77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Anti Money Laundering Officer Germany: Duties, Liability, GwG Compliance
Geldwäscheprävention

Anti Money Laundering Officer Germany: Duties, Liability, GwG Compliance

23 July 202613 min readBy Dr. Henrik Bauer
CIVAC

Germany's GwG forces a defined list of obliged entities to appoint an AML officer with personal liability. This guide explains the legal basis, daily duties, documentation evidence BaFin expects and how CIVAC structures the role as platform or officer-as-a-service.

Section 7 of the German Money Laundering Act (Geldwaeschegesetz, GwG), in force since 26 June 2017 and last amended by the Financial Market Digitisation Act of 2023, obliges defined categories of companies to appoint a Geldwaeschebeauftragter, the German equivalent of an Anti Money Laundering Officer. The obligation applies to credit institutions, financial services providers, payment institutions, insurance intermediaries with life products, real estate agents above the 10.000 Euro cash threshold, traders in high-value goods, art dealers, and notaries. BaFin enforces the rule and fined obliged entities a total of 8,4 million Euro in 2024 for AML governance defects.

This article is written for executives who need clarity before they sign the appointment letter. You will learn which entities qualify as obliged, what § 7 GwG actually demands from the officer, how the personal liability under § 56 GwG is structured, which documentation BaFin inspectors request first, and how CIVAC operates the role as Compliance-Plattform und Officer-as-a-Service. Both the platform license for in-house AML officers and the fully outsourced mandate are covered, with the relevant templates, deadlines and reporting lines mapped to the day-to-day reality of an obliged entity in 2026.

Auf einen Blick

  • Section 7 GwG requires a named AML officer plus a designated deputy at management level, notified to BaFin in writing before the appointment takes effect.
  • Personal fines under § 56 GwG reach 150.000 Euro for individuals and 5 million Euro or 10 percent of annual turnover for the obliged entity.
  • CIVAC provides a 37-template AML workspace covering risk analysis, SAR drafts, training logs and the appointment certificate, audit-ready within 2 working days.

Which Companies Need an AML Officer in Germany

The catalogue of obliged entities is defined in § 2 GwG and runs across 16 categories. The most relevant in practice are credit institutions and their German branches, financial services institutions licensed under the KWG, payment and e-money institutions under the ZAG, insurance undertakings selling life or investment products, asset management companies, real estate agents handling rentals above 10.000 Euro per month or sales of any value, tax advisors, lawyers when they act as fiduciaries, notaries, auditors, traders in goods above the 10.000 Euro cash threshold, and explicitly since 2020 art and antiquity dealers and intermediaries above 10.000 Euro per transaction. Crypto-asset service providers were added in 2020 and reconfirmed under the MiCAR regime from 30 December 2024.

The duty to appoint a dedicated AML officer under § 7 GwG is automatic for credit and financial institutions. For other obliged entities BaFin can order the appointment if the business risk profile justifies it, typically when the company processes more than 100 transactions above the threshold per year, operates across multiple federal states, or has previously been flagged for documentation gaps. The 2024 BaFin annual report lists 312 such individual orders, a 41 percent increase versus 2023. Sole proprietors below 10 employees can be exempted on application but must still execute the risk analysis under § 5 GwG and document internal safeguards. For the structured role page see our Geldwaeschebeauftragter overview, which lists the appointment workflow and the template package included in the CIVAC workspace.

Statutory Duties Under Section 7 GwG

The AML officer is the operational guardian of the entity's compliance with the GwG, the EU Funds Transfer Regulation 2015/847, and the indirectly applicable EU AML Regulation 2024/1624 which enters into force on 10 July 2027. Section 7 paragraph 5 GwG lists the core duties: oversee the company-specific risk analysis under § 5, design and maintain internal safeguards under § 6, train staff under § 6 paragraph 2 number 6, screen employees for reliability, investigate suspicious transactions, and file Suspicious Activity Reports (Verdachtsmeldungen) to the FIU at the General Customs Directorate under § 43 GwG. The duties extend to the second-level review of KYC files for high-risk customers and politically exposed persons, plus the sign-off on enhanced due diligence under § 15 GwG for high-risk jurisdictions.

