> ## Content Index
> Fetch the complete content index at: https://www.waldvorlauternormen.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Impact of the AMLR on the Insurance Sector: Outsourcing the AML/CFT Compliance Officer Function?
- URL: https://www.waldvorlauternormen.com/en/amlr-insurance-sector-outsourcing-compliance-officer-function/
- Published: 2026-09-11T14:26:58.000Z
- Updated: 2026-09-11T14:26:58.000Z
- Description: Art. 18(3) AMLR prohibits outsourcing certain core tasks of the AML/CFT compliance officer. Does this spell the end of the outsourced compliance officer function? A comparison with the EBA Guidelines shows the prohibitions are hardly new – and the better arguments favour outsourceability.
- Author: Dr. Paul Schultess
- Tags: Geldwäsche & Sanktionen, AMLR für Versicherungsunternehmen, AMLR, Auslagerung, #en

*This article is part of our series on the AMLR for insurance undertakings. Further articles in the series (in German) can be found* [*here*](https://www.waldvorlauternormen.com/tag/amlr-versicherer-2/)*.*

Can the function of the AML/CFT compliance officer still be outsourced in its entirety under the AMLR? The weight of the arguments says yes.

## I. Background and practical relevance

Many insurers subject to German anti-money laundering law have so far made use of the option to outsource the function of the AML/CFT compliance officer (*Geldwäschebeauftragter*, “GwB”) and/or their deputy (the “*compliance officer function*”) – in the terminology of insurance supervisory law: to “*ausgliedern*” – to locate it within another undertaking and to staff it with a person to be specifically designated there.

Intra-group outsourcing is particularly relevant: the compliance officer function, which as a rule every obliged insurer must appoint itself, is concentrated within a group undertaking (e.g. the group’s own service company or the parent holding company) by way of outsourcing.

This approach is common and permissible, is accepted by BaFin as the supervisory authority (BaFin AuA, General Part, section 3.2.6: “*Insofar as the function of the AML/CFT compliance officer \[…\] has been outsourced*”; own translation) and reflects the general principle of insurance supervisory law that almost all corporate functions – including key functions and self-defined key tasks – may be outsourced up to the limit of original management tasks and responsibility ([Art. 274(1) Solvency II Delegated Regulation](https://publications.europa.eu/resource/cellar/d4117d51-ac28-11ef-acb1-01aa75ed71a1.0002.03/DOC%5F1?ref=waldvorlauternormen.com); [BaFin MaGo, paras. 205, 206](https://www.bafin.de/SharedDocs/Veroeffentlichungen/DE/Rundschreiben/2025/rs%5Frundschreiben%5F09%5F25%5Fva.html?ref=waldvorlauternormen.com)).

## II. A de facto outsourcing ban through the back door?

Does the AMLR threaten a de facto ban on outsourcing the compliance officer function through the back door? The second sentence of Art. 18(3) AMLR contains specific outsourcing prohibitions that also affect core competences of the compliance officer function.

****Art. 18(3) AMLR**  
“**The following tasks shall not be outsourced under any circumstances:*  
**(a) the proposal and approval of the obliged entity’s business-wide risk assessment pursuant to Article 10(2);*  
**(b) the approval of the obliged entity’s internal policies, procedures and controls pursuant to Article 9;*  
**(c) decision on the risk profile to be attributed to the customer;*  
**(d) the decision to enter into a business relationship or carry out an occasional transaction with a client;*  
**(e) the reporting to FIU of suspicious activities pursuant to Article 69 or threshold-based reports pursuant to Article 74 and 80, except where such activities are outsourced to another obliged entity belonging to the same group and established in the same Member State;*  
**(f) the approval of the criteria for the detection of suspicious or unusual transactions and activities.*”

In view of these prohibitions, one might think that they also rule out outsourcing the compliance officer function as a whole. After all, the “proposal” of the business-wide risk assessment (point (a)), the “reporting of suspicious activities” (point (e)) and the “approval of the criteria” for transaction monitoring (point (f)) are among the core competences of the AML/CFT compliance officer.

Art. 18(3) sentence 2 AMLR and the outsourcing prohibitions it lays down allow for three readings:

### 1\. First reading: prohibition of isolated outsourcing

The tasks listed there may not be outsourced on their own, in isolation. For example, the filing of suspicious activity reports could not be carried out by an external service provider outside the group (point (e)). Outsourcing the compliance officer function as a whole, which then also performs the associated tasks – such as filing suspicious activity reports – would, however, remain possible.

