Anti-Money Laundering & Financial Crime Prevention
Practical AML & Financial Crime Compliance Training for German and EU Regulations
Learn the latest updates to Germany's Anti-Money Laundering Act (GwG) 2026. Understand customer due diligence, SAR reporting via goAML, BaFin guidance, crypto obligations, and regulatory penalties to ensure full compliance.
Practical AML & Financial Crime Compliance Training for German and EU Regulations
Imagine a mid-sized financial services firm in Frankfurt discovers, during a routine internal audit, that it has been onboarding customers without properly verifying beneficial ownership - a clear breach of Germany's Anti-Money Laundering Act. The firm faces a BaFin investigation, a potential fine of up to €5 million, and the very real risk of its managing directors being removed from office. This scenario is no longer hypothetical. Across Germany, regulators are tightening their grip, and compliance failures are becoming costlier than ever.

Germany is one of Europe's most scrutinised jurisdictions when it comes to AML compliance. With the Geldwäschegesetz (GwG) - Germany's central Anti-Money Laundering Act - having undergone significant updates in 2024 and 2025, and further reforms on the horizon in 2026, the stakes for banks, financial institutions, law firms, notaries, accountants, and real estate professionals have never been higher.
For compliance officers, finance professionals, and anyone responsible for AML oversight in Germany, staying current with German money laundering law is not optional- it is a legal obligation. Non-compliance exposes your organisation to severe penalties, reputational damage, and even criminal liability.
This guide provides a comprehensive, up-to-date overview of the German AML legal framework, breaking down the key rules under the GwG, BaFin's latest guidance, FIU reporting obligations, and what your organisation must do to remain compliant in 2026.
Germany's approach to combating money laundering and terrorist financing rests on a layered legal architecture. Understanding this structure is the first step toward effective compliance.
The Geldwäschegesetz (GwG), or German Anti-Money Laundering Act, is the primary legislative instrument governing AML obligations in Germany. Originally enacted in 1993 and fundamentally reformed in 2017 to transpose the EU's 4th Anti-Money Laundering Directive, the GwG has since been continuously amended to reflect evolving EU directives, FATF recommendations, and domestic risk findings.
The most significant recent developments include:
The German AML framework operates through three interconnected pillars:
GwG (Legislation) → BaFin (Supervisory Authority) → FIU (Financial Intelligence Unit) → Obliged Entities (Businesses)
The EU AML Package of 2024 (including the 6th AML Directive and the AML Regulation) further shapes the trajectory of German AML law, with the EU's new Anti-Money Laundering Authority (AMLA) set to assume supervisory responsibilities and issue standardised EU-wide reporting formats from 10 July 2027 onward.

Before exploring your compliance obligations, it is essential to understand the core terminology embedded in the GwG. These definitions determine what is regulated, who is regulated, and what triggers reporting obligations.
Under Section 261 of the German Criminal Code (StGB), money laundering involves concealing, disguising, obtaining, converting, or transferring assets that originate from a criminal offence. The GwG aligns its definition directly with this provision. Critically, following the transposition of the EU's 5th AMLD, all criminal offences can now serve as predicate offences — eliminating the previously restrictive catalogue approach.
Defined in Section 1(2) GwG, terrorist financing means providing or collecting assets knowing they will be used for terrorist acts or organisations. BaFin has recently emphasised that terrorist financing is now treated as a distinct and separate risk from money laundering, requiring dedicated controls.
The beneficial owner is the natural person who ultimately owns or controls a legal entity -generally defined as holding more than 25% of shares or voting rights, or exercising control by other means. Identifying beneficial ownership is a cornerstone of customer due diligence under the GwG.
Where no natural person meets the threshold, the GwG provides for a notional beneficial owner (fiktiv wirtschaftlich Berechtigter) - typically a senior managing director. Importantly, BaFin's 2025 AuA update retained the rule that generally only one notional beneficial owner needs to be identified (a change from the proposed consultation draft).
Germany's Transparenzregister is a publicly accessible register in which legal entities must disclose their beneficial owners. Obliged entities must verify beneficial ownership information against this register as part of their customer due diligence process. Under the proposed ZFG reforms, access rights to the Transparenzregister are being expanded in line with AMLD6 requirements.

The GwG imposes a broad set of obligations on obliged entities (Verpflichtete). These span both financial institutions (banks, insurance companies, investment firms, payment institutions, crypto-asset service providers) and non-financial businesses and professions (notaries, lawyers, accountants, real estate agents, tax advisors, and others listed in Section 2 GwG).
Customer due diligence is the foundation of GwG compliance. Under Sections 10–17 GwG, obliged entities must:
Three levels of due diligence apply depending on risk:

Under Section 43 GwG, obliged entities must file a Suspicious Activity Report (SAR) with the FIU immediately - at the latest by the next working day - upon becoming aware of facts that may indicate money laundering or terrorist financing.
Key rules for SARs include:
The FIU analyses SARs, coordinates with law enforcement and international authorities, and can halt suspicious transactions for up to one month.
Under Section 8 GwG, obliged entities must document all customer due diligence measures and retain records for a minimum of five years following the end of the business relationship or the execution of a transaction. Records must be stored in a manner that is accessible and auditable by competent authorities, including BaFin.
Use the following checklist to assess your organisation's baseline obligations under the GwG:

The risk-based approach is the conceptual backbone of the GwG. It requires obliged entities to tailor the intensity of their AML measures to the actual money laundering and terrorist financing risks they face - rather than applying one-size-fits-all procedures.
Under Section 5 GwG, every obliged entity must prepare and maintain a written risk analysis that identifies and evaluates the risks associated with its:
BaFin's 2025 AuA now specifies a minimum list of information sources that must be used in risk assessments, significantly reducing previous uncertainty. These include national risk analyses, BaFin's own risk publications, and FATF country assessments. The scope and type of the obliged entity's business activities must be factored in, and the risk analysis must be reviewed and updated regularly - particularly when business activities change.
Based on the risk analysis, obliged entities must implement proportionate internal safeguards under Section 6 GwG:
The risk-based approach plays out differently across sectors:
Banks and financial institutions in Frankfurt and other financial centres must contend with complex product suites, cross-border transactions, and direct BaFin supervision. Their risk analyses must be granular, their monitoring automated, and their MLRO functions formally structured.

Non-financial businesses and professions (DNFBPs) - such as notaries, lawyers, auditors, and real estate agents - face a different risk landscape. For example, under the GwGMeldV-Immobilien, notaries and real estate agents must file SARs in real estate transactions involving PEPs, opaque ownership structures, or transactions with unjustified valuations.

Strengthen your AML knowledge with expert-led training. The Anti-Money Laundering & Financial Crime Prevention Course at the German Compliance Institute is designed for compliance professionals, finance teams, and anyone seeking Weiterbildung in AML and financial crime prevention in Germany. Covering GwG obligations, risk-based approaches, SAR filing, and more - it equips you with the practical skills to protect your organisation and advance your career.
Customer Due Diligence (CDD) - known in German as Sorgfaltspflichten - is one of the most operationally demanding pillars of the GwG. It is not a one-time box-ticking exercise. Under the GwG, CDD is a continuous obligation that must be applied at the start of every business relationship and maintained throughout its entire duration.
Before establishing a business relationship or executing a significant transaction, obliged entities must:
Identifying a customer once is not sufficient. Under Section 10(1) No. 5 GwG, obliged entities must continuously monitor business relationships and scrutinise transactions to ensure they are consistent with the entity's knowledge of the customer, their business profile, and risk classification. Where anomalies arise, they must trigger a reassessment - and potentially a suspicious activity report.
BaFin's updated guidance introduced shortened timelines for refreshing customer data. Higher-risk customers must be reviewed more frequently, with BaFin stipulating an implementation deadline of July 2027 for the full roll-out of new update cycle requirements.


Filing Suspicious Activity Reports (SARs) is one of the most critical - and most scrutinised - obligations under the GwG. German regulators have made it unambiguously clear: late, incomplete, or missing SARs will be punished.
Under Section 43(1) GwG, an obliged entity must file a SAR with the German FIU immediately upon becoming aware of facts that - after considering the overall circumstances - indicate the existence of money laundering, terrorist financing, or a related predicate offence. There is no minimum transaction threshold for SAR filing.
The reporting obligation is triggered when there is a factual basis for suspicion — not certainty. Where the facts are not yet sufficient to meet the threshold, the obliged entity must first clarify the facts further, and do so promptly.
From 1 March 2026, all SARs must be submitted exclusively through the goAML digital platform operated by the FIU (GwGMeldV). Post, fax, and manual submissions are no longer permitted.
Step-by-step SAR filing process:
Obliged entities are strictly prohibited from informing the customer, or any third party, that a SAR has been filed or that an investigation is underway (Tipping Off Verbot, Section 47 GwG). Violation of this prohibition is itself a criminal offence
.
The FIU analyses incoming SARs, coordinates with prosecution authorities, and can halt suspicious transactions for up to one month. If no feedback is received within 21 calendar days, enhanced due diligence is no longer mandatory - unless independent indicators of elevated risk remain. For suspected terrorist financing, enhanced due diligence must be maintained for at least 6 months following the SAR, regardless of FIU feedback.
Germany's Transparenzregister (Transparency Register) is a publicly accessible register that records the beneficial owners - the natural persons who ultimately own or control legal entities registered in Germany. Maintained by the Bundesanzeiger Verlag on behalf of the Federal Ministry of Finance, it is a cornerstone instrument of the GwG's anti-money laundering framework.
Legal entities - including GmbHs, AGs, partnerships, foundations, and trusts — are required to report their beneficial owners to the Transparenzregister. A beneficial owner is defined as any natural person who directly or indirectly holds more than 25% of the shares or voting rights, or exercises control by other means.
The quality and completeness of the register continue to improve. From January 2025, identity and verification checks were introduced to ensure only authorised persons can submit entries. Voluntary disclosure of full ownership and control structure overviews is permitted from July 2025, and from January 2027, the place of birth of beneficial owners becomes a mandatory data field.
For obliged entities, the Transparenzregister is not just a reference tool - it is a mandatory checkpoint in the CDD process. When onboarding corporate clients, obliged entities must:
Germany's regulators have demonstrated, with increasing force, that AML non-compliance carries severe financial, reputational, and professional consequences. The era of token fines for procedural breaches is over.
The GwG provides for a tiered penalty structure:
Recent BaFin enforcement actions make the risk landscape unmistakably clear:
|
Year |
Entity |
Fine |
Reason |
|
2023 |
Sofort GmbH |
€150,000 |
Inadequate monitoring controls and failure to identify contractual partners |
|
March 2024 |
Solaris SE |
€6.5 million |
Systematic late filing of suspicious activity reports |
|
May 2024 |
N26 Bank AG |
€9.2 million |
Systematic delays in SAR filing for money laundering cases in 2022 |
|
February 2025 |
Deutsche Bank AG |
€23.05 million |
Regulatory breaches spanning securities, investment advice, and retail banking compliance |
|
October 2025 |
J.P. Morgan SE |
€45 million |
Systemic failure to submit suspicious transaction reports without undue delay (2021–2022) |
The J.P. Morgan case is particularly instructive: the fine was calculated on a turnover-based formula under Section 56(3) GwG, illustrating that for large institutions, a fixed ceiling of €5 million no longer applies — the exposure scales with the size of the business.

