AfterWorc Blog · Compliance

Hiring for AML compliance at an EMI or PSP: which roles, in which order

Victor Birjukov · 9 Oct 2026 · 12 min read

  • The first AML hire is usually the compliance officer; the board member responsible for AML/CFT is a role, not a new person.
  • Add KYC and monitoring analysts at go-live, then split roles when alerts and reviews start to wait.
  • Some tasks can be outsourced, but the key decisions and the responsibility stay with your firm.

Building an AML compliance team at an EMI or PSP is mostly a question of order. The rules name a few roles you must fill before anything else, and the rest grows with your customers and transaction volume. This guide sets out the AML compliance team structure for an EMI or payment institution, stage by stage, with the rules behind each step.

It describes what the rules say and how firms can staff around them. It is not legal advice. Your supervisor and your own lawyers decide what applies to you.

Why AML hiring at a licensed firm starts at the top

Most teams hire from the bottom up: first the people who do the work, then someone to manage them. AML compliance at a regulated firm works the other way round.

Payment institutions and e-money institutions are obliged entities under anti-money laundering law. In Estonia, the Money Laundering and Terrorist Financing Prevention Act covers "financial institutions", and its definition of a financial institution includes payment service providers and e-money institutions. At EU level, the EBA guidelines on AML/CFT compliance officers apply to credit and financial institutions as defined in the 2015 Anti-Money Laundering Directive.

The law then names two roles before it says anything about analysts:

  • A management board member who is responsible for AML/CFT. The EBA guidelines on AML/CFT compliance officers (EBA/GL/2022/05) say firms should appoint one member of the management body who is ultimately responsible for implementing AML/CFT obligations.
  • An AML/CFT compliance officer. Under the Estonian Act, the management board appoints a compliance officer who is the contact person for the Financial Intelligence Unit and reports directly to the board.

So the first AML hire is often a senior one, and one of the first "roles" is a board responsibility, not a new person.

Stage 1: before the licence – who do you need first?

When you apply for a licence, the supervisor looks at your people and your controls, not just your business plan. Finantsinspektsioon's list of documents for payment and e-money institution licences asks for, among other things:

  • a description of internal controls and measures to ensure compliance with anti-money laundering rules;
  • a description of your organisational structure;
  • information on your managers, their education, employment history and areas of responsibility;
  • information on your auditor and internal auditor.

That shapes the first hires.

1. The board member responsible for AML/CFT. This can be an existing director who takes on the responsibility. Under the Estonian Act, if the board has more than one member, one of them must be appointed to oversee implementation of the Act. The EU Anti-Money Laundering Regulation (Regulation (EU) 2024/1624, the AMLR), which applies from 10 July 2027, keeps this idea: a member of the management body is responsible for compliance and reports to the board at least once a year.

2. The AML/CFT compliance officer (some firms call this role the MLRO). This is the first real AML hire and the most important one. The Estonian Act says the compliance officer must have the education, professional suitability, abilities, personal qualities, experience and impeccable reputation needed for the role, and must work permanently in Estonia. Under the AMLR, the compliance officer is appointed by the management body, needs sufficiently high standing in the firm, handles day-to-day AML/CFT work including targeted financial sanctions, and reports suspicious transactions to the FIU.

3. Someone to write and own the internal rules. In a small firm this is the compliance officer. The Act requires written internal rules, and the licence application asks for them. If your compliance officer is strong on operations but new to drafting, a short fixed-scope task with an experienced policy writer can fill the gap.

4. Internal audit. Internal audit checks that the AML rules work. Under the Estonian Act, where a firm has an internal audit obligation, its AML rules must be checked during the internal audit. Decide early whether it will be done in-house or bought in.

At this stage you usually do not need a team of analysts. You need one person who can build the framework and defend it to the supervisor.

Stage 2: going live – who handles the daily work?

Once you have customers, the work becomes daily and steady. Alerts, onboarding files and screening hits arrive every day. This is when you add analysts.

KYC / onboarding analyst. Checks customer identity, ownership and source of funds when an account is opened, and carries out periodic reviews. If you onboard businesses or merchants, look for KYB experience: reading company registers, mapping ownership, and spotting nominee structures. Our article on hiring an AML / KYC analyst for an EMI covers what to check on the CV and in the interview.

Transaction monitoring analyst. Reviews alerts from your monitoring system, investigates unusual activity, and prepares cases for the compliance officer. The compliance officer decides whether to report to the FIU, so the analyst's job is to build a clear, documented case file.

Sanctions screening. In a small team, the KYC analyst can also clear screening hits. The AMLR places targeted financial sanctions inside the compliance officer's day-to-day responsibilities, so whoever clears hits needs clear rules for escalation.

Training for everyone else. The Estonian Act requires firms to make sure relevant staff are trained when they start the job, and then regularly or when needed. If the compliance officer runs the training, it needs time in their week. Plan for it.

At go-live, one or two analysts who can each cover KYC and monitoring are often more useful than two narrow specialists. Cover for holidays and sick leave matters more than depth at this point.

Stage 3: scaling – when do you split the roles?

As volumes grow, generalists start to fall behind. Signs that it is time to split roles:

  • monitoring alerts wait days before anyone opens them;
  • periodic reviews of higher-risk customers run late;
  • the compliance officer spends most of the week on case work rather than oversight;
  • the supervisor or internal audit points to weak or inconsistent case files.

Typical splits at this stage:

  • Separate KYC/KYB and transaction monitoring teams. Each needs different habits: one checks documents and ownership, the other looks for patterns over time.
  • A deputy compliance officer. Gives cover when the compliance officer is away and a path for succession.
  • Quality assurance. A reviewer who samples closed alerts and onboarding files and checks they meet your own rules before an auditor does.
  • Compliance tooling or data role. Someone who tunes monitoring scenarios and screening settings, and works with engineering on data quality.
  • Group compliance officer. If you run several licensed entities, the EBA guidelines expect a group AML/CFT compliance officer to coordinate the local compliance officers.

The EBA guidelines also say the management body should assess, at least once a year, whether the human and technical resources given to the AML/CFT compliance function are adequate. The compliance officer's activity report, at least annually, is the natural place to make that case.

AML compliance team structure by stage

A simple way to picture it:

  1. Before the licence: board member responsible for AML/CFT; AML/CFT compliance officer; internal audit (in-house or bought in); help with written rules if needed.
  2. At go-live: add one or two analysts who can each cover KYC/onboarding, transaction monitoring and screening; set up training.
  3. At scale: split KYC/KYB from monitoring; add a deputy compliance officer, quality assurance and a tooling role; add a group compliance officer if you run several entities.

The order matters more than the head count. A firm with many analysts and no strong compliance officer is in a weaker position than a firm with one strong compliance officer and one analyst.

Can one person hold several roles?

Sometimes. The AMLR allows the responsible board member and the compliance officer to be the same person where justified by the firm's nature, risks, complexity and size. The EBA guidelines also allow a management body, on proportionality grounds, not to appoint a separate compliance officer, but the reasons must be justified and documented.

Keeping the roles apart makes it easier for the compliance officer to challenge the business. The EBA guidelines say the compliance officer should be independent from the business lines and have direct access to the information they need.

Should you hire, outsource or combine?

Three models to consider:

  • Employ the key roles, outsource the rest. The compliance officer is employed; internal audit and some reviews are bought in.
  • Employ everyone. Gives control and keeps knowledge in-house, but takes longer to build.
  • Use outside specialists for peaks. For example, extra analysts to clear an onboarding backlog or a periodic review cycle, with your compliance officer keeping the decisions.

Outsourcing has limits. According to the CSSF's summary of the EBA guidelines, certain strategic AML/CFT decisions should not be outsourced, and outsourcing of the compliance officer's operational tasks must follow the ESAs' outsourcing guidelines. The responsibility stays with your firm.

If you are building the wider payments function at the same time, our payments team hiring guide shows how compliance fits next to operations, engineering and finance, and the five roles your payments team needs before your first PSP goes live covers the go-live roles in more detail.

How much does an AML compliance team cost?

We do not publish salary figures here, because they vary by country, seniority and language. The cost of each person is easier to read as a formula:

  • Hired through AfterWorc: salary + employer taxes + 10% AfterWorc margin.
  • Fixed-price task (for example, a policy review or a backlog of periodic reviews): the agreed price plus a 5–8% fee, with funds held until you accept the work.

Add your tools (screening, monitoring, ID verification) and internal audit on top. Budget for absence cover too: a single compliance officer with no deputy is a risk in itself.

What to check before each hire

  1. Match the experience to your customers. Consumer e-money, merchant acquiring and business accounts each need different KYC and monitoring skills.
  2. Ask for real cases. A good candidate can walk you through an alert they escalated: what they saw, what they checked and what was decided.
  3. Check the tools. Ask which screening and monitoring systems they have used, and whether they only cleared alerts or also tuned rules.
  4. Check languages. Analysts read documents and talk to customers. Their languages should match your customer base.
  5. For the compliance officer, check standing and independence. They need the seniority to challenge the board and, in Estonia, must work permanently in Estonia.
  6. Ask who reviewed their work. References from someone who checked their case files tell you more than references from a peer.
  7. Plan cover. Before you hire the second analyst, decide who covers the compliance officer when they are away.

When you hire through AfterWorc, you meet each candidate in a video interview before you decide. Start a hiring request and tell us which stage you are at.

FAQ

Who should be the first AML hire at a new EMI or payment institution? Usually the AML/CFT compliance officer. The rules require one, the supervisor will look at them during licensing, and they build the framework the rest of the team works within.

Is the compliance officer the same as an MLRO? Job titles vary between firms. Under the AMLR, reporting suspicious transactions to the FIU is a task of the compliance officer, and under the Estonian Act the compliance officer is the FIU's contact person. Check the term your supervisor uses.

Can we outsource the AML compliance officer? Some tasks can be outsourced, but certain strategic AML/CFT decisions should not be, and outsourcing must follow the ESAs' outsourcing guidelines. In Estonia, the compliance officer must also work permanently in Estonia. Speak to your lawyers before choosing this model.

When should we hire a second AML analyst? When alerts or reviews start to wait, when the compliance officer is doing case work most of the week, or when you need holiday cover. Volume and risk decide, not a fixed ratio.

What changes when the AMLR applies in July 2027? The AMLR applies from 10 July 2027 and sets the compliance manager and compliance officer roles directly in an EU regulation. Firms should compare their current set-up with Article 11 well before that date.

Sources

Building your AML compliance team? Tell us the role and get three matching profiles. Start hiring on AfterWorc. The first 10 business clients get €190 off their first hire and a free technical assessment.