### 2\. Second reading: the compliance officer function can no longer be outsourced at all

The outsourcing prohibitions cover tasks that fall within the original remit of the AML/CFT compliance officer and are inseparably linked to that function. If these individual tasks may not be outsourced, then the compliance officer function as such can no longer be outsourced either.

### 3\. Third reading: partial outsourcing of the compliance officer function

The compliance officer function may still be outsourced, but as an external function it may no longer perform the tasks covered by the outsourcing prohibitions. The external compliance officer could thus, for example, handle PEP hits and transaction monitoring alerts, but would in principle not be permitted to file suspicious activity reports (point (e)) or to set the indicators used by the monitoring systems (point (f)).

Some have already concluded from the outsourcing prohibitions that a [complete outsourcing of the AML/CFT compliance officer function will in future be de facto excluded](https://klardenker.kpmg.de/financialservices-hub/eu-vorgaben-zu-aml-so-veraendert-sich-die-rolle-des-geldwaeschebeauftragten/?ref=waldvorlauternormen.com) (= second reading; in German). Legal scholarship takes the opposite view and shows why the EU legislator can hardly have intended to deny the compliance officer function its capacity to be outsourced (e.g. *Schultess*, [VersR 2025, 521, 529](https://juris.de/r3/document/jzs-VersR-2025-9-001-521?ref=waldvorlauternormen.com); *Wegner/Haffke*, [BKR 2026, 393](https://beck-online.beck.de/Dokument?vpath=bibdata%2Fzeits%2Fbkr%2F2026%2Fcont%2Fbkr.2026.393.1.htm&anchor=Y-300-Z-BKR-B-2026-S-393&jumpType=Jump&jumpWords=BKR%2B2026%252c%2B393&readable=Suche%2Bnach%2BFundstelle%253a%2BBKR%2B2026%2B%2B393%2Bnur%2Bin%2Bmeinen%2BModulen&ref=waldvorlauternormen.com); both in German and behind a paywall).

A definitive answer to this question can only come from AMLA. By 10 July 2027, it is required to issue guidelines on the key requirements and supervisory expectations regarding outsourcing arrangements (Art. 18(8) AMLR). These guidelines will hopefully also clarify the outsourcing of the compliance officer function.

Until then, it is up to each obliged entity to prepare for the outsourcing prohibitions under the AMLR. The better arguments support the view that the compliance officer function can continue to be outsourced in the future.

## III. Arguments in favour of outsourcing the compliance officer function remaining possible

The concerns raised against outsourcing as a whole (second reading) or in favour of only partial outsourcing of the compliance officer function (third reading) all rest on the (mistaken) assumption that the outsourcing prohibitions under Art. 18(3) sentence 2 AMLR are new and did not apply previously. In fact, compared with the status quo, they bring little that is new. Time for a calm assessment:

### 1\. No real novelty compared with the status quo

The outsourcing prohibitions of Art. 18(3) sentence 2 AMLR can already be found today in very similar form in the EBA Guidelines on policies and procedures in relation to compliance management and the role and responsibilities of the AML/CFT compliance officer ([EBA/GL/2022/05 of 14 June 2022](https://www.eba.europa.eu/sites/default/files/document%5Flibrary/Publications/Guidelines/2022/EBA-GL-2022-05%20GLs%20on%20AML%20compliance%20officers/1035126/Guidelines%20on%20AMLCFT%20compliance%20officers.pdf?ref=waldvorlauternormen.com), the “*EBA Guidelines*”). Under the heading “*Outsourcing of operational functions of the AML/CFT compliance officer*”, paragraph 68(e) states:

****EBA Guidelines, paragraph 68(e)**  
“**The outsourcing of functions cannot result in the delegation of the management body’s responsibilities. Strategic decisions in relation to AML/CFT should not be outsourced. These decisions include, in particular:*  
**i. the approval of the business-wide ML/TF risk assessment;*  
**ii. the decision on the internal organisation of the AML/CFT framework of the credit and financial institution;*  
**iii. the adoption of internal AML/CFT policies and procedures;*  
**iv. the approval of the methodology used to determine the ML/TF risk presented by a given business relationship and the assignment of the risk profile;*  
**v. the approval of the criteria to be used by the credit or financial institution to detect suspicious or unusual transactions for its ongoing monitoring and/or reporting purposes.*  
**Credit and financial institutions remain ultimately responsible for the decision to report suspicious transactions to the FIU, including in situations where the identification and reporting of suspicious transactions is outsourced.*”

