AML Package (2): Risk Management under the AML Regulation

AML Package Pt. 3: Risk Management under the AML Regulation | Sebastian Glaab & Till Christopher Otto

The AML package encompasses a multitude of changes compared to the previous legal framework. The third part of our series addresses the alterations in risk management for obligated entities.

Expansion of Internal Safeguard Measures

The components of internal risk management, as currently regulated in § 4 GwG, will henceforth be governed by the directly applicable AML Regulation (“AML-R”). The central norm here is Article 7 – Scope of internal policies, procedures, and controls of the AML-R.

Already in the first paragraph, a paradigm shift becomes apparent: the guidelines, processes, and controls to be introduced by obligated entities are intended not only to serve the risks of money laundering and terrorism financing but also specifically the risks arising from a lack of implementation of measures to enforce sanctions or circumvent them.

Differences from the Previous Legal Framework

While the fundamental systematics are largely continued, there are some innovations under the AML-R compared to the previous legal framework:

Outsourcing and Reliance on Third-Party Identification Records

The internal policies and procedures should explicitly encompass regulations regarding outsourcing and reliance on third parties.

Assessment of Risk Management and Dealing with Deficiencies

The internal policies and procedures must include procedures for assessing the implemented policies and procedures, the implementation of processes for identifying and dealing with deficiencies, as well as remedial measures.

Communication of Policies and Procedures to Employees, Distribution Channels, and Agents

The policies and procedures should furthermore stipulate how the developed measures are communicated internally within the obligated entity. When utilizing external distribution companies or agents, the policies and procedures should also encompass communication with them.

Independent Audit of Policies and Procedures

A certain explosive potential lies in the obligation for the independent audit of the developed policies and procedures (Article 7 (2) lit. b) AML-R). According to this, the developed policies and procedures should be controlled and reviewed by an independent internal audit. In the absence of such an internal audit, the audit should be conducted by “external experts.”

For obligated entities in the financial sector that have a compliance organization following the three lines of defense model, as is standard for credit or securities institutions, the obligation does not pose a significant novelty. The regulation regarding independent audit is likely to be challenging for obligated entities outside the financial sector, such as lawyers or tax advisors, who typically do not have such an internal organization with independent audit capabilities. The obligation for external audit is likely to entail a significant additional workload here.

 



By continuing, you accept our privacy policy.
You May Also Like
Virtuelle IBANs im Visier Was die neue Bafin-Aufsichtsmitteilung für Banken und Zahlungsdienstleister bedeutet Virtual IBANs under BaFin scrutiny: New AML expectations for banks and payment service providers
Read More

Virtual IBANs under BaFin scrutiny: New AML expectations for banks and payment service providers

Virtual IBANs have become an established component of modern payment models. With Supervisory Notice 06/2026, BaFin now clarifies its expectations for credit institutions and payment service providers regarding transparency, anti-money laundering compliance and risk management in complex virtual IBAN structures.
Read More
FIU-Jahresbericht 2025 – Wesentliche Entwicklungen im Überblick FIU Annual Report 2025 – Key Developments at a Glance
Read More

FIU Annual Report 2025 – Key Developments at a Glance

Germany's FIU recorded a historic number of suspicious activity reports in 2025, while the number of analytical reports declined significantly. Alongside new regulatory requirements and a stronger international focus, neobanks have emerged as a key pillar of reporting activity. This article analyses the most important developments and highlights the questions that remain unanswered in the annual report.
Read More
Neues Listungspaket und 21. EU-Sanktionspaket gegen Russland: Auswirkungen auf den Finanzsektor EU expands Russia sanctions lists and prepares 21st sanctions package
Read More

EU expands Russia sanctions lists and prepares 21st sanctions package

The EU's listing package of 15 June 2026 and the proposed 21st sanctions package significantly expand sanctions against Russia. Financial institutions will increasingly need to address indirect risks, third-country involvement and complex payment structures within their sanctions compliance frameworks.
Read More
AMLA konsultiert Leitlinien zur laufenden Überwachung von Geschäftsbeziehungen – Was auf Verpflichtete zukommt AMLA Consults on Guidelines for the Ongoing Monitoring of Business Relationships – What You Should Expect
Read More

AMLA Consults on Guidelines for the Ongoing Monitoring of Business Relationships – What You Should Expect

Continuous monitoring is already one of the core obligations in anti-money laundering compliance today. However, the AMLR elevates this principle to a new level. Obliged entities must not only review individual transactions but continuously analyse and assess the entire business relationship throughout its lifecycle.
Read More