1. Get your appointment letter on file
The board or senior management must appoint you in writing, with the scope and the authority spelled out. Inspectors ask for this early, and a verbal appointment is not an answer.
2. Read the business-wide risk assessment
It should be current and should describe your actual client book. If it is more than twelve months old, or reads like a template with the firm name dropped in, refreshing it is the first substantive job.
3. Read the AML policies and procedures
They have to line up with the Acts, with Central Bank guidance, and with the risk assessment. Look specifically for gaps in beneficial ownership, sanctions screening, enhanced due diligence triggers, STR escalation, tipping-off safeguards, training cadence and record retention.
4. Meet the team
Sit with each team lead and ask how CDD is applied in practice, what makes someone escalate, who has been trained, and how a PEP gets identified. The gap between the policy and the practice is where most AML failures live, and you will only find it by asking.
5. Review the STR log
Look at internal escalations and filed reports over twelve months against the size and risk of the client book. Zero escalations from a firm of any size is a red flag. So is a high volume with no recorded outcomes.
6. Check sanctions screening
Confirm screening happens at onboarding and on an ongoing basis, and that the lists cover EU, UN, and where relevant OFAC and HMT. Pull a random sample of clients and ask to see the evidence.
7. Audit the training file
Twelve months of records: who was trained, when, what they scored, and which version of the content they took. If the answer is a folder of slide decks with an attendance sheet, this is the quickest meaningful improvement available to you.
8. Test sample CDD files
Take five recent files across risk categories and read them as an inspector would. Is everything present? Is the risk rating defensible on its face? Does the monitoring log show anything actually happened?
9. Review what reaches the board
Board packs should carry AML metrics: training completion, STR volumes, risk assessment refresh dates, and open findings. If none of that is going up, design the report and get it signed off.
10. Test the breach-response process
Run a tabletop. A suspicious transaction lands at four o’clock on a Friday. Who does what? If the answer takes longer than the exercise, rebuild the process and retest inside thirty days.
11. Check record retention
Six years after the relationship ends, for CDD and transaction records. Confirm where they live, that the clock starts on the right date, and that disposal happens. Resolve any contradiction between the AML retention rule and the GDPR storage limitation policy now, in writing.
12. Plan your own training
The Central Bank expects an MLRO to be competent, current and able to evidence both. Keep your own training up to date, subscribe to the Central Bank bulletins, and put a quarterly typology review in the diary.
The first MLRO report
At the end of the hundred days, write it up for the board: what you found, what you have fixed, what is still open and by when. Present it and have it minuted. It is the single clearest piece of evidence that the role is being discharged.
Items 7 and 12, handled.
Harrington covers the firm-wide training record and the MLRO’s own currency, with a dashboard that exports the evidence for the board report.