Business Strategy

German Money Laundering Law (GwG) Explained: Key Rules You Must Know (2026 Edition)

MC
Md Tahmid Chowdhury
May 21, 2026
  • 24 mins read
A German bank employee verifying a client’s ID documents at a desk with forms, pen, stamp, and computer in a modern office.
In this article

Learn the latest updates to Germany's Anti-Money Laundering Act (GwG) 2026. Understand customer due diligence, SAR reporting via goAML, BaFin guidance, crypto obligations, and regulatory penalties to ensure full compliance. 

Introduction

Imagine a mid-sized financial services firm in Frankfurt discovers, during a routine internal audit, that it has been onboarding customers without properly verifying beneficial ownership - a clear breach of Germany's Anti-Money Laundering Act. The firm faces a BaFin investigation, a potential fine of up to €5 million, and the very real risk of its managing directors being removed from office. This scenario is no longer hypothetical. Across Germany, regulators are tightening their grip, and compliance failures are becoming costlier than ever.

 

Infographic showing money laundering process from dirty to clean money using a washing machine metaphor.

Germany is one of Europe's most scrutinised jurisdictions when it comes to AML compliance. With the Geldwäschegesetz (GwG) - Germany's central Anti-Money Laundering Act - having undergone significant updates in 2024 and 2025, and further reforms on the horizon in 2026, the stakes for banks, financial institutions, law firms, notaries, accountants, and real estate professionals have never been higher.

For compliance officers, finance professionals, and anyone responsible for AML oversight in Germany, staying current with German money laundering law is not optional- it is a legal obligation. Non-compliance exposes your organisation to severe penalties, reputational damage, and even criminal liability.

This guide provides a comprehensive, up-to-date overview of the German AML legal framework, breaking down the key rules under the GwG, BaFin's latest guidance, FIU reporting obligations, and what your organisation must do to remain compliant in 2026.

Overview of the German AML Legal Framework

Germany's approach to combating money laundering and terrorist financing rests on a layered legal architecture. Understanding this structure is the first step toward effective compliance.

The Core Statute: Geldwäschegesetz (GwG)

The Geldwäschegesetz (GwG), or German Anti-Money Laundering Act, is the primary legislative instrument governing AML obligations in Germany. Originally enacted in 1993 and fundamentally reformed in 2017 to transpose the EU's 4th Anti-Money Laundering Directive, the GwG has since been continuously amended to reflect evolving EU directives, FATF recommendations, and domestic risk findings.

The most significant recent developments include:

  • BaFin's revised Interpretation and Application Guidance (Auslegungs- und Anwendungshinweise, "AuA"), published on 29 November 2024 and effective from 1 February 2025, which introduced expanded obligations around risk assessments, documentation, and suspicious activity reporting.
  • The GwGMeldV (Regulation on Reporting Obligations), published on 1 September 2025, which entered into force on 1 March 2026, mandating fully digital submission of suspicious activity reports via the FIU's goAML system.
  • The Customs Financial Integrity Act (Zollfinanzgerechtigkeitsgesetz – ZFG), a draft reform bill published by the Federal Ministry of Finance on 3 March 2026, which proposes further structural amendments to the GwG, including expanded scope for obliged entities.

The Regulatory Architecture

The German AML framework operates through three interconnected pillars:

GwG (Legislation)BaFin (Supervisory Authority)FIU (Financial Intelligence Unit)Obliged Entities (Businesses)

  • BaFin (Bundesanstalt für Finanzdienstleistungsaufsicht) is Germany's Federal Financial Supervisory Authority. It supervises financial institutions' compliance with the GwG and issues binding interpretive guidance (AuA).
  • The FIU (Zentralstelle für Finanztransaktionsuntersuchungen), hosted within the General Directorate of Customs (Generalzolldirektion), receives, analyses, and forwards suspicious activity reports to prosecution authorities.
  • Obliged entities - including banks, insurance companies, crypto-asset service providers, lawyers, notaries, auditors, and real estate agents — must implement AML measures in line with GwG requirements.

The EU AML Package of 2024 (including the 6th AML Directive and the AML Regulation) further shapes the trajectory of German AML law, with the EU's new Anti-Money Laundering Authority (AMLA) set to assume supervisory responsibilities and issue standardised EU-wide reporting formats from 10 July 2027 onward.