The German AML landscape has undergone its most intensive period of regulatory activity in years. Professionals working in compliance must track several parallel developments — all of which carry immediate implementation consequences.
1. Mandatory Digital SAR Reporting via goAML (from 1 March 2026) The GwGMeldV (Reporting Obligation Ordinance) entered into force on 1 March 2026. All SARs must now be submitted exclusively through the FIU's goAML digital system in XML format. Manual submission methods - fax, post, and non-structured electronic communication - are permanently prohibited. Deficiencies in SAR completeness can themselves trigger administrative fines.
2. BaFin's Revised AuA - Effective from February 2025, Updated July 2025 BaFin's comprehensive update to its Interpretation and Application Guidance brought sweeping changes: expanded risk assessment standards, new mandatory minimum information sources, faster customer data update cycles for high-risk clients, and clarified MLRO outsourcing rules. A further amendment in July 2025 introduced mandatory electronic MLRO registration via BaFin's online portal.
3. Crypto-Asset Service Providers: New Scope and EDD Requirements Since December 2024, crypto-asset service providers and certain issuers of asset-referenced tokens have been explicitly brought within the GwG's scope under the Financial Market Digitisation Act. Enhanced due diligence requirements for transfers to or from self-hosted wallet addresses (Section 15a GwG) apply from March 2025.
4. AMLA Operational in Frankfurt (from July 2025) The EU's Anti-Money Laundering Authority (AMLA), headquartered in Frankfurt, became operational in July 2025. AMLA will directly supervise approximately 40 high-risk financial institutions (including major crypto service providers) from 2028, and will develop EU-wide standardised AML reporting formats that will ultimately supersede the GwGMeldV from 10 July 2027.
5. ZFG Draft Reform - Under Consultation in 2026 Germany's Federal Ministry of Finance published the draft Customs Financial Integrity Act (Zollfinanzgerechtigkeitsgesetz – ZFG) on 3 March 2026. Key proposed changes include:
6. Heightened BaFin Supervision - More On-Site Inspections BaFin has intensified its on-site AML inspection programme across the financial sector. Inspection findings have consistently highlighted weaknesses in risk analysis documentation, customer data update processes, and SAR filing practices. Institutions in the crypto, fintech, and payments sectors are under particularly heightened supervisory scrutiny heading into 2026.

Germany's AML legal framework has never been more demanding - or more actively enforced. The events of 2024 and 2025 made that clear: regulators fined the country's largest banks tens of millions of euros, expanded the obligations of crypto-asset providers, tightened SAR filing standards, and digitised the entire reporting infrastructure ahead of the March 2026 goAML mandate.
For compliance officers, finance professionals, auditors, and anyone working within or alongside Germany's financial system, the message is unambiguous: GwG compliance is not optional, not a back-office function, and not a set-and-forget programme. It is a live, continuously evolving obligation that demands structured processes, properly documented risk assessments, trained staff, and - above all - a culture that treats financial crime prevention as a genuine priority.

Whether you are new to compliance, looking to formalise your knowledge, or seeking structured Weiterbildung in anti-money laundering, the Anti-Money Laundering & Financial Crime Prevention Course by the German Compliance Institute equips you with everything you need.
Covering the full GwG framework, BaFin expectations, SAR filing obligations, risk-based approaches, and the latest 2026 regulatory updates — this course is purpose-built for compliance professionals, bank employees, auditors, finance teams, and anyone working in a regulated environment in Germany.