Outsourcing Money Laundering Officer (German-language service page)
The German-language counterpart of this service, for German-speaking stakeholders within your organization.
View serviceMoney Laundering Reporting Officer under Sec. 7 GwG and Sec. 25h KWG
S+P Compliance takes on the function of your Money Laundering Reporting Officer – with a clear separation of duties, audit-proof documentation, and a substitution arrangement fixed by contract.
Obliged entities under Sec. 2(1) of the German Anti-Money Laundering Act (Geldwäschegesetz, GwG) must appoint a Money Laundering Reporting Officer and a deputy at management level. The function must be adequately resourced, reachable, and based in Germany, in line with Sec. 7 GwG. For credit institutions, Sec. 25h of the German Banking Act (Kreditwesengesetz, KWG) adds requirements for transaction monitoring systems.
These tasks can be outsourced, responsibility cannot: transferring internal safeguards to a third party must be notified to the supervisory authority in advance, and responsibility for fulfilling these safeguards remains with the obliged entity under Sec. 6(7) GwG. We set up the mandate so that this allocation of responsibility is documented and can be evidenced at any time.
Audit note: every work product is version-controlled, time-stamped, and logged with a decision record. On request, auditors receive a structured trail of who made which decision and when.
Outsourcing a control function means you must monitor the service provider and be able to evidence that monitoring. S+P Compliance provides audited evidence that your external auditor, internal audit function, and supervisor can use directly. It shortens your own audit procedures, it does not replace them: outsourcing shifts execution, not responsibility.
S+P Compliance’s internal control system has been audited under the German IDW standard for service organizations. The report describes control objectives, controls, and their effectiveness, and can be included in your own assessment of the outsourcing arrangement.
Outsourcing auditFor groups with a foreign parent company or an internationally operating group auditor, the equivalent report under the international standard is available. That removes any debate over whether a purely national standard is sufficient for group audit purposes.
InternationalThe quality management system is certified. Processes, responsibilities, document control, and corrective actions are defined and regularly audited – the basis for meeting agreed response times and reporting cycles.
Quality managementThe information security management system is certified. This matters because outsourcing this function means customer data, case files, and suspicious activity reports are processed outside your own organization, and this is a point supervisors regularly review.
Information securityS+P Compliance holds a confirmed ESG rating. This simplifies your vendor assessment process and allows you to include the service provider in your own sustainability reporting.
SustainabilityAudit reports and certificates are provided on request – including directly to your external auditor or your supervisory authority. This is anchored in the outsourcing agreement as an information and audit right.
On requestAn outsourcing arrangement only works if decision-making authority is set out in writing beforehand. We apply one fixed principle: S+P Compliance prepares and documents, your institution decides.
Outsourcing shifts execution, not responsibility. Under Sec. 6(7) GwG and Sec. 25h(4) KWG, responsibility for the internal safeguards remains with the obliged entity; under Sec. 7(1) GwG, the responsibility of senior management remains unaffected. Where the appointed Money Laundering Reporting Officer intends to file a report under Sec. 43(1) GwG, they are not subject to management’s right to issue instructions in that respect (Sec. 7(5) GwG) – the filing obligation itself remains with the obliged entity.
Three developments hit AML compliance at the same time – each on its own could be absorbed internally, together they add up.
Internal safeguards under Sec. 6 GwG cover risk analysis, transaction monitoring, case investigation, suspicious activity reporting, and staff training. For a single internal role, covering this range with the required depth is rarely sustainable in smaller and mid-sized institutions, particularly once monitoring alerts start competing with reporting deadlines for attention.
Sec. 6 GwG – scope of internal safeguardsThe Money Laundering Reporting Officer and their deputy must be appointed, qualified, reachable, and active in Germany at all times. When the deputy is bestowed in name only, without a working handover of open cases, the gap becomes visible the moment the primary officer is unavailable – and shows up in the next audit report.
