Germany: Key Insights on BaFin’s Supervisory Practice on Anti-Money Laundering
15th January 2025
On 13 January 2025, the German Federal Financial Supervisory Authority, Bundesanstalt für Finanzdienstleistungsaufsicht (“BaFin”), published a comprehensive report on the findings from its special audits (Sonderprüfungen) regarding anti-money laundering (“AML”) practices within the financial sector.
This detailed report offers an in-depth view of BaFin’s supervisory focus and heightened scrutiny of AML processes which may serve as a valuable guide for companies under BaFin’s supervision.
BaFin’s Increased Focus on Anti-Money Laundering Special Audits
BaFin has ramped up its oversight of AML practices, conducting a growing number of special audits to ensure compliance within the financial industry. These audits are designed to assess the effectiveness of the systems financial institutions have in place to detect and prevent money laundering activities. The recent report provides crucial insights into BaFin’s findings, and it is expected to serve as a reference for BaFin-supervised firms when structuring and maintaining their internal AML processes.
This report should be taken into account by BaFin-regulated firms which are subject to the German Anti-Money Laundering Act (Geldwäschegesetz – “GwG“), which includes German management companies and investment firms.
Summary of BaFin’s Key Findings
- Money Laundering Officer (“MLRO”)
One of the central points raised by BaFin is the critical role of the MLRO. The MLRO is responsible for overseeing the firm’s compliance with applicable money laundering laws and regulations, as well as ensuring that the firm’s AML policies are effectively implemented.
BaFin acknowledged both advantages and disadvantages when the MLRO and their deputy hold additional roles within their organisations. On the positive side, depending on the size, business model, and risk profile of the firm, such multiple responsibilities can often be manageable and even create synergies. However, the downside is that this dual responsibility can thin the MLRO’s time and attention, ultimately resulting in insufficient focus on their key obligations in combating money laundering.
BaFin found that, in such cases, MLROs often lack the necessary resources and time to adequately oversee the firm’s AML activities. This shortcoming could leave firms vulnerable to regulatory non-compliance and heightened money laundering risks.
- Monitoring Deficiencies (Control Plan)
BaFin’s special audits also revealed that, in many cases, the firm’s AML monitoring activities were inadequate. The findings show that deficiencies in monitoring were a major concern in evaluating the appropriateness and effectiveness of safeguards and diligence duties. The starting point for monitoring is a complete, all-encompassing control plan, which should take into account the outcomes of the risk analysis.
However, the audits revealed that control plans often did not cover all relevant business areas or key issues related to money laundering. Moreover, these plans were not regularly reviewed for accuracy and up-to-date practices. In addition, BaFin found that monitoring actions were often ineffective, with the subject of control or its execution not addressing the actual risks. Also, the documentation of monitoring actions was often incomplete and insufficient.
- Risk Analysis
- Incomplete Assessment
BaFin also found that firms’ risk assessments were not comprehensive. A thorough and complete risk assessment is the foundation of a firm’s risk analysis and must be properly executed to be effective. When incomplete, a risk analysis cannot serve as the basis for identifying and evaluating potential risks. Therefore, firms need to present their customer and product structures in detail and in a structured manner, ensuring a comprehensive overview of the business landscape.
- No Structured Identification or Evaluation of Risks
BaFin observed that in several audits, the methodology used to identify and evaluate risks in the risk analysis was unclear and the evaluation of existing safeguards often received insufficient attention. BaFin found that the used methodology was often designed/used to assess other criminal activities rather than money laundering or terrorist financing. BaFin noted that firms rarely assessed the effectiveness of their safeguards or their risk-mitigating impact. Instead, the mere presence of a safeguard was considered sufficient.
- Risk Mismanagement
Another major issue highlighted by BaFin was the failure of firms to clearly differentiate their firms-specific risks. In particular, risks associated with terrorist financing were either not considered at all or were inadequately addressed. The audit revealed that firms often analysed and assessed money laundering and terrorist financing risks together, rather than addressing them separately.
