Insights / Regulatory & Compliance

Can You Outsource Your Money Laundering Reporting Officer in Kenya?

By Clay & Associates Advocates · 6 min read ·

A calculator and financial charts on an office desk, representing the transaction monitoring work behind an anti-money laundering compliance programme.

Businesses asking whether they can outsource their Money Laundering Reporting Officer function are usually really asking two different questions at once, and conflating them leads to bad compliance decisions. One question is whether external specialists can carry the day-to-day weight of an anti-money laundering programme. The other is whether the designated MLRO role itself, the person the law actually holds accountable, can be handed to an outside firm. Kenya’s anti-money laundering regulations answer these two questions differently, and a reporting institution that treats them as the same question risks a compliance gap it does not know it has.

The Proceeds of Crime and Anti-Money Laundering Regulations, made under the Proceeds of Crime and Anti-Money Laundering Act, 2009, require every reporting institution to appoint a Money Laundering Reporting Officer. Regulation 12(2) sets the qualifying standard for that appointment: the officer must be of management level and must have relevant and necessary competence, authority and independence. Regulation 12(7) then lists the officer’s specific responsibilities, which include being informed of all suspicious activity available to the institution, applying internal risk-management procedures to disclosures, reporting suspicious transactions to the Financial Reporting Centre, ensuring staff are trained and aware of the institution’s anti-money laundering obligations, and being involved in screening new hires alongside human resources. Regulation 12(3) requires the appointment or removal of the officer to be communicated to the Centre and to the institution’s supervisory body within fourteen days.

Why “Management Level” Is a Different Standard From the Data Protection Act’s

This site has previously covered how Kenya’s Data Protection Act expressly permits an external data protection officer, because section 24(2) of that Act says a DPO “may be” a staff member, language that only makes sense if a non-staff appointment is also contemplated. Regulation 12(2) of the POCAMLA Regulations is drafted differently and more restrictively. It does not say the Money Laundering Reporting Officer may be a staff member; it requires the officer to be of management level, a phrase that describes a position within the reporting institution’s own organisational hierarchy, not a description any outside consultant, however senior, could hold at a business that is not their employer. Read together with the regulation 12(3) duty to notify the Centre of the officer’s appointment and removal as an internal personnel event, and the regulation 12(7)(e) duty to work directly with the institution’s own human resources function on staff screening, the more natural reading is that the designated MLRO must be an internal, management-level appointment rather than an outsourced function performed by an external firm.

What This Means in Practice: The Role Cannot Be Fully Outsourced

A reporting institution should not treat “we have engaged an AML compliance firm” as equivalent to having satisfied regulation 12. The statutory Money Laundering Reporting Officer, the individual whose name goes to the Financial Reporting Centre and the institution’s supervisory body, needs to be a management-level person inside the institution with real authority to act on suspicious activity, not merely a named contact for an external provider. An institution that designates an outside consultant as its MLRO, without that person holding genuine management-level standing and authority within the institution itself, is taking a compliance risk that a more careful reading of regulation 12 would have avoided. This is a more conservative conclusion than the position for data protection officers, and it is the correct one: the two regulations are simply drafted differently, and a business should not assume that because one compliance role can be outsourced, the other automatically can be too.

What Can Legitimately Be Outsourced

None of this means external AML expertise is unavailable to Kenyan businesses, or that an in-house MLRO has to build every part of the programme alone. Regulation 12 fixes who must hold the reporting and decision-making role; it says nothing that prevents an institution from buying in support for the work around that role. Transaction monitoring systems and their ongoing tuning, AML training design and delivery for staff, drafting and maintaining the compliance manual the officer’s duties under regulation 12(7) require, customer due diligence file reviews, and advisory support on how a specific suspicious activity report should be framed before the internal MLRO signs off and submits it, are all functions a specialist external provider can properly perform. The distinction is between the institution’s own management-level officer making the calls the law assigns to that role, with expert support behind them, and an external party purporting to be that role. Structured this way, outsourcing AML compliance support is both lawful and often the more capable option for a smaller institution that cannot justify a full internal compliance department.

Getting the Structure Right

A reporting institution considering external AML support should confirm three things before engaging a provider. First, that a genuine management-level employee is formally designated as the institution’s Money Laundering Reporting Officer, with that appointment properly communicated to the Financial Reporting Centre and the institution’s supervisory body within the fourteen-day window regulation 12(3) sets. Second, that the engagement with any external provider is documented as advisory and support services to that internal officer, not as a delegation of the officer’s own statutory decision-making. Third, that the internal MLRO retains actual authority and independence, as regulation 12(2) requires, rather than functioning as a rubber stamp for conclusions reached entirely outside the institution.

How We Can Help

Clay & Associates Advocates advises reporting institutions on structuring anti-money laundering compliance programmes correctly, including the internal governance a designated Money Laundering Reporting Officer needs and the external support that can lawfully sit around that role. Our practical guide to anti-money laundering obligations for Kenyan businesses covers the wider compliance framework this role sits within, and our analysis of reporting obligations to the Financial Reporting Centre addresses what the MLRO actually has to file. Contact our Regulatory & Compliance practice to review whether your AML compliance structure meets regulation 12.

Sources: The Proceeds of Crime and Anti-Money Laundering Regulations, 2023, regulation 12; The Proceeds of Crime and Anti-Money Laundering Act, 2009.

Frequently asked questions

Can a Kenyan business fully outsource its Money Laundering Reporting Officer to an external firm?
Not the designated role itself. Regulation 12(2) of the POCAMLA Regulations requires the Money Laundering Reporting Officer to be of management level, which describes a position inside the reporting institution rather than an external party. The institution should appoint an internal, management-level officer and can then engage external providers to support that officer’s work.

How is this different from outsourcing a data protection officer?
The Data Protection Act expressly permits a DPO to be a non-staff appointment. The POCAMLA Regulations use different, more restrictive language for the MLRO, requiring management-level standing within the institution, so the same outsourcing structure does not transfer across without modification.

What AML functions can be safely outsourced?
Transaction monitoring systems, staff training, compliance manual drafting, customer due diligence reviews, and advisory support on suspicious activity reports can all be performed by external specialists, provided the institution’s own management-level MLRO remains the person exercising the statutory reporting and decision-making authority.

What happens if the MLRO appointment does not meet regulation 12?
A reporting institution risks non-compliance with a core requirement of its anti-money laundering obligations, which is a matter its supervisory body and the Financial Reporting Centre can test directly, given that the appointment itself must be reported to both within fourteen days.

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more