Germany enforces one of the most rigorous anti-money laundering and know-your-customer regimes in the European Union. The German Money Laundering Act - the Geldwäschegesetz, or GwG - sets out binding obligations for a broad range of businesses, from banks and payment institutions to real estate agents and notaries. Non-compliance carries substantial administrative fines and, in serious cases, criminal liability. This guide covers the legal framework, the obligations it imposes, the supervisory landscape, recent legislative developments, and the practical steps businesses must take to remain compliant with AML and KYC requirements in Germany.
The primary statute is the Geldwäschegesetz (GwG), which transposes successive EU Anti-Money Laundering Directives into German law. Germany has implemented the Fourth, Fifth, and Sixth EU AML Directives, each expanding the scope of obliged entities and tightening due diligence standards. The GwG is supplemented by sector-specific regulations issued by the Federal Financial Supervisory Authority - BaFin - and by guidance from the Financial Intelligence Unit (FIU), which operates under the Federal Customs Administration.
The GwG applies to a wide category of obliged entities. These include:
Each category faces obligations calibrated to the money laundering and terrorist financing risks inherent in its business model. The GwG requires obliged entities to conduct customer due diligence, maintain records, appoint a money laundering compliance officer, and file suspicious activity reports with the FIU.
Germany is also a member of the Financial Action Task Force (FATF), the intergovernmental body that sets global AML and counter-terrorist financing standards. Germany';s compliance with FATF recommendations is subject to periodic mutual evaluation, and the results of those evaluations directly influence domestic regulatory priorities.
Know-your-customer requirements under the GwG are structured around three tiers of due diligence: simplified, standard, and enhanced. The appropriate tier depends on the assessed risk profile of the customer, the transaction, and the business relationship.
Standard customer due diligence applies to the majority of business relationships. It requires obliged entities to identify the customer using reliable, independent source documents, verify the identity of any beneficial owner holding more than 25 percent of shares or voting rights, understand the purpose and intended nature of the business relationship, and conduct ongoing monitoring of transactions.
Simplified due diligence is permitted only where the risk of money laundering or terrorist financing is demonstrably low. BaFin guidance specifies the circumstances in which simplified measures may be applied, and entities must document their reasoning carefully. A common mistake is treating simplified due diligence as a default rather than an exception.
Enhanced due diligence is mandatory in higher-risk situations. These include business relationships with customers from high-risk third countries identified by the European Commission, transactions involving politically exposed persons (PEPs), and complex or unusually large transactions with no apparent economic purpose. For PEPs, enhanced measures include senior management approval for establishing or continuing the relationship, and ongoing enhanced monitoring.
In practice, the identification of beneficial owners is one of the most operationally demanding aspects of KYC in Germany. Corporate customers must provide documentation tracing the ownership chain to the ultimate natural person. Where no natural person can be identified above the 25 percent threshold, the senior managing official is treated as the beneficial owner by default - a rule that catches many foreign founders off guard.
Germany operates a Transparency Register (Transparenzregister) under the GwG, which records the beneficial owners of legal entities established in Germany. Since a recent legislative reform, the Transparency Register has become a full register: entities can no longer rely on information being available in other public registers such as the Commercial Register to satisfy their disclosure obligation. Every obliged legal entity must now make a direct entry.
Obliged entities must verify beneficial ownership information against the Transparency Register as part of their KYC process. Discrepancies between the information provided by a customer and the register entry must be reported to the body administering the register. This creates a practical compliance loop: KYC checks feed into register oversight, and register data informs ongoing monitoring.
Failure to register beneficial ownership information, or providing inaccurate data, exposes the entity and its managing directors to administrative fines. BaFin and the Federal Office of Administration (Bundesverwaltungsamt), which administers the Transparency Register, have both increased enforcement activity in recent periods. Many smaller businesses and foreign-owned subsidiaries underestimate the ongoing obligation to update the register when ownership structures change.
For foreign businesses operating in Germany through a branch or subsidiary, the obligation extends to the German entity. A non-obvious requirement is that changes in the beneficial ownership of a foreign parent company can trigger an update obligation for the German subsidiary, even if the German entity itself has not changed.
If you are uncertain whether your entity';s current Transparency Register entry is accurate and complete, we can assist with a compliance review. Contact us at info@vlolawfirm.com.
The Financial Intelligence Unit (FIU) - Zentralstelle für Finanztransaktionsuntersuchungen - is Germany';s central body for receiving, analysing, and disseminating suspicious activity reports (SARs). It operates within the General Customs Directorate and processes a substantial volume of reports each year.
Obliged entities must file a SAR with the FIU whenever they know, suspect, or have reasonable grounds to suspect that a transaction or business relationship involves the proceeds of a criminal offence or is connected to terrorist financing. The obligation to report arises regardless of the amount involved. Filing a SAR does not require certainty; a reasonable suspicion is sufficient.
A critical procedural rule is the tipping-off prohibition. Once a SAR has been filed, the obliged entity must not inform the customer or any third party that a report has been made or that an investigation is underway. Breach of this prohibition is itself a criminal offence under the GwG.
In practice, many obliged entities - particularly those outside the financial sector - underestimate the breadth of the reporting obligation. Real estate agents, notaries, and dealers in high-value goods are all subject to the same reporting duty as banks, yet compliance rates in these sectors have historically been lower. BaFin and sector-specific supervisors have intensified their scrutiny of non-financial obliged entities as a result.
After filing a SAR, the obliged entity must generally wait three business days before executing the transaction, unless the FIU instructs otherwise or the delay is not possible without arousing suspicion. This waiting period is a practical operational consideration that businesses in fast-moving sectors must plan for.