Sec. 7 GwG – appointment and deputyThe 9th MaRisk amendment of 30 June 2026 has cautiously widened the scope for outsourcing arrangements, and the EU Anti-Money Laundering Regulation (Regulation (EU) 2024/1624) will apply directly from 10 July 2027, with the new Anti-Money Laundering Authority already operational. Institutions that document their AML organization cleanly now carry less transition burden into these changes.
10 July 2027 – EU AMLR becomes directly applicableThe following findings show up in audit reports on a regular basis. They describe typical patterns, not specific institutions.
Resignation, extended leave, or illness hit a function that must be continuously staffed. The deputy is formally appointed but often lacks day-to-day access to open matters, and that gap surfaces at the next audit.
The supervisory authority can require the withdrawal of an appointment if the required qualification or reliability is missing. Evidence of ongoing training and technical fitness is often assembled only once it is requested.
The risk analysis describes a business model the institution no longer runs: new products, new distribution channels, and new countries are missing. Once that happens, the safeguards derived from it lose their foundation.
Credit institutions must operate data processing systems under Sec. 25h(2) KWG that detect unusual business relationships and transactions. If scenarios and thresholds have never been calibrated to the actual customer portfolio, the result is an alert flood without discriminating power.
Investigated matters must be adequately documented under Sec. 8 GwG and Sec. 25h(3) KWG. In practice, the reasoning behind cases that were not reported is often missing – and these are exactly the cases auditors focus on.
Group-wide obligations under Sec. 9 GwG, diverging standards across subsidiaries, and the EU AMLR taking direct effect from July 2027 all increase coordination effort. Without a clearly assigned owner for reconciling requirements, two rulebooks end up running side by side.
The scope is set out in the outsourcing agreement. You can transfer the mandate in full or engage individual building blocks alongside an existing internal function.
A named function with a fixed contact and a defined deputy arrangement.
A derivation that shows the path from business model to control measure.
Parameters calibrated to your portfolio, with a documented rationale.
Allocation: S+P Compliance proposes scenarios and thresholds, tests them, and documents the outcome. Approval is given by your institution. S+P Compliance is vendor-independent and does not assess third-party products.
A clean split between preparation, decision, and filing.
Allocation: the reporting obligation under Sec. 43 GwG rests with the obliged entity. Where the appointed Money Laundering Reporting Officer intends to file a report, they are not subject to management’s right to issue instructions in that respect (Sec. 7(5) GwG). Your institution decides on the discrepancy report under Sec. 23a GwG.
Hits are prepared and assessed – holds are placed by your institution.
Allocation: the decision to place or lift a sanctions hold, and communication with authorities, rests with your institution. S+P Compliance prepares and documents.
Evidence that already exists before it is requested.
An outsourcing arrangement does not become reliable through service delivery alone, but through its governance. We fix these four elements before the mandate starts.
Scope of services, quality standards, response times, and reporting duties are fixed in writing. We prepare the notification to the supervisory authority; your institution files it.
Your institution keeps the ability to steer the mandate. Access, information, and audit rights are agreed for the institution, internal audit, external auditors, and the supervisory authority.
Alongside the named individual, a properly onboarded deputy is fixed by contract. Availability windows and escalation paths are part of the agreement, not an informal understanding.
A defined procedure exists for termination, transition, or bringing the function back in-house: data handover, transition documentation, and onboarding of a successor are described in advance.
The right model depends on size, the licence held, and your existing internal staffing. Models can be switched over time.
S+P Compliance provides the Money Laundering Reporting Officer. Your institution retains the decision-making rights it cannot delegate.
Officer functionThe internal function remains in place, S+P Compliance takes on the deputy role. That makes the substitution arrangement genuinely operational, not just a formal appointment.
Deputy arrangementFixed-term staffing during a vacancy, a new hire process, or the build-out of a new unit, combined with a structured handover to the internal successor.
Transition periodSupport for individual tasks without an officer mandate. Pure advisory input that only supports the obliged entity does not, on its own, constitute an outsourcing arrangement under Sec. 6(7) GwG.
No mandateTiming depends on how complete your risk analysis and existing documentation already are, and on how quickly the notification to the supervisory authority can be coordinated.
