Zum Hauptinhalt springen
European AML Compliance

German AML compliance for international banks

A global policy is not a German operating model. Branches and subsidiaries need local responsibilities, working controls, reliable reporting and evidence that withstands scrutiny.

International banks operating in Germany have to align global standards with German legal, supervisory and operational requirements. S+P Compliance supports head offices, EU parent undertakings, German branches and local subsidiaries with local governance, reporting officer arrangements, customer due diligence and beneficial ownership controls, screening, transaction monitoring, bilingual reporting, remediation and audit preparation — and with the readiness work for the European framework that applies from 10 July 2027.

See our services

What you get

  • Group standards translated into German controls
  • Clear local reporting officer and management responsibilities
  • Working customer due diligence, screening and monitoring processes
  • German and English reporting for local management and head office
§ 6 GwG § 7 GwG § 10 GwG § 43 GwG AMLR from 10 July 2027

Audit-ready for BaFin and external auditors

Division of responsibilities

What S+P delivers

  • Assessment of local governance, processes, data and evidence
  • German policies, addenda and work instructions
  • Local business-wide risk assessment and control design
  • Operational processing of customer files, screening hits and alerts
  • Bilingual reporting and preparation for audit and supervisory review

What remains with the institution

  • Statutory appointments and notifications to the supervisor
  • Approval of policies, risk assessment and control framework
  • Decisions on suspicious activity reports under § 43 GwG
  • Decisions on sanctions freezes, customer acceptance and termination
  • Communication with BaFin and responses to formal measures

Outsourcing shifts execution, not accountability. The German entity remains answerable to its supervisor even where standards, systems and reporting formats are set centrally.

German AML compliance in context

The German framework for financial institutions is shaped by the Money Laundering Act, by BaFin supervision and its published interpretation and application guidance, by EU requirements, and from 10 July 2027 by the directly applicable Anti-Money Laundering Regulation. For an international bank the difficulty is rarely any single one of these. It is the intersection.

Group policies and global minimum standards have to sit alongside German obligations and supervisory expectations. The role of the German branch or subsidiary has to be defined against head office oversight. Reporting routes to the German financial intelligence unit, local record-keeping and evidence requirements, data protection limits on cross-border information sharing and local management accountability all have to work together — and be documented in a form an examiner can follow.

The consequences of getting this wrong are not theoretical. Material shortcomings in this area can lead to remedial orders, administrative fines and, in serious cases, the appointment of a special representative to monitor implementation. That makes local implementation a governance question for head office, not only a task for the German compliance team.

The international-bank challenge

Six patterns we see repeatedly in German branches and subsidiaries.

Group policy is not local implementation

Global standards may set a solid baseline, but the German entity needs its own procedures, responsibilities, approval routes, reporting and evidence that reflect German requirements. Without that layer, the policy exists and the control does not.

Local accountability is unclear

Who carries responsibility for German compliance, who is appointed as reporting officer and deputy, how they report to local management and to the group, who approves local addenda and who owns escalation to the authorities — these questions are often unresolved in writing.

German and group reporting diverge

Head office wants comparable global risk reporting while local management, audit and supervisory processes need German-specific information, evidence and escalation documentation. Two report sets emerge and neither is complete.

Central systems miss local process

Group platforms for customer files, screening, monitoring or case management do not fully reflect German workflows, local data sources, documentation standards, escalation routes or approval requirements. Work then happens outside the system.

Local capacity is thin

A small branch may carry a meaningful customer base, complex products, cross-border activity and higher-risk segments with very few dedicated staff. The reporting officer ends up doing case work instead of oversight.

Evidence is assembled late

Files are reconstructed when an audit is announced rather than produced as work happens. That consumes the capacity the team does not have and rarely convinces an experienced examiner.

Our services

Eight building blocks, available individually or as one programme.

German compliance assessment

A structured view of the current state for a branch, subsidiary or German group entity, with a prioritised remediation roadmap.

  • Local governance and management responsibilities
  • Reporting officer and deputy arrangements
  • German policies, procedures and work instructions
  • Business-wide risk assessment
  • Customer due diligence and beneficial ownership processes
  • Screening, transaction monitoring and case management
  • Escalation and reporting governance
  • Technology, data, workflow controls and audit evidence
  • Gap assessment, maturity heatmap and bilingual executive summary

Reporting officer support

Design and operation of the local governance model around the money laundering reporting officer and deputy.

  • Operating model for the officer and the deputy
  • Role descriptions, authority matrix and delegation framework
  • Interfaces with local management and the group function
  • Reporting, escalation and committee structure
  • Risk assessment and control oversight
  • Policy ownership and annual review planning
  • Preparation of notification and appointment documentation
  • Training and awareness programme
  • Capacity, succession and continuity planning

Credit and financial institutions are generally required under § 7 GwG to appoint a money laundering reporting officer and a deputy. The appointment itself, the notification to the supervisor, final decisions and communication with authorities remain with the institution and its authorised representatives. S+P supports the design, documentation, operation and assurance of the governance model behind them.

German policies and procedures

Group standards translated into local documentation that teams can actually work from.

  • German policy and local addendum to the group policy
  • Work instructions for customer due diligence and enhanced due diligence
  • Procedures for beneficial ownership and control structures
  • Procedures for exposed persons, sanctions, embargoes and adverse media
  • Monitoring and case management procedures
  • Escalation and reporting workflow for suspicious activity
  • Record-keeping, retention and evidence requirements
  • Outsourcing and third-party controls
  • Exception handling, version control, approval and periodic review

Local business-wide risk assessment

An assessment that reflects the German entity rather than a translated extract of the group document.

  • Local methodology and risk taxonomy
  • Customer, product, service and transaction risk analysis
  • Geographic, country and cross-border exposure
  • Delivery channel, technology and outsourcing risk
  • Ownership, control and legal entity risk factors
  • Inputs from exposed persons, sanctions and adverse media
  • Inherent and residual risk methodology
  • Risk appetite, indicators and escalation thresholds
  • Linkage to due diligence, screening and monitoring intensity

Customer due diligence and ownership

Due diligence across the lifecycle, from onboarding through periodic and event-driven review to exit.

  • Identification and verification of natural persons and legal entities
  • Authority to act and representation checks
  • Customer risk classification
  • Purpose and intended nature of the business relationship
  • Beneficial ownership and control mapping, with register checks
  • Processes for exposed persons, family members and close associates
  • Enhanced due diligence for higher-risk relationships
  • Source of funds and source of wealth where required
  • Periodic and trigger-based reviews with file quality assurance

Decisions on discrepancy reports to the German transparency register remain with the authorised function of the institution. S+P prepares the case and documents the assessment.

Screening and restrictive measures

German implementation and daily operation of screening controls, at the volumes they actually produce.

  • Screening scope and population definition
  • Coverage of customers, owners, authorised persons, counterparties and payments
  • Workflows for exposed persons and close associates
  • Sanctions, embargo and restrictive measures assessment
  • Matching, tuning and alert triage rules
  • Case management, evidence and escalation
  • Rescreening and trigger event workflows
  • Quality assurance and error analysis
  • Backlog and aged alert remediation

Transaction monitoring and cases

Risk-based monitoring that reflects the German entity’s business model rather than the group average.

  • Monitoring risk assessment and customer segmentation
  • Scenario, indicator and threshold review
  • Customer profile and expected activity data
  • Alert prioritisation and investigation workflow
  • Case file standards, documentation and evidence
  • Escalation routes and decision authorities
  • Preparation of cases for reporting decisions
  • Rulebook, scenario and change governance
  • Backtesting, ageing analysis and quality assurance

Decisions on suspicious activity reports under § 43 GwG, on sanctions freezes and on terminating a relationship remain with the authorised function of the German entity and cannot be transferred to head office.

Bilingual reporting

Management information that serves German decision-making and group oversight from one data set.

  • Reporting officer reports and local dashboards
  • Customer file completeness, review and backlog reporting
  • Ownership data quality reporting
  • Screening and sanctions alert reporting
  • Monitoring and case management reporting
  • Escalation metrics and emerging risk reporting
  • Findings, remediation and closure reporting
  • Group reporting pack and local management information
  • Reporting calendar, thresholds and escalation rules

Readiness priorities for a German entity

Four questions that determine how much work lies ahead before July 2027.

Governance

Are the responsibilities of local management, the reporting officer and deputy, the group function and head office documented and free of overlap?

Risk and customer files

Does the local risk assessment reflect the German business model, and are customer files, ownership data and review cycles complete and evidenced?

Screening and monitoring

Are screening controls complete, timely and documented, and are scenarios, thresholds, alerts and case files risk-based and governed?

Technology and evidence

Do central systems reflect German workflows, data sources and escalation routes, and can control effectiveness be demonstrated on request?

Four ways to engage

Depending on the size of the entity and the pressure you are under.

Assessment

Compliance assessment

An initial view of maturity, risk, gaps and priorities for a German branch, subsidiary or financial institution, with a bilingual summary for head office.

Ongoing

German branch support

Continuous local support: governance, reporting officer arrangements, policy implementation, oversight of customer files, reporting and audit readiness.

Programme

Readiness programme

Aligning German controls with the European framework, supervisory expectations and group governance ahead of July 2027, with owners and milestones.

Remediation

Audit and findings support

Preparing for audit or working through findings: validation, root cause analysis, file and data remediation, evidence and closure validation.

How we work

  1. 1

    Scope and context

    The German entity or branch, its products, customers, countries, group arrangements, technology landscape, outsourcing model and stakeholders.

  2. 2

    Assessment

    Governance, policies, risk assessment, customer files, ownership data, screening, monitoring, data, reporting, evidence and remediation status.

  3. 3

    Target model and delivery

    Local target state for roles, processes, controls, reporting, technology and evidence, followed by policy updates, remediation and workflow implementation.

  4. 4

    Ongoing support

    Local governance, reporting officer support, customer file and alert operations, reporting, audit readiness and regulatory remediation.

Roles in the German entity

Group oversight does not replace local accountability. Operational delivery, second-line oversight and independent assurance have to stay separated within the German entity, and the separation has to be visible in the documentation.

Where S+P supports more than one of these levels, we separate them through distinct teams, roles, access rights, decision limits and reporting lines.

Line of defenceRole in German AML complianceS+P support
First line Executes customer files, data maintenance, screening hits, monitoring and cases Managed operations, backlog support and operational quality assurance
Second line Sets standards, performs the risk assessment, oversees controls, challenges and escalates Reporting officer support, governance, monitoring and reporting
Third line Provides independent assurance over governance, controls and remediation Internal audit, audit readiness and independent closure validation
Local management Approves the framework and carries accountability towards the supervisor Decision papers, bilingual reporting and committee material

What you gain

Local without losing consistency

Group minimum standards become German processes, with transparent interfaces back to head office.

Consistency

Clear local accountability

Roles, decision rights, escalation paths and reporting are defined for every function involved.

Governance

Stronger customer controls

Files, ownership information, risk classification, enhanced due diligence and reviews improve measurably.

Quality

Workable screening and monitoring

Controls are calibrated to the local business and can be operated with the capacity available.

Effectiveness

Reporting both sides can use

One data set produces German management information and comparable group reporting.

Steering

Audit-ready evidence

Policy, process, system, data, case file, testing and approval evidence connect into one trail.

Assurance

Who we support

  • Foreign banks establishing or operating German branches
  • International banking groups with German subsidiaries
  • EU parent undertakings with German entities
  • International payment and e-money institutions
  • Investment firms and asset managers with German operations
  • Fintechs and embedded finance providers
  • Crypto-asset service providers
  • Institutions with central AML technology and local German responsibilities

Related services

European AML Compliance

The overview of our European AML services, from assessment through implementation to managed operations.

Back to the hub

AMLR Readiness

Gap assessment against AMLR and AMLA standards, with a prioritised roadmap to 10 July 2027.

Explore AMLR Readiness

Group AML Governance

Consistent standards across head office, EU parent, branches and subsidiaries, implementable locally.

Explore Group AML Governance

AML Audit & Remediation

Audit readiness, evidence management and closure of supervisory and audit findings.

Explore Audit & Remediation

Talk to us

Describe your German entity, the processes in scope and your timeline, and we will respond with an assessment.

Contact S+P Compliance

Frequently asked questions

Does a German branch need its own AML arrangements?

A German branch needs a framework that reflects its legal structure, business model, local regulatory requirements, group arrangements and operational delivery. The precise design depends on the institution, but it must define local accountability, escalation and evidence requirements in a form that can be shown to the supervisor.

What is the role of the German reporting officer?

The money laundering reporting officer is a central element of the local governance framework. The role typically covers oversight of controls, escalation, reporting, the risk assessment, policy governance and interaction with local management and the authorities. Credit and financial institutions are generally required under § 7 GwG to appoint an officer and a deputy, and the responsibilities should be documented in the governance model.

Can group policies be used in Germany?

Yes, as a baseline. They should be assessed against German requirements and supplemented with local addenda, procedures, work instructions, approval routes, reporting and evidence standards where the German framework goes further or works differently. Deviations should be documented and approved rather than left implicit.

Can S+P support a branch with limited local resources?

Yes. We support local governance, policy implementation, the risk assessment, reporting, customer file remediation, screening and monitoring operations, quality assurance, audit preparation and remediation. The service design preserves the institution’s responsibility for its obligations and for material decisions.

Can S+P provide German and English reporting?

Yes. We produce reports, dashboards, action plans, committee material and executive summaries in both languages for local management, head office, group functions and audit stakeholders, built from one data set so the figures reconcile.

How should an international bank prepare for the European framework in Germany?

Start with a local gap assessment covering governance, group interfaces, the risk assessment, customer files, beneficial ownership, screening, monitoring, technology, data, reporting and audit evidence. Then set a prioritised roadmap with accountable owners, milestones, dependencies and closure criteria, leaving room for data remediation and testing before the application date.

Global standards need local accountability

Operating in Germany requires more than central policies. It requires locally effective controls, clear responsibility, reliable information flows and evidence that withstands audit and supervisory review. S+P Compliance helps international banks build a German model that is aligned with group governance, ready for the European framework and workable in daily operations.

German AML compliance for international banks