Menu Close

Evaluating fractional MLROs: A 2026 guide for UK FinTechs

Many scaling UK FinTechs struggle to maintain compliance with the Financial Conduct Authority (FCA) while managing limited operating budgets in 2026. This decision guide from Compliance Consultant explains how a fractional Money Laundering Reporting Officer (MLRO) solves this operational tension by acting as the designated Senior Management Function 17 (SMF17) nominee on a part-time, retained basis. For firms outgrowing initial compliance setups but not yet ready to fund a full-time senior executive, a fractional MLRO ensures professional financial crime governance without the six-figure overhead. We examine how this model satisfies the strict independence requirements of the FCA under the Senior Managers and Certification Regime (SMCR) and the Proceeds of Crime Act 2002.

A base salary of £60,000 to £80,000 for an in-house compliance manager is a fixed overhead that many early-stage FinTech firms cannot carry. Yet, assigning complex anti-money laundering (AML) responsibilities to an unapproved junior staff member exposes the business and its board of directors to personal regulatory liability. In 2026, the convergence of fraud and financial crime—driven by strict authorised push payment (APP) fraud liability and evolving digital asset rules—means that nominal compliance measures are a significant operational risk.

Compliance Consultant provides chartered-grade FCA compliance expertise and fractional MLRO support specifically designed for the FinTech sector. We regularly guide scaling financial services firms through complex AML framework reviews, controls design, and FCA authorisation applications, ensuring businesses meet stringent regulatory standards while remaining commercially viable.

The FCA’s unbending standard for the MLRO function

Regulated firms must understand that the FCA does not accept scaled-down compliance standards simply because a business is in its early growth phases. When a firm applies for regulatory permissions, the authorisations team inspects the financial crime framework with intense scrutiny. To secure approval, a firm must present a complete AML framework built on several non-negotiable compliance elements:

  • A documented, firm-wide AML and counter-terrorist financing (CTF) risk assessment.
  • A structured Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) system.
  • Defined internal and external procedures for reporting suspicious activity.
  • Active transaction monitoring systems built for the firm’s specific risk profile.

The designated MLRO must possess the seniority and independence to challenge the board on financial crime risks. The FCA’s supervisory teams are highly experienced at detecting nominal appointments—situations where a junior employee is given the title of MLRO on paper but lacks the authority, tools, or knowledge to execute the function. If the regulator believes the named individual is merely a figurehead, it will reject the application or initiate enforcement proceedings.

For firms currently going through the licensing pipeline, timing is a major factor. While the official FCA target for processing application authorisations is 4 months, current typical processing ranges sit closer to ~6 months. This delay makes it commercially impractical to hire a full-time, salaried MLRO who sits idle during the determination phase. Managing this gap is a key reason firms work with Compliance Consultant to establish compliant, part-time SMF17 coverage that meets the regulator’s standards from day one. You can read more about managing these stages in our guide on how to get FCA authorisation in 2026: a step-by-step guide – Compliance Consultant London.

Comparing MLRO resourcing options

FinTech founders generally choose between three models when structuring the SMF17 role. Each approach carries distinct financial and operational consequences that affect the firm’s risk profile.

| Option | Best for | Typical cost | Key tradeoff |
| :— | :— | :— | :— |
| Full-time senior MLRO hire | Established firms with high transaction volumes | £80,000+ base salary plus benefits and National Insurance | Significant fixed overhead; recruitment delays; single-point-of-failure risk |
| Internal promotion of operations staff | Seed-stage firms with minimal activity | Low direct salary increase | High risk of FCA rejection due to lack of independence; personal liability exposure |
| Fractional MLRO | Scaling FinTechs, payment services, and EMIs | Retainer starting from £3,000 to £6,000 per month | Requires structured communication hand-offs and defined operating days |

For many scaling firms, a full-time senior hire is commercially unviable. UK regulatory compliance firm Compliance Consultant offers structured retained advisory options that bridge this gap. For example, our Gold compliance retainer costs £1,345 per month under annual billing, providing access to our specialist advisory team and an array of digital frameworks. Even when paired with a fractional officer, this combined approach costs less than 17% of employing a full-time compliance manager—with no national insurance contributions, pension commitments, or recruitment fees. This comparison is discussed further in our analysis of a full-time MLRO vs fractional specialist: A 2026 cost and risk comparison.

Selecting the right model depends on the specific complexity of your financial products. A firm handling cross-border payments faces completely different risks than a domestic peer-to-peer lender. Relying on a generalist recruitment agency to fill this role often results in mismatching candidate skills with your actual operational risks. For a breakdown of these dynamics, consult our comparison of a specialist FCA consultant vs generalist firm: A 2026 comparison.

Two colleagues review documents while walking through a contemporary office space.

