Compliance

Can One Person Be Both Compliance Officer and MLRO?

Regulation 5.2 lets a PVARA applicant combine Compliance Officer and MLRO where justified by size and complexity — here is what that actually means.

Small and early-stage applicants for a PVARA no objection certificate often ask whether they really need two separate, full-time senior compliance roles from day one. For one specific pairing of roles, the Regulations give a direct answer — but it comes with conditions that are easy to misread.

This piece explains what Regulation 5.2 of the NOC Regulations permits, what “justified by size and complexity” is likely to mean in practice, and why this flexibility does not extend to the other six Key Individual roles.

Can a PVARA applicant combine the Compliance Officer and MLRO roles?

Yes. Regulation 5.2 of the PVARA No Objection Certificate Regulations 2025 states plainly that the functions of Compliance Officer and Money Laundering Reporting Officer (“MLRO”) “may be combined where justified by the size and complexity of the applicant.” This is the only role-combination provision stated anywhere in the Regulations’ Key Individual requirements.

“5.2 The functions of Compliance Officer and MLRO may be combined where justified by the size and complexity of the applicant.”

The provision sits immediately after Regulation 5.1, which lists the eight key individual roles an applicant must maintain — Chief Executive Officer, Director, Chief Financial Officer, Compliance Officer, MLRO, Head of Internal Audit, Head of Risk Management and Head of Information Security. Regulation 5.2 is a narrow exception carved out of that list, not a general rule about combining roles.

What does “justified by the size and complexity of the applicant” actually mean?

The Regulations do not define a threshold — no headcount figure, no transaction volume, no revenue level — at which combination becomes justified or stops being justified. Regulation 4.1 uses similar language elsewhere, requiring governance arrangements to be “proportionate the nature, scale and complexity” of the applicant’s operations, which suggests the two provisions are meant to be read together as part of the same proportionality principle running through the Regulations.

In practice, our reading is that a smaller applicant offering a narrower scope of AML-Registered Services — for example, a single custody or broker-dealer operation with a limited customer base — has a stronger case for combining the two roles than a larger, multi-service applicant with higher transaction volumes and a broader risk footprint. Where guidance has not been issued specifying an exact size threshold, applicants should treat this as a case-by-case justification they need to make affirmatively in their application, not an entitlement they can assume applies to them.

What does the applicant actually have to submit if it wants to combine the roles?

The Regulations do not prescribe a separate form specifically for requesting combination. Form A1, Section 3.2 requires the applicant to list Key Individuals including both the Compliance Officer and MLRO roles — if one person holds both, the application would need to reflect that clearly, together with a Form A3 Fit & Proper Questionnaire covering both functions for that individual.

Section 3.3 of Form A1 additionally asks the applicant to “list any other senior roles… and provide brief descriptions of their responsibilities.” Our reading is that where the roles are combined, the applicant’s business model description required under Form A1 Section 2.5 is the natural place to set out the justification contemplated by Regulation 5.2 — explaining why the applicant’s size and complexity supports a combined role, rather than leaving PVARA to infer it from the organisational chart alone. The Regulations do not confirm this is the required mechanism, so applicants should confirm the expected format for making this case directly with PVARA.

What are the practical duties that would sit with a combined Compliance Officer / MLRO?

Even combined into one person, the underlying obligations attached to each function do not shrink. The Compliance Officer side of the role carries responsibility for the AML/CFT framework required under Regulation 8.2 — the Board-approved AML/CFT policy, customer due diligence and enhanced due diligence procedures, targeted financial sanctions screening, transaction monitoring, recordkeeping and training. Form A5, the Outsourcing Declaration & Register, must specifically be completed and signed by “the Compliance Officer of the Applicant.”

The MLRO side carries the reporting-specific duties: filing suspicious transaction reports and currency transaction reports under Regulation 11.2 and 11.3, making the determination on Form A7 — the Internal Suspicious Activity Report — on whether to file an STR, and jointly signing Form A4 and Form A6 alongside the CEO. A combined role holder is accountable for both sets of duties simultaneously, which is precisely why the Regulations frame combination as something that must be “justified,” rather than a default cost-saving option.

Function Key duties that remain even if combined
Compliance Officer side Board-approved policy oversight, CDD/EDD procedures, outsourcing register (Form A5), training programme
MLRO side STR/CTR filing decisions, ISAR determinations (Form A7), goAML reporting-entity responsibilities

Does combining Compliance Officer and MLRO affect who assesses fitness and propriety?

No — the split of responsibility set out in Section 20 of the Virtual Assets Act 2026 does not change based on whether the roles are combined. Section 20(1) reserves direct assessment to PVARA only for the Controller, Sponsor, Chief Executive Officer and Director. The Compliance Officer and MLRO — combined or not — fall within Section 20(2), meaning it remains “the responsibility of the applicant for a licence or the Licensee to assess and maintain” that individual’s fitness and propriety, backed by a written undertaking to PVARA.

A combined role holder is still subject to the same automatic disqualifiers set out in Regulation 6.3 of the NOC Regulations — conviction for an offence involving dishonesty, fraud, financial misconduct or a breach of the Anti-Money Laundering Act 2010, sanction by a regulatory body, or undischarged bankruptcy or insolvency — and to interview by PVARA under Regulation 16.2 if the Authority chooses to exercise that power.

Can other Key Individual roles be combined the same way?

The Regulations do not say so. Regulation 5.2 is worded narrowly, referring only to “the functions of Compliance Officer and MLRO.” No equivalent provision appears for combining, for example, Head of Risk Management with Head of Internal Audit, or Chief Financial Officer with any other role.

In practice, this suggests PVARA sees the Compliance Officer/MLRO pairing as functionally closer than the other six roles — both sit within the same AML/CFT reporting chain, whereas internal audit is meant to provide independent assurance over the very functions compliance and risk management perform, which is a structural reason regulators in many jurisdictions keep audit separate. Our reading is that combining internal audit with any operational compliance function would run against the purpose of having an independent audit function at all, even though the Regulations do not say this explicitly. Applicants considering any combination outside the one expressly permitted in Regulation 5.2 should raise it directly with PVARA rather than assume silence in the Regulations means it is allowed.

About this analysis

This analysis was prepared by the CoinConnect research desk from the PVARA No Objection Certificate Regulations 2025 — principally Regulations 4.1, 5.1, 5.2, 6.3, 8.2, 11.2, 11.3 and 16.2, and Forms A1, A3, A4, A5, A6 and A7 in Annex A — read alongside Section 20 of the Virtual Assets Act 2026, as published.

Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.

Entering Pakistan's crypto market?

CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.

Visit CoinConnect