A comparison with the (supposedly new) outsourcing prohibitions under Art. 18(3) sentence 2 AMLR shows that they are largely congruent with the requirements of the EBA Guidelines, which already apply today:

| No.                                                                                                                                                                                                                                                                                                                                                                                                                                                   | AMLRThe following tasks shall not be outsourced under any circumstances: …                                                                                                                                                                | EBA GuidelinesStrategic decisions in relation to AML/CFT should not be outsourced. These decisions include, in particular: …                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | Assessment |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| 1.                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Business-wide risk assessment                                                                                                                                                                                                             |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |            |
| *… the proposal and approval of the obliged entity’s business-wide risk assessment pursuant to Article 10(2)*                                                                                                                                                                                                                                                                                                                                         | *… the approval of the business-wide ML/TF risk assessment*                                                                                                                                                                               | Partial novelty compared with the EBA Guidelines, owing to the additional prohibition on outsourcing the “proposal” of the risk assessmentThis may be a response to the widespread practice of having the risk assessment prepared entirely by external service providersIn the non-financial sector (relevant, among others, for insurance intermediaries), outsourcing the preparation of the risk assessment in isolation – i.e. without also outsourcing the compliance officer function – is already expressly prohibited today: “*The preparation of a risk assessment, as a classic task of the AML/CFT compliance officer, may therefore only be carried out externally where an external AML/CFT compliance officer is appointed by way of outsourcing*” ([Joint AuA of the German federal states, as of 18 June 2025, section 3.3.9](https://rp.baden-wuerttemberg.de/fileadmin/RP-Internet/Themenportal/Sicherheit/%5FDocumentLibraries/Documents/Geldwaesche/Allgemeingueltige%5FInformationen%5Fund%5FFormulare/Geldwaesche%5FAuA%5FLaender.pdf?ref=waldvorlauternormen.com); own translation)The position is therefore already the same today: outsourcing the preparation of the risk assessment in isolation is not permitted (first reading), whereas preparation by a compliance officer function that has been outsourced as a whole is possible |            |
| No novelty regarding the approval of the business-wide risk assessmentApproving the risk assessment is the original responsibility of the competent member of the management board (Section 4(3) sentence 2 GwG) and could not be outsourced in the past eitherNo substantive difference between “Billigung” (German version of the AMLR) and “Genehmigung” (German version of the EBA Guidelines); the English versions use “approval” in both cases |                                                                                                                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |            |
| 2.                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Internal policies, procedures and controls                                                                                                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |            |
| *… the approval of the obliged entity’s internal policies, procedures and controls pursuant to Article 9*                                                                                                                                                                                                                                                                                                                                             | *… the decision on the internal organisation of the AML/CFT framework of the credit and financial institution*                                                                                                                            | The prohibition on outsourcing the “approval of the internal policies, procedures and controls” brings nothing newIn substance and structure, the “internal policies, procedures and controls” (Art. 9 AMLR) largely correspond to the “internal safeguards” (Interne Sicherungsmaßnahmen, Section 6 GwG)Approving the internal safeguards has always been the original responsibility of the competent member of the management board (Section 4(3) sentence 2 GwG)Accordingly, this could not be outsourced in the past either (cf. [BaFin Circular 09/2025 (VA) – MaGo of 14 July 2025, section 13.2 para. 206](https://www.bafin.de/SharedDocs/Veroeffentlichungen/DE/Rundschreiben/2025/rs%5Frundschreiben%5F09%5F25%5Fva.html?ref=waldvorlauternormen.com): “*Original management tasks, including responsibility for establishing and further developing the risk management system and the internal control system, cannot be outsourced*”; own translation)                                                                                                                                                                                                                                                                                                                                                                                                |            |
| *… the adoption of internal AML/CFT policies and procedures*                                                                                                                                                                                                                                                                                                                                                                                          |                                                                                                                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |            |
| 3.                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Customer risk profile                                                                                                                                                                                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |            |
| *… decision on the risk profile to be attributed to the customer*                                                                                                                                                                                                                                                                                                                                                                                     | *… the approval of the methodology used to determine the ML/TF risk presented by a given business relationship and the assignment of the risk profile*                                                                                    | No novelty regarding the decision on the risk profile to be attributed to the customerAt the level of the AMLR, the requirements have in fact been narrowed compared with the previous EBA positionThe decision on the individual customer risk profile is taken as part of customer onboarding and thus typically within the first line of defence, e.g. in customer service or customer administration, but not by the compliance officer functionThe compliance officer function is involved in defining the customer risk classification methodology – but this, in turn, is not covered by the AMLR outsourcing prohibition                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |            |
| 4.                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Customer acceptance decision                                                                                                                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |            |
| *… the decision to enter into a business relationship or carry out an occasional transaction with a client*                                                                                                                                                                                                                                                                                                                                           | /                                                                                                                                                                                                                                         | The EBA Guidelines have so far contained no such outsourcing prohibitionNor does this prohibition concern any original tasks of the AML/CFT compliance officerThe “decision to enter into a business relationship or carry out an occasional transaction with a client” is fundamentally not a question of money laundering prevention and not part of the compliance officer’s remit, but the result of a private-law agreement between the customer and the obliged entityThe decision is taken in the course of onboarding, typically by the first line of defenceIf this is also meant to cover obtaining senior management approval for establishing or continuing the business relationship as part of enhanced due diligence (Art. 34(4)(e) AMLR), this again need not be done by the compliance officer function; senior management also includes the responsible member of the management board and other officers and employees with sufficient knowledge and hierarchical standing (Art. 2(1), point (40) AMLR)                                                                                                                                                                                                                                                                                                                                          |            |
| 5.                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Filing suspicious activity reports                                                                                                                                                                                                        |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |            |
| *… the reporting to FIU of suspicious activities pursuant to Article 69 or threshold-based reports pursuant to Article 74 and 80, except where such activities are outsourced to another obliged entity belonging to the same group and established in the same Member State*                                                                                                                                                                         | *Credit and financial institutions remain ultimately responsible for the decision to report suspicious transactions to the FIU, including in situations where the identification and reporting of suspicious transactions is outsourced.* | The prohibition on outsourcing the filing of suspicious activity reports is new compared with the EBA Guidelines, which in principle permitted itOn this point, however, BaFin’s administrative practice has always been stricter than the EBA Guidelines and has long taken a critical view of external filing of suspicious activity reportsFor German undertakings, the express AMLR rule that the “reporting of suspicious activities” may only be outsourced to group entities in the same Member State is therefore, in effect, less a prohibition than a partial extension of the previous status quo                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |            |
| 6.                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Monitoring criteria                                                                                                                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |            |
| *… the approval of the criteria for the detection of suspicious or unusual transactions and activities*                                                                                                                                                                                                                                                                                                                                               | *… the approval of the criteria to be used by the credit or financial institution to detect suspicious or unusual transactions for its ongoing monitoring and/or reporting purposes*                                                      | No novelty regarding the approval of the criteria for the detection of suspicious or unusual transactions and activitiesAt the level of the AMLR, the requirements have in fact been narrowed compared with the previous EBA positionNo substantive difference between “Billigung” (German version of the AMLR) and “Genehmigung” (German version of the EBA Guidelines); the English versions use “approval” in both cases                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |            |

