Insights - BeyondFS

What 30 MLROs told us about the job right now

Written by Jonathan Kohler | Aug 10, 2026, 5:14:40 PM

I was fortunate to spend a morning recently with around 30 brilliant, lively and very candid MLROs at a roundtable sponsored by Michelman Robinson and run in conjunction with The Institute.

I was there with three BeyondFS colleagues, and the room had exactly the kind of energy you hope for at these events. Practical, honest and grounded in the real world.

MLROs are under pressure to influence senior leaders, stay independent, help the business move safely, manage regulatory scrutiny, and make their functions more useful without becoming the business’s safety net.

The clearest takeaway for me was that the MLRO role is becoming more commercial in how it communicates, while remaining just as serious in what it stands for.

Credibility is still the currency.

Some priorities never go away. Gaining and retaining senior management attention is one of them.

MLROs don’t get buy-in by simply communicating the rules. They get buy-in when they show they understand the business and can apply those rules in context.

That means knowing the clients, products, markets and commercial pressures. It means walking into senior conversations with options, a clear view of the consequences of non-compliance, and a practical understanding of the firm’s risk appetite.

It also means avoiding two traps. Being seen as the person who always says no, or being seen as the person who waves things through whenever the business is under pressure.

The board needs to understand real-world consequences

Another familiar priority is making Financial Crime risk feel real to senior leaders.

The threat of regulatory fines may get attention, but in some firms fines can still be seen as absorbable. What often gets more cut-through is explaining the wider cost across the business. Skilled Person reviews, VREQs, remediation spend, management distraction, restrictions on growth, customer impact, reputational damage and personal accountability under SMCR.

This isn’t about turning compliance into Project Fear. It’s about making sure senior leaders have the full picture before decisions are made.

One useful reminder was that existing governance artefacts are often underused. MLRO reports, audit findings, risk assessments and regulatory updates aren’t simply a record of what has happened. Used well, they can help build the case for action, evidence management attention and keep emerging issues visible before they become urgent.

The priority today is early influence

The most interesting part of the conversation was how frequently, and how passionately, MLROs talked about being involved earlier in business change.

Financial Crime Compliance teams are still brought in too late too often, after key decisions have already been taken on a product, process, strategy or client approach. By that point, momentum has built and changing course becomes much harder. Too often, the MLRO is left trying to retrofit controls into a project that’s already moving at pace.

That creates unnecessary conflict and reinforces the perception of Compliance as a blocker. Early involvement gives the second line a chance to shape better outcomes before positions harden.

That doesn’t mean nothing should ever be blocked. Independence still counts, but the function should be able to provide advice and guardrails early enough to be useful.

For material change, six months’ notice felt like a sensible benchmark. Whether that’s always possible is another matter. But it’s a useful test of whether MLROs, or their teams, are in the room early enough.

AI is here, but the need for judgement has gone nowhere

AI came up, as it does in almost every Financial Crime conversation now.

What I found encouraging was the balance in the discussion. MLROs could see the value in AI tools that help the first line understand policies, interpret guidance and get faster answers to common questions.

But there wasn’t any appetite for AI replacing professional judgement or second-line advice.

The immediate priority is to put proper governance around its use, understand where it’s being adopted by the first line, and make sure people don’t treat a system-generated answer as a decision they no longer have to own.

AI may be the new kid on the block, but it needs to be kept in check by its older siblings, accountability, evidence and judgement.

The first line relationship is more important than ever

A lot of the discussion came back to the criticality of the relationship with the first line.

MLROs want business colleagues to raise concerns early, test options and ask questions before issues become difficult. That only happens when MLROs are approachable and trusted.

At the same time, roles aren’t always clear. Several people talked about the risk of blurred accountabilities, especially in smaller firms or where a 1.5 line model exists. That blurring can be helpful at times, but it can also make escalation harder and weaken ownership.

The phrase “firm but fair” came through strongly. It’s as good a description as any of the modern MLRO posture.

So what is the state of the MLRO nation?

Based on that morning, I’d say the role of the MLRO is under pressure, but MLROs are clear-sighted and certainly not drifting.

They know the job is changing. They know they need to speak the language of the business, show measurable improvement and help senior leaders make better decisions.

They also know the core of the role remains the same. Independence, judgement, escalation and accountability.

The tension is obvious, and its difficult work. But the mood in the room felt positive and practical rather than defensive.

Three things to take back to the office

For any MLRO reflecting on this, I’d start with three actions.

First, build or refresh your senior stakeholder map. Be honest about who you need to influence, what they care about, how they think about risk, and whether your current messages are landing. You may need to pull slightly different levers depending on whether you’re speaking to a CEO, CFO, CRO, General Counsel or business head.

Second, take proactive steps to redefine your relationship with your first line colleagues. Take the lead on establishing formalised structures to foster two-way open communication and continually reinforce the message that everyone’s aim is business success.

Third, pick one recent area where Financial Crime Compliance was brought on board too late. It might be product change, branch governance, client strategy or process design. Use that example to agree a simple rule with the business for earlier Compliance involvement in similar situations in future. Keep it practical. Don’t try to fix everything at once.

Being a successful MLRO is ultimately about achieving the right outcomes to balance protecting the business with enabling growth. And that seems to come from three things. Getting close to the business, showing the consequences of failure clearly, and getting involved before poor decisions have already been made.