German AML compliance in 2026 is shaped by three things at once: the Money Laundering Act (Geldwäschegesetz, GwG) as it stands, BaFin's updated interpretation guidance which tightened several practical obligations, and the approaching EU AML Regulation which will supersede much of the national substance from 10 July 2027.
For a bank or asset manager operating in Germany, the useful framing is that the current work is not an end state. Investments made now in how customer data is kept current will carry over; investments made in paraphrasing the GwG will not.
1. Who supervises, and where the data goes
BaFin is the supervisory authority for financial institutions under the GwG. Suspicious activity reports go to the Financial Intelligence Unit, and beneficial ownership information is notified to the Transparenzregister.
One development worth noting for anyone working in Frankfurt: the EU's new anti-money-laundering authority, AMLA, operates from Frankfurt as of 2026. It will not supervise most institutions directly — its remit centres on selected cross-border obliged entities and on convergence of supervisory practice — but its presence means German supervisory practice will be unusually close to the emerging European standard.
2. What the GwG requires
The GwG implements the EU directives into German law and sets the familiar obligations: identify and verify the contracting party and any person acting on their behalf, establish the beneficial owner, apply enhanced due diligence where risk warrants it, monitor the business relationship on an ongoing basis, keep records, and report suspicion without delay.
Two features distinguish German practice. First, the firm-wide risk analysis (Risikoanalyse) is a formal, documented instrument that supervision examines directly, not an internal memo. Second, remote identification is subject to specific requirements — a recurring friction point for digital onboarding, and one where the permissible methods have evolved.
3. BaFin's updated guidance: three concrete tightenings
BaFin's revised Interpretation and Application Guidance (Auslegungs- und Anwendungshinweise, AuA) came into effect in March 2025. Three changes matter operationally.
The risk analysis has to carry more weight. Expectations on its granularity and on the traceability from identified risk to applied control both increased. A risk analysis that lists risks without showing which control addresses each is now the weaker position.
Documentation obligations were enhanced. The practical test is whether a reviewer can reconstruct not just the outcome of a decision but the reasoning and the evidence available at the time it was taken.
Deadlines for updating customer data were shortened. This is the change with the largest operational consequence and the least visibility, because it does not alter what you do — only how quickly. A shorter update deadline applied across a large book converts a manageable periodic workload into a continuous one. It is the same structural shift we describe in perpetual KYC, arriving through supervisory guidance rather than legislation.
4. Reporting: goAML from March 2026
From March 2026, suspicious activity reports must be filed without delay via goAML. Institutions that had been treating reporting as a periodic batch process need it to be an event-driven one, which in practice means the detection step has to be timely enough to make the filing step possible.
The dependency runs backwards from the deadline: you cannot report without delay if the underlying monitoring surfaces the concern weeks late.
5. Transparenzregister: wider notification duties
EU-wide harmonisation has expanded the obligations of both German and foreign companies to notify their beneficial owners to the Transparenzregister. For an institution, the relevant consequence is twofold: register data becomes a more useful input to your own verification, and your corporate clients face their own compliance burden — which is frequently where the friction in onboarding actually sits.
Register data remains an input, not a substitute. The obligation to establish the beneficial owner rests with you; a register entry is evidence to be assessed, and discrepancies between what a client tells you and what the register says are themselves a risk signal. The method is set out in automating UBO and beneficial ownership verification.
