What digital businesses must know about identity checks under BaFin rules — prepared for selfruby.de
Germany has one of the more demanding KYC compliance environments in Europe. If you're running a digital business that operates in financial services, crypto assets, payments, or regulated lending in Germany, you're operating under BaFin supervision, and BaFin's approach to know your customer requirements is worth mentioning thorough. This isn't the jurisdiction where a light-touch compliance posture survives a supervisory review.
The framework has several layers, and understanding how they interact matters whether you're building from scratch or adapting an existing compliance program for the German market.
German KYC requirements flow primarily from the Geldwäschegesetz, Germany's Money Laundering Act. The GwG implements EU Anti-Money Laundering Directives into German domestic law and is updated regularly as new directive versions are transposed. The current framework reflects the 5th and 6th AML Directives, with the 6th adding expanded criminal liability provisions and extending the list of predicate offenses that trigger AML obligations.
For businesses providing financial services in the banking or payment sector, the Kreditwesengesetz adds product-specific requirements. Crypto asset service providers are regulated under Germany's domestic crypto framework that brought them within BaFin's supervisory perimeter in 2020, ahead of similar regulatory moves in most other EU member states. This meant German crypto firms faced BaFin oversight while competitors elsewhere operated in relative regulatory ambiguity.
KYC compliance under German law requires identifying and verifying the identity of customers, beneficial owners, and contractual partners before establishing a business relationship. The verification has to be based on reliable, independent sources, not simply what the customer asserts. Self-declarations are insufficient without corroboration from documents or database checks.
For individual customers, the core requirement is identifying the person by full name, date of birth, and place of residence, then verifying that information against a government-issued identity document. In face-to-face interactions, this means a trained document examination process. For digital onboarding, the BaFin-approved remote verification methods define what's acceptable.
Germany was an early adopter of video identification as a regulated remote verification method. BaFin published formal guidance in 2014 defining the technical and procedural standards for video ID, making Germany one of the first EU regulators to formally accept this approach for customer onboarding in financial services. The requirements cover specific document capture steps, mandatory liveness verification, agent qualification standards, and technical requirements for the video connection itself.
More recently, automated eKYC approaches using NFC chip reading from e-passports and the German electronic identity card have gained regulatory acceptance. Germany's national ID card has carried an eID function since 2010, and BaFin has progressively expanded acceptance of eID-based onboarding as a compliant verification method for digital services. For digital businesses aiming at scale onboarding in Germany, eID integration is increasingly the standard approach rather than the exception.
For legal entity customers, the KYC process extends to beneficial ownership identification: any natural person who owns or controls more than 25% of the entity, or the most senior management person if no qualifying beneficial owner can be identified. Germany's Transparenzregister, the national beneficial ownership register, is a required cross-reference for legal entity customers. Firms can't simply accept a customer's declaration about their ownership structure without checking the register.
The GwG mandates a risk-based approach to due diligence. Not every customer receives the same level of scrutiny. Simplified due diligence is permitted for customers in lower-risk categories. Enhanced due diligence is required for higher-risk customers, including PEPs, customers with connections to high-risk third countries, non-face-to-face business relationships in certain product categories, and complex or opaque corporate structures.
BaFin expects firms to document their risk classification methodology explicitly and to apply it consistently across their customer base. Both the methodology and its consistent application are things examiners will look at. Having a well-designed risk framework that isn't applied uniformly is almost as problematic as not having one.
KYC compliance in Germany doesn't terminate at onboarding. The GwG requires ongoing monitoring of established business relationships: transaction monitoring to detect patterns inconsistent with the customer's risk profile and stated purpose, and periodic re-verification when customer circumstances or risk factors change materially.
For crypto asset service providers, ongoing monitoring is a specific examination focus for BaFin. The Travel Rule implementation for crypto transactions above EUR 1,000 adds data collection and transmission requirements that sit alongside standard KYC obligations. Compliance with both the Travel Rule and ongoing monitoring requirements requires technical infrastructure that many smaller providers haven't fully built out.
One aspect of German KYC compliance that surprises some international operators is the expectation around staff training. The GwG requires that employees who handle customer due diligence receive regular, documented AML training appropriate to their roles. An onboarding agent who cannot explain the difference between simplified and enhanced due diligence is a compliance gap that BaFin examiners will notice. Building training programs and maintaining records of completion is part of the compliance obligation, not an optional extra.
BaFin has historically been willing to engage with firms on compliance program design, but that engagement has limits. Firms that approach the regulator with a plan for building compliant infrastructure are treated differently from firms that are discovered to have gaps through examination or incident. The proactive approach, building compliance before being required to explain its absence, is consistently the less expensive path. International businesses entering the German market should assume the bar is higher than what they experienced in their home jurisdiction and plan accordingly.
Operating compliantly under BaFin isn't the most flexible regulatory environment in Europe, and that's somewhat by design. German financial regulation is built to be taken seriously. Digital businesses that invest in compliant KYC infrastructure upfront spend less time managing supervisory conversations and more time building their actual product. Compliance with BaFin requirements also creates a credible signal to German enterprise customers and banking partners who view regulatory standing as a prerequisite for doing business.