Compliance Manager & Compliance Officer under the AMLR

The AMLR introduces significant changes to institutions' governance, with a new emphasis on the role of senior management. This article sets out the new requirements and their impact on obliged entities.

Compliance Manager & Compliance Officer under the AMLR

The (numerous) changes made by the AMLR include new governance requirements for obliged entities, set out chiefly in Chapter II AMLR (Art. 9-18 AMLR).

The basics

Art. 11 AMLR governs the structure and tasks of the compliance function. The compliance function to be established under Art. 11 AMLR consists of

  • the Compliance Manager (Art. 11(1) UAbs. 1 AMLR) and
  • the AML/CFT compliance officer ("Compliance Officer")

who together make up the compliance function.

💡
The German translation of the AMLR is, at the very least, confusing for German practice. The term "Compliance Manager" has so far mostly been used for compliance function staff below management level. The "Compliance Officer" of the English-language version is rendered in the German translation of the AMLR as "Geldwäschebeauftragter" (AML/CFT compliance officer) - except in Art. 11(7) AMLR, which refers to the "Compliance-Beauftragte", but presumably means the AML/CFT compliance officer.

This structure is nothing fundamentally new. The 5th AMLD already provided in Art. 46(4) that a responsible member of management had to be appointed for combating money laundering and terrorist financing, and Art. 8(4)(a) provided for the appointment of an AML/CFT compliance officer. What is new is the contour of the respective responsibilities and their effect on the liability of the Compliance Manager and the compliance officer (see below).

The Compliance Manager under the AMLR

Term and functional allocation

The Compliance Manager is a member of the management body in its management function, "responsible for ensuring compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative acts issued by supervisors" (Art. 11(1) UAbs. 1 AMLR). The term is newly introduced by the AMLR.

The Compliance Manager must accordingly be a member of the management body (Art. 2(1) No. 5 AMLR) - and thus of senior management ("management body in its management function", Art. 2(1) No. 6 AMLR). The management level must be distinguished from the senior management level defined in Art. 2(1) No. 8. Allocating the Compliance Manager function at that lower level is not sufficient.

Responsibilities of the Compliance Manager

The Compliance Manager's duties include in particular the following:

Binding intensity
EnsureArt. 11(1) UAbs. 2 AMLR
Policies, procedures and controls consistent with the risk profile — and actually implemented
Adequate human and material resources
Recipient of information on significant or material deficiencies
ReportArt. 11(6) AMLR
Regular reporting to the management body
Annually — or more often: report on the implementation of the AML/CFT compliance officer's rulebook
Ongoing briefing on audit findings
ApproveArt. 9(2) UAbs. 3 sentence 3 AMLR
Internal procedures and controls: approval at least at the level of the Compliance Manager
This approval cannot be outsourced (Art. 18(3) UAbs. 2 lit. b)
ActArt. 11(6) sentence 4 AMLR
"Takes the necessary measures to promptly remedy any deficiencies identified."
Not a duty to recommend — a duty to achieve results

Duty to ensure, Art. 11(1) UAbs. 2 AMLR

  • The Compliance Manager must ensure that the obliged entity's internal policies, procedures and controls are consistent with the entity's risk profile and implemented (Art. 11(1) UAbs. 2 sentence 1 AMLR). The Compliance Manager therefore has to check, on the one hand, whether the rulebook developed matches the risk profile as it emerges from the business-wide risk assessment (adequacy of design). The second part of the exercise consists in checking the implementation of the rulebook, i.e. its effectiveness.
  • The Compliance Manager must likewise ensure that adequate human and material resources are provided (Art. 11(1) UAbs. 2 sentence 2 AMLR). Responsibility that in principle rests with the obliged entity (Art. 11(3) AMLR) is thereby allocated to the Compliance Manager.
💡
The obligation on the Compliance Manager to ensure adequate resourcing is one of the central innovations under the AMLR. Previously, it was the AML/CFT compliance officer's task to flag insufficient resources (cf. EBA/GL/2022/05 para. 48(d)). Under the AMLR, this "pull" duty of the AML/CFT compliance officer becomes a "push" duty of the Compliance Manager.
  • Finally, the Compliance Manager is obliged to receive information about deficiencies. If the Compliance Manager obtains information about such deficiencies, they must take the necessary measures to remedy the deficiencies identified in a timely manner (Art. 11(6) sentence 4 AMLR).

Reporting duty, Art. 11(6) sentences 1-3 AMLR

The reporting duties set out in Art. 11(6) sentences 1-3 AMLR consist of three elements:

  • Sentence 1 requires the Compliance Manager to report "regularly" on the implementation of the internal policies, procedures and controls in place. The AMLR does not further define what "regularly" means. The Compliance Manager therefore has to choose - and be able to justify - an appropriate frequency.
  • As a rule annually, and where appropriate more frequently, the Compliance Manager reports on the implementation of the AML/CFT compliance officer's rulebook (Art. 11(6) sentence 2, 1st half-sentence AMLR). A shorter interval is likely to be called for in particular where material objections have previously been identified.
  • At the same cadence, the Compliance Manager reports (formally) on the results of (internal and external) audits, for example by internal audit, the statutory auditor or the supervisor. Here too, considerably more frequent reporting is required where significant findings arise.
💡
The recipient of the reports is the "management body", which can cover both the management body in its management function and in its supervisory function. This is likely to mean both bodies - senior management and the supervisory board - which is why the reports should be made available to both.