Core duties assumed by a fractional MLRO

A fractional MLRO is not an external advisor who simply reviews paperwork once a quarter. Under the Senior Managers and Certification Regime, the individual officially holds the SMF17 designation. This means they carry the exact same personal regulatory liability as a permanent, full-time hire. A professional fractional MLRO placed by Compliance Consultant executes several tasks to keep the firm compliant.

Suspicious Activity Reports and NCA liaison

The fractional MLRO acts as the firm’s nominated officer under the Proceeds of Crime Act 2002. They receive internal reports of suspicious activity from your operations team, perform secondary investigations, and determine whether the threshold for an external report is met. If required, they submit Suspicious Activity Reports (SARs) directly to the National Crime Agency (NCA). They also manage any subsequent consent requests, ensuring the firm does not commit a tipping-off offence. This function is further detailed in the professional guide to fractional MLRO | FCA regulated firms | Exec Capital.

Board reporting and management information

A major risk for scaling FinTechs is a lack of financial crime visibility at board level. The fractional MLRO establishes clear key risk indicators (KRIs) and drafts the annual MLRO report. This report is a regulatory requirement that details the effectiveness of the firm’s controls, any residual risks, and future resource priorities. By presenting this management information to the board, the MLRO ensures that directors are aware of the firm’s actual risk posture and can make informed strategic choices.

Regulatory change assessment and FCA correspondence

Financial crime rules are constantly shifting. In 2026, MLROs must track the practical operational impacts of data-led supervision and new sanctions requirements. A fractional MLRO monitors these changes, updates the firm-wide risk assessment, and manages all direct correspondence with the FCA. If the regulator initiates a desk-based review, the fractional MLRO leads the firm’s response, presenting the necessary evidence of active compliance monitoring.

Real-world application: Remediation during rapid growth

To understand the value of this structured oversight, consider a scenario based on our work with a rapidly growing FinTech innovator. In our analysis of emerging financial firms, we often see a common pattern: customer acquisition and technology development outpace the development of compliance controls.

A FinTech firm experiencing rapid transaction growth and expanding its user base across Europe found its internal processes lagging behind its commercial expansion. Onboarding checks became inconsistent, transaction monitoring systems generated a high volume of false positives, and the firm accumulated a backlog of unreviewed alerts. The internal compliance team, overwhelmed by day-to-day operations, lacked the senior leadership to redesign the system.

Our project specialists conducted a comprehensive review of the firm’s AML framework to identify systemic weaknesses. Rather than forcing generic, off-the-shelf templates onto the firm, we designed a customized approach tailored to their specific technology stack and payment flows. This intervention resolved the onboarding inconsistencies, updated the transaction monitoring rules, and established clear lines of senior accountability. You can read more about these interventions on our page dedicated to Compliance Case Studies | FCA & PRA Regulatory Projects.

Our approach to such projects is guided by four clear principles of implementation:

  1. Demonstrating business return on investment before implementation by providing exceptional value.
  2. Driving process and organisational change early in parallel with infrastructure development; this involves the direct methodology to engage (establish regulatory requirements before infrastructure is built), execute (drive process and organisational change in parallel with technology development), and embed (integrate compliance into real-world operations through testing and scaling).
  3. Starting with a sample department or area to test processes and technology in real business situations, then applying scale to other or all areas as required.
  4. Compliantly gaining momentum and then rapidly deploying solutions to the remainder of the organisation and providing support through to embedding.

Close-up of a person analyzing a colorful graph chart with a pen in a modern office setting.

What most people get wrong

When considering a fractional MLRO arrangement, FinTech founders and boards frequently make two critical mistakes that draw immediate regulatory scrutiny.

Appointing a nominal MLRO to tick a box

The first common error is trying to pass off a junior operations manager as the MLRO during the FCA authorisation process. Founders often assume that having any named individual in the seat is sufficient to satisfy the regulator. However, the FCA’s authorisations team quickly identifies applicants who lack the genuine authority, independence, or technical expertise to manage financial crime risks. An unapproved or unqualified individual performing the function exposes the firm to severe penalties and reputational damage.

Treating the MLRO as a purely administrative function

The second mistake is viewing the MLRO as an administrative reporting clerk. FinTech leaders often believe the role is limited to filing SARs and filling out annual forms. In reality, the SMF17 holder is personally accountable to the board for the entire anti-money laundering and counter-terrorist financing framework. They must have the expertise to design transaction monitoring thresholds, audit complex onboarding flows, and handle direct supervisory liaison with the FCA. Treating this as a clerical task leaves the firm’s directors personally exposed if a systemic compliance failure occurs.

To discuss your FinTech’s specific MLRO requirements and evaluate whether fractional support is appropriate for your business model, contact our team. You can book a free 30-minute discovery call with a specialist at Compliance Consultant by calling 0800 689 0190 or emailing info@complianceconsultant.org with the subject “Retainer Discovery Call”.

author avatar
Lee Werrell