Money laundering prevention training: Obligations, frequency and evidence according to Section 6 GwG
Mandatory content, frequencies, evidence and fine risks for AMLA employee training. How you can implement the training obligation in accordance with Section 6 Paragraph 2 No. 6 GwG in an audit-proof manner, what BaFin checks in the AuA-BT and how the CIVAC platform stores training certificates in an audit-proof manner.
Those required under Section 2 of the GwG must regularly train their employees in the area of money laundering prevention. This obligation arises from Section 6 Paragraph 2 No. 6 GwG and is specified in BaFin's interpretation and application instructions (AuA-BT for credit institutions, AuA-General Part for other obligated parties). Anyone who misses the training violates Section 56 Paragraph 1 No. 11 GwG and exposes themselves to fines, which can range up to 150,000 euros for simple violations, up to 5 million euros or 10 percent of the previous year's total turnover for serious, repeated or systematic violations.
This article explains what mandatory content the training must include, how the frequency according to the legal requirements and the BaFin practice must determine which target groups are to be represented, how evidence is stored in an audit-proof manner and how CIVAC's compliance platform and Officer-as-a-Service integrates the entire process in a workspace. The appointment certificate, signed, filed, verifiable. In this way, the training obligation creates an operational compliance tool that is used in the audit and at the same time safeguards the management's supervisory obligation in accordance with Section 4 Paragraph 1 of the GwG. In addition, we show how the training requirements can be interlinked with the BaFin AuA, the FATF recommendations and the EU sanctions lists and what minimum documentary requirements the FIU sets in the context of suspicious activity reporting.
Key Takeaways
- According to Section 6 Para. 2 No. 6 GwG, the AMLA training is mandatory for all employees who act in connection with money laundering-related activities to be repeated and documented regularly.
- BaFin expects annual repetitions as well as event-related training courses in the event of significant changes to the legal situation or in the event of abnormalities in the internal security structure.
- Fines according to Section 56 GwG range up to 5 million euros or 10 percent of the annual turnover for serious, repeated or systematic violations, including failure to train.
Who needs to train: Overview of those required under Section 2 of the GwG
The training obligation according to Section 6 Paragraph 2 No. 6 GwG applies to all those obliged according to Section 2 GwG. These are not only banks and financial service providers, but also insurance companies, capital management companies, payment institutions, crypto custodians, lawyers and notaries for certain activities, tax advisors, auditors, real estate agents from a threshold of 10,000 euros, goods dealers for cash transactions over 10,000 euros, art brokers, precious metal dealers as well as organizers and brokers of games of chance.
A cascade of obligations follows from the obligated status: Appointment of a money laundering officer in accordance with Section 7 GwG (with exceptions), establishment of internal security measures in accordance with Section 6 GwG, risk analysis in accordance with Section 5 GwG, due diligence in business relationships in accordance with Sections 10 to 17 GwG, reporting obligation in accordance with Section 43 GwG, as well as ongoing employee training. Anyone in management who does not carry out this cascade of duties systematically risks not only fines, but also personal liability in accordance with Section 130 OWiG and, in the event of a repeat, reputation-damaging publications by BaFin.
Precisely determining the target group is crucial for the training requirement. Not all employees of an obligated party have to be trained identically, but rather according to function: employees with customer contact, employees with authority to approve transactions, employees in the compliance function, employees in complaint management, employees in internal auditing. If you as a Money Laundering Officer do not reflect this differentiation in a training catalogue, you are training too much and too little at the same time: too much general content for most people, not enough specific content for risk functions. BaFin requires a function-specific training matrix in which the content, depth, frequency and comprehension check are documented for each function. This matrix is part of the risk analysis in accordance with Section 5 of the AMLA and must be updated in the event of significant changes, particularly after internal incidents, new sanctions lists or amendments to the AMLA. A rigid, annual training policy without any reference to the occasion is no longer sufficient in the audit.
