German AML compliance in 2026 is shaped by three things at once: the Money Laundering Act (Geldwäschegesetz, GwG) as it stands, BaFin's updated interpretation guidance which tightened several practical obligations, and the approaching EU AML Regulation which will supersede much of the national substance from 10 July 2027.
For a bank or asset manager operating in Germany, the useful framing is that the current work is not an end state. Investments made now in how customer data is kept current will carry over; investments made in paraphrasing the GwG will not.
1. Who supervises, and where the data goes
BaFin is the supervisory authority for financial institutions under the GwG. Suspicious activity reports go to the Financial Intelligence Unit, and beneficial ownership information is notified to the Transparenzregister.
One development worth noting for anyone working in Frankfurt: the EU's new anti-money-laundering authority, AMLA, operates from Frankfurt as of 2026. It will not supervise most institutions directly — its remit centres on selected cross-border obliged entities and on convergence of supervisory practice — but its presence means German supervisory practice will be unusually close to the emerging European standard.
2. What the GwG requires
The GwG implements the EU directives into German law and sets the familiar obligations: identify and verify the contracting party and any person acting on their behalf, establish the beneficial owner, apply enhanced due diligence where risk warrants it, monitor the business relationship on an ongoing basis, keep records, and report suspicion without delay.
Two features distinguish German practice. First, the firm-wide risk analysis (Risikoanalyse) is a formal, documented instrument that supervision examines directly, not an internal memo. Second, remote identification is subject to specific requirements — a recurring friction point for digital onboarding, and one where the permissible methods have evolved.
3. BaFin's updated guidance: three concrete tightenings
BaFin's revised Interpretation and Application Guidance (Auslegungs- und Anwendungshinweise, AuA) came into effect in March 2025. Three changes matter operationally.
The risk analysis has to carry more weight. Expectations on its granularity and on the traceability from identified risk to applied control both increased. A risk analysis that lists risks without showing which control addresses each is now the weaker position.
Documentation obligations were enhanced. The practical test is whether a reviewer can reconstruct not just the outcome of a decision but the reasoning and the evidence available at the time it was taken.
Deadlines for updating customer data were shortened. This is the change with the largest operational consequence and the least visibility, because it does not alter what you do — only how quickly. A shorter update deadline applied across a large book converts a manageable periodic workload into a continuous one. It is the same structural shift we describe in perpetual KYC, arriving through supervisory guidance rather than legislation.
4. Reporting: goAML from March 2026
From March 2026, suspicious activity reports must be filed without delay via goAML. Institutions that had been treating reporting as a periodic batch process need it to be an event-driven one, which in practice means the detection step has to be timely enough to make the filing step possible.
The dependency runs backwards from the deadline: you cannot report without delay if the underlying monitoring surfaces the concern weeks late.
5. Transparenzregister: wider notification duties
EU-wide harmonisation has expanded the obligations of both German and foreign companies to notify their beneficial owners to the Transparenzregister. For an institution, the relevant consequence is twofold: register data becomes a more useful input to your own verification, and your corporate clients face their own compliance burden — which is frequently where the friction in onboarding actually sits.
Register data remains an input, not a substitute. The obligation to establish the beneficial owner rests with you; a register entry is evidence to be assessed, and discrepancies between what a client tells you and what the register says are themselves a risk signal. The method is set out in automating UBO and beneficial ownership verification.
6. What is coming, and the dates
| When | What |
|---|---|
| March 2025 | BaFin's updated AuA in effect — risk analysis, documentation, shorter data-update deadlines |
| 2026 | AMLA operational in Frankfurt |
| March 2026 | Suspicious activity reports without delay via goAML |
| 1 January 2027 | Financial holding companies proposed to become GwG-obliged entities |
| 10 July 2027 | EU AML Regulation applies, superseding much of the national substance |
The 2027 date is the one to plan against. A regulation applies directly and as written, which removes the layer of national interpretation German compliance functions are accustomed to working through. Policies drafted as commentary on GwG sections will need rewriting against the Regulation text rather than annotating.
7. A practical checklist
- Re-read your Risikoanalyse against the updated AuA and make the risk-to-control mapping explicit rather than implied.
- Measure your actual customer data update cycle — not the policy, the observed one — against the shortened deadlines. The gap between the two is your exposure.
- Confirm your detection-to-report path is fast enough for a without-delay goAML filing.
- Treat Transparenzregister entries as evidence to reconcile, and record the reconciliation, including where it disagreed.
- Check whether any group entity becomes obliged as a financial holding company from January 2027.
- Start mapping obligations to the AMLR text now, so that July 2027 is a change of reference rather than a rewrite under time pressure.
8. Frequently asked questions
What is the GwG?
The Geldwäschegesetz, Germany's Money Laundering Act. It transposes the EU anti-money-laundering directives into German law and sets out customer due diligence, beneficial ownership, record-keeping and reporting obligations for obliged entities.
Who supervises AML compliance in Germany?
BaFin supervises financial institutions under the GwG. Suspicious activity reports go to the Financial Intelligence Unit, and beneficial ownership data is notified to the Transparenzregister.
What changed in BaFin's updated guidance?
The revised Interpretation and Application Guidance took effect in March 2025, with higher expectations on the firm-wide risk analysis, enhanced documentation obligations, and shortened deadlines for updating customer data.
When do suspicious activity reports have to be filed via goAML?
From March 2026, without delay.
Does the EU AML Regulation replace the GwG?
It supersedes much of the national substantive law from 10 July 2027, applying directly rather than through German implementation. National law continues to matter for supervision, sanctions and the areas the Regulation leaves to member states, but the substantive due-diligence requirements will be read from the Regulation.
Does AMLA in Frankfurt supervise my institution?
For most institutions, no. AMLA's direct supervisory remit centres on selected cross-border obliged entities, alongside a broader role in converging supervisory practice across member states.
9. How Wecan fits
The two German-specific pressures described above — shorter data-update deadlines and without-delay reporting — are both problems of currency, not of process design. They are hard to solve by working faster and comparatively easy to solve by changing when the work happens.
Wecan Comply keeps each client file continuously current rather than revisiting it on a calendar: documents are structured on capture, screening runs against fresh sources instead of at review time, and a material change surfaces when it occurs rather than at the next cycle. Every step carries a timestamped audit trail with its author, which is what BaFin's enhanced documentation expectations ultimately ask for — the reasoning and the evidence as they stood at the moment of the decision.
For neighbouring frameworks see our guides to the EU AML package through a Luxembourg lens and Swiss AML in 2026.