 

Diagram showing Germany's AML regulatory framework: law (GwG) → supervisor (BaFin) → reporting (FIU) → obliged entities (banks, lawyers, real estate, crypto), with timeline of key amendments for 2024, 2025, and 2026.


Key Definitions Under the GwG

Before exploring your compliance obligations, it is essential to understand the core terminology embedded in the GwG. These definitions determine what is regulated, who is regulated, and what triggers reporting obligations.

Money Laundering (Geldwäsche)

Under Section 261 of the German Criminal Code (StGB), money laundering involves concealing, disguising, obtaining, converting, or transferring assets that originate from a criminal offence. The GwG aligns its definition directly with this provision. Critically, following the transposition of the EU's 5th AMLD, all criminal offences can now serve as predicate offences — eliminating the previously restrictive catalogue approach.

Terrorist Financing (Terrorismusfinanzierung)

Defined in Section 1(2) GwG, terrorist financing means providing or collecting assets knowing they will be used for terrorist acts or organisations. BaFin has recently emphasised that terrorist financing is now treated as a distinct and separate risk from money laundering, requiring dedicated controls.

Beneficial Owner (Wirtschaftlich Berechtigter)

The beneficial owner is the natural person who ultimately owns or controls a legal entity -generally defined as holding more than 25% of shares or voting rights, or exercising control by other means. Identifying beneficial ownership is a cornerstone of customer due diligence under the GwG.

Where no natural person meets the threshold, the GwG provides for a notional beneficial owner (fiktiv wirtschaftlich Berechtigter) - typically a senior managing director. Importantly, BaFin's 2025 AuA update retained the rule that generally only one notional beneficial owner needs to be identified (a change from the proposed consultation draft).

Transparency Register (Transparenzregister)

Germany's Transparenzregister is a publicly accessible register in which legal entities must disclose their beneficial owners. Obliged entities must verify beneficial ownership information against this register as part of their customer due diligence process. Under the proposed ZFG reforms, access rights to the Transparenzregister are being expanded in line with AMLD6 requirements.

Cheat sheet showing key AML definitions under Germany's GwG: Money Laundering, Terrorist Financing, Beneficial Owner, and Transparenzregister.

AML Obligations for Businesses

The GwG imposes a broad set of obligations on obliged entities (Verpflichtete). These span both financial institutions (banks, insurance companies, investment firms, payment institutions, crypto-asset service providers) and non-financial businesses and professions (notaries, lawyers, accountants, real estate agents, tax advisors, and others listed in Section 2 GwG).

 

1. Customer Due Diligence (CDD) — Sorgfaltspflichten

Customer due diligence is the foundation of GwG compliance. Under Sections 10–17 GwG, obliged entities must:

  • Identify and verify the identity of customers and, where applicable, beneficial owners using original or equivalent documents (Section 12 ff. GwG). BaFin has clarified that verification documents must be available in the original unless a legal exception applies.
  • Understand the purpose and nature of the business relationship.
  • Continuously monitor business relationships and update customer data on a risk-proportionate basis. BaFin's 2025 AuA introduced shortened deadlines for updating customer information for higher-risk customers.
  • Identify the beneficial owner and take reasonable steps to verify their identity. For legal entities, this includes checking the Transparenzregister. BaFin now also requires obliged entities to identify the country of residence of the beneficial owner on a risk-based basis.

Three levels of due diligence apply depending on risk:

Table showing three levels of customer due diligence under Germany's GwG: Simplified CDD for low-risk, Standard CDD for most business, and Enhanced CDD for high-risk customers and transactions.

2. Reporting Obligations: Suspicious Activity Reports (SARs)

Under Section 43 GwG, obliged entities must file a Suspicious Activity Report (SAR) with the FIU immediately - at the latest by the next working day - upon becoming aware of facts that may indicate money laundering or terrorist financing.

Key rules for SARs include:

  • Duty to stand still: Once a SAR is filed, the transaction may generally not be executed until either the FIU or public prosecutor's office provides consent, or three working days have passed without prohibition (Section 46(1) GwG).
  • From 1 March 2026, all SARs must be submitted exclusively through the goAML digital platform provided by the FIU (GwGMeldV). Postal, fax, or manual submission methods are no longer permitted. Reports must be submitted in machine-readable XML format, and attachments must be electronically searchable.
  • Enhanced due diligence after a SAR: Where a SAR is filed and the FIU does not provide feedback within 21 calendar days, enhanced due diligence is no longer mandatory. However, for cases involving suspected terrorist financing, enhanced due diligence must be maintained for at least 6 months following the SAR.

The FIU analyses SARs, coordinates with law enforcement and international authorities, and can halt suspicious transactions for up to one month.

 

3. Record-Keeping (Aufzeichnungs- und Aufbewahrungspflichten)

Under Section 8 GwG, obliged entities must document all customer due diligence measures and retain records for a minimum of five years following the end of the business relationship or the execution of a transaction. Records must be stored in a manner that is accessible and auditable by competent authorities, including BaFin.

 

4. Compliance Checklist for Businesses

Use the following checklist to assess your organisation's baseline obligations under the GwG:

  • Scope check: Is your business or profession listed as an obliged entity under Section 2 GwG?
  • CDD procedures: Do you have documented processes for identifying customers and beneficial owners?
  • Risk assessment: Have you conducted a written risk analysis tailored to your customer base and business activities?
  • Transparenzregister: Do you query the transparency register as part of your CDD process?
  • SAR procedure: Is there a clear internal process for filing SARs via goAML?
  • Record-keeping: Are records of CDD measures retained for at least five years?
  • MLRO appointment: Have you appointed a Money Laundering Reporting Officer (if required)?
  • Employee training: Is AML training provided regularly to relevant staff?

 

Diagram showing AML obligations for businesses: Customer Due Diligence flow, Suspicious Activity Report filing flow, and a compliance checklist including CDD procedures, risk assessment, MLRO, training, and SAR process.

Risk-Based Approach and AML Policies

The risk-based approach is the conceptual backbone of the GwG. It requires obliged entities to tailor the intensity of their AML measures to the actual money laundering and terrorist financing risks they face - rather than applying one-size-fits-all procedures.

Conducting a Risk Assessment (Risikoanalyse)

Under Section 5 GwG, every obliged entity must prepare and maintain a written risk analysis that identifies and evaluates the risks associated with its:

  • Customer base (types, sectors, geographic origin)
  • Products and services offered
  • Transaction volumes and channels
  • Geographic exposure (e.g., dealings with high-risk third countries)

BaFin's 2025 AuA now specifies a minimum list of information sources that must be used in risk assessments, significantly reducing previous uncertainty. These include national risk analyses, BaFin's own risk publications, and FATF country assessments. The scope and type of the obliged entity's business activities must be factored in, and the risk analysis must be reviewed and updated regularly - particularly when business activities change.

Internal Safeguards (Interne Sicherungsmaßnahmen)

Based on the risk analysis, obliged entities must implement proportionate internal safeguards under Section 6 GwG:

  • Appointment of a Money Laundering Reporting Officer (MLRO): Required for most financial institutions. The MLRO must be based in Germany and carry out their activities domestically. Notably, from July 2025, MLRO notifications to BaFin must be submitted electronically via the BaFin notification and publication portal.
  • Internal policies, controls, and procedures: Written AML policies covering customer acceptance, CDD, SAR filing, and escalation procedures.
  • Employee screening: Reliability checks for relevant staff. BaFin has clarified that outsourcing the assessment of employee reliability always qualifies as outsourcing of a critical or important function, requiring compliance with EBA and MaRisk outsourcing requirements.
  • Employee training: Regular and documented AML training for all relevant staff. This is a mandatory obligation, not a best practice.
  • IT and data systems: Adequate transaction monitoring systems and the technical ability to submit SARs via goAML.

 

AML for Banks vs Non-Financial Institutions

The risk-based approach plays out differently across sectors:

Banks and financial institutions in Frankfurt and other financial centres must contend with complex product suites, cross-border transactions, and direct BaFin supervision. Their risk analyses must be granular, their monitoring automated, and their MLRO functions formally structured.

 

Walter White from Breaking Bad negotiating with a bank officer over a briefcase full of cash, illustrating money laundering and suspicious transactions

 

Non-financial businesses and professions (DNFBPs) - such as notaries, lawyers, auditors, and real estate agents - face a different risk landscape. For example, under the GwGMeldV-Immobilien, notaries and real estate agents must file SARs in real estate transactions involving PEPs, opaque ownership structures, or transactions with unjustified valuations.

 

List of seven actionable steps for implementing a risk-based AML framework, including risk analysis, customer classification, MLRO appointment, AML policies, staff training, SAR process testing, and ongoing review of risk and CDD procedures.

                  

Strengthen your AML knowledge with expert-led training. The Anti-Money Laundering & Financial Crime Prevention Course at the German Compliance Institute is designed for compliance professionals, finance teams, and anyone seeking Weiterbildung in AML and financial crime prevention in Germany. Covering GwG obligations, risk-based approaches, SAR filing, and more - it equips you with the practical skills to protect your organisation and advance your career.

Customer Due Diligence and Ongoing Monitoring

Customer Due Diligence (CDD) - known in German as Sorgfaltspflichten - is one of the most operationally demanding pillars of the GwG. It is not a one-time box-ticking exercise. Under the GwG, CDD is a continuous obligation that must be applied at the start of every business relationship and maintained throughout its entire duration.

 

Identifying and Verifying Clients

Before establishing a business relationship or executing a significant transaction, obliged entities must:

  1. Collect identifying data - full name, date of birth, nationality, and address for natural persons; company name, legal form, registered address, and registration number for legal entities.
  2. Verify identity using original documents — typically a government-issued ID or passport for individuals, and commercial register excerpts (Handelsregisterauszug) for companies. BaFin's updated AuA (effective February 2025) confirmed that verification documents must be available in the original, unless a specific legal exception applies.
  3. Identify and verify the beneficial owner (wirtschaftlich Berechtigter) — the natural person who ultimately owns or controls the customer, generally at a 25% threshold. This includes checking the Transparenzregister and, where relevant, the country of residence of the beneficial owner.
  4. Assess Politically Exposed Persons (PEPs) - individuals holding or having held prominent public positions require enhanced due diligence regardless of their formal risk classification.

 

Ongoing Transaction Monitoring

Identifying a customer once is not sufficient. Under Section 10(1) No. 5 GwG, obliged entities must continuously monitor business relationships and scrutinise transactions to ensure they are consistent with the entity's knowledge of the customer, their business profile, and risk classification. Where anomalies arise, they must trigger a reassessment - and potentially a suspicious activity report.

BaFin's updated guidance introduced shortened timelines for refreshing customer data. Higher-risk customers must be reviewed more frequently, with BaFin stipulating an implementation deadline of July 2027 for the full roll-out of new update cycle requirements.

 

Diagram showing the CDD lifecycle and ongoing monitoring: Onboarding → Verification → Monitoring → Update → Escalation → SAR Trigger, with automation tips including KYC software, risk-tiering, automated alerts, and audit log

 

Tips for Efficient CDD Implementation

  • Automate where possible: Use KYC software and document verification tools to manage high customer volumes, especially for identity checks and sanctions screening.
  • Risk-tier your customers: Not every customer needs the same level of scrutiny. Invest heavily in high-risk cases and streamline low-risk onboarding.
  • Document everything: BaFin's on-site inspections have revealed widespread deficiencies in documentation. If it isn't written down and auditable, it does not exist in regulators' eyes.
  • Build review triggers: Set automated alerts for life events, transaction anomalies, PEP matches, sanctions list hits, and inconsistency notices from the Transparenzregister.

 

Flowchart of the CDD process: New customer → Collect data → Verify identity → Verify beneficial owner → Assess PEP/sanctions → Risk classification → Apply due diligence → Ongoing monitoring → SAR reporting via goAML if suspicion arises.

Suspicious Activity Reporting & FIU Guidelines

Filing Suspicious Activity Reports (SARs) is one of the most critical - and most scrutinised - obligations under the GwG. German regulators have made it unambiguously clear: late, incomplete, or missing SARs will be punished.

When Must You Report?

Under Section 43(1) GwG, an obliged entity must file a SAR with the German FIU immediately upon becoming aware of facts that - after considering the overall circumstances - indicate the existence of money laundering, terrorist financing, or a related predicate offence. There is no minimum transaction threshold for SAR filing.

The reporting obligation is triggered when there is a factual basis for suspicion — not certainty. Where the facts are not yet sufficient to meet the threshold, the obliged entity must first clarify the facts further, and do so promptly.

Common SAR Triggers in German Practice

  • Large or structurally unusual cash transactions with no clear economic justification
  • Customers providing inconsistent or implausible explanations for transactions
  • Discrepancies between declared business activity and actual transaction patterns
  • Transactions involving high-risk jurisdictions flagged by FATF or the EU
  • Inconsistency notices received from the Transparenzregister regarding beneficial ownership
  • Transactions involving Politically Exposed Persons (PEPs) or their close associates
  • Real estate transactions with inflated purchase prices, PEP involvement, or opaque structures (GwGMeldV-Immobilien)
  • Unusual activity in crypto-asset accounts or transfers to/from self-hosted wallet addresses

 

How to File: The goAML System

From 1 March 2026, all SARs must be submitted exclusively through the goAML digital platform operated by the FIU (GwGMeldV). Post, fax, and manual submissions are no longer permitted.

Step-by-step SAR filing process:

  1. Identify the suspicion - document the facts and the reasoning that triggered the threshold for suspicion.
  2. Complete the SAR form - enter all required data directly into the goAML system or submit in XML format. Key data fields include: persons involved, accounts, transactions, and a clear narrative description of the suspicious activity. Do not bury critical information in attachments — relevant facts must be entered directly into the report.
  3. Submit without delay - as a general rule, the SAR must be submitted on the same working day, or at the latest on the next working day, after suspicion arises.
  4. Apply the duty to stand still - once a SAR is filed, the transaction may generally not proceed until either the FIU or public prosecutor's office has given consent, or three working days have passed without a prohibition.
  5. Document internally — retain all assessments, decisions, and supporting materials, even in cases where a SAR is ultimately not filed.

 

Confidentiality - The "Tipping Off" Prohibition

Obliged entities are strictly prohibited from informing the customer, or any third party, that a SAR has been filed or that an investigation is underway (Tipping Off Verbot, Section 47 GwG). Violation of this prohibition is itself a criminal offence

.

After the SAR: FIU Feedback and Due Diligence

The FIU analyses incoming SARs, coordinates with prosecution authorities, and can halt suspicious transactions for up to one month. If no feedback is received within 21 calendar days, enhanced due diligence is no longer mandatory - unless independent indicators of elevated risk remain. For suspected terrorist financing, enhanced due diligence must be maintained for at least 6 months following the SAR, regardless of FIU feedback.

Transparency Register & Beneficial Ownership

Germany's Transparenzregister (Transparency Register) is a publicly accessible register that records the beneficial owners - the natural persons who ultimately own or control legal entities registered in Germany. Maintained by the Bundesanzeiger Verlag on behalf of the Federal Ministry of Finance, it is a cornerstone instrument of the GwG's anti-money laundering framework.

Who Must Register?

Legal entities - including GmbHs, AGs, partnerships, foundations, and trusts — are required to report their beneficial owners to the Transparenzregister. A beneficial owner is defined as any natural person who directly or indirectly holds more than 25% of the shares or voting rights, or exercises control by other means.

The quality and completeness of the register continue to improve. From January 2025, identity and verification checks were introduced to ensure only authorised persons can submit entries. Voluntary disclosure of full ownership and control structure overviews is permitted from July 2025, and from January 2027, the place of birth of beneficial owners becomes a mandatory data field.

 

CDD Obligations Linked to the Register

For obliged entities, the Transparenzregister is not just a reference tool - it is a mandatory checkpoint in the CDD process. When onboarding corporate clients, obliged entities must:

  • Query the Transparenzregister as part of beneficial ownership verification
  • Report any inconsistencies (Unstimmigkeiten) they detect between the register entry and their own CDD findings to the Bundesanzeiger (Section 23a GwG) - without this automatically triggering a SAR obligation
  • Document the results of the register query and retain them for at least five years

 

Practical Guidance for Registration and Verification

  • Verify register entries actively - do not treat the Transparenzregister as infallible. Cross-check against commercial register extracts, company documents, and customer-provided information.
  • Log your queries - BaFin expects evidence that the register was checked as part of your CDD workflow. Automated logging within your KYC system is recommended.
  • Act on inconsistencies - if the register data contradicts your CDD findings, report the inconsistency to the Bundesanzeiger and escalate internally.
  • Access rights are expanding - under the proposed ZFG reform, access rights to the Transparenzregister are being broadened in line with EU AMLD6 requirements, making information more widely available to authorised parties.

AML Penalties and Regulatory Consequences

Germany's regulators have demonstrated, with increasing force, that AML non-compliance carries severe financial, reputational, and professional consequences. The era of token fines for procedural breaches is over.