The GwG requires obliged entities above a certain size threshold to establish internal controls proportionate to the nature and scale of their business. These controls must include a documented risk assessment, written internal policies and procedures, an employee training programme, and the appointment of a dedicated money laundering compliance officer (Geldwäschebeauftragter).
The compliance officer must be appointed at management level and must have the authority and resources to carry out their function effectively. BaFin has issued detailed guidance on the qualifications and responsibilities expected of compliance officers in the financial sector. For non-financial obliged entities, sector-specific supervisory bodies - such as the relevant chamber of notaries or the state-level supervisory authority for real estate agents - set equivalent standards.
The internal risk assessment is the foundation of the entire compliance programme. It must identify the money laundering and terrorist financing risks specific to the entity';s customer base, products, services, delivery channels, and geographic exposure. The assessment must be reviewed and updated regularly, and whenever there is a material change in the business. A common mistake is producing a risk assessment as a one-time exercise and then failing to update it when the business expands into new markets or product lines.
Employee training is a mandatory component. Staff who deal with customers or handle transactions must be trained to recognise suspicious indicators and understand their reporting obligations. Training records must be maintained and made available to supervisors on request. Many businesses treat training as a box-ticking exercise; supervisors increasingly look for evidence that training is substantive and tailored to the entity';s actual risk profile.
For smaller obliged entities - such as sole-practitioner lawyers or small real estate agencies - the GwG allows for proportionate measures, but does not exempt them from the core obligations. In practice, founders should consider whether their current compliance arrangements would withstand a supervisory inspection.
Germany';s AML and KYC landscape is in a period of significant transition, driven by the EU';s comprehensive AML reform package. The package includes a directly applicable EU AML Regulation, which will replace the current directive-based approach and create uniform rules across all member states, and a new directive establishing a harmonised supervisory framework.
The EU AML Regulation will apply directly in Germany without the need for national transposition. This means that some provisions of the GwG will be superseded, while others will remain in force to address matters outside the regulation';s scope. German businesses should expect a period of regulatory adjustment as the national framework is aligned with the new EU rules.
A new EU-level supervisory authority - the Anti-Money Laundering Authority, known as AMLA - is being established to directly supervise the highest-risk obliged entities across the EU, including certain credit institutions and crypto-asset service providers. For entities that fall within AMLA';s direct supervisory perimeter, the primary supervisory relationship will shift from BaFin to AMLA, though BaFin will retain responsibility for the broader population of German obliged entities.
The EU AML Regulation also introduces stricter rules on cash payments, tightening the threshold for mandatory due diligence on large cash transactions. Germany, which has historically had a strong cash culture, will need to adapt business practices in sectors such as retail, hospitality, and luxury goods.
For crypto-asset service providers, the regulatory perimeter has expanded significantly. Providers operating in Germany must register with BaFin and comply with full AML and KYC obligations equivalent to those applied to traditional financial institutions. Recent enforcement actions by BaFin signal that this sector is under close supervisory scrutiny.
Businesses operating in Germany should review their compliance programmes now to identify gaps relative to the incoming EU rules. We advise international clients on navigating both the current GwG framework and the transition to the new EU AML regime. Contact us at info@vlolawfirm.com to discuss your specific situation.
What triggers enhanced due diligence for a business relationship in Germany?
Enhanced due diligence is required under the GwG whenever a business relationship or transaction presents a higher risk of money laundering or terrorist financing. Specific triggers include customers or transactions connected to countries on the European Commission';s list of high-risk third countries, business relationships involving politically exposed persons, and transactions that are complex, unusually large, or have no apparent economic rationale. In these cases, obliged entities must obtain additional information about the customer and the source of funds, seek senior management approval, and apply heightened ongoing monitoring. The obligation is not discretionary; failure to apply enhanced measures in a high-risk situation is itself a compliance breach that supervisors actively look for during inspections.
How long does it take to set up a compliant AML and KYC programme in Germany, and what does it cost?
The timeline and cost depend heavily on the size and complexity of the business. A small obliged entity - such as a boutique real estate agency or a single-partner law firm - can implement a proportionate compliance framework within a few weeks if it engages experienced advisers from the outset. Larger financial institutions or multi-entity groups typically require several months to complete a full risk assessment, draft internal policies, train staff, and appoint a qualified compliance officer. Professional fees for setting up a compliance programme vary widely; smaller entities should budget at least a few thousand euros for advisory and documentation work, while larger organisations face materially higher costs. Ongoing costs include annual training, periodic risk assessment updates, and compliance officer time.
Can a foreign company operating in Germany rely on KYC checks performed in its home country?
In limited circumstances, yes. The GwG permits obliged entities to rely on customer due diligence carried out by a third party, provided that third party is itself subject to equivalent AML obligations and supervision in a jurisdiction recognised as having adequate standards. However, the obliged entity in Germany retains full legal responsibility for the adequacy of the due diligence, even when relying on a third party. If the third party';s checks are later found to be deficient, the German entity bears the regulatory consequences. In practice, reliance arrangements must be documented carefully, and the German entity must be able to obtain the underlying due diligence information from the third party on request. Many foreign businesses underestimate the documentation burden this creates.
Germany';s AML and KYC framework is comprehensive, actively enforced, and currently undergoing significant reform driven by EU-level legislation. Obliged entities - whether financial institutions, professional service providers, or businesses in high-risk sectors - must maintain robust compliance programmes, keep Transparency Register entries current, and prepare for the transition to the new EU AML Regulation and AMLA supervision.
VLO Law Firms advises international clients on AML and KYC compliance in Germany. We can assist with risk assessments, compliance programme design, Transparency Register filings, suspicious activity reporting procedures, and preparation for supervisory inspections. To request a consultation, contact: info@vlolawfirm.com