Comparing the outsourcing prohibitions of Art. 18(3) sentence 2 AMLR with the requirements of the EBA Guidelines shows: these prohibitions are not that new!

Substantive changes arise only with regard to the “proposal” of the risk assessment, which can no longer be outsourced in future, and the filing of suspicious activity reports. In these areas, however, German administrative practice in particular has always been stricter or more precise than the EBA Guidelines: preparing the risk assessment in isolation by an external party, including submitting it to senior management, was not permitted in the past either (expressly stated for the non-financial sector), and suspicious activity reports could only be prepared externally, while the final act of filing them could not be outsourced in isolation (BaFin administrative practice).

💡

If, however, the outsourcing prohibitions as such already existed to a very large extent while outsourcing the compliance officer function was at the same time possible, this should not change significantly under Art. 18(3) sentence 2 AMLR.

Nor should it make a difference that the AMLR is now a Level 1 act, whereas the EBA Guidelines are “only” a Level 3 measure. BaFin has incorporated the requirements of the EBA Guidelines into its national administrative practice by way of its comply notification and applied them accordingly. There is no indication that this has ever resulted in a ban on outsourcing the compliance officer function as a whole.

This comparison with the status quo under the EBA Guidelines supports the **first reading**: Art. 18(3) sentence 2 AMLR is intended to prohibit the isolated outsourcing of certain strategically important tasks, but not the outsourcing of the compliance officer function in its entirety. The largely congruent EBA Guidelines have always stated exactly this as the premise of their outsourcing prohibitions (“*Strategic decisions in relation to AML/CFT should not be outsourced. These decisions include, in particular …*”).

