Money laundering risk analysis according to Section 5 GwG: template, methodology, chain of evidence
Section 5 GwG requires a written risk analysis. These instructions, including a template structure, show you which risk factors are included, what the evaluation matrix must look like and how you can update the analysis annually.
According to Section 5 Paragraph 1 of the Money Laundering Act (GwG), obliged entities must prepare a written risk analysis, review it regularly and present it to the supervisory authority upon request. What is important here is not the mere existence of a document, but rather its content viability: The analysis must systematically record, evaluate and translate customer-related, product-related, transaction-related and geographical risk factors into measures. Anyone who works as a real estate agent, goods dealer, money laundering officer in a financial company or casino operator knows the deadline after a supervisory request: The submission is required at short notice and decides whether the supervisory authority classifies the internal organisation as compliant with Section 4 of the GwG or whether a fine procedure is initiated. Even an inadequate methodology can trigger a procedure.
A generic risk analysis template from the Internet only helps as a skeleton. It must be specifically tailored to the business activity, the customer structure and the sales channels used and requires a comprehensible evaluation methodology with scales, threshold values and assignment of measures. This article explains the structure and mandatory components of an AMLA risk analysis, shows a practical assessment matrix, explains the obligation to update according to Section 5 Paragraph 2 AMLA and describes how the analysis interacts with the other obligations from Sections 6 to 10 AMLA so that the result is not only formally available, but is operationally sustainable and stands up to the audit. A clearly managed update cycle, a written evaluation matrix and management approval are the three visible signals of a serious AMLA organisation.
Key Takeaways
- The risk analysis according to Section 5 GwG must be written, documented, regularly updated and presented to the supervisory authority upon request; A pure template without adaptation does not fulfil the obligation.
- Mandatory components are the four risk dimensions customer, product/service, transaction and geography, each with an evaluation scale, justification and derived security measures.
- Fines according to Section 56 GwG range up to 150,000 euros per individual violation and up to 5 million euros for serious or repeated violations; legal entities are also liable according to Section 30 OWiG.
What Section 5 GwG specifically requires
§ 5 GwG requires every obliged entity under § 2 GwG to provide a written risk analysis of their business activities with regard to money laundering and terrorist financing. The regulation defines four dimensions that must be recorded: risks related to customers, to products and services, to transactions and distribution channels, and to countries and geographical areas. The analysis must take into account the factors in Annexes 1 and 2 to the AMLA as well as the national risk assessments of the Federal Ministry of Finance and apply them to your own business model. It must be kept documented, presented to the supervisory authority upon request and checked at least annually or as required. The obligation to submit information takes effect immediately after a supervisory request; the authorities generally do not allow a longer period of preparation.
Which supervisory authority is responsible depends on the obliged entity status. Banks, financial service providers and insurance companies are monitored by BaFin, real estate agents, goods traders, precious metal dealers and casino operators by the respective state authorities, lawyers and notaries by their professional chambers. Bafa supervises certain goods traders, for example in the area of crypto assets or high-priced goods. A risk analysis that is accepted in one federal state may need to be improved in another due to different supervisory priorities. Anyone who is obliged to appoint money laundering officers in accordance with Section 7 of the GwG should see the analysis as a central control basis from which the internal security measures, customer due diligence obligations and training plans are derived. Without this integration, the risk analysis is a paper without consequences, and that is exactly what supervisors check. In addition, even if a separate money laundering officer does not have to be appointed according to Section 7 Paragraph 2 GwG, the risk analysis remains mandatory because it does not affect the appointment, but rather the management itself according to Section 4 Paragraph 3 GwG.
Mandatory components of an audit-proof template
A complete risk analysis template begins with a cover sheet that identifies the obligor, business address, responsible supervision, validity period, creation date, responsible person and management approval. What follows is a brief description of the business model, the areas of activity, the sales channels and the number of employees, as these factors determine the depth of the subsequent analysis. Anyone who sells services exclusively to domestic commercial customers has a different risk profile than a provider who serves international private customers via online sales channels.
The core of the template consists of four structured sections, one for each risk dimension. Each section lists the risk factors relevant to your own business, assigns them a rating (typically a scale with three to five levels, such as low, medium, high, very high), justifies the classification with reference to the AMLA investments or the national risk assessment and derives concrete security measures. These measures range from customer due diligence regulations and special contractual clauses to the frequency of training for affected employees. The conclusion is an overall assessment with aggregated residual risk, a list of open points with deadlines and approval by management in accordance with Section 4 Paragraph 3 of the GwG. Others run compliance like a filing cabinet. We run it like software. The risk analysis is stored as a workflow in CIVAC's 490 ready-to-use audit templates, so that each assessment is documented with the source and date and the supervisory authority can understand the creation process. Annexes document the national risk assessment, the EU high risk list, the FATF list and any industry guidance that was incorporated into the assessment. In addition, a glossary of terms used in the document and a version list should be included at the end of the template so that supervisors can understand the genesis of the analysis.
Customer risk factors: example matrix and evaluation
Customer risks are already detailed in Annex 2 of the AMLA. Factors that indicate increased risk include politically exposed persons (PEP) and their family members, customers from third countries with high risk according to the EU list, customers with complex ownership or control structures, cash transactions above certain thresholds and business relationships without personal identification of the beneficial owner. The suddenness of the business relationship, unusual transaction patterns or frequent changes of beneficial owners are also indicators. In return, listed customers, regulated financial companies or public bodies lower the risk profile.
A practical evaluation matrix takes these factors into account and multiplies them by the frequency of their occurrence in one's own portfolio. Example: If 80 percent of the customers are existing domestic commercial customers and 20 percent are new international customers, then the focus of the risk analysis shifts to the second group. For each risk class, it is determined which due diligence obligations apply in accordance with Sections 10 to 17 of the GwG: simplified due diligence for low risk, increased due diligence for high risk, for example additional PEP review, management approval for the business relationship and closer monitoring intervals. An external sanctions list check becomes mandatory if greater care is taken and can be automatically mapped using the Money Laundering Officer Role in the workspace. In this way, every customer risk becomes a derivable measure, not just a note in a Word document. Anyone who plans a periodic review of existing customers, approximately every 12, 24 or 36 months for each risk class, also meets the requirement for continuous monitoring of the business relationship in accordance with Section 10 Paragraph 1 No. 5 GwG. A documented threshold concept for update reasons (change of address, change of ownership, unusual transaction patterns) also belongs in this section of the analysis.
Risk factors product, transaction and geography
Product risks arise from the characteristics of the services or goods offered. High-value movable goods such as precious metals, works of art, luxury vehicles or jewelry are generally considered to be susceptible to money laundering, as are trust accounts, escrow accounts, investment products with a high degree of complexity or contract models that can conceal beneficial ownership. Cross-border payment services, crypto services or cash transactions over 10,000 euros according to Section 3 GwG are also increased risk factors. In contrast, standard products with transparent payment flows, identifiable business partners and established contract models are to be rated lower, but this must be justified in a documented manner.
Transaction risks are assessed based on volume, frequency, payment method and plausibility of the business model. Anyone who, as a real estate agent, receives a purchase price of 1.2 million euros transferred in installments with three different foreign banks will see a different picture than with regular bank financing with a notarial escrow account. Geographical risks follow the EU lists of high-risk countries (annex to the AMLA Regulation), the FATF list and our own findings on certain regions with a connection to sanctions or embargoes. Anyone who conducts business related to Russia, Iran, Belarus, North Korea or other sanctioned areas must also comply with the sanctions rules according to EU regulations and include the sanctions list check in the risk analysis. Deadline expires as soon as we become aware of it: Anyone who discovers a hit must immediately terminate the business relationship and report the incident to the FIU in accordance with Section 43 of the GwG. The distinction between the geographical risk of the customer and the geographical risk of the transaction is also relevant in practice, because both can differ: an existing domestic customer with sudden payments from a high-risk country only changes the risk picture in the transaction dimension, not in the customer profile, which requires a differentiated reaction. A clean separation of the three dimensions prevents wrong decisions and makes later audits comprehensible.
Assessment methodology: scales, thresholds, aggregation
A verifiable evaluation methodology documents how an overall picture emerges from individual risk factors. A two-dimensional model is common, which multiplies the probability of a money laundering case occurring by the extent of the damage. Both axes are divided into levels, often four (low, medium, high, very high), and multiplication results in a risk class. It is important that the threshold values for each axis are justified, for example by internal experience, industry statistics or national risk assessment. A methods page in the risk analysis that explains this logic is mandatory so that a supervisor can understand how the individual assessment was achieved.
