Our Expert in Germany
No results available
Suspicious transaction reporting Germany sits at the heart of every obliged entity’s anti-money-laundering programme, and in 2026 the stakes have risen sharply. The statutory duties under §§ 43–49 of the German Money Laundering Act (Geldwäschegesetz, GwG) require companies, professionals and their boards to identify, escalate and report suspicious activity to the Financial Intelligence Unit (FIU) through the goAML portal, promptly, accurately and without alerting the customer. With the EU anti-money-laundering package and the new Anti-Money Laundering Authority (AMLA), based in Frankfurt, driving supervisory alignment across the bloc, German supervisors expect demonstrably higher standards for the timeliness, quality and board-level oversight of these reports.
This guide sets out, in plain English, exactly what money laundering reporting officers, compliance officers, in-house counsel and boards must do to remain compliant, from scope and thresholds to filing mechanics, tipping-off rules and governance.
Who this is for: Money laundering reporting officers (Geldwäschebeauftragte), compliance officers, in-house counsel, company secretaries and boards of mid-size and larger companies operating in Germany, whether financial or non-financial obliged entities.
What you will get: Statute-backed obligations under §§ 43–49 GwG, a practical internal process, the goAML filing steps, sample timelines and a board-level checklist calibrated for 2026 supervisory expectations.
The obligation to report suspicious transactions is anchored in §§ 43–49 of the Geldwäschegesetz (GwG). In essence, any obliged entity that has facts indicating that assets are connected to money laundering, terrorist financing or a predicate offence, or that a customer has failed to comply with beneficial ownership disclosure duties, must report that suspicion to the FIU, regardless of the transaction’s value. The report is filed electronically through the goAML system operated by the German FIU, which is organisationally located within the Generalzolldirektion (the central customs authority under the Federal Ministry of Finance). Alongside the duty to report runs a strict prohibition on “tipping off”, informing the customer or third parties that a report has been, or may be, filed.
Because the reporting duty is triggered by suspicion rather than a fixed monetary threshold, a robust internal detection and escalation process is indispensable. The board carries ultimate responsibility for ensuring that a functioning suspicious transaction reporting system exists, is resourced, and is documented.
The GwG casts a wide net. Obliged persons (Verpflichtete), listed in § 2 GwG, include credit institutions, financial services institutions, payment and e-money institutions, insurers and investment firms on the financial side, and a broad range of non-financial businesses and professions on the other. The latter category, often described as the designated non-financial businesses and professions, encompasses lawyers, notaries, tax advisers, auditors, trust and company service providers, real estate agents, dealers in high-value goods and providers of certain crypto-asset services. Each of these actors falls within the German AML reporting obligations set out in the statute, and each must maintain internal safeguards proportionate to its risk exposure.
The critical feature of suspicious transaction reporting Germany is that the trigger is qualitative, not quantitative. There is no de minimis floor below which suspicion may be ignored. Where facts indicate that assets stem from a criminal act capable of being a predicate offence to money laundering, that they are connected to terrorist financing, or that a customer has failed to disclose beneficial ownership, the reporting duty arises. Certain cash-intensive activities and transactions above defined values do trigger enhanced due diligence, but the reporting obligation itself is not gated by a threshold.
While the reporting duty applies uniformly, the operating environment differs markedly between financial institutions and non-financial obliged persons. Financial institutions typically run automated transaction-monitoring systems, employ larger compliance teams and are subject to intensive, direct supervision. Non-financial obliged persons, a mid-size real estate agency or a professional services firm, for example, more often rely on manual detection, professional judgement and supervision by sector-specific or regional authorities, yet remain fully bound by the same core reporting standard. AML compliance for non-financial companies in Germany is therefore frequently the area of greatest supervisory concern, precisely because detection capability is less mature.
| Obligation | Financial institutions | Non-financial obliged persons | Practical implication |
|---|---|---|---|
| Transaction monitoring | Automated, continuous, system-driven | Often manual, judgement-led | Non-financial firms must define clear red-flag lists and train staff to spot them |
| Customer due diligence depth | Extensive, risk-tiered, ongoing | Risk-based but frequently transaction-triggered | Document the risk rationale for the depth applied to each relationship |
| Typical red flags | Structuring, rapid movement of funds, unusual counterparties | Unexplained cash, opaque ownership, atypical deal structures | Tailor detection scenarios to the sector’s specific vulnerabilities |
| Frequency of reporting | Higher volume, routine filings | Lower volume, event-driven | Low volume does not equal low risk; each case still demands full assessment |
| Supervision | Direct BaFin supervision | Sector supervisors and regional (Länder) authorities | Know your supervisor and its published expectations |
Boards do not file individual reports, but they are firmly inside the accountability chain. The board must ensure an MLRO is appointed where required, that internal reporting channels function, that resourcing is adequate and that the system’s effectiveness is periodically reviewed. Trigger points for board-level attention include a spike or unexplained drop in report volumes, an escalation the MLRO cannot resolve, a supervisory enquiry, or a suspicious matter involving a significant client or a member of senior management. In each of these situations, evidence of prompt, informed board engagement becomes a key line of defence.
Companies seeking bespoke input can consult an English-speaking regulatory lawyer in Germany to align their governance model with statutory expectations, and can review the broader German Compliance practice area for related obligations.
A suspicious activity report Germany filing must give the FIU enough to understand and act on the suspicion. In practice this means mapping the statutory elements to concrete data points: the identity of the customer and any beneficial owner; the details of the transaction or attempted transaction, including amounts, dates, accounts and counterparties; a clear articulation of the facts giving rise to the suspicion; supporting documents; an internal case reference; and the MLRO’s sign-off. Precision matters, a vague narrative that fails to explain why the activity is suspicious undermines the report’s usefulness and invites supervisory criticism.
The evidential file behind each report is as important as the report itself. Retain the transaction records, the monitoring alert or the observation that surfaced the concern, the analysis performed, any customer correspondence, and the reasoning that led to the decision to report, or not to report. Where the MLRO decides not to file, that decision and its rationale should be recorded with equal care, because a defensible “no-file” decision is only defensible if it is documented. These records must be preserved for the statutory retention period and be readily retrievable in the event of a supervisory inspection.
Compliance teams sometimes hesitate over how much identifying data to include when the picture is incomplete. The guiding principle is that a report to the FIU must contain the identifying information the statute requires, anonymisation is not appropriate for the report itself, which is a confidential channel to the authorities. Internally, however, case discussions and management information can and should use anonymised references to reduce the risk of inadvertent disclosure and to keep tipping-off exposure to an absolute minimum until the MLRO has made a decision.
The operational core of suspicious transaction reporting Germany is the goAML portal, the official electronic filing channel operated by the German FIU. Every obliged entity must register with goAML in advance, registration is not something to attempt for the first time when a report is already due. The following workflow reflects good practice for a compliant filing.
On timing, the statutory expectation is that reports are made without undue delay (unverzüglich). A written standard operating procedure should set out clear internal triggers and timelines, immediate internal escalation on detection, prompt MLRO assessment, and prompt external filing, so that no case stalls for lack of ownership. Where a report is filed in connection with a transaction, the GwG restricts execution of that transaction until the FIU has consented or a defined period has elapsed without objection; teams should confirm the current statutory suspension periods before proceeding.
Because goAML handles highly sensitive data, secure file handling is non-negotiable. Adopt a standard naming convention for attachments, for example, an internal case reference followed by a document type, and restrict access to the reporting workspace to authorised users only. Do not circulate draft reports over general email, and store working files in an access-controlled location. Any internal training material illustrating the portal should use redacted or mock data rather than live client information.
Where suspicious activity spans borders, the German report to the FIU remains the primary domestic obligation, but compliance teams should consider whether related filings are required in other jurisdictions where the entity is obliged. The EU AML package and AMLA are designed to improve cross-border information exchange between FIUs, and industry observers expect closer coordination between national units to become a routine feature of supervisory practice. For groups operating across the EU, aligning report content and timing across jurisdictions, while respecting each country’s confidentiality rules, will reduce inconsistency and supervisory friction.
Running parallel to the duty to report is the prohibition on tipping off under the GwG. An obliged entity, its officers and its employees must not disclose to the customer or to any third party that a suspicious transaction report has been filed, is being prepared, or that an investigation is under way. The rationale is straightforward: alerting the subject would allow assets to be moved or evidence destroyed, defeating the purpose of the report. Breaching the tipping-off prohibition (tipping off GwG Germany) can attract administrative sanctions and, depending on the circumstances, further legal consequences, and it exposes the company to reputational and corporate-liability risk.
The prohibition is not absolute. Disclosures to the competent authorities, the FIU, supervisors and law enforcement, are not only permitted but required. Good-faith reporting also carries statutory protection: under the GwG, an obliged person who files a report in good faith is generally shielded from liability for having done so, even if the suspicion is ultimately unfounded, unless the report was made in a grossly negligent or wilfully improper manner. There are also limited exceptions permitting information sharing within a group or between certain professionals in defined circumstances, but these must be applied narrowly and documented. When in doubt, the safest course is to route any external communication through the MLRO and legal counsel.
Practical controls reduce the risk of accidental tipping-off. Adopt neutral internal wording that references an “internal review” rather than a “report to the FIU,” restrict knowledge of a filing to those who genuinely need it, and prohibit any explanation to the customer that could reveal the existence of a report. For example, where a transaction is delayed, front-line staff should use pre-approved, non-committal language rather than improvising an explanation. Lawyers and notaries face additional profession-specific considerations, and the Deutscher Anwaltverein provides guidance relevant to how professional privilege interacts with reporting duties.
Effective suspicious transaction reporting Germany depends on internal reporting channels that are clear, confidential and consistently used. Every obliged entity of any scale should provide a defined route by which staff escalate concerns to the MLRO, protection for those who report in good faith, and a documented process for how the MLRO assesses and acts on what they receive.
The MLRO (Geldwäschebeauftragter) is the linchpin. Where a designated MLRO is required under § 7 GwG, the role must be filled by a suitably senior and reliable individual, granted the powers and information access needed to investigate, and afforded sufficient independence to make reporting decisions without commercial interference. The MLRO reports to senior management and the board, maintains the reporting records, and is a primary point of contact for the FIU and supervisors. Adequate deputisation ensures the function continues during absence.
A workable escalation flow runs from the front line to the board:
Boards should treat AML as a standing governance item, not an occasional briefing. Effective oversight is evidenced by regular, for many entities, quarterly, MLRO reports covering the number and quality of reports filed, the outcomes of investigations, any tipping-off near-misses, resourcing adequacy and training completion. Meaningful KPIs distinguish genuine oversight from box-ticking: not merely how many reports were filed, but the timeliness of filing, the proportion of alerts converted to reports, and how supervisory feedback was addressed. Minutes should record that the board challenged the data and directed action where necessary.
BaFin supervises AML obligations for the financial sector and issues guidance that shapes expectations across obliged entities, while the FIU analyses reports and channels intelligence to law enforcement. For the non-financial sector, supervision is carried out by sector-specific or regional (Länder) authorities. BaFin’s oversight includes the power to conduct off-site reviews and on-site inspections, to require remediation, and to impose administrative fines for deficient systems or failures to report. Penalties can attach both to systemic control failures and to specific breaches such as tipping-off or non-reporting, and serious cases can feed into wider corporate-liability exposure.
The 2026 backdrop is one of intensifying scrutiny. As the EU AML package is implemented and AMLA becomes operational, supervisors are aligning around common standards for the quality, timeliness and governance of reporting. The likely practical effect will be less tolerance for late, incomplete or poorly reasoned filings, and closer examination of whether boards can evidence genuine oversight rather than nominal compliance.
Common triggers include anomalous reporting patterns, a whistleblower complaint, adverse media concerning a client or the entity, referrals from other authorities, thematic supervisory campaigns targeting a sector, and prior deficiencies that require follow-up. Entities that maintain complete, well-organised records, clear escalation logs, documented reporting decisions and evidence of board engagement, are far better placed to withstand such reviews.
To operationalise these obligations, compliance teams should maintain a small suite of standard documents, reviewed by counsel and customisable to the entity’s risk profile:
These templates are explanatory tools, not legal advice, and should be tailored before use. Related obligations, such as verifying beneficial ownership through the Transparenzregister, should be addressed alongside the reporting framework.
Boards can discharge their responsibilities for suspicious transaction reporting Germany by confirming the following are in place:
This article was produced by Global Law Experts. For specialist advice on this topic, contact Markus Bauer at RITTERSHAUS Rechtsanwalte PartmbB, a member of the Global Law Experts network.
posted 38 minutes ago
posted 38 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message