Duty to act, Art. 11(6) sentence 4 AMLR

The obligation under Art. 11(6) sentence 4 AMLR is likely one of the most severe for the responsible member of management, since they ultimately have to answer for an outcome - the taking of adequate measures. The EBA guidelines previously in force still provided here for a recommendation by the responsible member of the management body. The (indeterminate legal term) of "promptly" remedying deficiencies also opens the door wide to disputes with auditors and supervisors. Finally, the provision creates a dilemma for the Compliance Manager: they must ensure the relevant outcome (the remedying of the shortcomings) but do not have sole decision-making authority over the measures needed to remedy them. To relieve the Compliance Manager, a clarification in the rules of procedure of senior management is advisable here.

Approval of policies, procedures and controls, Art. 9(2) UAbs. 3

The procedure for approving the written rulebook, as it is to be developed by the AML/CFT compliance officer, is likewise staggered:

  • Internal policies must be approved by the management body in its management function;
  • Internal procedures and controls are approved at least at the level of the Compliance Manager. The Compliance Manager can therefore decide alone on the sign-off of such procedures and controls - but can also require sign-off by senior management as a whole.

Relationship to senior management as a whole

Allocating responsibilities to the Compliance Manager does not relieve senior management as a whole of its overall responsibility. Recital 38, sentence 2 expressly clarifies that appointing a responsible member as Compliance Manager does not change the fact that overall responsibility "ultimately rests with the entity's management body" . In collegially organised bodies, the Compliance Manager's role is to "support and advise the body and to prepare its decisions".

Allocating a specific portfolio in this way changes nothing about the continuing supervisory duty of the other members of senior management - meaning that regular reports at senior management meetings on the risk situation and the adequacy of the controls implemented (including their effectiveness) should be a mandatory agenda item.

Correspondingly, Art. 11(5) AMLR provides that the AML/CFT compliance officer reports to the (entire) management and supervisory function, and specifically not exclusively to the Compliance Manager.

The approval cascade shows the Compliance Manager as an intermediate layer, not a substitute for the body:

 
Subject matter Who approves
Internal policies Management body in its management function (Art. 9(2) UAbs. 3 sentence 2)
Internal procedures and controls at least the Compliance Manager (Art. 9(2) UAbs. 3 sentence 3)
Business-wide risk assessment Management body in its management function — not the Compliance Manager (Art. 10(2) UAbs. 2)

Compliance Officer

Duties of the Compliance Officer

Unlike the Compliance Manager, the AMLR does not define the term Compliance Officer, i.e. AML/CFT compliance officer. Art. 11(2) UAbs. 1 AMLR provides the central definition:

Obliged entities must have an AML/CFT compliance officer, to be appointed by the management body in its management function, who has a sufficiently senior position in the hierarchy and is responsible for the policies, procedures and controls in the day-to-day implementation of the requirements for combating money laundering and terrorist financing applicable to the obliged entity, including with regard to the implementation of targeted financial sanctions, and who serves as the point of contact for the competent authorities. The AML/CFT compliance officer is also responsible for reporting suspicious transactions to the central Financial Intelligence Unit under Article 69(6).

The AML/CFT compliance officer is thus responsible for:

  • ongoing ("day-to-day") implementation of the requirements to combat money laundering and terrorist financing,
  • compliance with targeted restrictive measures,
  • acting as point of contact for authorities, and
  • filing suspicious transaction reports.

From the exception to the rule

For the non-financial sector, the key change is the abolition of the exceptions and relief currently available. Whereas under Section 7 GwG an AML/CFT compliance officer only had to be appointed in the cases specified in Section 7(1) sentence 1 GwG, and the competent supervisory authorities could otherwise only order the appointment of an AML/CFT compliance officer in all other cases (Section 7(3) GwG), Art. 11(2) AMLR provides for the appointment of an AML/CFT compliance officer for all obliged entities .

Protecting independence

The independence of the AML/CFT compliance officer is significantly strengthened under the AMLR (see Art. 11(2) UAbs. 4 AMLR):

  • On the one hand, dismissal requires a prior notification of the entire senior management;
  • before dismissal, the (planned) dismissal must be notified to the supervisor, including information on whether the dismissal is connected with the performance of the officer's duties;
  • the AML/CFT compliance officer is given an independent right to information vis-à-vis the supervisor.

The AML/CFT compliance officer's decision-making authority is also significantly strengthened (Art. 11(4) AMLR):

  • Art. 11(4) AMLR protects the AML/CFT compliance officer against retaliation, discrimination and any other unfair treatment;
  • a particular protection lies in the fact that decisions of the AML/CFT compliance officer must "not be impaired or improperly influenced by the obliged entity's commercial interests" .

The final requirement carries real force: obliged entities must ensure that commercial interests do not jeopardise the performance of these duties. Senior management therefore bears the burden of demonstrating that decisions taken against the advice of the AML/CFT compliance officer were not taken for commercial reasons.

Under Art. 11(5) AMLR, the AML/CFT compliance officer is entitled to report directly to the management body in its supervisory function, including the right to raise concerns and warnings. The exceptional case previously provided for in Section 7(5) sentence 5 GwG thus becomes the rule.

Further changes

Conclusion

The AMLR's requirements place considerably greater emphasis than before on the responsibility of the Compliance Manager as the responsible member of the management body. This relieves the AML/CFT compliance officer to a certain extent. Given the case law on the AML/CFT compliance officer's personal liability (see, by way of example, the judgment of the Frankfurt Higher Regional Court of 10 April 2018 - 2 Ss-Owi 1059/17, and by contrast the CJEU judgment of 29 January 2026 - Case C-291/24, see also the article by Preni Giragosian) this is a welcome development.

For companies, this means adjustments to their governance, in particular at the level of senior management.