The officer must have direct reporting access to the management board, must not be subject to instructions when filing SARs, and must be reachable for FIU and BaFin queries during business hours. The deputy is a hard requirement, not optional, and must be similarly qualified. CIVAC structures the daily workload in the Workspace with 490 einsatzbereite Audit-Vorlagen including the risk analysis matrix, the KYC monitoring log, the SAR draft form, the staff training register, and the annual report to the management board. The platform also produces the Bestellurkunde, unterschrieben, abgelegt, belegbar. Lizenzieren Sie den Workspace für Ihre internen Beauftragten, oder lassen Sie unsere Beauftragten bestellen. The Berichtslinie inside the workspace timestamps every escalation so the board cannot claim it never knew. Each template ships with a German-law reference column linking the relevant § to the BaFin interpretation note.

Appointment, Notification and the Bestellurkunde

The appointment is a formal act, not a job description handed over the desk. The management board adopts a written resolution, signs the Bestellurkunde naming the officer and the deputy, and notifies BaFin in writing under § 7 paragraph 4 GwG. The notification must reach BaFin before the officer takes up duties, not after. The letter contains full name, date of birth, professional qualifications, contact details, and a declaration that the officer has the time, authority and access needed to perform the role. BaFin maintains a register and can object within four weeks if the qualification or independence is insufficient. A rejected appointment must be replaced within 30 days, and the obliged entity continues to carry the underlying duty in the meantime.

Qualification is not codified as a single certificate but BaFin's Auslegungs- und Anwendungshinweise of August 2024 reference the BaFin examination, the certified anti-financial-crime specialist (CAFCS), or equivalent practical experience of at least three years in a comparable role. The officer must complete continuous training, evidenced by a training log. The CIVAC workspace stores the Bestellurkunde, the BaFin notification copy, the qualification certificates, and the training log in a single audit-ready folder per role. Der Prüfer ruft an, der Nachweis liegt bereit. The same workflow is reused for the deputy and any sub-delegates inside the second line of defence. Templates cover both the initial appointment and any later change of person, including the standard BaFin cover letter, the resolution minute, and the internal communication to staff that the new officer is in post.

Risk Analysis Under Section 5 GwG

The risk analysis is the foundation document. Section 5 GwG requires the obliged entity to identify and assess the AML and terrorism financing risks specific to its business, customers, products, countries of operation, and distribution channels. The analysis must be documented in writing, updated regularly, presented to the management board, and made available to BaFin on request. There is no statutory page count, but BaFin inspectors typically expect 25 to 60 pages for a mid-size obliged entity. The supranational risk assessment of the European Commission, last published in October 2022, must be referenced explicitly, and the national risk assessment of the Federal Ministry of Finance, last updated in 2023, must be reflected in the methodology.

The analysis covers six dimensions: customer risk (PEPs, high-risk jurisdictions, complex ownership structures), product risk (cash-intensive, anonymous, cross-border), geographic risk referencing the FATF and EU high-risk lists last updated in March 2025, transaction risk, distribution channel risk including non-face-to-face onboarding, and emerging risk such as crypto-asset service providers under the MiCAR. CIVAC ships a risk analysis template with pre-populated scoring matrices, integrates the official FATF and EU lists, and produces the management-board presentation as a PDF deliverable. The template version is timestamped, the previous versions remain accessible, and BaFin's audit question on update frequency is answered without manual search. Andere führen Compliance wie einen Aktenschrank. Wir führen sie wie Software. The update cycle defaults to annually plus event-driven revisions whenever the product mix or customer base shifts materially, with automated reminders 90 days before the next scheduled review.

Suspicious Activity Reports to the FIU

Filing a Suspicious Activity Report is the highest-stakes daily duty. Section 43 GwG requires immediate reporting to the Financial Intelligence Unit at the General Customs Directorate in Cologne whenever facts indicate that an asset is connected to money laundering or terrorism financing, irrespective of value. The report is filed via goAML, the FIU's encrypted reporting portal. The transaction must be suspended until the FIU clears it or until three working days have passed under § 46 GwG, the so-called Standstill obligation. Frist laeuft ab Kenntnis. Tipping off the customer is a criminal offence under § 47 GwG punishable with up to five years imprisonment, and applies to any internal communication that could leak the SAR to the customer.

