Structuring an MLRO Annual Report That Satisfies SYSC 6 Without Triggering FCA Intervention
This guide sets out how to structure and write the MLRO annual report so it meets SYSC 6.3.9G expectations and gives the board a defensible record of financial crime oversight. After reading it, senior decision-makers will know what to include, what to leave out, and how to frame weaknesses without inviting supervisory follow-up.
The MLRO annual report is one of the few documents the FCA can request cold and read as a proxy for the entire financial crime control environment. A weak report invites a Section 166, a targeted assessment, or a Dear CEO follow-up. A defensive, box-ticking report is almost as damaging: supervisors read reassurance without evidence as a governance signal in itself. The task is to produce a report that is candid about weaknesses, precise about remediation, and structured so the board can demonstrably discharge its SYSC 6.3 obligations.
Key Executive Takeaways
- The report must evidence board-level oversight of financial crime risk, not just describe MLRO activity, and its structure should mirror the SYSC 6.3.9G factors explicitly.
- Candour about control weaknesses, paired with dated, owned remediation, is treated more favourably by supervisors than a clean report that later proves optimistic.
- The highest-risk sections are typology exposure, SAR quality, and sanctions screening effectiveness: these are where supervisors probe first and where most reports underperform.
Anchor the report to SYSC 6.3.9G, not a generic template
Supervisors read MLRO reports with SYSC 6.3.9G open beside them. Structure your contents page so each required factor maps to a numbered section: business-wide risk assessment, policies and procedures, customer due diligence, ongoing monitoring, PEPs and correspondent relationships, SAR regime, training, record keeping, and MLRO resourcing. If a section is thin, say so and explain why. Do not bury statutory factors inside thematic chapters. This makes it obvious to a reviewer that nothing has been omitted, and it forces internal honesty during drafting.
Lead with the risk assessment, not the activity log
Most reports open with SAR volumes and training completion rates. This is the wrong signal. Open with the firm-wide financial crime risk assessment: what changed in the customer base, product set, geographies, and delivery channels during the year, and how the residual risk profile shifted as a result. Tie this to specific control responses. If the risk assessment has not been refreshed in the period, say when it was last done and when it will next be done. A stale risk assessment is the single most common finding in FCA financial crime work.
Be specific about SAR quality, not just volume
Report internal SAR volumes, external SAR volumes, decline rates, and average time from trigger to submission. Then go further: sample-test a proportion of SARs and comment on quality, including whether glossary codes were used correctly and whether DAML requests were timely. Supervisors know that firms with low external conversion rates often have a defensive reporting culture; firms with high conversion but slow submission times often have a resourcing issue. Address both possibilities directly.
Treat sanctions and screening as a standalone section
Since 2022, sanctions effectiveness has been a priority supervisory theme. Cover screening tool calibration, fuzzy matching thresholds, false positive rates, backlog aging, and the results of any assurance testing. If you outsource screening, name the provider and describe the oversight model. Silence here is read as weakness.
Handle weaknesses with dated remediation, owned by name
The report should include a consolidated remediation tracker: issue, source (internal audit, compliance monitoring, external review, self-identified), owner by SMF or senior role, target date, and current status. Slippage should be explained, not hidden. Supervisors accept honest slippage with a credible revised plan. They do not accept issues that quietly disappear between reports.
What most firms get wrong
The three recurring failures are: describing activity rather than assessing effectiveness; declaring the framework "adequate" without stating the test applied; and burying MLRO resourcing concerns in an appendix. If the MLRO does not have enough people, the report is the place to say so, because SYSC 6.3.9G(6) requires it and the board minute approving the report becomes the audit trail.
Close with a board attestation, not a signature block
Include a short section recording the board's consideration of the report, the challenge raised, decisions taken, and any matters escalated. This converts the report from an MLRO document into evidence of governance. Without it, the board cannot demonstrate it has discharged its SYSC 6 responsibility, no matter how good the underlying content.
Before signing off this year's report, ask one question: if the FCA requested it tomorrow with a 48-hour deadline, would you send it as drafted, or would you want to redraft it first? If the answer is redraft, do it now.
Frequently Asked Questions
How long should the report be?
There is no fixed length, but 25 to 60 pages is typical for a mid-sized regulated firm. Shorter than 20 pages usually signals insufficient depth on the SYSC 6.3.9G factors. Longer than 80 pages usually signals padding that obscures the assessment.
Should the report include personal data or specific case detail?
Use anonymised case studies to illustrate typology exposure and SAR quality. Do not include client-identifiable data in the main report. Keep detailed case files available separately for supervisory inspection if requested.
Who should approve the report?
The board, or a board-level committee with a clear delegation from the board. Approval by the executive committee alone is not sufficient evidence of board oversight under SYSC 6.
How candid is too candid about weaknesses?
Candour paired with dated remediation is protective. Candour without a remediation plan is an invitation for supervisory action. If you identify a material weakness, the report must show what is being done about it, by whom, and by when.
Does the FCA read every MLRO report?
No. But they request them during authorisations, changes in control, thematic reviews, and whenever a concern arises. The report should be written as if it will be read cold by a supervisor who has never met the firm.
Frequently asked questions
How long should the report be?
There is no fixed length, but 25 to 60 pages is typical for a mid-sized regulated firm. Shorter than 20 pages usually signals insufficient depth on the SYSC 6.3.9G factors. Longer than 80 pages usually signals padding that obscures the assessment.
Should the report include personal data or specific case detail?
Use anonymised case studies to illustrate typology exposure and SAR quality. Do not include client-identifiable data in the main report. Keep detailed case files available separately for supervisory inspection if requested.
Who should approve the report?
The board, or a board-level committee with a clear delegation from the board. Approval by the executive committee alone is not sufficient evidence of board oversight under SYSC 6.
How candid is too candid about weaknesses?
Candour paired with dated remediation is protective. Candour without a remediation plan is an invitation for supervisory action. If you identify a material weakness, the report must show what is being done about it, by whom, and by when.
Does the FCA read every MLRO report?
No. But they request them during authorisations, changes in control, thematic reviews, and whenever a concern arises. The report should be written as if it will be read cold by a supervisor who has never met the firm.
Related guides
What Makes a Decision Defensible to Regulators: A Practical Guide
This guide explains what regulators actually look for when they test a major decision after the fact, and how to build defensibility into the decision itself rather than reconstruct it later. You will finish with a clear view of what to document, who to involve, and where most firms leave themselves exposed.
How to Handle a Pre-Emptive Regulator Meeting After a Governance Failure
This guide covers how to prepare for and run a self-initiated regulator meeting when you have discovered a material governance failure inside your firm. After reading, you will know how to sequence the disclosure, frame the failure, and position remediation in a way that preserves credibility and controls the supervisory response.
How to Structure a Section 166 Response That Preserves Board Credibility
A practical guide to responding to a Skilled Person review in a way that protects the board's standing with the regulator. Covers how to sequence the engagement, where boards typically damage their own credibility, and how to convert findings into a credible remediation posture.
How to Structure a Basel 3.1 Board Paper That Secures Approval
This guide sets out how to write a Basel 3.1 implementation board paper that wins approval without softening the capital impact numbers. Read it to sharpen your framing, sequencing, and stakeholder handling before the paper goes to committee.
Structuring an ORSA Board Narrative That Satisfies PRA Without Boxing In Strategy
This guide sets out how to write an ORSA board narrative that meets PRA forward-looking assessment expectations while preserving the board's room to change direction. It shows how to sequence risk, capital and strategy so the document is credible to supervisors without hardcoding decisions the board has not yet taken.
Where internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder Proximity