The aggregation of the individual risks to form an overall risk is typically weighted, as not all factors are equally relevant. In the real estate sector, the geographical and transaction risk weighs more heavily than in classic B2B wholesale with existing customers. The weighting must be justified in writing. The analysis derives packages of measures from the aggregated risk: which due diligence obligations apply as standard, which ones are reinforced, which additional controls are carried out by the money laundering officer, and how frequently the monitoring is readjusted. Audit-proof, documented, § 5 GwG-proof. Anyone who saves this methodology in the workspace can reproduce the assessment at any time, which makes the difference between calm explanations and explanatory hecticness during supervisory visits. A proven addition is the annual plausibility check with historical incidents, such as suspicious activity reports, rejected business relationships or evaluated anomalies. If reality contradicts the statistics, this observation should be included in the next major update, accompanied by a note adjusting the weighting and justifying the new thresholds. An internal four-eye principle when assessing major risk changes also increases the robustness of the methodology and reduces the risk of subjective biases.
Obligation to update and event assessment
§ 5 Paragraph 2 GwG requires the risk analysis to be regularly reviewed and updated. In practice, an annual rhythm has been established, combined with event-related updates. Triggers for event updates include new business areas, new products or sales channels, new findings on high-risk countries, changes in sanctions, an FIU suspicious transaction report with a larger volume, an audit finding or a supervisory notification. A takeover, merger or realignment of the business is also an occasion. If you do not record these triggers systematically, you risk that the analysis no longer keeps pace with reality.
Operationally, this means: An update calendar is maintained in the workspace, with an annual main update and quarterly query of relevant triggers. The respective version is stored dated; old versions remain available for documentation reasons. Management releases each major version, documented by signature or qualified electronic signature. The appointment certificate, signed, filed, verifiable: This logic also applies to the risk analysis itself. In the event of a supervisory inquiry, not only the current version can be presented, but also the version history, which significantly increases the credibility of the compliance organisation. Anyone who continues to control the update process only via Outlook reminder will not be able to provide proof in the event of an escalation that a trigger has been seriously checked. It is also recommended to comment on each trigger with a short note, even if the check shows that no update is necessary. This creates a continuous chain of evidence that proves that monitoring has taken place actively. Without these notes, the impression arises that the obligated party simply ignored Trigger. In practice, a short quarterly note per trigger is sufficient as long as it shows the date, verified source, evaluation result and person responsible.
Interlinking with other AMLA obligations and training
The risk analysis is not an end in itself, but rather the basis for controlling the other MLA obligations. The internal security measures according to Section 6 GwG, the customer due diligence obligations according to Sections 10 to 17 GwG, the obligations to identify and record the beneficial owner according to Section 11 GwG and the monitoring according to Section 10 Paragraph 1 No. 5 GwG are derived from this. The training obligation according to Section 6 Paragraph 2 No. 3 GwG is also measured by the identified risk: employees in risk-related areas are trained more frequently and more deeply than colleagues with standard processes. The training plans should therefore be directly linked to the risk analysis.
The money laundering officer according to Section 7 GwG is responsible for maintaining and applying the analysis. He reports to the management, has his own right to speak and is authorised to give instructions to employees as far as the enforcement of security measures is concerned. CIVAC offers this role as an officer-as-a-service or as a licence solution. Licence the workspace for your internal representatives, or have our representatives order it. In both cases, the risk analysis is the central link between the appointment certificate, reporting line, due diligence and training, with a continuous chain of evidence from the document to the operational process. Without this interlinking, the typical double damage occurs in supervisory cases: formally existing analysis, operationally ignored. The interface to the general internal control system (ICS) should also be mentioned so that the money laundering-specific audit procedures are differentiated from the general controls without creating gaps. A compact overview of the interlocking points should be included in the appendix of the analysis and saves later discussions with the supervisor. The annual hearing of the management by the money laundering officer, in which the main findings, trends and recommendations are recorded in writing, is also relevant to practice.
Common mistakes with self-created templates
The most common mistake is adopting a template without adapting the content. According to Section 5 GwG, a risk analysis that does not describe the actual business is not a risk analysis, but rather a decorative document. The second most common error is scoring without methodology: without a scale, without a threshold and without an aggregation rule, the supervisor cannot reproduce the classification. Thirdly, management approval is often missing or not dated. Fourth, updates are not documented, so old versions suddenly have to be sold as current. Fifthly, the connection with the due diligence requirements is forgotten, so that the analysis is formally available but has no operational consequences.