The FIU received 326.190 SARs in 2024 according to its annual report published 25 March 2025, a 17 percent decrease versus 2023 but with a higher conversion rate to law-enforcement investigations. False positives remain the largest operational problem. CIVAC's SAR draft template structures the report along the FIU's mandatory fields, links to the underlying customer file in the workspace, and stores the goAML reference number after submission. Internal approvals are logged, the three-day standstill clock starts automatically, and the deputy is notified if the officer is unreachable. For the role-specific workflow inside the platform, see the Geldwaeschebeauftragter role page. The training register feeds directly from completed SAR cases so junior staff learn from real anonymised material rather than abstract scenarios, which the BaFin examiners explicitly reward in their on-site reviews.

Personal Liability and BaFin Sanctions

Personal liability is the reason most candidates hesitate before signing the Bestellurkunde. Section 56 GwG lists 75 separate fineable offences. The most common in BaFin enforcement practice are failure to file an SAR (§ 56 paragraph 1 number 69), insufficient risk analysis (number 13), missing internal safeguards (number 17), and inadequate training (number 23). For a natural person the maximum fine is 150.000 Euro per offence, raised to 1 million Euro for grossly negligent or repeated breaches under § 56 paragraph 3. For the obliged entity the cap is 5 million Euro or 10 percent of total annual turnover, whichever is higher. Section 130 OWiG can add organisational-fault fines for management board members on top, which BaFin has increasingly leveraged since 2023.

Beyond fines, BaFin can publicly name the sanctioned entity under § 57 GwG, order the dismissal of the officer under § 16 KWG by reference, and in severe cases withdraw the banking or payment licence. The 2024 BaFin sanctions list shows 47 published cases with a median fine of 180.000 Euro per entity. Personal liability is not extinguished when the officer leaves the company, and the limitation period is five years from the offence under § 31 OWiG. CIVAC mitigates the personal-risk dimension through documented escalation paths, the four-eye principle on SAR decisions, and the Berichtslinie that connects the officer directly to the management board with timestamped read receipts. Audit-fest, dokumentiert, GwG-fest. The platform also retains an immutable audit log under EU-Datenresidenz that survives staff turnover and legal disputes.

Training, Screening and the Annual Report

Section 6 paragraph 2 number 6 GwG requires regular training of all employees who deal with customers, transactions or products in scope. BaFin's interpretation note expects at minimum one annual training session, documented with attendee list, content outline, and a comprehension test. New employees must be trained within their first 30 days. Section 6 paragraph 2 number 5 GwG requires a reliability check (Zuverlaessigkeitspruefung) of relevant staff, typically through a police clearance certificate (Führungszeugnis) updated every three years. The training must cover red flags, customer due diligence, sanctions screening and the SAR workflow specific to the business, plus the tipping-off prohibition under § 47 GwG and the standstill obligation under § 46 GwG.

The annual report to the management board under § 7 paragraph 5 number 6 GwG summarises the year's risk analysis updates, SAR statistics, training completion rates, internal audit findings and remediation status. The report is presented in writing and discussed in a board meeting; the minutes are part of the BaFin audit trail. The CIVAC workspace generates the annual report from the underlying logs in 30 minutes, automatically pulling SAR counts, training completion percentages, and risk analysis revision history. The CIVAC SLA for the full appointment package, including the BaFin notification draft, the risk analysis, the SAR template and the training plan, is 2 Werktage statt 2 bis 6 Wochen klassisch. The same workspace handles the parallel reporting for the Compliance-Beauftragter where one person covers both roles, with role-segregated permission layers on every document.

Outsourcing the AML Officer: Legal Limits and Practice

Section 6 paragraph 7 GwG permits outsourcing of AML functions to a third party subject to a written agreement, supervisory control by the obliged entity, and BaFin notification. The AML officer role itself can be performed by an external natural person provided that person has the same authority, independence and access to the management board as an internal officer. The external officer must be physically present in Germany for FIU and BaFin interactions, and EU data residency is mandatory for the underlying records. The contractual responsibility of the obliged entity stays unchanged, which is why the choice of external provider is itself a BaFin-relevant decision and is reviewed in every on-site inspection.

