Your MLRO Annual Report from real data: 5 days down to 5 minutes.
Trusted by 250+ UK-regulated firms · Built by compliance professionals, so you don’t have to be one.
14-day free trial · Take the tour
Compliance should be proportionate to the risk. Not sure? Our experts can help.
You have subscribed to the core module Compliance Monitoring Hub, AND
You have subscribed to the core module Compliance Monitoring Hub, AND
Note: All firms have Financial Crime obligations. The above speaks to which approach is appropriate for your needs. This does not represent advice.
Spreadsheets, Outlook folders and a consultant's inbox — one supervisory letter away from a very bad month. Where most small regulated firms are stuck.
Customer risk, PEP register, UBO list, sanctions hits, SAR log, G&H, third-party DD. Every MLR 2017 obligation scattered across workbooks nobody version-controls. When the regulator asks for your 5-year evidence trail, you're flicking between FINAL_v7 and an email thread.
You can outsource the work. You can't outsource SMF17. You still sign the MLRO Annual, you still carry the personal regulatory risk, and the consultant still hands you back a Word doc every December that's half template and half last year's version.
SAMLA 2018 is strict liability. A confirmed sanctions match means OFSI within 24 hours, a detailed report in 21 days, and a frozen-funds report inside a month. If you're still emailing the sanctions screener asking “is this a true hit?”, you're already late.
The 15-section MLRO Annual Report under JMLSG takes an experienced MLRO 3–5 days to write from scratch each year. REP-CRIM. Board quarterly. Audit findings. Training matrices. The regulatory reports never stop arriving, and they're all due at once.
If your MLRO workflow currently lives in spreadsheets, a consultant's inbox and the fortnight before the supervisory visit, the Financial Crime Suite is for you.
Three things make it different. Nine capabilities turn it into the system the SMF17 holder runs the firm from. One module covering every UK financial-crime regime — live, evidenced, locked, the day the visit lands. Included from the Growth plan.
Most financial-crime tools ship templates and generic chatbots. RegTechPRO is built on three load-bearing principles that produce regulator-grade output your supervisor can read.
Four regulator-grade reports — 15-section JMLSG MLRO Annual, REP-CRIM data return, Executive Summary, FCA Supervisory Readiness dry-run — all grounded in your live registers. PEPs by name. Sanctions hits as tables. SARs from your log.
137 structured questions across 14 chapters. Every one Otto-remediable with a Critical/High/Medium/Low action plan citing MLR 2017, POCA, SAMLA, Bribery Act, CFA 2017, UK MAR, FCG or JMLSG by regulation. Tracked. Evidenced. Always live.
AML, CDD/EDD, TM, Sanctions, ABC, SAR/STOR, Market Abuse, Tax Evasion, Anti-Fraud — every UK obligation in one module. A pillar-weighted Health score the Board can read at a glance and click through to the work. Not a status view. A routing system.
Built for the regulator visit. Built to stand up.
Every closed year auto-locks into a permanent read-only snapshot on 1 January. The 2026 report you signed still looks identical in 2029 when the regulator asks.
Audit-grade · Calendar-lockedEvery field change carries the email and role of who attested it. SMF17 accountability stops being a claim and becomes a click-through history — cited by name into Otto's reports.
SM&CR-readyEvery document attached anywhere — section, gap question, register — collated into one filterable view. Files live in your own Drive, open in one click. "Show me the evidence" stops being a 4-hour spreadsheet hunt.
Drive-nativeOtto sits as regulator and runs a 12-question desk-based exam — verbatim regulatory anchors, evidence cited from your registers, GREEN/AMBER/RED grade with remediations. Signable PDF in 30 seconds.
RAG-graded · SignableOtto won't draft a thin report. Before generation, every section is graded GREEN/AMBER/RED — and a single "Fix this" button takes you straight to the missing fields. No more half-drafted reports the MLRO has to bin.
QA-gatedRegulator letter lands. 14-day window. Click once: ZIP with all 6 Otto reports, Disclosures Log CSV, Gap Analysis CSV, every register CSV, MLRO Calendar as .ics. Everything they could ask for, packed in seconds.
Built for SUP 1513 recurring obligations seeded out of the box — REP-CRIM, OFSI Annual Frozen Funds, FATF reviews, BWRA refresh, sanctions checks. Mark complete and the next due date auto-advances. Export to Outlook or Google in one click.
SUP 16.23 · MLR reg 24Internal SARs, external SARs, DAML requests, STORs, sanctions hits, tipping-off events — every disclosure-class event in one cross-cutting view. Filter, search, export. True MLRO oversight in one click.
POCA · UK MAR · OFSIGetting Started Wizard imports your customer-risk and PEP registers from CSV, attaches your last MLRO Annual and BWRA, opens the 137-question Gap Analysis. Permanently on the dashboard for every refresh.