Mandatory content: What the training must include in accordance with Section 6 GwG
According to Section 6 Paragraph 2 No. 6 GwG, the training must convey to employees the regulations relevant to money laundering and terrorist financing and enable them to recognise money laundering-relevant circumstances. BaFin specifies this in its interpretation and application notes with the following mandatory modules: legal basis (AMLA, KWG, sectoral regulations), risk analysis and risk factors, due diligence obligations and simplified and enhanced due diligence obligations, identification and verification of contractual partners and beneficial owners, recognition of suspicious transactions, reporting channels and reporting obligation in accordance with Section 43 of the AMLA, ban on passing on information to the customer (no-tipping-off according to § 47 GwG), internal security measures and escalation channels, sanctions and consequences for violations.
The content must be updated as soon as the legal situation, BaFin information or industry-specific risks change. In particular, the EU's AMLD money laundering guidelines, the national AMLA amendments, the FATF recommendations, the EU sanctions lists and the BMF's national risk analyses should be mentioned. Anyone who runs the training as a static document runs the risk that the content will be outdated after 12 months and the supervisory authority will complain in the audit that it is not up to date.
Methodologically, the content must be supported with concrete case studies from the respective industry. Training for real estate agents is fundamentally different from training for crypto custodians: different risk patterns, different due diligence requirements, different reporting reasons. BaFin expects sectoral specificity. Anyone who wants to get by with a generic standard AMLA training across all areas signals a lack of risk analysis and deprives themselves of the line of defence that specific training in the fine procedure offers. Another mandatory component is the integration with the BMF's national risk analyses, which are regularly updated and specify sectoral risk focuses. According to BaFin's interpretation, training courses that are based on outdated risk analysis are not sufficient because they do not reflect the current risk picture of the industry and therefore underestimate the true detection performance of the employees.
Frequency and occasions: When to train
The AMLA itself does not specify a fixed frequency, but requires regular instruction. BaFin specifies in the AuA that annual training is the norm, supplemented by event-related training in the event of significant changes. Significant changes include: Changes to the AMLA itself, new BaFin information, new EU sanctions lists with relevant effects, new internal security measures, identified risks from internal auditing or external audits, as well as noticeably frequent or serious suspected cases in your own organisation.
Onboarding is its own reason: New employees must be trained within four weeks of joining, at least before taking on money laundering-related tasks. Anyone who delays the onboarding training as a money laundering officer creates a gap that cannot be closed in the audit because the time lag between entry and training remains documented.
Role and risk determine the depth of training. Boards of directors, managing directors and money laundering officers are subject to extended obligations, for example according to Section 4 Paragraph 3 GwG (responsibility of the management), according to Section 7 GwG (requirements for the GwB) and according to the AuA-specific information. These groups require in-depth training with an individual frequency pattern tailored to the organisation's overall risk. Deadline expires as soon as we become aware of it: Anyone in management who learns of a new risk must immediately check the suitability of the existing training and, if necessary, re-train it as necessary. A documented delay can be viewed as a serious violation in the fine procedure. A rule of thumb from supervisory practice: Significant changes should be implemented in training content within 60 days, and in the case of particularly critical sanctions list changes (e.g. after geopolitical events) within 14 days. Simply emailing information to the workforce is not enough; instead, a structured short training course with comprehension checks and documentation is required.
Target group differentiation: From the counter employee to the board of directors
Effective AMLA training addresses the activity, not the person. It makes sense to differentiate between four main groups. First: operational employees with customer contact (counter staff, sales, onboarding specialists, brokers). You need training on identification, verification, abnormality detection, and escalation paths. Second: back office employees with transaction processing (settlement, payment transactions, card management). You need training on transaction monitoring, sanctions list comparison, KYC updating.
Third: compliance and risk functions (money laundering officer and deputy, compliance staff, internal audit). You need in-depth training on risk analysis according to Section 5 GwG, internal security measures according to Section 6 GwG, reporting channels, sanctions regimes (EU, OFAC, UK), national risk analyses and FATF recommendations. Fourth: management, board and supervisory bodies. You need training on personal responsibility according to Section 4 GwG, on the supervisory obligation according to Section 130 OWiG, on risk management and on the reputation and sanctions risk perspective.
Whoever operationalizes this differentiation in a training catalogue as a Compliance Officer creates the double benefit of efficiency (each employee only receives the content relevant to them) and audit depth (supervision can filter by group and specifically request evidence). An integrated training directory must therefore reflect employees, functions, assigned training modules, completion dates and results. Excel-based solutions are regularly prone to errors because changes in functions, changes in responsibility and onboarding are not systematically taken into account and master data quickly expires without a source system connection. A fifth, often forgotten target group are temporary external consultants and working students with access to AMLA-relevant processes. Before starting their work, they must receive appropriate training, which is documented and has an expiry date. This obligation must be secured contractually and recorded in the order processing contract or consultant service contract so that training responsibility can be clearly assigned in the event of a conflict. A sixth target group are members of supervisory bodies such as the supervisory board or administrative board, whose training obligations are derived from Section 25d KWG or sector-specific regulations and must be proven separately.
Evidence storage: What is specifically presented in the BaFin audit
BaFin systematically checks the training documentation as part of its supervisory and special audits. Training plans with target groups and frequency, training content with version number and proof of up-to-dateness, lists of participants with personnel number, function and training date, examination or comprehension checks, documentation of repeat dates and event-related follow-up training must be submitted. For online training, additional: learning time logs, click paths, passing thresholds and proof of identity.
According to Section 8 GwG, the evidence must be kept for at least five years, starting from the end of the calendar year in which the training was completed. This period applies in parallel to the retention periods for other money laundering-relevant documents, such as identification documents, due diligence documentation and suspicious transaction reports. From an operational perspective, it is recommended to store it in a system with version control, access logging and tamper protection. Word files on network drives do not meet these requirements.
The CIVAC platform contains a training register that is linked to the money laundering officer's appointment certificate, the processing directory in accordance with Art. 30 GDPR and the risk register. Training certificates are automatically generated, digitally signed and stored with an audit trail. The auditor calls, the evidence is ready. In addition, it should be noted that BaFin often takes samples from the last 24 months as part of special audits and checks in detail both the topicality of the content and the individual training completion of the selected employees. Anyone who does not have the ability to evaluate the data automatically will lose several days of preparation per requirement in the exam. A key date evaluation is recommended, which shows at the push of a button which employees have completed which training courses on the respective date, with the version number of the content and the passing threshold. Reports on repeat appointments, event-related follow-up training and corrective measures, which can act as a mitigating circumstance in fine proceedings, are also helpful.
Outsourcing training: What must be contractually secured
Many obliged entities outsource the conception and implementation of the AMLA training to specialised providers. Section 6 (7) of the AMLA permits the outsourcing of internal security measures under the condition that responsibility remains with the obligated party and the outsourced field of activity does not lead to the circumvention of the AMLA obligations. The outsourcing contract must contain clear regulations on content, frequency, quality, reporting obligations, audit rights, termination modalities and data protection.
In terms of data protection law, training outsourcing is order processing in accordance with Art. 28 GDPR as soon as personal employee data is processed. The AVV must contain EU data residency or documented third country guarantees, sub-processors must be listed with the controller's right to object, and obligations to support data subjects' rights and DPIA must be regulated. Anyone who, as a money laundering officer, outsources without a properly designed AVV does not shift the risk, but doubles it: AMLA risk plus GDPR risk.
BaFin reserves the right to inspect outsourcing contracts and training documentation during the audit. Outsourcing does not release the obligated party from the obligation to evaluate the training results themselves and feed them into the internal risk analysis. With multi-stage outsourcing (training provider, learning platform, AI component), these requirements become more stringent. As an officer-as-a-service, CIVAC offers the appointment of an external money laundering officer who assumes full training responsibility, with an appointment certificate, reporting line and audit trail. Licence the workspace for your internal representatives, or have our representatives order it. Also contractually relevant are clauses on sub-processors, audit rights, service level agreements for the availability of the training platform and data export rules in the event of a later provider decision. Anyone who overlooks these points when first concluding a contract will later maneuver themselves into a vendor lock-in, which can be viewed as a structural weakness in BaFin audits. In addition, it must be checked whether the training provider has adequate cyber and professional liability insurance, as training failures and data losses can have a direct impact on compliance.
Suspicion reports: Training as a prerequisite for effective reporting channels
The obligation to report suspicions in accordance with Section 43 of the AMLA is probably the most consequential obligation of the AMLA regime. Any obligated party who recognises a suspected case must immediately report it to the Financial Intelligence Unit (FIU). The threshold is low: facts that indicate that an asset came from a crime that could constitute a predicate offense of money laundering. Anyone who fails to report despite obvious indications is violating Section 56 Paragraph 1 No. 56 GwG and is exposed to fines of up to 150,000 euros, or more in individual cases.
For the reporting requirement to be effective, every employee must be able to recognise the threshold. Training here is not a fulfilment of an obligation, but rather a mechanism of action. Contents: What is a predicate offense? What indicators indicate money laundering or terrorist financing? Who is the internal contact person? What deadline applies? What consequences does the report have for the employee and the obligated party? How does the no-tipping-off ban according to Section 47 GwG work? Which protective mechanisms apply to reporting employees according to Section 53 GwG?
Audit-proof, documented, Section 43 GwG-proof. Anyone who supports the reporting chain in training with concrete case studies and regularly runs through the internal reporting channels through practice not only improves the detection rate, but also reduces the reaction time. Supervisory practice: The FIU has repeatedly pointed out in recent years that the quality of reports is more important than the quantity of reports. Training that leads to knee-jerk reports of suspicion without clarifying the facts is counterproductive. The platform supports this through structured preliminary recording of the facts, so that the subsequent report to the FIU is precise and comprehensible. It is also important to distinguish between reporting suspicions to the FIU and internal escalation to the money laundering officer: both methods must be clearly distinguished in the training because the responsibility for the FIU report usually lies with the GwB.
Integration into the entire compliance system
An AMLA training only becomes effective through integration into the overall compliance architecture. Four interfaces are critical. First: HR system. Master data, functional changes, entries and exits must flow automatically into the training register so that training plans are always up to date. Second: risk analysis according to Section 5 GwG. The training content must be derived from the risk analysis, not the other way around. Anyone who identifies a high risk in a specific product area must intensify the training accordingly.
Third: security measures in accordance with Section 6 GwG. Training is one safety measure among many. It is linked to the risk analysis, the internal control system, the audit plan, the whistleblower system and the escalation matrix. Isolated training without connection to these mechanisms is a loss of friction. Fourth: Suspicion reporting channels in accordance with Section 43 of the GwG. The training must map the internal reporting channels and the FIU interface so that employees are able to act in the event of suspicion.
The CIVAC platform integrates these four interfaces in a data model. Training, risk analysis, internal security measures, suspicious transaction reporting channels and the money laundering officer's appointment document are consistently linked. Others run compliance like a filing cabinet. We run it like software. In addition, the connection to the ISO/IEC 27001:2022-compliant data architecture should be mentioned: AMLA data is one of the most sensitive information in an organisation and must be secured accordingly in terms of confidentiality, integrity and availability. The CIVAC workspace meets these requirements with EU data residency and audit-proof access control, so that AMLA compliance and IT security compliance share a uniform data model. A fifth interface is the KYC system: training content for identification and verification must be consistent with the procedures stored in the KYC system. Anyone who designs the training separately from the specific KYC workflow risks a discrepancy between trained knowledge and lived practice. Ideally, training modules are linked directly to the KYC process so that employees can access the relevant training material in the event of specific anomalies.
AMLA training with CIVAC: Licence your workspace or appoint a representative
Money laundering prevention is not a one-off obligation, but an ongoing process: annual training, event-related follow-up training, onboarding, updates with every AMLA change cycle, interlinking with risk analysis and internal security measures. Anyone who conducts this process in tables and file folders loses overview and quality of supervision. CIVAC is a compliance platform and officer-as-a-service in one system: 490 audit templates, 93 controls according to ISO/IEC 27001:2022, EU data residency, audit-proof workspace with integrated training register.
Licence the workspace for your internal representatives, or have our representatives appointed. In the platform model, your money laundering officer receives an integrated workspace with training modules, repetition control, audit trail and reporting function for management. In the officer-as-a-service model, CIVAC handles the appointment of the money laundering officer externally, with an appointment document, reporting line to management and a response time of 2 working days instead of the industry standard 2 to 6 weeks. The selection depends on your industry, size, the level of maturity of the existing compliance function and the risk analysis according to Section 5 GwG.
Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. We will respond within two working days with a needs analysis as to whether a workspace licence or external order is the quicker way to an audit-proof AMLA practice in your company. You will also be sent a checklist for self-assessment of your training situation and a suggestion for annual planning, which can be linked to your current risk analysis and the BaFin application instructions. The appointment certificate, signed, filed, verifiable. Section 6 (2) No. 6 of the GwG creates an operational control instrument that carries out BaFin audits and documents the responsibility of management. If requested, we can also check your existing training content against the current risk analysis and the latest BaFin AuA and provide a commented list of gaps with concrete corrective steps.
FAQ
Who has to train their employees according to Section 6 GwG?
All obligated parties according to Section 2 GwG, i.e. banks, financial service providers, insurers, payment institutions, crypto custodians, lawyers and notaries for certain activities, real estate agents from 10,000 euros, goods dealers for cash transactions over 10,000 euros, precious metal dealers and gaming providers. The training obligation includes employees with activities relevant to money laundering, including the board of directors, management and supervisory bodies with extended responsibilities in accordance with Section 4 GwG.
How often does the AMLA training have to be repeated?
In its AuA, BaFin expects annual repetitions as well as event-related follow-up training in the event of significant changes to the legal situation, new information, new sanctions lists or anomalies in the internal risk situation. New employees must be trained within four weeks of joining, at least before taking on money laundering-related tasks. A fixed frequency is not required by law; annual is the minimum standard.
What content does the AMLA training have to cover?
Legal basis (GwG, KWG, sectoral regulations), risk analysis according to Section 5 GwG, due diligence, identification and verification, detection of suspicious transactions, reporting obligation according to Section 43 GwG, ban on passing on information according to Section 47 GwG, internal security measures, escalation channels, sanctions and consequences for violations. The content must be supported by sector-specific case studies; generic training does not meet BaFin's expectations.
How long do AMLA training certificates have to be kept?
At least five years in accordance with Section 8 GwG, calculated from the end of the calendar year in which the training was completed. Storage must be audit-proof with version control, access logging and security against manipulation. Word files on network drives do not meet BaFin's requirements. The deadline applies in parallel to the retention periods for other money laundering-relevant documents such as identification documents, due diligence documentation and suspicious transaction reports.
What fines are there if there is no or insufficient training?
According to Section 56 Paragraph 1 No. 11 GwG, simple violations can result in fines of up to 150,000 euros. For serious, repeated or systematic violations, the fine ranges up to 5 million euros or 10 percent of the previous year's total turnover, whichever is higher. In addition, BaFin can take measures in accordance with Section 51 GwG, including publication of violations that could damage the reputation of the obliged entity.
How does CIVAC support AMLA training as an officer-as-a-service?
The CIVAC platform delivers a training register, recurrence control, an audit trail in EU data residency and sector-specific templates for 25 officer roles. As an officer-as-a-service, CIVAC appoints an external money laundering officer with an appointment document, reporting line to management and a response time of 2 working days instead of the industry standard 2 to 6 weeks. Training obligations, risk analysis according to Section 5 GwG and reporting channels remain consistently linked in one system.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.