CIVAC operates the externally appointed AML officer as a service across credit institutions below 50 million Euro balance sheet, payment institutions, real estate agencies, and traders in high-value goods. The external mandate includes the appointment certificate, the BaFin notification, the risk analysis, the monthly transaction review, the SAR drafting and filing via goAML, the training delivery, and the annual report. The dual-model principle applies: Lizenzieren Sie den Workspace für Ihre internen Beauftragten, oder lassen Sie unsere Beauftragten bestellen. The workspace and the officer share one data layer hosted in Frankfurt with EU-Datenresidenz, ISO/IEC 27001:2022 ISMS, and the 93 controls of the updated standard. For the BaFin notification template and the appointment workflow, see the dedicated Geldwaeschebeauftragter role page and the FAQ on outsourcing obligations. Termination clauses and substitution rights are pre-drafted in the standard mandate.

From Reading to Mandate: Next Steps with CIVAC

If your entity falls under § 2 GwG and you have not yet appointed an AML officer, three steps follow this article. First, confirm the obliged-entity status through a 30-minute legal screening using the CIVAC obliged-entity matrix, which maps the 16 categories of § 2 GwG against your actual transaction flows, customer base and product mix. Second, decide between the dual model: workspace license for your internal officer team, or full officer-as-a-service mandate where CIVAC provides a qualified external officer. Third, sign the engagement letter, receive the Bestellurkunde and the BaFin notification draft within 2 Werktage, and start the risk analysis from a populated template instead of a blank page.

CIVAC is a Compliance-Plattform und Officer-as-a-Service operating from Frankfurt under German law, with 25 Beauftragten-Rollen live, 490 einsatzbereite Audit-Vorlagen, and EU-Datenresidenz. The platform also supports parallel mandates for the Compliance-Beauftragter, the Datenschutzbeauftragter and the Informationssicherheitsbeauftragter when the obliged entity needs more than the AML role. Aus dem Lesen einen Auftrag machen. Write to info@civac.de or use the contact form on civac.de to schedule the obliged-entity screening. The screening is non-binding, takes 30 minutes, and produces a written recommendation on appointment timeline, scope, and the choice between platform license and external officer mandate. References from existing clients are available on request under NDA, including credit institutions, payment institutions and traders in high-value goods. CIVAC also runs a quarterly BaFin regulatory update for licensed clients, summarising new interpretation notes, fine practice and EU AML Regulation milestones in a 20-minute briefing that the AML officer can present directly to the management board.

FAQ

Who is required to appoint an AML officer in Germany?

Section 7 GwG requires credit and financial institutions to appoint an AML officer automatically. Other obliged entities under § 2 GwG must appoint when BaFin orders it, typically based on transaction volume, geographic spread or prior findings. Sole proprietors below 10 employees can apply for exemption but must still document the risk analysis under § 5 GwG.

What is the personal fine exposure for an AML officer in Germany?

Section 56 GwG sets the personal fine at up to 150.000 Euro per offence and up to 1 million Euro for grossly negligent or repeated breaches. The obliged entity is liable up to 5 million Euro or 10 percent of annual turnover. BaFin can also publish the sanction under § 57 GwG and order dismissal under § 16 KWG.

How fast must a Suspicious Activity Report be filed with the FIU?

Section 43 GwG requires immediate filing once the suspicion arises. The underlying transaction is suspended under § 46 GwG until the FIU clears it or three working days have passed. Filing is done via the goAML portal of the General Customs Directorate in Cologne, and tipping off the customer is a criminal offence under § 47 GwG.

Can the AML officer role be outsourced to an external provider?

Yes, under § 6 paragraph 7 GwG. The external officer needs the same independence, board access and management authority as an internal officer, must be physically present in Germany, and the obliged entity remains supervisory accountable. BaFin must be notified of the external appointment in advance, and the underlying records must stay within EU data residency.

What qualifications does BaFin expect from an AML officer?

BaFin's August 2024 interpretation note references the BaFin examination, the CAFCS certificate, or at least three years of practical AML experience in a comparable obliged entity. Continuous training is mandatory, evidenced through a documented training log. The officer must also have the time and resources to perform the role independently of operational profit incentives.

How does CIVAC structure the AML officer appointment?

CIVAC offers the dual model: license the workspace for your internal officer with 37 audit templates, or have CIVAC's external AML officer bestellen. The appointment package, BaFin notification, risk analysis and SAR template are delivered within the CIVAC SLA of 2 working days. EU data residency and the ISO/IEC 27001:2022 ISMS with 93 controls apply throughout.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles