77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Introduce the KYC process: Duties, stages and roles according to the AMLA
Anti-Money Laundering

Introduce the KYC process: Duties, stages and roles according to the AMLA

5 July 202613 min readBy Dr. Henrik Bauer
CIVAC

A KYC process is more than just identification on onboarding. It includes risk analysis, due diligence requirements per risk class, continuous monitoring and suspicious activity reporting. This guide shows what obliged entities must set up structurally in accordance with Section 2 of the GwG.

The obligation to use the know-your-customer process is rooted in the Money Laundering Act, which was significantly tightened with the fourth and fifth EU Money Laundering Directives. Section 10 GwG requires those obliged under Section 2 GwG to identify their contractual partners, determine their beneficial owners, assess business relationships on a risk-based basis and continuously monitor them. Obligated parties are not only banks and insurers, but also real estate agents, goods dealers for cash transactions over 10,000 euros, crypto custodians, lawyers and notaries for certain activities, auditors and trustees. The range is wide and often underestimated in practice.

This article shows how a KYC process is introduced in a structured manner, which stages it includes, which roles it requires and which documentation is included in the audit by the supervisory authorities, such as BaFin or the state supervisory authority. You will receive an overview of the legal anchors, a sketch of the three levels of care, a description of the typical interfaces to sales, onboarding and compliance, as well as a classification of how CIVAC, as a compliance platform and officer-as-a-service, maps the role of the money laundering officer and the KYC workflow in a workspace. 490 audit templates, multi-client capable multi-location management, EU data residency and an SLA of two working days for external orders instead of the industry standard two to six weeks round off the offer for medium-sized and larger companies.

Key Takeaways

  • KYC obligations apply to all obliged entities in accordance with Section 2 of the GwG and include identification, beneficial ownership, risk classification and monitoring.
  • The KYC process is characterized by three stages: simplified, general and enhanced due diligence, each with its own verification requirements.
  • The money laundering officer is responsible for the entire process; Personal liability and fines of up to 5 million euros make documentation central.

Who is the obligated party according to Section 2 GwG and what does that mean in practice

§ 2 GwG lists the obligated parties conclusively. Classically covered are credit institutions, financial services institutions, payment service providers, e-money institutions, insurance companies with life insurance, insurance intermediaries in the life sector and capital management companies. The obligations have been expanded significantly in recent years. Today this includes real estate agents for purchase and rental transactions, goods dealers for cash payments over 10,000 euros and art dealers for transactions over 10,000 euros, as well as crypto custodians according to Section 1 KWG. The freelance professions include lawyers, notaries, auditors and tax consultants in certain activities, as well as trustees and service providers for companies.

In practice, this means: Even a medium-sized mechanical engineering company that runs a subsidiary with cash transactions over 10,000 euros can be subject to the AMLA. A real estate agent with three employees is also subject to the AMLA and must appoint a money laundering officer if they reach certain thresholds. An art gallery that sells collector's works above the 10,000 euro mark is also subject to the AMLA. If you are unsure, check your own classification with the money laundering officer and document the result in writing. An incorrect self-assessment does not provide any protection in the audit and can lead to fines according to Section 56 GwG. CIVAC provides the role of Money Laundering Officer as a workspace function and supports houses in the initial analysis of their obliged entity status with structured templates and decision trees that remain comprehensible in the audit. This initial analysis is not trivial and should be recorded in writing because the obligated party status can change dynamically as the business expands, for example through new product lines, crypto purchases or new sales partners with a cash business connection. An annual self-assessment is mandatory and should be recorded. Anyone who does not take their own obligated status seriously risks not only fines, but also personal legal action against management in accordance with Section 130 OWiG.

Risk analysis as the foundation of the KYC process

§ 5 GwG requires every obligated party to provide a written, documented and regularly updated risk analysis. This risk analysis assesses which money laundering and terrorist financing risks exist in the company, broken down by customer groups, products, sales channels, geographical areas and transaction types. It is the foundation on which all further KYC activities are built. Without a proper risk analysis, the due diligence obligations cannot be controlled and the KYC process is assessed as unstructured in the audit, which results in fines in an emergency.

