Zum Hauptinhalt springen

Money Laundering Reporting Officer under Sec. 7 GwG and Sec. 25h KWG

Outsourcing of Money Laundering Reporting Officer (MLRO)

S+P Compliance takes on the function of your Money Laundering Reporting Officer – with a clear separation of duties, audit-proof documentation, and a substitution arrangement fixed by contract.

Obliged entities under Sec. 2(1) of the German Anti-Money Laundering Act (Geldwäschegesetz, GwG) must appoint a Money Laundering Reporting Officer and a deputy at management level. The function must be adequately resourced, reachable, and based in Germany, in line with Sec. 7 GwG. For credit institutions, Sec. 25h of the German Banking Act (Kreditwesengesetz, KWG) adds requirements for transaction monitoring systems.

These tasks can be outsourced, responsibility cannot: transferring internal safeguards to a third party must be notified to the supervisory authority in advance, and responsibility for fulfilling these safeguards remains with the obliged entity under Sec. 6(7) GwG. We set up the mandate so that this allocation of responsibility is documented and can be evidenced at any time.

  • Appointment as MLRO or deputy, with a substitution arrangement fixed by contract.
  • Risk analysis, transaction monitoring, and suspicious activity reporting handled from a single source.
  • Documentation that holds up in year-end, special, and supervisory audits.
  • Preparation of the notifications required under Sec. 7(4) and Sec. 6(7) GwG, without shifting management’s responsibility.

Legal basis and audit evidence

  • Sec. 7 GwG
  • Sec. 6(7) GwG
  • Sec. 25h KWG
  • AT 9 MaRisk
  • Sec. 43 GwG

Audit note: every work product is version-controlled, time-stamped, and logged with a decision record. On request, auditors receive a structured trail of who made which decision and when.

Outsourcing a control function means you must monitor the service provider and be able to evidence that monitoring. S+P Compliance provides audited evidence that your external auditor, internal audit function, and supervisor can use directly. It shortens your own audit procedures, it does not replace them: outsourcing shifts execution, not responsibility.

IDW PS 951

S+P Compliance’s internal control system has been audited under the German IDW standard for service organizations. The report describes control objectives, controls, and their effectiveness, and can be included in your own assessment of the outsourcing arrangement.

Outsourcing audit

ISAE 3402

For groups with a foreign parent company or an internationally operating group auditor, the equivalent report under the international standard is available. That removes any debate over whether a purely national standard is sufficient for group audit purposes.

International

ISO 9001

The quality management system is certified. Processes, responsibilities, document control, and corrective actions are defined and regularly audited – the basis for meeting agreed response times and reporting cycles.

Quality management

ISO 27001

The information security management system is certified. This matters because outsourcing this function means customer data, case files, and suspicious activity reports are processed outside your own organization, and this is a point supervisors regularly review.

Information security

ESG rating

S+P Compliance holds a confirmed ESG rating. This simplifies your vendor assessment process and allows you to include the service provider in your own sustainability reporting.

Sustainability

Provision of documents

Audit reports and certificates are provided on request – including directly to your external auditor or your supervisory authority. This is anchored in the outsourcing agreement as an information and audit right.

On request

What is outsourced – and what stays with your institution

An outsourcing arrangement only works if decision-making authority is set out in writing beforehand. We apply one fixed principle: S+P Compliance prepares and documents, your institution decides.

S+P Compliance prepares and documents

  • Risk analysis and derivation of internal safeguards
  • Monitoring, alert handling, and case investigation
  • Drafting suspicious activity reports and supporting documentation
  • Training concepts and awareness measures
  • Annual report and interim reporting to management

Your institution decides and remains responsible

  • Filing the suspicious activity report under Sec. 43 GwG
  • Placing or lifting sanctions and embargo holds
  • Discrepancy reports to the transparency register under Sec. 23a GwG
  • Approval of monitoring scenarios and thresholds
  • Approval of the risk analysis and internal safeguards by senior management

Outsourcing shifts execution, not responsibility. Under Sec. 6(7) GwG and Sec. 25h(4) KWG, responsibility for the internal safeguards remains with the obliged entity; under Sec. 7(1) GwG, the responsibility of senior management remains unaffected. Where the appointed Money Laundering Reporting Officer intends to file a report under Sec. 43(1) GwG, they are not subject to management’s right to issue instructions in that respect (Sec. 7(5) GwG) – the filing obligation itself remains with the obliged entity.

Why institutions outsource this function

Three developments hit AML compliance at the same time – each on its own could be absorbed internally, together they add up.

  1. A workload that outgrows a single desk

    Internal safeguards under Sec. 6 GwG cover risk analysis, transaction monitoring, case investigation, suspicious activity reporting, and staff training. For a single internal role, covering this range with the required depth is rarely sustainable in smaller and mid-sized institutions, particularly once monitoring alerts start competing with reporting deadlines for attention.

    Sec. 6 GwG – scope of internal safeguards
  2. Continuity that one person cannot guarantee

    The Money Laundering Reporting Officer and their deputy must be appointed, qualified, reachable, and active in Germany at all times. When the deputy is bestowed in name only, without a working handover of open cases, the gap becomes visible the moment the primary officer is unavailable – and shows up in the next audit report.

    Sec. 7 GwG – appointment and deputy
  3. A framework that keeps shifting

    The 9th MaRisk amendment of 30 June 2026 has cautiously widened the scope for outsourcing arrangements, and the EU Anti-Money Laundering Regulation (Regulation (EU) 2024/1624) will apply directly from 10 July 2027, with the new Anti-Money Laundering Authority already operational. Institutions that document their AML organization cleanly now carry less transition burden into these changes.

    10 July 2027 – EU AMLR becomes directly applicable

Six points that recur in practice

The following findings show up in audit reports on a regular basis. They describe typical patterns, not specific institutions.

Vacancy and deputy arrangements

Resignation, extended leave, or illness hit a function that must be continuously staffed. The deputy is formally appointed but often lacks day-to-day access to open matters, and that gap surfaces at the next audit.

Resourcing not tested against qualification

The supervisory authority can require the withdrawal of an appointment if the required qualification or reliability is missing. Evidence of ongoing training and technical fitness is often assembled only once it is requested.

Risk analysis disconnected from the business

The risk analysis describes a business model the institution no longer runs: new products, new distribution channels, and new countries are missing. Once that happens, the safeguards derived from it lose their foundation.

Monitoring that generates alerts, not insight

Credit institutions must operate data processing systems under Sec. 25h(2) KWG that detect unusual business relationships and transactions. If scenarios and thresholds have never been calibrated to the actual customer portfolio, the result is an alert flood without discriminating power.

Documentation that does not survive an audit

Investigated matters must be adequately documented under Sec. 8 GwG and Sec. 25h(3) KWG. In practice, the reasoning behind cases that were not reported is often missing – and these are exactly the cases auditors focus on.

Group and cross-border coordination

Group-wide obligations under Sec. 9 GwG, diverging standards across subsidiaries, and the EU AMLR taking direct effect from July 2027 all increase coordination effort. Without a clearly assigned owner for reconciling requirements, two rulebooks end up running side by side.

Scope of services

The scope is set out in the outsourcing agreement. You can transfer the mandate in full or engage individual building blocks alongside an existing internal function.

Mandate as Money Laundering Reporting Officer

A named function with a fixed contact and a defined deputy arrangement.

  • Appointment of a named individual with evidence of professional qualification
  • Preparation of the notification of appointment under Sec. 7(4) GwG
  • Preparation of the notification of outsourcing under Sec. 6(7) GwG or Sec. 25h(4) KWG
  • Activity carried out in Germany, reachable for supervisors, the FIU, and law enforcement
  • Fixed deputy arrangement with a properly onboarded second individual
  • Direct reporting line to the management board member designated under Sec. 4(3) GwG
  • Alignment of interfaces, escalation paths, and response times
  • Handover documentation at the start and end of the mandate

Risk analysis and internal safeguards

A derivation that shows the path from business model to control measure.

  • Assessment of products, distribution channels, customer structure, and country exposure
  • Risk assessment under Sec. 5 GwG with a documented methodology
  • Derivation of internal safeguards under Sec. 6 GwG
  • Drafting and maintenance of policies, work instructions, and control plans
  • Group-wide coordination under Sec. 9 GwG where applicable
  • Annual update and event-driven review
  • Preparation of approval by senior management
  • Comparison against the requirements of the EU AMLR from July 2027

Monitoring, scenarios, and thresholds

Parameters calibrated to your portfolio, with a documented rationale.

  • Analysis of existing scenarios and rules against the risk analysis
  • Proposal of adjusted thresholds with a rationale per customer segment
  • Back-testing against historical data and evaluation of hit quality
  • Alert handling under a documented procedure
  • Investigation of unusual transactions under Sec. 25h(3) KWG
  • Documentation of matters closed without a report, including the rationale
  • Regular effectiveness review and recalibration
  • Neutral description of the systems landscape, without endorsing any vendor

Allocation: S+P Compliance proposes scenarios and thresholds, tests them, and documents the outcome. Approval is given by your institution. S+P Compliance is vendor-independent and does not assess third-party products.

Suspicious activity reporting, FIU, and transparency register

A clean split between preparation, decision, and filing.

  • Preparation of the case with a chronology, evidence, and assessment
  • Drafting the report for filing via goAML, including attachments
  • Deadline monitoring and follow-up on open matters
  • Handling requests for information from the FIU under Sec. 30(3) GwG
  • Reconciliation of beneficial ownership data against the transparency register
  • Preparation of discrepancy reports under Sec. 23a GwG with a decision proposal
  • Documentation of the reporting decision, including cases not reported
  • Analysis of reporting volumes for management reporting

Allocation: the reporting obligation under Sec. 43 GwG rests with the obliged entity. Where the appointed Money Laundering Reporting Officer intends to file a report, they are not subject to management’s right to issue instructions in that respect (Sec. 7(5) GwG). Your institution decides on the discrepancy report under Sec. 23a GwG.

Sanctions and embargo screening

Hits are prepared and assessed – holds are placed by your institution.

  • Review of list coverage and update intervals
  • Assessment of match fuzziness and proposal of adjusted tolerances
  • Preparation of hits with identity matching and supporting evidence
  • Decision proposal with a clear recommendation and rationale
  • Documentation of the handling, including discarded hits
  • Coordination of the interface with payments and customer relationship teams
  • Re-screening after list updates and re-screening of the existing customer base
  • Preparation of case files for internal audit and external review

Allocation: the decision to place or lift a sanctions hold, and communication with authorities, rests with your institution. S+P Compliance prepares and documents.

Training, reporting, and audit support

Evidence that already exists before it is requested.

  • Initial and ongoing staff training under Sec. 6(2) GwG
  • Role-specific content for sales, back office, and senior management
  • Attendance records and learning assessment with retention
  • Annual report of the Money Laundering Reporting Officer to management
  • Interim reporting on alerts, filings, deadlines, and open items
  • Preparation of documents for year-end and special audits
  • Audit support and preparation of responses to follow-up questions
  • Follow-up on audit findings through to documented closure

Outsourcing agreement and ongoing governance

An outsourcing arrangement does not become reliable through service delivery alone, but through its governance. We fix these four elements before the mandate starts.

Contract and appointments

Scope of services, quality standards, response times, and reporting duties are fixed in writing. We prepare the notification to the supervisory authority; your institution files it.

Instruction and information rights

Your institution keeps the ability to steer the mandate. Access, information, and audit rights are agreed for the institution, internal audit, external auditors, and the supervisory authority.

Deputy and availability

Alongside the named individual, a properly onboarded deputy is fixed by contract. Availability windows and escalation paths are part of the agreement, not an informal understanding.

Exit and reintegration

A defined procedure exists for termination, transition, or bringing the function back in-house: data handover, transition documentation, and onboarding of a successor are described in advance.

Four engagement models

The right model depends on size, the licence held, and your existing internal staffing. Models can be switched over time.

Full mandate

S+P Compliance provides the Money Laundering Reporting Officer. Your institution retains the decision-making rights it cannot delegate.

Officer function

Deputy role

The internal function remains in place, S+P Compliance takes on the deputy role. That makes the substitution arrangement genuinely operational, not just a formal appointment.

Deputy arrangement

Interim

Fixed-term staffing during a vacancy, a new hire process, or the build-out of a new unit, combined with a structured handover to the internal successor.

Transition period

Technical support

Support for individual tasks without an officer mandate. Pure advisory input that only supports the obliged entity does not, on its own, constitute an outsourcing arrangement under Sec. 6(7) GwG.

No mandate

Four steps to an outsourced mandate

Timing depends on how complete your risk analysis and existing documentation already are, and on how quickly the notification to the supervisory authority can be coordinated.

1

Clarify requirements

Licence type, business model, existing staffing, and open findings are captured. The result is a stocktake with clear priorities.

2

Outsourcing analysis and proposal

We assess materiality, interfaces, and controllability, and present a proposal with a defined scope of services, response times, and reporting rhythm.

3

Agreement, appointment, notifications

The outsourcing agreement and appointment are signed. We prepare the notifications under Sec. 7(4) and Sec. 6(7) GwG; your institution submits them.

4

Operation, control, reporting

Ongoing operation with documented controls, interim reporting, an annual report to management, and support during audits.

Role allocation for liability-relevant decisions

Four processes determine, in the event of an audit, whether an outsourcing arrangement was set up cleanly. For each of them, we set out in writing who prepares, who advises, and who decides. This allocation is part of the outsourcing agreement and is not negotiated in day-to-day business.

The principle applies throughout: S+P Compliance prepares and documents, your institution decides. Outsourcing shifts execution, not responsibility. Where the appointed Money Laundering Reporting Officer intends to file a report under Sec. 43(1) GwG, they are not subject to management’s right to issue instructions in that respect; the reporting obligation itself remains with the obliged entity.

Process S+P Compliance prepares and documents Decision and responsibility at the institution Legal reference
Suspicious activity report Case preparation, assessment, draft report, deadline monitoring, documentation including cases not reported Reporting obligation of the obliged entity; the appointed officer’s reporting decision is not subject to management’s right to instruct Sec. 43 GwG, Sec. 7(5) GwG
Sanctions hit Identity matching, hit assessment, decision proposal, evidence trail Placing, lifting, and releasing a hold; communication with authorities EU sanctions regulations, Sec. 6 GwG
Discrepancy report Reconciliation of beneficial ownership data, preparation of the discrepancy, draft report Decision on filing the discrepancy report with the register-keeping body Sec. 23a GwG
Scenarios and thresholds Analysis, proposal, back-testing against historical data, rationale per segment Approval of the parameters and of the internal safeguards by senior management Sec. 25h(2) KWG, Sec. 4(3) GwG

Is outsourcing the right fit for your setup?

In an initial conversation we clarify licence type, existing staffing, and any open findings from your last audit. The outcome is an assessment of which engagement model fits and which decisions must stay with your institution.

Request initial conversationCompare engagement models

What changes for your institution

The function is continuously staffed

The officer and deputy are contractually fixed, onboarded, and reachable – including during holidays and periods of illness.

Continuity

Audit-proof documentation

Decisions, rationales, and controls are structured and available before auditors request them.

Documentation

Predictable cost

Scope of services and fees are contractually defined. Recruitment, onboarding, and training no longer appear as separate line items.

Cost predictability

Sharper monitoring

Scenarios and thresholds are tested against your own customer portfolio, rather than carried over from default settings.

Effectiveness

Clear roles

Who prepares and who decides is set out in writing. That reduces follow-up questions during internal audit and supervisory review.

Governance

Prepared for 2027

The AML organization is continuously checked against the EU AMLR, which becomes directly applicable on 10 July 2027.

AMLR

Who this service is for

This service is aimed at obliged entities under Sec. 2(1) GwG with a registered office or branch in Germany, required or ordered to appoint a Money Laundering Reporting Officer.

  • Credit institutions
  • Investment firms
  • Payment institutions
  • E-money institutions
  • Capital management companies
  • Crypto custodians and crypto service providers
  • FinTechs with a German KWG or ZAG licence
  • Branches of foreign institutions
  • Financial companies and insurance undertakings

Further outsourcing services from S+P Compliance

Outsourcing the Money Laundering Reporting Officer can be combined with further control functions. All mandates follow the same role logic: execution is external, responsibility stays with your institution.

Control function

Outsourcing Compliance Officer

General compliance function under AT 4.4.2 MaRisk, with monitoring, advice, and management reporting.

View service
Data protection

Outsourcing Data Protection Officer

Data protection organization under the GDPR, with a records of processing activities and audit-proof documentation.

View service
Outsourcing governance

Central Outsourcing Management

Steering and control of all outsourcing arrangements, including the outsourcing register, risk analyses, and reporting.

View service
Operational delivery

AML Operations

Operational support for alert handling, case closure, and backlog reduction – available at short notice and scalable.

View service
Operational delivery

KYC Operations

Customer due diligence in day-to-day operations: onboarding, periodic refresh, and clearance of outstanding cases.

View service
Third line of defense

Outsourcing Internal Audit

Independent audits under a risk-based audit plan, delivered with English-language reporting for international groups.

View service

Frequently asked questions about outsourcing the MLRO

What specific tasks does S+P take over as the external MLRO?

S+P Compliance provides a named individual as Money Laundering Reporting Officer and carries out the operational AML work: risk analysis under Sec. 5 GwG, internal safeguards under Sec. 6 GwG, transaction monitoring, alert handling, case preparation, staff training, and reporting. The role is carried out in Germany, and availability for supervisors, the FIU, and law enforcement is part of the mandate. The exact scope is set out in the outsourcing agreement.

Which companies benefit from outsourcing the MLRO?

This applies to obliged entities under Sec. 2(1) GwG for which a Money Laundering Reporting Officer must be appointed or has been ordered by the supervisory authority: credit institutions, investment firms, payment and e-money institutions, capital management companies, crypto custodians, and FinTechs with a German KWG or ZAG licence, as well as German branches of foreign institutions. Outsourcing is most useful where the function needs continuous, qualified coverage but the volume of business does not justify a full-time position with sufficient breadth of expertise.

Does senior management retain overall AML responsibility?

Yes. Outsourcing shifts execution, not responsibility. Under Sec. 6(7) GwG, responsibility for fulfilling the internal safeguards remains with the obliged entity, and Sec. 25h(4) KWG contains a corresponding provision for credit institutions. The responsibility of senior management under Sec. 7(1) GwG also remains unaffected. The transfer must be notified to the supervisory authority in advance, and the authority can prohibit the transfer or require it to be reversed if steering or control capabilities are impaired.

Can the Money Laundering Reporting Officer be overruled when filing a suspicious activity report?

No, not on the reporting decision itself. Where the appointed Money Laundering Reporting Officer intends to file a report under Sec. 43(1) GwG, they are not subject to management’s right to issue instructions in that respect, under Sec. 7(5) GwG. This safeguards the independence of the reporting decision. The underlying reporting obligation continues to rest with the obliged entity, not with the individual officer personally.

How does S+P ensure audit-proof documentation?

Every case, every monitoring decision, and every training record is version-controlled, time-stamped, and logged with a rationale, including matters closed without a report. S+P Compliance’s own control system is audited under IDW PS 951 and ISAE 3402, see the Legal basis and audit evidence section. That allows your institution and your supervisor to trace, at any point, when a given decision was taken and on what basis.

Which legal framework applies to this mandate?

The mandate is grounded in the German Anti-Money Laundering Act, in particular Sec. 4 to 9, Sec. 23a, and Sec. 43 GwG, and, for credit institutions, Sec. 25h KWG together with the relevant MaRisk outsourcing requirements. Sanctions law under EU regulations applies alongside sector-specific rules under KWG, ZAG, WpIG, or KAGB depending on the licence held. The EU Anti-Money Laundering Regulation (Regulation (EU) 2024/1624), directly applicable from 10 July 2027, is continuously reconciled against the existing organization. This overview reflects the legal position as of September 2026.

Outsourcing with a clear separation of roles

An outsourced Money Laundering Reporting Officer function works when two things come together: expert work that follows your business model, and a role allocation that can be evidenced in an audit. S+P Compliance sets up both together with you – execution is transferred, regulatory responsibility stays with your institution.

Solution Outsourcing MLRO
Achim Schulz
Ihr Ansprechpartner

Achim Schulz

Geschäftsführer S+P Compliance

Achim Schulz verantwortet die S+P Compliance Services. Da S+P als Dienstleister für regulierte Institute fortlaufend von Wirtschaftsprüfern und Aufsichtsbehörden geprüft wird, ist die Prüfungsexpertise seines Teams immer auf dem neuesten Stand. Ihr Vorteil: Er weiß aus der täglichen Praxis exakt, welche Nachweise und Kontrollen in aktuellen Audits zwingend gefordert werden. Diese tagesaktuelle Expertise fließt direkt in Ihre Auslagerung ein. Sie profitieren von zertifizierten Prozessen (IDW PS 951, ISO), die jedem Audit durch die BaFin oder Ihren Abschlussprüfer absolut sicher standhalten.

LinkedIn-Profil → · Redaktion & Experten → · S+P Compliance Services →