The Penalty Framework Under Section 56 GwG

The GwG provides for a tiered penalty structure:

  • Standard administrative fines: Up to €150,000 for most violations, depending on the severity and culpability.
  • Grave and systematic offences (Section 56(2) and (3) GwG): For serious or repeated violations by financial institutions, the maximum fine is the higher of €1–5 million or 10% of the gross annual income of the entity in the preceding year.
  • Criminal liability: Separate from administrative fines, individuals involved in facilitating or concealing money laundering face criminal prosecution under Section 261 StGB.
  • Additional sanctions: BaFin may demand the removal of responsible managers, prohibit individuals from exercising management functions, revoke licences, and order specific remedial measures.

 

Real Enforcement Cases - What German Regulators Have Penalised

Recent BaFin enforcement actions make the risk landscape unmistakably clear:

Year

Entity

Fine

Reason

2023

Sofort GmbH

€150,000

Inadequate monitoring controls and failure to identify contractual partners

March 2024

Solaris SE

€6.5 million

Systematic late filing of suspicious activity reports

May 2024

N26 Bank AG

€9.2 million

Systematic delays in SAR filing for money laundering cases in 2022

February 2025

Deutsche Bank AG

€23.05 million

Regulatory breaches spanning securities, investment advice, and retail banking compliance

October 2025

J.P. Morgan SE

€45 million

Systemic failure to submit suspicious transaction reports without undue delay (2021–2022)

 

The J.P. Morgan case is particularly instructive: the fine was calculated on a turnover-based formula under Section 56(3) GwG, illustrating that for large institutions, a fixed ceiling of €5 million no longer applies — the exposure scales with the size of the business.

 'Checklist of AML compliance do's and don'ts, including SAR filing, CDD documentation, MLRO registration, risk analysis updates, reporting ownership inconsistencies, staff training, and goAML reporting deadlines.

 

Recent Updates & 2026 Changes

The German AML landscape has undergone its most intensive period of regulatory activity in years. Professionals working in compliance must track several parallel developments — all of which carry immediate implementation consequences.

Key Changes You Need to Know in 2026

1. Mandatory Digital SAR Reporting via goAML (from 1 March 2026) The GwGMeldV (Reporting Obligation Ordinance) entered into force on 1 March 2026. All SARs must now be submitted exclusively through the FIU's goAML digital system in XML format. Manual submission methods - fax, post, and non-structured electronic communication - are permanently prohibited. Deficiencies in SAR completeness can themselves trigger administrative fines.

2. BaFin's Revised AuA - Effective from February 2025, Updated July 2025 BaFin's comprehensive update to its Interpretation and Application Guidance brought sweeping changes: expanded risk assessment standards, new mandatory minimum information sources, faster customer data update cycles for high-risk clients, and clarified MLRO outsourcing rules. A further amendment in July 2025 introduced mandatory electronic MLRO registration via BaFin's online portal.

3. Crypto-Asset Service Providers: New Scope and EDD Requirements Since December 2024, crypto-asset service providers and certain issuers of asset-referenced tokens have been explicitly brought within the GwG's scope under the Financial Market Digitisation Act. Enhanced due diligence requirements for transfers to or from self-hosted wallet addresses (Section 15a GwG) apply from March 2025.

4. AMLA Operational in Frankfurt (from July 2025) The EU's Anti-Money Laundering Authority (AMLA), headquartered in Frankfurt, became operational in July 2025. AMLA will directly supervise approximately 40 high-risk financial institutions (including major crypto service providers) from 2028, and will develop EU-wide standardised AML reporting formats that will ultimately supersede the GwGMeldV from 10 July 2027.

5. ZFG Draft Reform - Under Consultation in 2026 Germany's Federal Ministry of Finance published the draft Customs Financial Integrity Act (Zollfinanzgerechtigkeitsgesetz – ZFG) on 3 March 2026. Key proposed changes include:

  • Financial holding companies to become GwG-obliged entities from 1 January 2027
  • Expanded SAR triggers: a mere suspicion of any criminal act under Section 261 StGB will suffice, broadening the reporting threshold
  • Expanded Transparenzregister access rights in line with EU AMLD6
  • Non-registration with goAML to become a fineable administrative offence (from January 2027 for most entities)

6. Heightened BaFin Supervision - More On-Site Inspections BaFin has intensified its on-site AML inspection programme across the financial sector. Inspection findings have consistently highlighted weaknesses in risk analysis documentation, customer data update processes, and SAR filing practices. Institutions in the crypto, fintech, and payments sectors are under particularly heightened supervisory scrutiny heading into 2026.

 

Timeline of 2025–2027 AML changes: goAML SAR submission mandatory in March 2026, BaFin revised rules effective 2025, crypto-asset obligations from March 2025, AMLA operational July 2025, ZFG draft March 2026, EU AML Regulation applicable July 2027

 

Conclusion & Key Takeaways

Germany's AML legal framework has never been more demanding - or more actively enforced. The events of 2024 and 2025 made that clear: regulators fined the country's largest banks tens of millions of euros, expanded the obligations of crypto-asset providers, tightened SAR filing standards, and digitised the entire reporting infrastructure ahead of the March 2026 goAML mandate.

For compliance officers, finance professionals, auditors, and anyone working within or alongside Germany's financial system, the message is unambiguous: GwG compliance is not optional, not a back-office function, and not a set-and-forget programme. It is a live, continuously evolving obligation that demands structured processes, properly documented risk assessments, trained staff, and - above all - a culture that treats financial crime prevention as a genuine priority.

Key Takeaways

  • The Geldwäschegesetz (GwG) is the central AML statute, supplemented by BaFin's AuA guidance and FIU reporting rules.
  • Customer due diligence must be applied continuously - not just at onboarding. Documentation is everything.
  • SARs must be filed without delay - same or next working day - exclusively via goAML from March 2026 onwards.
  • The Transparenzregister is a mandatory CDD tool; inconsistencies must be reported.
  • Fines are escalating: from €150,000 for procedural failures to €45 million+ for systemic SAR deficiencies.
  • The 2026 landscape includes new SAR reporting infrastructure, crypto-asset obligations, AMLA operations in Frankfurt, and pending ZFG reforms.
  • The risk-based approach requires a living, documented, and regularly reviewed compliance framework - not a static policy document.

 

Top 10 AML obligations under GwG 2026: risk analysis, CDD procedures, beneficial owner checks, PEP & sanctions screening, risk classification, ongoing monitoring, MLRO appointment, policies & staff training, SAR reporting via goAML, and record keeping, with focus on risk-based framework and goAML readiness.

 

Build Your AML Expertise with the German Compliance Institute

Whether you are new to compliance, looking to formalise your knowledge, or seeking structured Weiterbildung in anti-money laundering, the Anti-Money Laundering & Financial Crime Prevention Course by the German Compliance Institute equips you with everything you need.

Covering the full GwG framework, BaFin expectations, SAR filing obligations, risk-based approaches, and the latest 2026 regulatory updates — this course is purpose-built for compliance professionals, bank employees, auditors, finance teams, and anyone working in a regulated environment in Germany.

Enrol today →

 

Tags:

Frequently Asked Questions

01 What is the German Geldwäschegesetz (GwG) 2026? +


The GwG is Germany’s Anti-Money Laundering Act, regulating AML compliance for banks, law firms, auditors, and real estate professionals.

02 Who must comply with the GwG in Germany? +


Banks, insurance companies, crypto service providers, lawyers, notaries, accountants, and real estate agents are all obliged entities under the GwG.

03 What are the key customer due diligence (CDD) obligations? +


Entities must verify clients’ identities, beneficial owners, monitor transactions continuously, and document all procedures for at least five years.

04 How are Suspicious Activity Reports (SARs) submitted? +


From 1 March 2026, all SARs must be filed digitally via the FIU’s goAML platform, with no paper, fax, or email submissions allowed.

05 What is the role of Germany’s Transparenzregister? +


The Transparency Register tracks beneficial owners of legal entities; entities must verify ownership during onboarding and report inconsistencies.

06 What penalties exist for non-compliance with the GwG? +


Fines range from €150,000 to €45 million, plus potential criminal liability, removal of managers, and license revocations for systemic breaches.

07 What are the 2026 AML updates and reforms? +


Mandatory digital SAR reporting, enhanced crypto-asset obligations, AMLA supervision, and proposed ZFG reforms expanding transparency and penalties.

Here your growth begins.

Unleash your potential. Learn anytime, anywhere.