- Transaction Monitoring Systems
With regard to credit institutions, payment institutions, and management companies, BaFin’s audits revealed that the systems to monitor business relationships and transactions had inadequate parameters. The systems’ parameters often failed to cover the specific risk areas identified in the institutions’ risk analysis.
Moreover, BaFin discovered that relevant typologies from the Financial Intelligence Unit (“FIU”) were not adequately integrated into the monitoring systems. Firms often did not use sound methods (e.g., statistical methods) to determine threshold values and comparison groups that reflect their customer and product structures.
- Deficiencies in Record-Keeping and Storage
BaFin’s audits found deficiencies in the recording of customer identification documents in accordance with the GwG. Often, photographs or copies of identification documents were provided electronically by clients, which is not permitted unless the documents were examined in person.
BaFin stressed that photographs of documents presented on-site are permissible, provided that it is ensured and proven that no copies created beforehand were used and that the document was indeed presented in person.
Our Key Takeaways and Recommendations
BaFin-regulated firms should take this opportunity to evaluate their existing procedures and ensure they align with the latest regulatory expectations.
We recommend that BaFin-regulated firms should review their monitoring systems and ensure they are tailored and regularly updated to reflect evolving risks.
In this regard, we have summarised our key takeaways from BaFin’s report, along with recommendations for implementation, below:
MLRO and deputy:
BaFin has emphasised the importance of providing the MLRO (and their deputy) with sufficient time, authority, and resources to effectively fulfil their duties. In addition, BaFin highlights the need for the “Tone from the Top” principle, where leadership actively promotes a strong compliance culture. Senior management must lead by example and prioritise AML compliance to ensure it is embedded throughout the organisation.
Our Recommendation: Review the internal responsibilities of the MLRO and their deputy and reorganise roles if necessary to ensure sufficient focus on AML duties.
Control Plan:
A comprehensive control plan covering all risk areas, business segments, and preventive measures must be established and maintained. This plan should clearly outline essential details, including the control objective, scope, and frequency of reviews.
Our Recommendation: Regularly review the control plan for accuracy and ensure complete and meaningful documentation of all monitoring activities.
Risk Assessment:
The objective of risk analysis should not be to present minimal risk but to achieve a realistic assessment of existing risks. A structured, objective methodology should be followed, including factors such as “likelihood of occurrence” and “impact.”
Our Recommendation: Ensure the risk assessment considers both qualitative and quantitative factors and reassess safeguards regularly for both their presence and actual effectiveness in risk mitigation.
Risk Management:
BaFin has recommended a more differentiated approach to risk assessment. Specifically, risks related to money laundering and terrorist financing should be analysed and assessed separately to avoid oversimplification.
Our Recommendation: Structure the risk assessment process into distinct sections for money laundering and terrorist financing risks.
Transaction Monitoring Systems:
Transaction monitoring systems should be regularly validated and their parameters updated based on the firm’s risk assessment. This ensures they are aligned with evolving risks and effectively detect suspicious activities.
Our Recommendation: Conduct periodic validation and ensure the monitoring system’s settings reflect the latest identified risks.
Deficiencies in Record-Keeping and Storage:
BaFin identified deficiencies in record-keeping, particularly in the documentation of on-site customer identification. Firms often lacked clear proof of whether ID documents were checked in person.
Our Recommendation: To ensure compliance, firms should consider using a company-owned camera for documenting on-site customer identification or have employee-conducted photo documentation that is clearly recorded and traceable.
To read the full BaFin report, visit BaFin Report on Money Laundering Audits (Geldwäscheprävention: Erfahrungen aus Sonderprüfungen). Please note that the report is only available in German.
How can Zeidler help?
Zeidler Group is here to assist with any questions or support you may need in reviewing, enhancing, and implementing your internal AML practices, to ensure compliance with German legal and regulatory requirements. We can help you navigate the complexities of regulatory compliance and improve your firm’s resilience against financial crime.
Our dedicated team of professionals is well-versed in the latest BaFin standards and can assist you in aligning your AML framework with the expectations set out by the GwG. If you need further information or assistance, feel free to reach out to us.