Another pitfall is geography. Anyone who says across the board that they don't have any foreign customers without checking whether suppliers, ownership structures or beneficial owners refer abroad is overlooking the most common hits in a supervisory audit. A blanket sanctions list check that is not documented is also problematic: a sanctions check is only considered to have been carried out if hit protocols, false hit clarifications and negative comparisons are available in writing. The auditor calls, the evidence is ready., or not. In any case, it is worth subjecting your own submission to a peer plausibility check, for example by an external security consultant or through the annual hearing report of the money laundering officer, in which the methodology should also be critically reflected. A final, often overlooked mistake is the lack of connection between risk analysis and the specific content of the customer file: If the due diligence level of a specific customer cannot be derived from its risk class, there is no control effect. A clear evaluation rule helps here, which automatically assigns a due diligence profile to each customer file.
How CIVAC carries out the AMLA risk analysis
CIVAC is a compliance platform and officer-as-a-service with 25 officer roles, all live. For the AMLA world, this means: appointment certificate from the money laundering officer, reporting line to management, 490 audit templates including a risk analysis skeleton with the four mandatory dimensions, training plan in accordance with Section 6 Paragraph 2 No. 3 GwG, suspicious transaction reporting workflow in accordance with Section 43 AMLA and a comprehensible update calendar for annual and event-related updates. Audit-proof, documented, § 5 GwG-proof. In addition, there is the EU data residency and the ISMS according to ISO/IEC 27001:2022 with 93 controls so that customer and transaction-related data remains protected in the same document chain.
Two models are available. Licence the workspace for your internal representatives, or have our representatives order it. In the licence model, your internal money laundering officer receives a template and workflow infrastructure; in the mandate model, a money laundering officer appointed by CIVAC takes over the external appointment with all obligations according to Section 7 GwG, including reporting and representation. Both paths end in the same audit trail: auditable, dated, released. Turn reading into an assignment. Write to info@civac.de or use the contact form at civac.de/faq. Within the CIVAC SLA of 2 working days, you will receive an assessment of whether your existing risk analysis holds up or whether you should make better adjustments for the next supervisory request. Instead of the classic 2 to 6 week processing time with external consultants, the first indication is on the table, including a short list of defects that you can use as a basis for the next main update of your risk analysis. This closes the circle of mandatory analysis, measures and chain of evidence.
FAQ
Who is obliged to prepare a risk analysis according to Section 5 GwG?
All obligated parties according to Section 2 GwG: credit institutions, financial service providers, insurance companies, real estate agents, goods dealers above certain thresholds, precious metal dealers, casino operators, lawyers and notaries for certain transactions, tax advisors and others. The obligation applies regardless of the size of the company. However, the depth of the analysis may be appropriately tailored to the business model; a sole proprietor will not provide the same level of detail as an international financial house.
How often does the risk analysis need to be updated?
At least annually or as needed. Reasons include new business areas, products, sales channels, changed sanction rules, adjustments to high-risk lists, suspicious activity reports with a larger volume or audit findings. The update process should be documented, old versions remain archived, and each new major version is released and dated by management. Triggers that have been tested but not implemented should also be noted to demonstrate that the monitoring is complete.
Is a Word template from the internet enough?
Just a skeleton. A generic template without adaptation to the actual business, without an evaluation methodology and without interlinking with the security measures does not fulfil Section 5 GwG. Supervisory authorities check whether the analysis actually reflects one's own risk profile and whether the assessments are reproducible, otherwise it is considered non-existent. A structured template with industry benchmarks and a methods page that is filled internally is recommended.
What fines are there if there is no or incorrect risk analysis?
According to Section 56 GwG, fines of up to 150,000 euros per individual violation are possible, for serious or repeated violations up to 5 million euros or up to twice the economic benefit. Legal entities are additionally liable in accordance with Section 30 OWiG, and management is personally liable in accordance with Section 130 OWiG in the event of a breach of supervisory duty. In addition, there is damage to reputation, publications on BaFin lists and possible civil consequences against contractual partners.
Does management have to sign the analysis?
Yes. Section 4 Paragraph 3 of the GwG obliges management to be responsible for setting up risk management, which includes risk analysis. The release is dated, ideally on the cover page and in a version history, so that older versions can also be assigned to a named release. A qualified electronic signature is possible, but the handwritten signature remains the documentary gold standard.
How is the risk analysis related to the sanctions list check?
The risk analysis determines which customer categories or transactions are subject to sanctions review and at what frequency. A sanctions check that has been carried out must be documented, with a hit and false hit log. Without this interlinking, the analysis remains formal and the obligation to impose sanctions unrelated. An automated solution in the workspace ensures that every exam is filed in an audit-proof manner with a time stamp and result.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.