There's no prescribed template. The FCA expects the MLRO to report to the governing body at least once a year on how well the firm's anti-money laundering systems and controls work (SYSC 6.3.7G), and payment and e-money firms have the same yearly duty in law (MLR reg. 21(7)(d)). A useful report follows the Money Laundering Regulations: the risks, the controls, how they performed, what went wrong and what the board needs to decide.

Who has to produce one
- FCA firms subject to the financial crime rules in SYSC 6.3 appoint an MLRO (SYSC 6.3.9R), who reports to the governing body and senior management at least once a year on the operation and effectiveness of the AML systems and controls (SYSC 6.3.7G(2)).
- Payment service providers and e-money issuers must appoint someone to give senior management information on the operation and effectiveness of their AML policies, controls and procedures whenever appropriate and at least once a year (MLR reg. 21(7)(d)).
What to include
Each section gives the board evidence for one of the firm's obligations:
- Risk assessment: what changed in your customers, countries, products, transactions and delivery channels, and in your proliferation financing risk (regs. 18 and 18A).
- Policies, controls and procedures: which were reviewed, changed and approved, and how changes were communicated to staff (reg. 19).
- Customer due diligence: the number of high-risk customers and politically exposed persons, and any backlog in keeping their information up to date (reg. 28(11)).
- Internal reports and SARs: how many internal suspicion reports staff made, how many were reported to the NCA, and how long decisions took (reg. 21(5)).
- Training and screening: who completed AML training and who is overdue, and how relevant staff were screened (regs. 24 and 21(1)(b)).
- Audit and monitoring: findings from the independent audit and compliance monitoring, and progress on earlier recommendations (reg. 21(1)(c)).
- Resources: whether the MLRO function has the people, systems and access it needs (FCG 3.2.2).
- Recommendations: what the board is asked to approve, fund or change.
What the board does with it
The FCA's Financial Crime Guide asks how often senior management commission reports from the MLRO, what they do with them and how they follow up the recommendations. A board that never considers MLRO reports is one of its examples of poor practice (FCG 3.2.1).
Minute the discussion and the decisions, and track each recommendation to completion. Next year's report should say what happened to them.
When to schedule it
Pick a fixed board meeting each year. Scheduling it soon after your financial year end lets the same figures feed the REP-CRIM annual financial crime report, due 60 business days after your accounting reference date. The AML compliance checklist sets the report up as a yearly reminder alongside your risk assessment, training and audit.
Get reminded before each deadline
Regmindr sets up your compliance calendar from a template in about two minutes, and emails your team before each deadline is due.
Sources
- FCA Handbook: SYSC 6.3 Financial crime
- FCA Handbook: FCG 3.2 Money laundering and terrorist financing: themes
- The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017
This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.