MLRO Responsibilities: A First-100-Days Checklist

The Criminal Justice Acts make the MLRO the firm’s single point of accountability for AML. When the Central Bank arrives, the MLRO is who they ask first. This is the list to work through before that happens.

5 March 2026 10 min read Irish legislation

1. Get your appointment letter on file

The board or senior management must appoint you in writing, with the scope and the authority spelled out. Inspectors ask for this early, and a verbal appointment is not an answer.

2. Read the business-wide risk assessment

It should be current and should describe your actual client book. If it is more than twelve months old, or reads like a template with the firm name dropped in, refreshing it is the first substantive job.

3. Read the AML policies and procedures

They have to line up with the Acts, with Central Bank guidance, and with the risk assessment. Look specifically for gaps in beneficial ownership, sanctions screening, enhanced due diligence triggers, STR escalation, tipping-off safeguards, training cadence and record retention.

4. Meet the team

Sit with each team lead and ask how CDD is applied in practice, what makes someone escalate, who has been trained, and how a PEP gets identified. The gap between the policy and the practice is where most AML failures live, and you will only find it by asking.

5. Review the STR log

Look at internal escalations and filed reports over twelve months against the size and risk of the client book. Zero escalations from a firm of any size is a red flag. So is a high volume with no recorded outcomes.

6. Check sanctions screening

Confirm screening happens at onboarding and on an ongoing basis, and that the lists cover EU, UN, and where relevant OFAC and HMT. Pull a random sample of clients and ask to see the evidence.

7. Audit the training file

Twelve months of records: who was trained, when, what they scored, and which version of the content they took. If the answer is a folder of slide decks with an attendance sheet, this is the quickest meaningful improvement available to you.

8. Test sample CDD files

Take five recent files across risk categories and read them as an inspector would. Is everything present? Is the risk rating defensible on its face? Does the monitoring log show anything actually happened?

9. Review what reaches the board

Board packs should carry AML metrics: training completion, STR volumes, risk assessment refresh dates, and open findings. If none of that is going up, design the report and get it signed off.

10. Test the breach-response process

Run a tabletop. A suspicious transaction lands at four o’clock on a Friday. Who does what? If the answer takes longer than the exercise, rebuild the process and retest inside thirty days.

11. Check record retention

Six years after the relationship ends, for CDD and transaction records. Confirm where they live, that the clock starts on the right date, and that disposal happens. Resolve any contradiction between the AML retention rule and the GDPR storage limitation policy now, in writing.

12. Plan your own training

The Central Bank expects an MLRO to be competent, current and able to evidence both. Keep your own training up to date, subscribe to the Central Bank bulletins, and put a quarterly typology review in the diary.

The first MLRO report

At the end of the hundred days, write it up for the board: what you found, what you have fixed, what is still open and by when. Present it and have it minuted. It is the single clearest piece of evidence that the role is being discharged.

Items 7 and 12, handled.

Harrington covers the firm-wide training record and the MLRO’s own currency, with a dashboard that exports the evidence for the board report.