The risk analysis follows a three-stage structure. Firstly, identifying the risk factors: Which customers, products, channels and countries are potentially relevant? Second, assessing the risks: How high is the inherent risk and how do controls affect it? Thirdly, the measures: Which due diligence obligations apply in which constellation, which monitoring rules, which reporting thresholds? BaFin publishes interpretation and application instructions that are considered binding guidance. The anti-money laundering officer is responsible for drawing up and updating it, usually once a year and when there are significant changes, such as new products, new markets or new sales partners. In a platform like CIVAC, the risk analysis is stored in a version-safe manner, linked to specific KYC workflows and exported in the audit module at the push of a button. The appointment certificate, signed, filed, verifiable. This structuring saves the tedious search from tables and mailboxes during the audit and significantly reduces the preparation time. At the same time, the risk analysis becomes operationally effective by linking it to the KYC workflow, instead of just gathering dust on the shelf as a document. Supervisory authorities recognise this interaction as an indicator of maturity and give it a positive weight in the fine procedure. A pure desk risk analysis without connection to day-to-day business does not meet the requirement and will be critically questioned in the audit.

Three levels of care: simplified, general, reinforced

The AMLA distinguishes between three levels of due diligence that must be applied depending on the customer's risk classification. The general due diligence obligations according to Section 10 GwG are the norm and include the identification of the contractual partner, the determination of the beneficial owner according to Section 3 GwG, the assessment of the purpose and type of the business relationship as well as continuous monitoring. The simplified due diligence obligations under Section 14 of the GwG apply to low risks, such as listed EU companies or certain government bodies. They reduce the scope, but not the existence, of the obligations.

The increased due diligence obligations under Section 15 GwG apply when there is a higher risk. These include politically exposed persons in accordance with Section 1 Paragraph 12 of the GwG with family members and close persons, high-risk countries in accordance with Annex III of the EU Money Laundering Directive, unusual or complex transactions without a recognizable economic background and correspondent banking relationships with third countries. In the case of increased due diligence requirements, approval from management level to begin or continue the business relationship is required, more intensive monitoring and additional evidence of the origin of the funds. The stages must be technically mapped in the KYC process so that each business relationship is assigned to a stage and the respective measures are triggered automatically. In the CIVAC platform, the assignment is made based on the risk analysis and is updated throughout the life cycle of the business relationship. Others run compliance like a filing cabinet, a platform runs it like software. This means that the KYC process is not only compliant with the rules, but also documented in a comprehensible and reproducible manner in the audit. The clean level allocation protects against two classic errors: under-level treatment of PEPs and over-level treatment of bulk business, which ties up resources without reducing risk.

Identification and beneficial owner: technical implementation

§ 11 GwG regulates the identification of natural persons and § 12 GwG that of legal persons. For natural persons, the first name, last name, place of birth, date of birth, nationality and residential address must be recorded using an official identification document. Identification can be done in person, via Postident, via Video-Ident in accordance with BaFin specifications or via a qualified electronic signature. For legal entities, the company, legal form, registration number, registered office and the names of the legal representatives must be recorded, providing an extract from the relevant register.

§ 3 GwG defines the beneficial owner as the natural person who ultimately owns or controls the contractual partner. For legal entities, the presumption threshold is more than 25 percent of capital or voting rights or comparable control. More complex structures such as trust relationships, foundations or foreign holding companies require a breakdown down to the natural person. The transparency register according to Sections 18 ff. of the GwG is used for research, but does not replace the obligated party's independent duty of care. If discrepancies are found between the transparency register and your own research, a report must be submitted to the transparency register. A digital KYC process should record all of these data points in a structured manner, provide them with a documented source and version status, and store them in the workspace in a version-safe manner. CIVAC uses standard templates that can be linked to HR master data and data sources such as the transparency register. Deadline begins as soon as we become aware of it. The auditor calls, the evidence is ready. This data architecture is the basis for later updates and suspected case assessments to be carried out quickly and on an up-to-date basis without having to collect master data again. Master data quality is therefore the invisible success factor of the entire KYC process and should be regularly checked on a sample basis.

Monitoring and suspicious activity reporting: ongoing obligations

KYC doesn’t end with onboarding. Section 10 Paragraph 1 No. 5 GwG requires continuous monitoring of the business relationship, including updating customer data and checking the plausibility of transactions. This ongoing obligation is the most important regulatory lever for money laundering prevention and is a frequent point of complaint in audits because many companies see KYC as a one-off onboarding act and neglect monitoring or limit it exclusively to negative lists against sanctions registers.

Effective monitoring combines several layers. Firstly, sanctions screening against relevant lists such as the EU Consolidated Sanctions List, OFAC and foreign trade embargo lists. Second, negative screening against PEP databases with family member and close associate detection. Third party transaction-related monitoring for pattern recognition, such as unusual amounts, unexpected recipient countries, atypical frequencies or structuring. In accordance with Section 43 of the GwG, suspected cases are reported immediately to the FIU, regardless of the economic relationship. The report is made electronically via the FIU’s goAML platform. The money laundering officer is responsible for managing and documenting reports, including non-reports with reasons. A platform like CIVAC manages every suspected case from the trigger to the assessment to the report in a comprehensible workflow, with deadline timers, escalation rules and automatic linking to the business relationship. This trace is crucial in the audit because the FIU and BaFin regularly check the plausibility of reporting practices and non-reports and can sanction failures with fines. Anyone who documents the monitoring architecture properly provides protection in the audit even if no suspicious activity report was made, because the non-report is systematically justified and filed in an audit-proof manner and cannot be interpreted as an omission. This documentation discipline is therefore the most important investment point in the KYC structure because it pays off immediately in the audit.

Role and personal liability of the money laundering officer

§ 7 GwG obliges most obliged entities to appoint a money laundering officer at management level and a deputy. The order is made in writing and the person appointed must be professionally qualified and reliable. The task is reported to the supervisory authority. The money laundering officer is responsible for compliance with the AMLA obligations, prepares and updates the risk analysis, controls the internal security measures in accordance with Section 6 AMLA, coordinates suspicious activity reports, trains employees and reports to management and the supervisory authority.

The personal liability of the money laundering officer is real and has been specified in recent years by BGH case law. In the event of breaches of duty, fines of up to 5 million euros or 10 percent of the annual turnover can be imposed in accordance with Section 56 GwG, and in serious cases also personally. In addition, there are criminal and regulatory consequences if suspicions are not reported or the duty of care is grossly negligent. The money laundering officer must therefore document his tasks, store risk analyses and reports in a version-proof manner and be able to provide evidence of his advice to management. A platform like CIVAC offers this structure in a workspace: appointment certificate, activity report, training matrix, risk analysis, suspected case register and reporting line are stored there. Audit-proof, documented, § 7-proof. Licence the workspace for your internal representatives, or have our representatives order it. Both models use the same platform, the same templates and the same reporting line and are to be assessed comparable according to BaFin practice if the suitability of the external person is proven. This freedom of choice is an essential lever, especially for medium-sized companies without a dedicated compliance department, because it flexibly compensates for personnel bottlenecks and suitability requirements and bridges short-term bottlenecks without breaking the audit, including clean substitution arrangements with documented suitability in the workspace.

Interfaces to sales, onboarding and IT

A KYC process only works if it is integrated into the operational processes of sales and onboarding. In sales, the KYC process often begins with the first customer conversation, in which basic information about the contractual partner, economic background and purpose of the business relationship is recorded. This information forms the basis of the risk classification. If they are recorded in an unstructured or incomplete manner, the risk classification will not be reliable later and the due diligence requirements will be insufficient. Close integration between sales and compliance is therefore an operational success factor for KYC.

Onboarding is the central interface. Identification, data collection, beneficial ownership and risk classification are brought together here. Video identification, automated address verification and register queries are standard in digital onboarding routes. It is important that the results flow into the KYC system in a structured manner and do not remain as PDF attachments in email inboxes. Master data on accounts, contracts, transactions and sales partners comes from IT, ideally via an API interface. Sanctions screening runs as a background job with a configurable frequency. A platform like CIVAC bundles these interfaces in a workspace and makes the data flows transparent for the money laundering officer. Data minimization according to Art. 5 GDPR is technically enforced, so that only the personal data required for KYC is processed. A cleanly constructed interface architecture is the economic lever because it avoids manual double maintenance and measurably shortens the reaction time to suspected cases, which in an emergency can make the difference between a warning and a fine. The integration between sales, onboarding and KYC is therefore not an IT detail, but rather a governance question that should be answered in writing in every procurement. Anyone who builds properly here will not only gain audit stability, but also operational speed in the onboarding funnel.

Retention, updating and audit preparation

§ 8 GwG requires the KYC documents to be retained for five years after the end of the business relationship. In addition, there are retention periods from the HGB and AO, which in practice trigger longer periods, usually ten years. The records must be kept in such a way that they can be submitted to the supervisory authority within a reasonable period of time, usually within days. Storage in unstructured folders without a version or indexing does not meet the requirements and will lead to complaints in the audit.

Updating the KYC data is an ongoing obligation. If there are significant changes to the business relationship, such as new beneficial owners, new sales channels or new products, the data must be checked and updated. In practice, an update cycle of two to five years, depending on the risk level, supplemented by event-related updates, proves effective. Audit preparation is much easier if a central platform displays the status of all business relationships, risk levels, suspicious activity reports and documents. CIVAC provides 490 ready-to-use audit templates, including the risk analysis, the suspicious case register, the training matrix, the activity report of the money laundering officer and the security measures according to Section 6 GwG. During the audit, these documents can be exported with a click and validated by the auditor. This structuring reduces the effort required for audit preparation from weeks to days and eliminates one of the most common points of complaint: the difficulty of finding KYC documents over the five-year retention period. This means that compliance does not become a collective action before an audit, but rather an ongoing standard process with measurable maturity and a traceable audit trail. This maturity also affects costs and staffing requirements because audit preparation no longer triggers special projects with overtime, but is instead completed as a standard query in the platform.

How CIVAC maps the KYC process and the GwB role in one workspace

CIVAC maps the KYC process and the role of the money laundering officer in a central workspace. The risk analysis is carried out with client structure and version status, the KYC levels are stored with workflow rules, and the identification and update obligations are monitored with deadline timers. Suspicious activity reports follow a structured workflow from the trigger to the assessment by the money laundering officer to the report to the FIU via the goAML platform. The training matrix documents annual and event-related employee training, the sanctions screening runs as a background process with a configurable frequency.

In the dual model, you can licence the platform for your internal money laundering officer, or you can have CIVAC appoint the money laundering officer externally. Licence the workspace for your internal representatives, or have our representatives order it. The SLA for an external order is two business days instead of the industry standard two to six weeks. Both models use the same audit trail, templates and reporting line to management and regulators. If you want to introduce a KYC process in a structured manner or transfer an existing process to a central platform, a 30-minute initial consultation is worthwhile. Turn reading into an assignment. A short message to info@civac.de or an entry in the contact form is enough for an initial clarification of your needs. Within five working days you will receive a written inventory, a 90-day implementation schedule and a proposal for a licence or external order with a clear cost framework and named responsible person. In this way, the decision about the introduction or migration of the KYC process can be made on a reliable basis, without tying up resources in advance or unclear responsibilities in the project phase, with clear economic considerations and named milestones per phase.

FAQ

Who is obliged to introduce a KYC process?

All obligated parties according to Section 2 GwG. This includes banks, insurers, payment service providers, real estate agents, goods and art dealers for cash transactions over 10,000 euros, crypto custodians, lawyers and notaries for certain activities, auditors, tax advisors and trustees. If you are unsure, check your status in writing. A misjudgment does not provide protection in the audit and can trigger fines in accordance with Section 56 of the GwG.

What distinguishes the three levels of care?

The simplified due diligence obligations according to Section 14 GwG apply to low risks, such as listed EU companies. The general due diligence obligations in accordance with Section 10 of the GwG are the norm. The increased due diligence obligations under Section 15 GwG apply to politically exposed persons, high-risk countries or complex transactions. The latter require management approval and more intensive monitoring. The level results from the risk analysis for each business relationship.

How long must KYC documents be kept?

At least five years after termination of the business relationship in accordance with Section 8 GwG. In practice, longer periods from the HGB and AO apply, usually ten years. The documents must be kept structured, indexed and exportable. Storage in unstructured folders without a version status leads to objections in the audit and can make the submission requirement in the official procedure more difficult.

Who is responsible for the KYC process?

The money laundering officer according to Section 7 GwG, appointed at management level with a deputy. He is responsible for risk analysis, security measures, suspicious activity reports, training and reporting to management and the supervisory authority. An external order via Officer-as-a-Service is possible provided suitability is proven. CIVAC delivers both models with identical workspace functionality and an SLA of two business days for external orders.

How high are the fines for violations of AMLA obligations?

According to Section 56 GwG, fines of up to 5 million euros or 10 percent of the total turnover can be imposed, in serious cases also against the money laundering officer personally. In addition, there are fines against the management according to Section 130 OWiG and criminal consequences for intentional violations. BaFin regularly publishes fine decisions that can serve as guidance.

Can the process be mapped with existing software?

Partially. Bank stacks typically cover identification and sanctions screening, but risk analysis, training, activity reporting and suspicious case registers are often fragmented across multiple systems. A central platform bundles these building blocks, automates deadlines and exports audit evidence. CIVAC combines KYC workflow, agent role, training matrix and reporting line to management in a multi-client workspace with a revision-proof audit trail and EU data residency at the push of a button.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles