Zum Hauptinhalt springen
European AML Compliance

Group AML Governance: align head office, EU parent and local entities under AMLR

International groups need more than a group policy. They need a governance model that turns European standards, group requirements and local obligations into consistent roles, processes, reporting and delivery.

From 10 July 2027, AMLR applies directly across the European Union. For groups with branches, subsidiaries and cross-border relationships this creates a practical problem: central standards must be consistent, yet every local entity remains capable of meeting its own legal, supervisory and operational obligations. S+P Compliance helps head offices, EU parent undertakings, German branches and local subsidiaries connect group policies, risk assessment, customer due diligence, screening, monitoring, technology governance, reporting and audit-ready evidence.

See our services

What you get

  • Clear responsibilities between head office, EU parent and local entities
  • Group minimum standards with documented local addenda
  • Group-wide risk assessment that reflects local risk profiles
  • Bilingual reporting, evidence and audit-ready structures
Article 16 AMLR Article 17 AMLR Article 10 AMLR Article 26 AMLR Applies 10 July 2027

Audit-ready for BaFin and external auditors

Division of responsibilities

What S+P delivers

  • Assessment of group structure, roles, policies and information flows
  • Target operating model, decision rights and escalation matrix
  • Drafts for group policy, local addenda and work instructions
  • Metrics, reporting formats and evidence structures
  • Local reporting officer support or operational delivery, separately engaged

What remains with group and local entity

  • Approval of the group policy, risk assessment and control framework
  • Approval of local deviations from group standards
  • Decisions on suspicious activity reports to the national FIU
  • Decisions on sanctions freezes and termination of relationships
  • Responsibility of the local entity for its own business organisation

Outsourcing shifts execution, not accountability. A German branch or subsidiary remains answerable to its supervisor even where standards and systems are set centrally.

Why this matters now

Article 16 AMLR requires parent undertakings to ensure that internal policies, procedures and controls apply across branches and subsidiaries, to perform a group-wide risk assessment that takes account of the assessments performed by those entities, and to establish group-wide arrangements including data protection and the sharing of information relevant for AML and CFT purposes. Article 17 AMLR addresses the situation where a branch or subsidiary operates in a third country whose law prevents compliance.

AMLA consulted in 2026 on a single set of draft regulatory technical standards covering both mandates, under Articles 16(4) and 17(3) AMLR. The draft addresses organisational aspects of group-wide requirements, information sharing within a group, criteria for identifying the parent undertaking in the Union where several obliged entities are linked to a third-country head office, the extension of group requirements to structures other than traditional groups, and additional measures where branches or subsidiaries operate in third countries.

The practical consequence is that a single global policy document no longer answers the questions that matter. Which decisions sit with head office, which with the EU parent, which with the German entity? How does the local reporting officer operate within the group framework? Which customer, ownership, screening and monitoring information may be shared, and where do data protection or third-country restrictions apply? How are local deviations approved, documented and reported upward?

The governance challenge

Six patterns that recur across international groups.

Group policies stay high-level

Global standards describe principles but do not explain how a German branch implements, documents and controls local requirements for due diligence, ownership, screening, monitoring, reporting and evidence. The local level improvises, and the gap only becomes visible in files.

Local requirements are not embedded

A group policy has to interact with local AML law, supervisory expectations, reporting routes to the financial intelligence unit and local governance. Without addenda, work instructions and clear decision rights, implementation gaps appear that nobody owns.

Ownership of the framework is unclear

Who owns the group framework, who acts as EU parent undertaking, who sets minimum standards, who approves local deviations, who owns group technology and local data quality, and who receives which escalation? Unanswered, these questions become audit findings.

Information flows are fragmented

Customer data, ownership information, screening alerts, monitoring cases, control findings and remediation actions are not available in a consistent format across entities. Data protection, confidentiality and local data residency have to be designed in, not discovered later.

Central systems miss local reality

Group platforms for due diligence, screening or monitoring do not fully reflect local data sources, customer structures, language requirements, escalation routes or evidence expectations. The result is workarounds outside the system.

Reporting is not comparable

Entities report different metrics, periods, risk categories and thresholds. Head office therefore lacks a reliable view of backlogs, screening volumes, alerts, open findings and data quality — and sees local issues late.

Our services

Eight building blocks, available individually or as one programme.

Target operating model

Every activity has an owner, every decision an authority, every escalation a named recipient and an evidence trail.

  • Roles for head office, EU parent, branches and subsidiaries
  • Allocation of central and local responsibilities
  • Operating model for the local reporting officer and deputy
  • Interfaces between first, second and third line
  • Decision rights, approval limits and escalation matrix
  • Governance for local deviations and exceptions
  • Board, management and committee reporting lines
  • Resourcing, succession and delegated authority model
  • Governance for outsourced AML processes

Group policy and minimum standards

Binding minimum requirements for every entity, with room for documented local supplements.

  • Group AML and CFT policy
  • Minimum standards for customer due diligence and enhanced due diligence
  • Standards for beneficial ownership and control structures
  • Screening and restrictive measures standards
  • Requirements for transaction monitoring and case management
  • Minimum data quality and evidence requirements
  • Audit trail, retention and documentation standards
  • Local addenda for Germany and other jurisdictions
  • Review, version control, approval and attestation workflows

Article 16 AMLR requires group-wide policies, procedures and controls to include arrangements for data protection and for the sharing of information relevant to AML and CFT purposes within the group.

Group-wide and local risk assessment

One risk picture in which local specifics remain visible rather than averaged away.

  • Group methodology and shared risk taxonomy
  • Local business-wide risk assessment for German entities
  • Aggregation of customer, product, country, transaction and channel risks
  • Assessment of group structure, outsourcing and third-party dependencies
  • Data sources, assumptions and evidence requirements
  • Risk indicators, risk appetite and escalation thresholds
  • Linkage to due diligence, screening and monitoring intensity
  • Review, approval and refresh process
  • Board and senior management reporting

Under Article 16 AMLR the group-wide assessment takes account of the business-wide risk assessments performed by branches and subsidiaries. It should therefore not obscure local customer types, products, geographies or delivery channels.

Customer lifecycle and beneficial ownership

Harmonised standards for the customer lifecycle across entities, with local register realities respected.

  • Group data model and minimum documentation requirements
  • Standards for due diligence and enhanced due diligence
  • Customer risk classification and review cycle governance
  • Group standards for ownership and control structures
  • Local register and transparency register processes
  • Trigger events and event-driven customer refresh
  • Evidence, data quality and retention requirements
  • Local deviations and exception approval workflows
  • Group metrics for completeness, ageing and overdue reviews

Screening and monitoring governance

Group principles with local calibration, rather than one parameter set imposed on unlike markets.

  • Group screening policy and scope definition
  • Minimum standards for politically exposed persons, family members and close associates
  • Sanctions, embargo and restrictive measures governance
  • Screening scope for customers, owners, counterparties and payment flows
  • Matching, tuning and alert triage principles
  • Group monitoring rulebook with scenarios and thresholds
  • Local calibration requirements and documentation
  • Case management and escalation model
  • Backtesting, effectiveness analysis and quality assurance

Technology governance

A group platform works only when local data, processes, escalation routes and evidence requirements are correctly reflected.

  • Target architecture for due diligence, screening, monitoring and case management
  • Central versus local system components
  • Group data model and data ownership
  • Local data sources, enrichment and quality processes
  • Change governance and functional requirements
  • Rulebook, scenario and model governance
  • User access, roles and audit trail requirements
  • Functional testing, acceptance and release governance
  • Documentation of local system deviations

Reporting and information flows

Comparable metrics are the precondition for the group being able to steer at all.

  • Standardised group performance and risk indicators
  • Local and group management reporting
  • Reporting on customer files, screening, monitoring and backlogs
  • Reporting on higher-risk customers, exposed persons and sanctions
  • Findings, remediation and action plan reporting
  • Ad hoc escalation and crisis reporting
  • Reports tailored to head office, EU parent and local boards
  • German and English reporting templates
  • Reporting calendars, thresholds and approval documentation

German implementation on the ground

A German branch or subsidiary needs a self-standing, examinable model — not a translation of the group policy.

  • Local reporting officer and deputy support
  • German policy and local work instructions
  • Local business-wide risk assessment
  • Customer risk classification and due diligence processes
  • Ownership and transparency register processes
  • Local screening and monitoring workflows
  • Documentation prepared for the German supervisor
  • German and English management reporting to the group
  • Local audit readiness and remediation

Decisions on suspicious activity reports, sanctions freezes and transparency register discrepancy reports remain with the authorised function of the German entity and cannot be transferred to head office.

Four principles

Minimum standard, not uniformity

The group sets a binding floor. Local entities may go further where local law requires it, but never fall below the standard.

Deviations with a reason

Every departure from a group standard is justified in writing, approved and recorded in a register that can be produced on request.

Local decisions stay local

Reports, freezes and terminations are decided by the authorised function on the ground, whatever the central standard prescribes.

Evidence in both languages

Documentation is produced so it can be given to the German supervisor and to the group without rework or retranslation.

Four ways to engage

Depending on group structure and maturity.

Assessment

Governance assessment

Transparency over central and local responsibilities, policies, processes, technology, data and reporting, with findings and an action plan.

Transformation

AMLR alignment

Group policies, role model, risk assessment, customer processes and reporting aligned to the European framework before July 2027.

Project

German branch governance

For international banks with a German branch or subsidiary: connect local accountability with group-level steering in a workable way.

Ongoing

Managed local support

Continuous local expertise: reporting officer support, operations, bilingual reporting to the group and standing audit readiness.

How we work

  1. 1

    Assessment

    Group structure, central and local responsibilities, policies, risk assessments, systems, reporting, data flows and existing interfaces.

  2. 2

    Target model

    Target state for roles, processes, minimum standards, data, technology, reporting and escalation, agreed between group and local entity.

  3. 3

    Implementation

    Policies, local work instructions, customer processes, screening and monitoring workflows, data models, reporting and evidence structures.

  4. 4

    Ongoing support

    Local compliance support, group reporting, operations, quality assurance, audit readiness and regulatory remediation.

Roles between group and local entity

Group-level steering does not replace local accountability; it frames it. What matters is that operational delivery, independent oversight and assurance stay separated across borders as well as within an entity.

Where S+P supports more than one of these levels, we separate them through distinct teams, roles, access rights, delegated authorities and reporting lines.

LevelRole in the group modelS+P support
Head office and EU parent Sets minimum standards, assesses group risk, oversees implementation Policies, metrics model, reporting formats, governance advice
Local first line Maintains customer data, handles alerts, keeps evidence and deadlines Managed operations and backlog reduction on the ground
Local second line Translates standards locally, monitors, escalates and decides Reporting officer support, control plan, local risk assessment
Third line Provides independent assurance over group and local controls Internal audit, audit planning and follow-up

What you gain

Consistent minimum standards

A coherent framework across the group that integrates local legal and supervisory requirements rather than ignoring them.

Consistency

Clear accountability

Every level knows its responsibilities, decision limits and reporting obligations, and can evidence them.

Governance

Workable local implementation

Local processes fit into the group target model without overlooking German regulatory requirements.

Delivery

Reliable information flows

Customer, ownership, risk and remediation information is structured for both local and group steering.

Data

Comparable reporting

Bilingual reports with a shared metric set give management a basis it can actually act on.

Steering

Audit-ready governance

Policies, addenda, roles, controls, evidence and remediation are structured for supervisory and audit review.

Assurance

Who we support

  • International banking groups with German branches
  • EU parent undertakings with multiple subsidiaries
  • Foreign banks with German subsidiaries or branches
  • Payment and e-money institutions with cross-border operations
  • Investment firms and asset managers with EU presence
  • Fintechs and crypto-asset service providers with group structures
  • Institutions with central AML platforms and local compliance teams
  • Organisations with head office outside Germany or outside the EU

Related services

European AML Compliance

The overview of our European AML services, from assessment through implementation to managed operations.

Back to the hub

AMLR Readiness

Gap assessment against AMLR and AMLA standards, with a prioritised roadmap to 10 July 2027.

Explore AMLR Readiness

AML Audit & Remediation

Audit readiness, evidence management and closure of supervisory and audit findings.

Explore Audit & Remediation

German AML for International Banks

Local AML governance, reporting officer support and documentation prepared for the German supervisor.

Explore German AML Compliance

Talk to us

Describe your group structure, the entities in scope and your timeline, and we will respond with an assessment.

Contact S+P Compliance

Frequently asked questions

Does a group need one unified AML policy?

A consistent group policy with binding minimum standards is central to effective governance. Local laws, supervisory expectations and organisational differences are reflected through documented addenda, work instructions and exception procedures. Unified means no entity falls below the standard, not that every entity is identical.

Can head office centralise all AML responsibilities?

Only in part. Standards, methods, systems and reporting formats can be set centrally. Local accountability, escalation routes, the appointed function on the ground and the evidence owed to the German supervisor remain with the local entity. How far centralisation can go depends on group structure, business model and legal form.

What is the role of a local reporting officer?

The local officer is responsible for the tasks assigned locally and acts as the interface between local management, head office, business functions, the supervisor and, where applicable, the financial intelligence unit. The precise role reflects local legal requirements, group governance and delegated authority, and is set out in the appointment and the work instruction.

Can S+P provide German and English reporting?

Yes. Management and group reporting is produced in both languages. German regulatory requirements are prepared so they can be used at head office without retranslation, and group requirements so they remain comprehensible to the German supervisor.

Can local functions and group governance be combined?

Yes. Local reporting officer support, group governance, operations, technology governance, reporting and audit preparation can be combined. This requires clear separation of the lines of defence: distinct teams, roles, access rights and reporting lines, documented in the role model.

Can S+P support central AML systems?

Yes, independently of software providers and on the functional level: system governance, data models, rulebooks, scenarios, testing, local workflows, evidence and operations. Technical operation, system administration and vendor support remain with the institution, the provider or the appointed technical partner.

Group policy is not group governance

International groups need a model that connects European standards, local accountability, technology, operations, data and reporting — consistent across the group, workable at local level and defensible in front of both the German supervisor and head office.

Group AML Governance: align head office, EU parent and local entities under AMLR