[codicts-css-switcher id=”346″]

Global Law Experts Logo
suspicious transaction reporting germany

Suspicious Transaction Reporting in Germany (geldwäschegesetz §§ 43–49): What Companies and Boards Must Do

By Global Law Experts
– posted 2 hours ago

Suspicious transaction reporting Germany sits at the heart of every obliged entity’s anti-money-laundering programme, and in 2026 the stakes have risen sharply. The statutory duties under §§ 43–49 of the German Money Laundering Act (Geldwäschegesetz, GwG) require companies, professionals and their boards to identify, escalate and report suspicious activity to the Financial Intelligence Unit (FIU) through the goAML portal, promptly, accurately and without alerting the customer. With the EU anti-money-laundering package and the new Anti-Money Laundering Authority (AMLA), based in Frankfurt, driving supervisory alignment across the bloc, German supervisors expect demonstrably higher standards for the timeliness, quality and board-level oversight of these reports.

This guide sets out, in plain English, exactly what money laundering reporting officers, compliance officers, in-house counsel and boards must do to remain compliant, from scope and thresholds to filing mechanics, tipping-off rules and governance.

Who this is for: Money laundering reporting officers (Geldwäschebeauftragte), compliance officers, in-house counsel, company secretaries and boards of mid-size and larger companies operating in Germany, whether financial or non-financial obliged entities.

What you will get: Statute-backed obligations under §§ 43–49 GwG, a practical internal process, the goAML filing steps, sample timelines and a board-level checklist calibrated for 2026 supervisory expectations.

Quick summary, Key STR duties under §§ 43–49 GwG

The obligation to report suspicious transactions is anchored in §§ 43–49 of the Geldwäschegesetz (GwG). In essence, any obliged entity that has facts indicating that assets are connected to money laundering, terrorist financing or a predicate offence, or that a customer has failed to comply with beneficial ownership disclosure duties, must report that suspicion to the FIU, regardless of the transaction’s value. The report is filed electronically through the goAML system operated by the German FIU, which is organisationally located within the Generalzolldirektion (the central customs authority under the Federal Ministry of Finance). Alongside the duty to report runs a strict prohibition on “tipping off”, informing the customer or third parties that a report has been, or may be, filed.

Because the reporting duty is triggered by suspicion rather than a fixed monetary threshold, a robust internal detection and escalation process is indispensable. The board carries ultimate responsibility for ensuring that a functioning suspicious transaction reporting system exists, is resourced, and is documented.

At-a-glance: six-point compliance checklist

  • Detect. Monitor transactions and business relationships for red flags indicating money laundering or terrorist financing.
  • Escalate internally. Route suspicions immediately to the Money Laundering Reporting Officer (Geldwäschebeauftragter) via a defined channel.
  • Assess and decide. The MLRO evaluates the facts and decides whether the statutory reporting conditions under §§ 43 ff. GwG are met.
  • File via goAML. Submit the report to the FIU promptly and completely through the official electronic portal.
  • Do not tip off. Never disclose to the customer or unauthorised parties that a report is contemplated or filed.
  • Document and retain. Record the basis for the decision, the report and follow-up, and preserve the file for the statutory retention period.

Who is obliged to report? Scope and thresholds under the GwG

The GwG casts a wide net. Obliged persons (Verpflichtete), listed in § 2 GwG, include credit institutions, financial services institutions, payment and e-money institutions, insurers and investment firms on the financial side, and a broad range of non-financial businesses and professions on the other. The latter category, often described as the designated non-financial businesses and professions, encompasses lawyers, notaries, tax advisers, auditors, trust and company service providers, real estate agents, dealers in high-value goods and providers of certain crypto-asset services. Each of these actors falls within the German AML reporting obligations set out in the statute, and each must maintain internal safeguards proportionate to its risk exposure.

The critical feature of suspicious transaction reporting Germany is that the trigger is qualitative, not quantitative. There is no de minimis floor below which suspicion may be ignored. Where facts indicate that assets stem from a criminal act capable of being a predicate offence to money laundering, that they are connected to terrorist financing, or that a customer has failed to disclose beneficial ownership, the reporting duty arises. Certain cash-intensive activities and transactions above defined values do trigger enhanced due diligence, but the reporting obligation itself is not gated by a threshold.

Financial vs non-financial obliged persons, key differences

While the reporting duty applies uniformly, the operating environment differs markedly between financial institutions and non-financial obliged persons. Financial institutions typically run automated transaction-monitoring systems, employ larger compliance teams and are subject to intensive, direct supervision. Non-financial obliged persons, a mid-size real estate agency or a professional services firm, for example, more often rely on manual detection, professional judgement and supervision by sector-specific or regional authorities, yet remain fully bound by the same core reporting standard. AML compliance for non-financial companies in Germany is therefore frequently the area of greatest supervisory concern, precisely because detection capability is less mature.

Obligation Financial institutions Non-financial obliged persons Practical implication
Transaction monitoring Automated, continuous, system-driven Often manual, judgement-led Non-financial firms must define clear red-flag lists and train staff to spot them
Customer due diligence depth Extensive, risk-tiered, ongoing Risk-based but frequently transaction-triggered Document the risk rationale for the depth applied to each relationship
Typical red flags Structuring, rapid movement of funds, unusual counterparties Unexplained cash, opaque ownership, atypical deal structures Tailor detection scenarios to the sector’s specific vulnerabilities
Frequency of reporting Higher volume, routine filings Lower volume, event-driven Low volume does not equal low risk; each case still demands full assessment
Supervision Direct BaFin supervision Sector supervisors and regional (Länder) authorities Know your supervisor and its published expectations

When corporate officers and boards become involved

Boards do not file individual reports, but they are firmly inside the accountability chain. The board must ensure an MLRO is appointed where required, that internal reporting channels function, that resourcing is adequate and that the system’s effectiveness is periodically reviewed. Trigger points for board-level attention include a spike or unexplained drop in report volumes, an escalation the MLRO cannot resolve, a supervisory enquiry, or a suspicious matter involving a significant client or a member of senior management. In each of these situations, evidence of prompt, informed board engagement becomes a key line of defence.

Companies seeking bespoke input can consult an English-speaking regulatory lawyer in Germany to align their governance model with statutory expectations, and can review the broader German Compliance practice area for related obligations.

What must an STR contain? Required content under §§ 43–49 GwG and evidence best practice

A suspicious activity report Germany filing must give the FIU enough to understand and act on the suspicion. In practice this means mapping the statutory elements to concrete data points: the identity of the customer and any beneficial owner; the details of the transaction or attempted transaction, including amounts, dates, accounts and counterparties; a clear articulation of the facts giving rise to the suspicion; supporting documents; an internal case reference; and the MLRO’s sign-off. Precision matters, a vague narrative that fails to explain why the activity is suspicious undermines the report’s usefulness and invites supervisory criticism.

Documenting the basis for suspicion, what to retain

The evidential file behind each report is as important as the report itself. Retain the transaction records, the monitoring alert or the observation that surfaced the concern, the analysis performed, any customer correspondence, and the reasoning that led to the decision to report, or not to report. Where the MLRO decides not to file, that decision and its rationale should be recorded with equal care, because a defensible “no-file” decision is only defensible if it is documented. These records must be preserved for the statutory retention period and be readily retrievable in the event of a supervisory inspection.

Use of anonymised intelligence vs identifying data when uncertain

Compliance teams sometimes hesitate over how much identifying data to include when the picture is incomplete. The guiding principle is that a report to the FIU must contain the identifying information the statute requires, anonymisation is not appropriate for the report itself, which is a confidential channel to the authorities. Internally, however, case discussions and management information can and should use anonymised references to reduce the risk of inadvertent disclosure and to keep tipping-off exposure to an absolute minimum until the MLRO has made a decision.

How to file: FIU (goAML) step-by-step for compliance teams

The operational core of suspicious transaction reporting Germany is the goAML portal, the official electronic filing channel operated by the German FIU. Every obliged entity must register with goAML in advance, registration is not something to attempt for the first time when a report is already due. The following workflow reflects good practice for a compliant filing.

  1. Pre-checks. Confirm the entity is registered and that authorised users have valid goAML credentials. Verify the transaction data and gather supporting documents.
  2. Internal escalation. The employee who identifies the concern escalates it immediately to the MLRO through the defined internal channel, without delay and without discussing it with the customer.
  3. MLRO review. The MLRO assesses whether the statutory reporting conditions under §§ 43 ff. GwG are met, documents the analysis and decides to file.
  4. goAML login and data entry. Log into the goAML portal and complete the report fields: reporting entity details, subject (customer and beneficial owner) data, transaction details, and the free-text description of the grounds for suspicion.
  5. Attachments. Upload supporting documents using clear, consistent naming conventions and secure file handling. Avoid embedding unnecessary personal data in file names.
  6. Submission. Submit the report and capture the acknowledgement or reference issued by the system.
  7. Follow-up. Monitor for any FIU feedback or requests for further information and respond promptly. Where the transaction has not yet been executed, observe any suspension obligations that apply pending FIU response.

On timing, the statutory expectation is that reports are made without undue delay (unverzüglich). A written standard operating procedure should set out clear internal triggers and timelines, immediate internal escalation on detection, prompt MLRO assessment, and prompt external filing, so that no case stalls for lack of ownership. Where a report is filed in connection with a transaction, the GwG restricts execution of that transaction until the FIU has consented or a defined period has elapsed without objection; teams should confirm the current statutory suspension periods before proceeding.

File handling and naming conventions for attachments

Because goAML handles highly sensitive data, secure file handling is non-negotiable. Adopt a standard naming convention for attachments, for example, an internal case reference followed by a document type, and restrict access to the reporting workspace to authorised users only. Do not circulate draft reports over general email, and store working files in an access-controlled location. Any internal training material illustrating the portal should use redacted or mock data rather than live client information.

Handling cross-border or multi-jurisdictional suspicious activity

Where suspicious activity spans borders, the German report to the FIU remains the primary domestic obligation, but compliance teams should consider whether related filings are required in other jurisdictions where the entity is obliged. The EU AML package and AMLA are designed to improve cross-border information exchange between FIUs, and industry observers expect closer coordination between national units to become a routine feature of supervisory practice. For groups operating across the EU, aligning report content and timing across jurisdictions, while respecting each country’s confidentiality rules, will reduce inconsistency and supervisory friction.

Tipping-off prohibition and legal risks, what boards must know

Running parallel to the duty to report is the prohibition on tipping off under the GwG. An obliged entity, its officers and its employees must not disclose to the customer or to any third party that a suspicious transaction report has been filed, is being prepared, or that an investigation is under way. The rationale is straightforward: alerting the subject would allow assets to be moved or evidence destroyed, defeating the purpose of the report. Breaching the tipping-off prohibition (tipping off GwG Germany) can attract administrative sanctions and, depending on the circumstances, further legal consequences, and it exposes the company to reputational and corporate-liability risk.

Safe harbour rules and permitted disclosures to law enforcement

The prohibition is not absolute. Disclosures to the competent authorities, the FIU, supervisors and law enforcement, are not only permitted but required. Good-faith reporting also carries statutory protection: under the GwG, an obliged person who files a report in good faith is generally shielded from liability for having done so, even if the suspicion is ultimately unfounded, unless the report was made in a grossly negligent or wilfully improper manner. There are also limited exceptions permitting information sharing within a group or between certain professionals in defined circumstances, but these must be applied narrowly and documented. When in doubt, the safest course is to route any external communication through the MLRO and legal counsel.

Internal communications templates to avoid tipping-off

Practical controls reduce the risk of accidental tipping-off. Adopt neutral internal wording that references an “internal review” rather than a “report to the FIU,” restrict knowledge of a filing to those who genuinely need it, and prohibit any explanation to the customer that could reveal the existence of a report. For example, where a transaction is delayed, front-line staff should use pre-approved, non-committal language rather than improvising an explanation. Lawyers and notaries face additional profession-specific considerations, and the Deutscher Anwaltverein provides guidance relevant to how professional privilege interacts with reporting duties.

Internal reporting channels and governance, role of MLRO, escalation and board oversight

Effective suspicious transaction reporting Germany depends on internal reporting channels that are clear, confidential and consistently used. Every obliged entity of any scale should provide a defined route by which staff escalate concerns to the MLRO, protection for those who report in good faith, and a documented process for how the MLRO assesses and acts on what they receive.

The MLRO (Geldwäschebeauftragter) is the linchpin. Where a designated MLRO is required under § 7 GwG, the role must be filled by a suitably senior and reliable individual, granted the powers and information access needed to investigate, and afforded sufficient independence to make reporting decisions without commercial interference. The MLRO reports to senior management and the board, maintains the reporting records, and is a primary point of contact for the FIU and supervisors. Adequate deputisation ensures the function continues during absence.

Sample internal escalation flow

A workable escalation flow runs from the front line to the board:

  • Employee. Identifies a red flag and escalates immediately to the MLRO via the designated channel, without contacting the customer.
  • MLRO. Assesses the facts, gathers evidence, decides whether to file with the FIU and documents the decision.
  • Chief Compliance Officer. Is informed of significant or sensitive matters and supports resourcing and escalation where needed.
  • Board / Compliance Committee. Receives periodic reporting and is engaged directly on high-risk cases, systemic issues or supervisory enquiries.

Board-level agenda items and evidence of effective oversight

Boards should treat AML as a standing governance item, not an occasional briefing. Effective oversight is evidenced by regular, for many entities, quarterly, MLRO reports covering the number and quality of reports filed, the outcomes of investigations, any tipping-off near-misses, resourcing adequacy and training completion. Meaningful KPIs distinguish genuine oversight from box-ticking: not merely how many reports were filed, but the timeliness of filing, the proportion of alerts converted to reports, and how supervisory feedback was addressed. Minutes should record that the board challenged the data and directed action where necessary.

Enforcement, supervisory expectations and penalties

BaFin supervises AML obligations for the financial sector and issues guidance that shapes expectations across obliged entities, while the FIU analyses reports and channels intelligence to law enforcement. For the non-financial sector, supervision is carried out by sector-specific or regional (Länder) authorities. BaFin’s oversight includes the power to conduct off-site reviews and on-site inspections, to require remediation, and to impose administrative fines for deficient systems or failures to report. Penalties can attach both to systemic control failures and to specific breaches such as tipping-off or non-reporting, and serious cases can feed into wider corporate-liability exposure.

The 2026 backdrop is one of intensifying scrutiny. As the EU AML package is implemented and AMLA becomes operational, supervisors are aligning around common standards for the quality, timeliness and governance of reporting. The likely practical effect will be less tolerance for late, incomplete or poorly reasoned filings, and closer examination of whether boards can evidence genuine oversight rather than nominal compliance.

What triggers a supervisory review or on-site inspection

Common triggers include anomalous reporting patterns, a whistleblower complaint, adverse media concerning a client or the entity, referrals from other authorities, thematic supervisory campaigns targeting a sector, and prior deficiencies that require follow-up. Entities that maintain complete, well-organised records, clear escalation logs, documented reporting decisions and evidence of board engagement, are far better placed to withstand such reviews.

Practical templates and checklist

To operationalise these obligations, compliance teams should maintain a small suite of standard documents, reviewed by counsel and customisable to the entity’s risk profile:

  • STR submission checklist. A pre-filing verification list covering data completeness, attachments, naming conventions and MLRO sign-off.
  • MLRO investigation template. A structured record of the facts, analysis, decision and rationale for each matter, including “no-file” decisions.
  • Internal notification wording. Neutral, tipping-off-safe language for escalation and for any customer-facing interaction during a review.
  • Board reporting template. A periodic dashboard capturing report volumes, timeliness, outcomes, KPIs and open supervisory items.
  • Retention policy outline. A schedule confirming what is retained, for how long and how it is securely stored and retrieved.

These templates are explanatory tools, not legal advice, and should be tailored before use. Related obligations, such as verifying beneficial ownership through the Transparenzregister, should be addressed alongside the reporting framework.

Key takeaways and 10-step board checklist

Boards can discharge their responsibilities for suspicious transaction reporting Germany by confirming the following are in place:

  1. An MLRO is appointed where required, suitably senior, independent and resourced.
  2. Internal reporting channels are defined, confidential and known to staff.
  3. Detection scenarios and red-flag lists are tailored to the business.
  4. The entity is registered with goAML and authorised users are current.
  5. A written SOP sets escalation and filing timelines.
  6. Tipping-off controls and neutral communication templates are enforced.
  7. Reporting decisions, including “no-file” decisions, are documented and retained.
  8. The board receives regular, data-rich MLRO reporting with meaningful KPIs.
  9. Training is delivered and completion is tracked across relevant staff.
  10. The programme is periodically reviewed and updated for EU AML package and AMLA developments.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Markus Bauer at RITTERSHAUS Rechtsanwalte PartmbB, a member of the Global Law Experts network.

Sources

  1. Gesetze im Internet, Geldwäschegesetz (GwG)
  2. Financial Intelligence Unit (FIU), Generalzolldirektion, goAML
  3. Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin), Combating Money Laundering
  4. European Commission, Anti-Money Laundering and Countering the Financing of Terrorism
  5. Anti-Money Laundering Authority (AMLA)
  6. Deutscher Anwaltverein (DAV)
  7. Max Planck Institute for the Study of Crime, Security and Law

FAQs

Who must file a suspicious transaction report in Germany?
All obliged persons (Verpflichtete) under § 2 GwG must report, including credit and financial institutions, insurers and investment firms, as well as non-financial obliged persons such as lawyers, notaries, tax advisers, auditors, real estate agents, dealers in high-value goods and certain crypto-asset service providers. The obligation to report is set out in §§ 43–49 GwG and arises whenever there are facts indicating a link to money laundering, terrorist financing, a predicate offence, or a customer’s failure to comply with beneficial ownership disclosure duties.
Reports must be made without undue delay (unverzüglich). In practice, this means immediate internal escalation on detection, prompt MLRO assessment, and prompt external filing to the FIU. Where a transaction has not yet been executed and a statutory suspension applies, the transaction generally may not be carried out until the FIU has consented or the applicable statutory period has elapsed; confirm the current periods under the GwG before proceeding.
Only those with a genuine need to know should be aware of a filing, and the customer must never be told. The GwG prohibits tipping off, informing the customer or unauthorised third parties that a report has been filed or is contemplated. Disclosures to the FIU, supervisors and law enforcement are permitted and required, and good-faith reporting carries statutory protection from liability.
A complete goAML report includes the reporting entity’s details, the customer and beneficial owner identification, full transaction details (amounts, dates, accounts and counterparties), a clear narrative explaining the grounds for suspicion, and relevant supporting documents. An internal case reference and MLRO sign-off should accompany the file. Accuracy and a well-reasoned narrative are essential for the FIU to act effectively.
Failures in suspicious transaction reporting Germany can attract administrative fines and, depending on the circumstances, further legal consequences, alongside supervisory remediation orders and reputational harm. Both systemic control failures and specific breaches, such as non-reporting or tipping off, are enforceable, and supervisors (BaFin for the financial sector; sector and regional authorities elsewhere) exercise supervisory and inspection powers. Serious lapses can also contribute to wider corporate-liability exposure.
Boards should retain minuted evidence of regular MLRO reporting, documented escalation and reporting decisions, KPI dashboards covering volume, timeliness and outcomes, training completion records, and a record of how supervisory feedback was addressed. The test supervisors apply is whether the board genuinely challenged the information and directed action, not merely whether reports were tabled.
By Prof. Dr. Jochen Bauerreis

posted 2 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Suspicious Transaction Reporting in Germany (geldwäschegesetz §§ 43–49): What Companies and Boards Must Do

Send welcome message

Custom Message