CSV import · Always availableNine regimes, 30 live registers, 36 regulator-minimum controls and a 137-question Gap Analysis — all feeding Otto's four regulator-grade report formats.
Simple three-plan monthly pricing · Included from the Growth plan. No add-ons. No setup fee.
A glimpse of the operating system the MLRO works in every day — many more screens sit behind these. Click any tab to look inside.
The MLRO's morning glance. Financial Crime Health score, live operations across every regime, KPIs, the MLRO calendar and review SLAs — the whole function on one screen, every weakness one click from the work that fixes it.
The board-ready report, drafted in seconds. The 15-section MLRO Annual, REP-CRIM, the Executive Summary and Supervisor Readiness — all generated by Otto from your live data, then reviewed and signed by your MLRO.
Every customer, PEP and case in one register. Risk-rated, review-tracked and evidence-attached, with next-review dates and sanctions/EDD flags so a stale file never reaches the regulator's eye first.
Mapped to statute. Attested by name. The control checklist and 137-question gap analysis turn weaknesses into tracked actions with named owners, deadlines and attached evidence — supervisor-ready.
The regulation, explained where you work. Plain-English guidance notes sit on every screen — what the rule requires, what good looks like and where the evidence goes — so the team never needs a second tab open.
The JMLSG-aligned annual report your regulator asks for under SYSC 6.3 — drawn from your live BWRA, CDD registers, TM alerts, sanctions hits and SAR log. Three days of MLRO drafting compressed into one SMF17 review cycle.
Otto drafts all 15 sections of the JMLSG MLRO Annual from your live registers — BWRA ratings, customer risk, PEPs, TM alerts, sanctions hits, SARs and DAML outcomes — each claim cited to MLR 2017, POCA, SAMLA, the Bribery Act, CFA 2017, UK MAR, JMLSG or the FCG, traceable to source.
The NCA and your regulator both ask the same question on every supervisory visit: show us your disclosures log. Here it is. MLRO-decisioned within 72 hours, cross-referenced to the customer file, and preserved beyond the five-year MLR retention floor.
| Raised by | Disclosure / alert | Date raised | Status |
|---|---|---|---|
|
Amina Okonkwo
Onboarding Analyst · 1LoD
|
Internal SAR: UBO on corporate onboarding declined source-of-wealth question twice; PEP proximity flagged on OFSI rescreen. | Mar 24, 2026 | DAML filed |
|
Rajesh Iyer
TM Analyst · 2LoD
|
Structuring pattern on MID-risk SME: 14 sub-£10k inbound faster payments in 7 days against a £38k historic monthly average. | Mar 12, 2026 | MLRO review |
|
Helena Brandt
Sanctions Officer · 2LoD
|
OFSI 94% fuzzy match on beneficiary account. Name variant on Russia SSI list. Payment quarantined; OFSI notified within 24 hrs. | Feb 27, 2026 | Cleared |
|
Daniel Acheampong
Deputy MLRO · SMF17 cover
|
Tipping-off risk escalation: relationship manager asked about account freeze reason; POCA s333A briefing re-delivered firm-wide. | Feb 14, 2026 | Resolved |
|
Priya Narayanan
Head of Compliance · 2LoD
|
External SAR to NCA: politically exposed client instructed third-country transfer inconsistent with stated wealth source. | Jan 30, 2026 | NCA acknowledged |
MLR 2017 reg 21 and SYSC 6.3 demand personal accountability, not a committee. The MLRO (SMF17) confirms adequacy, the senior manager responsible for financial crime (SMF2) counter-signs, and the CEO (SMF1) attests. Once locked, the report is immutable and reproducible across the NCA’s five-year MLR retention window.
Click once. Otto drafts the 15-section JMLSG MLRO Annual and the REP-CRIM return from your live registers — a signable PDF in a minute, not the usual 3–5 days. Same for the Executive Summary and the FCA Supervisory Readiness dry-run.
Two jobs. It answers any AML, CDD/EDD, PEP, sanctions, SAR or market-abuse question — cited to MLR 2017, POCA, SAMLA, the Bribery Act, CFA 2017, UK MAR, JMLSG or FCG. And it drafts the 15-section MLRO Annual (plus five more formats) from your live registers — your actual PEPs, sanctions hits and SARs.
“When does EDD trigger under MLR 2017 reg 33?” “Is this OFSI hit a true match, and what do we do in 24 hours?” Otto answers from MLR 2017, POCA, SAMLA, the Bribery Act and JMLSG — and your live Financial Crime data — in seconds, with citations.
Otto writes the MLRO Annual, the REP-CRIM return and the Executive Summary from your live registers, and answers any AML, sanctions or SAR question — cited to statute. See it draft your MLRO Annual in a live demo.
Everything you need to know about the MLRO workflow, Otto’s 15-section report, the Gap Analysis, and how the module sits inside MLR 2017, POCA and SAMLA.
We use essential cookies to make the site work, and optional analytics cookies to understand how it's used. See our Cookie Policy.