Licence type, business model, existing staffing, and open findings are captured. The result is a stocktake with clear priorities.
We assess materiality, interfaces, and controllability, and present a proposal with a defined scope of services, response times, and reporting rhythm.
The outsourcing agreement and appointment are signed. We prepare the notifications under Sec. 7(4) and Sec. 6(7) GwG; your institution submits them.
Ongoing operation with documented controls, interim reporting, an annual report to management, and support during audits.
Four processes determine, in the event of an audit, whether an outsourcing arrangement was set up cleanly. For each of them, we set out in writing who prepares, who advises, and who decides. This allocation is part of the outsourcing agreement and is not negotiated in day-to-day business.
The principle applies throughout: S+P Compliance prepares and documents, your institution decides. Outsourcing shifts execution, not responsibility. Where the appointed Money Laundering Reporting Officer intends to file a report under Sec. 43(1) GwG, they are not subject to management’s right to issue instructions in that respect; the reporting obligation itself remains with the obliged entity.
| Process | S+P Compliance prepares and documents | Decision and responsibility at the institution | Legal reference |
|---|---|---|---|
| Suspicious activity report | Case preparation, assessment, draft report, deadline monitoring, documentation including cases not reported | Reporting obligation of the obliged entity; the appointed officer’s reporting decision is not subject to management’s right to instruct | Sec. 43 GwG, Sec. 7(5) GwG |
| Sanctions hit | Identity matching, hit assessment, decision proposal, evidence trail | Placing, lifting, and releasing a hold; communication with authorities | EU sanctions regulations, Sec. 6 GwG |
| Discrepancy report | Reconciliation of beneficial ownership data, preparation of the discrepancy, draft report | Decision on filing the discrepancy report with the register-keeping body | Sec. 23a GwG |
| Scenarios and thresholds | Analysis, proposal, back-testing against historical data, rationale per segment | Approval of the parameters and of the internal safeguards by senior management | Sec. 25h(2) KWG, Sec. 4(3) GwG |
In an initial conversation we clarify licence type, existing staffing, and any open findings from your last audit. The outcome is an assessment of which engagement model fits and which decisions must stay with your institution.
The officer and deputy are contractually fixed, onboarded, and reachable – including during holidays and periods of illness.
ContinuityDecisions, rationales, and controls are structured and available before auditors request them.
DocumentationScope of services and fees are contractually defined. Recruitment, onboarding, and training no longer appear as separate line items.
Cost predictabilityScenarios and thresholds are tested against your own customer portfolio, rather than carried over from default settings.
EffectivenessWho prepares and who decides is set out in writing. That reduces follow-up questions during internal audit and supervisory review.
GovernanceThe AML organization is continuously checked against the EU AMLR, which becomes directly applicable on 10 July 2027.
AMLRThis service is aimed at obliged entities under Sec. 2(1) GwG with a registered office or branch in Germany, required or ordered to appoint a Money Laundering Reporting Officer.
Outsourcing the Money Laundering Reporting Officer can be combined with further control functions. All mandates follow the same role logic: execution is external, responsibility stays with your institution.
The German-language counterpart of this service, for German-speaking stakeholders within your organization.
View serviceGeneral compliance function under AT 4.4.2 MaRisk, with monitoring, advice, and management reporting.
View serviceA focused mandate for MaRisk-compliant implementation and monitoring, including legal inventory management.
View serviceSecurities trading compliance under Sec. 80 WpHG, with product governance and complaints handling.
View serviceThe German-language internal audit outsourcing service, for German-speaking stakeholders within your organization.
View serviceInformation security officer function under BAIT and Art. 6(4) DORA, with organizational independence.
View serviceData protection organization under the GDPR, with a records of processing activities and audit-proof documentation.
View serviceSteering and control of all outsourcing arrangements, including the outsourcing register, risk analyses, and reporting.
View serviceTimely, technically validated XBRL filings for FINREP and COREP, without running your own reporting software.
View serviceOperational support for alert handling, case closure, and backlog reduction – available at short notice and scalable.
