance manager and compliance officer roles: who to appoint in a small firm

The AMLR prescribes a board-level compliance manager and a compliance officer from 10 July 2027. What each role involves and who to appoint in a small firm.

If your firm is a designated person under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, someone in the practice is probably already wearing the AML hat. In most small Irish firms that person is the MLRO — often a principal or partner who handles suspicious transaction reports, signs off on client due diligence and keeps the policy document vaguely up to date between busier jobs.

From 10 July 2027, Regulation (EU) 2024/1624 (AMLR) — the EU's directly applicable single rulebook — changes how that responsibility has to be structured. Instead of one loosely defined role, the AMLR prescribes two distinct compliance functions: a compliance manager at board level and a compliance officer of sufficiently high standing. For a firm of three or four people, that raises an obvious question: who fills these roles, and can it still be the same handful of people who do everything else?

This post explains what the two roles are, how they differ from the current Irish arrangement, and how a small firm should approach the appointments.

The two roles the AMLR prescribes

The AMLR requires obliged entities — the regulation's term for what Irish law calls designated persons — to designate:

  • A compliance manager. This is a member of the management body, in its management function. In a small firm, think of it as a director or partner who carries board-level accountability for AML/CTF compliance. The compliance manager is where responsibility for implementing the firm's policies, controls and procedures sits at the top of the organisation.
  • A compliance officer. This is the operational role: a person of sufficiently high standing within the firm who runs day-to-day compliance — the working level of customer due diligence oversight, suspicious transaction reporting, and monitoring that the programme is actually followed.

There is a further point worth flagging early because it is easy to miss. From 10 July 2027, the compliance officer also becomes responsible for the implementation of targeted financial sanctions within the firm. Sanctions screening is no longer a separate, informal task someone does when they remember — it lands formally on the compliance officer's desk alongside AML duties.

How this differs from the MLRO you have today

Under the CJA 2010 regime, most small firms operate with a single MLRO-style role, and the governance layer above that role is often undocumented. The partner who is the MLRO reports, in effect, to themselves.

The AMLR's structure deliberately separates two things:

FunctionCompliance managerCompliance officer
LevelManagement body (board level)Senior operational level
FocusAccountability for the programmeRunning the programme day to day
Typical outputApproving policies and the risk assessment, receiving reportsCDD oversight, STR handling, sanctions implementation, training

For Irish firms, the practical continuity is that the compliance officer function will absorb much of what the MLRO does now — including the reporting side. Remember that in Ireland suspicious transaction reports are dual-reported: to FIU Ireland via the goAML portal and to the Revenue Commissioners via ROS. Whoever holds the reporting function needs to be registered on both systems, and needs a process fast enough to answer FIU requests within the AMLR's five-working-day deadline (shorter for some categories).

Who to appoint in a small firm

Here is a hypothetical worked example. Imagine a three-partner accountancy practice in Galway: two audit partners and one tax partner, plus six staff.

  • Compliance manager: one of the partners. The role must sit within the management body, so in a partnership or small company this will almost always be a partner or director. Pick the person who will genuinely engage with the risk assessment and policy approvals — not simply the newest partner because nobody else wanted it.
  • Compliance officer: this could be a second partner, or a suitably senior manager. The test is standing and capability: the person needs enough seniority to challenge fee earners on due diligence, enough time to actually do the job, and direct access to management.

A few practical principles when deciding:

  1. Do not default to the most junior person. "Sufficiently high standing" is a real requirement. An officer who cannot push back on a partner's client acceptance decision does not meet the spirit of the role.
  2. Think about capacity, not just title. The compliance officer role now spans CDD oversight, STR preparation and filing, sanctions implementation and training records. Estimate the hours honestly before appointing.
  3. Document the appointments. Record who holds each role, when they were appointed, and what the role covers. Your policy pack should name both functions explicitly — a point where CJA 2010-era policy documents will typically be silent.
  4. Plan for cover. In a very small firm, illness or departure of one person can leave the function empty. Note in your procedures who deputises and how.
  5. Watch for supervisor and AMLA guidance. The detailed expectations for these roles — including how they apply proportionately in the smallest firms — will be shaped by technical standards and guidelines from AMLA, the new EU Anti-Money Laundering Authority (see amla.europa.eu), and by your own supervisor: the PSRA for property services providers, the Law Society of Ireland for solicitors, the designated accountancy bodies (Chartered Accountants Ireland, ACCA, CPA Ireland) for accountants, the AMLCU in the Department of Justice for TCSPs and unaffiliated practitioners, and the Central Bank of Ireland for financial firms. Check what your supervisor publishes as 2027 approaches.

What the appointed people will actually be responsible for

Whoever takes the roles should understand the workload attached. Under the AMLR the firm's programme will need, among other things: a refreshed business-wide risk assessment; customer due diligence built around the new thresholds (occasional transactions at 10,000 euro, occasional cash transactions from 3,000 euro); beneficial ownership checks against the harmonised 25 per cent rule, alongside the existing Irish duty to obtain an RBO extract and report discrepancies (see rbo.gov.ie); records retained for five years and then deleted; and ongoing training with evidence that it happened. The compliance officer runs this machinery; the compliance manager answers for it.

What to do now

  • List who currently acts as your MLRO and what they actually do, in writing.
  • Decide provisionally who will be compliance manager and who will be compliance officer from 10 July 2027, and record the reasoning.
  • Confirm your goAML and Revenue ROS registrations are current and held by the right person.
  • Add the two roles to your draft AMLR policy pack, with named holders and deputies.
  • Diarise a check of your supervisor's guidance and AMLA publications for detail on how the roles apply to firms of your size.
  • Brief the appointees on the sanctions responsibility that arrives with the role.

How CompliDesk helps

CompliDesk Ireland's policy pack and Business-Wide Risk Assessment generator include designation fields for both the compliance manager and compliance officer roles, so the appointments are documented from day one. See the AMLR explainer for how the wider rulebook changes on 10 July 2027.

General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.

Get AMLR-ready before 10 July 2027

Join the waitlist for CompliDesk Ireland and lock in founding-member pricing.

Join the waitlist