### 2\. Express possibility of concentrating the function within the group

Art. 11(2), third subparagraph, AMLR expressly clarifies that an insurance undertaking belonging to a group may appoint as its compliance officer an individual who already performs that function in another entity within the group. The prerequisite for such intra-group concentration is that it is justified by the size of the obliged insurance undertaking and the low risk of its activities. This already implicitly answers the question of whether the compliance officer function can be outsourced within the group – after all, intra-group pooling of the function always constitutes “genuine” outsourcing. BaFin (AuA, General Part, as of July 2025, section 3.10: “*The performance of tasks by a foreign parent company, head office or branch also constitutes outsourcing*”; own translation) and the EBA (EBA Guidelines, paragraph 68(d): “*Intra-group outsourcing should be subject to the same regulatory framework as outsourcing to service providers outside the group*”) have taken a similar view to date.

Art. 11(2), third subparagraph, AMLR does not address the outsourcing prohibitions under Art. 18(3) sentence 2 AMLR at all. Instead, it clarifies in Art. 11 AMLR – i.e. precisely where the compliance officer function as such is regulated – that compliance officer functions may be concentrated within a group.

This, too, supports the **first reading**, according to which Art. 18(3) sentence 2 AMLR is intended to prohibit handing over certain strategically important tasks in isolation, but not outsourcing the compliance officer function as such. Otherwise, Art. 11(2), third subparagraph, AMLR would conflict with the prohibitions in Art. 18(3) sentence 2 AMLR.

### 3\. What is likely meant? No isolated outsourcing of “strategic decisions”!

The outsourcing prohibitions already in force under the EBA Guidelines were expressly aimed at prohibiting the outsourcing of “*strategic decisions in relation to AML/CFT*”. The same rationale is likely to underlie Art. 18(3) sentence 2 AMLR.

Besides the extensive congruence between the outsourcing prohibitions under the EBA Guidelines and under Art. 18(3) sentence 2 AMLR, this is supported by the considerations underlying the AMLR: each individual undertaking must know and understand “its” safeguards and, to that end, understand the rationale behind the activities carried out by the service provider and the approach taken in carrying them out (Art. 18(2), third subparagraph, AMLR; Recital 48 AMLR).

Finally, this view is also supported by the legislative materials from the trilogue negotiations between the European Commission, the Council of the European Union and the European Parliament. The options for outsourcing and their limits were discussed particularly intensively and were steadily expanded in the course of the trilogue negotiations (see in particular the [four-column document ST 9356/2023 of 15 May 2023](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CONSIL:ST%5F9356%5F2023%5FINIT&ref=waldvorlauternormen.com)).

At an early stage of the trilogue negotiations, the Council made a remarkable statement: the amendments it proposed to the outsourcing rules were based on the premise that only “tasks”, but not “functions”, may be outsourced under the AMLR (“*The amendments are based on the premise that only tasks, not functions, can be outsourced and that responsibility itself cannot be delegated under Article 40(1) AMLR*”, [WK 11703/2022 INIT of 8 September 2022](https://data.consilium.europa.eu/doc/document/WK-11703-2022-INIT/en/pdf?ref=waldvorlauternormen.com)). This would speak directly against outsourcing the compliance officer function.

Clearly, however, this restrictive position of the Council did not prevail – on the contrary: the AMLR expressly assumes that critical functions may be outsourced and that the obliged entity may systematically outsource functions (Recital 49: “*where critical functions are outsourced or where the obliged entity systematically outsources its functions*”). The AMLA guidelines to be issued under Art. 18(8) AMLR are also to address, in particular, “*those functions that are to be regarded as critical*”.

This, too, supports the **first reading**: the point is not to deny individual functions, in their entirety, the capacity to be outsourced, but rather to prevent certain core tasks from being performed in isolation by external third parties.

## IV. Conclusion

The reflex of inferring from the supposedly “new” outsourcing prohibitions under Art. 18(3) sentence 2 AMLR that the compliance officer function can no longer be outsourced clearly falls short. These prohibitions are by no means new and, in very similar form, are well known to German undertakings in particular.

Only the AMLA guidelines will provide a definitive answer. Until then, the following applies: in view of the wording, the legislative history and the largely congruent EBA position that already applies today, there are very good arguments that the compliance officer function can continue to be outsourced in its entirety under the AMLR.