View serviceCustomer due diligence in day-to-day operations: onboarding, periodic refresh, and clearance of outstanding cases.
View serviceIndependent audits under a risk-based audit plan, delivered with English-language reporting for international groups.
View serviceS+P Compliance provides a named individual as Money Laundering Reporting Officer and carries out the operational AML work: risk analysis under Sec. 5 GwG, internal safeguards under Sec. 6 GwG, transaction monitoring, alert handling, case preparation, staff training, and reporting. The role is carried out in Germany, and availability for supervisors, the FIU, and law enforcement is part of the mandate. The exact scope is set out in the outsourcing agreement.
This applies to obliged entities under Sec. 2(1) GwG for which a Money Laundering Reporting Officer must be appointed or has been ordered by the supervisory authority: credit institutions, investment firms, payment and e-money institutions, capital management companies, crypto custodians, and FinTechs with a German KWG or ZAG licence, as well as German branches of foreign institutions. Outsourcing is most useful where the function needs continuous, qualified coverage but the volume of business does not justify a full-time position with sufficient breadth of expertise.
Yes. Outsourcing shifts execution, not responsibility. Under Sec. 6(7) GwG, responsibility for fulfilling the internal safeguards remains with the obliged entity, and Sec. 25h(4) KWG contains a corresponding provision for credit institutions. The responsibility of senior management under Sec. 7(1) GwG also remains unaffected. The transfer must be notified to the supervisory authority in advance, and the authority can prohibit the transfer or require it to be reversed if steering or control capabilities are impaired.
No, not on the reporting decision itself. Where the appointed Money Laundering Reporting Officer intends to file a report under Sec. 43(1) GwG, they are not subject to management’s right to issue instructions in that respect, under Sec. 7(5) GwG. This safeguards the independence of the reporting decision. The underlying reporting obligation continues to rest with the obliged entity, not with the individual officer personally.
Every case, every monitoring decision, and every training record is version-controlled, time-stamped, and logged with a rationale, including matters closed without a report. S+P Compliance’s own control system is audited under IDW PS 951 and ISAE 3402, see the Legal basis and audit evidence section. That allows your institution and your supervisor to trace, at any point, when a given decision was taken and on what basis.
The mandate is grounded in the German Anti-Money Laundering Act, in particular Sec. 4 to 9, Sec. 23a, and Sec. 43 GwG, and, for credit institutions, Sec. 25h KWG together with the relevant MaRisk outsourcing requirements. Sanctions law under EU regulations applies alongside sector-specific rules under KWG, ZAG, WpIG, or KAGB depending on the licence held. The EU Anti-Money Laundering Regulation (Regulation (EU) 2024/1624), directly applicable from 10 July 2027, is continuously reconciled against the existing organization. This overview reflects the legal position as of September 2026.
An outsourced Money Laundering Reporting Officer function works when two things come together: expert work that follows your business model, and a role allocation that can be evidenced in an audit. S+P Compliance sets up both together with you – execution is transferred, regulatory responsibility stays with your institution.


Achim Schulz verantwortet die S+P Compliance Services. Da S+P als Dienstleister für regulierte Institute fortlaufend von Wirtschaftsprüfern und Aufsichtsbehörden geprüft wird, ist die Prüfungsexpertise seines Teams immer auf dem neuesten Stand. Ihr Vorteil: Er weiß aus der täglichen Praxis exakt, welche Nachweise und Kontrollen in aktuellen Audits zwingend gefordert werden. Diese tagesaktuelle Expertise fließt direkt in Ihre Auslagerung ein. Sie profitieren von zertifizierten Prozessen (IDW PS 951, ISO), die jedem Audit durch die BaFin oder Ihren Abschlussprüfer absolut sicher standhalten.
LinkedIn-Profil → · Redaktion & Experten → · S+P Compliance Services →Wir verwenden Cookies und ähnliche Technologien, um Ihre Erfahrung auf unserer Website zu verbessern. Weitere Informationen in unserer Datenschutzerklärung.