Requirements for maintaining a BaFin Licence | FinTech online course #18

BaFin Licence | PayTechLaw | FinTech online course | sutthinon602

In our yesterday’s blog post, we dealt with the question how to obtain a BaFin licence for payment services or other activities requiring a licence. But once you’ve got a licence, the fun really starts: you have to work hard not to lose your licence again. In this article we want to deal with what you have to be aware of.

Use of the BaFin Licence

Above all, the licenced company has to make use of its licence in order not to lose it again. If the company does not use a licence for more than six months, BaFin may revoke it. If the company does not use the licence immediately after it was granted, it is even worse. Then the licence is gone after 12 months without BaFin having to do anything else. In this case it expires automatically. Just like that.

Supervision by BaFin

As a company with a BaFin licence, you are supervised by BaFin. This means that BaFin checks whether the company always complies with its supervisory duties (e.g. its organisational duties or the duties to report certain facts to BaFin). In most cases, BaFin does not audit this itself. Instead, this task is delegated to the annual auditor. At least once a year, the auditor checks whether the company complies with its regulatory obligations and prepares an audit report on this. BaFin also receives this audit report. If BaFin has the impression from the audit report that the company is not operating properly, it can conduct further investigations and take supervisory measures up to revoking the licence. The supervised company itself must pay for the audit by the auditor and the supervision by BaFin.

Compliance with Anti-Money Laundering Obligations

A company with a licence from BaFin must also comply with certain requirements to prevent money laundering and terrorist financing. These include, in particular, the identification of its customers, the reporting of suspicious cases of money laundering and various internal measures (e.g. the appointment of a money laundering officer, verification of the reliability of employees and the archiving of certain documents). Breaches of these obligations may result in more than just supervisory measures. They can also be punished by heavy fines.

Compliance with Civil Law Requirements

In addition, companies supervised by BaFin often have to comply with requirements when drafting their customer contracts. These include extensive information obligations vis-à-vis customers, but also certain requirements regarding the company’s liability. These requirements play a particularly important role in B2C business. Also BaFin is interested in whether a supervised company plays fair. For example, customers of payment service providers can complain to BaFin. This is another source of information for BaFin. If, as a result of customer complaints, BaFin gets the impression that a supervised company is not operating properly, it can investigate the matter and even take supervisory measures against the company.

 

LINK TO THE HOMEPAGE OF THE FINTECH ONLINE COURSE

 

Cover picture: Copyright © Adobe/ sutthinon602

 



By continuing, you accept our privacy policy.
You May Also Like
Virtuelle IBANs im Visier Was die neue Bafin-Aufsichtsmitteilung für Banken und Zahlungsdienstleister bedeutet Virtual IBANs under BaFin scrutiny: New AML expectations for banks and payment service providers
Read More

Virtual IBANs under BaFin scrutiny: New AML expectations for banks and payment service providers

Virtual IBANs have become an established component of modern payment models. With Supervisory Notice 06/2026, BaFin now clarifies its expectations for credit institutions and payment service providers regarding transparency, anti-money laundering compliance and risk management in complex virtual IBAN structures.
Read More
DigiFin26 – Rebuilding Resilience 1
Read More

DigiFin26 – Rebuilding Resilience

Digitisation, regulation, geopolitical uncertainty – the pace of change in the financial sector has rarely been as intense as it is today. DigiFin25 brings together the key players to discuss the future of the financial industry – and we’re right at the heart of it.
Read More
AI Act: Explanation of the icons suggested by the EU to identify AI-Generated content and entry into force of the transparency requirements under the AI Act
Read More

AI Act: Explanation of the icons suggested by the EU to identify AI-Generated content and entry into force of the transparency requirements under the AI Act

AI transparency rules are now a reality. From 2 August 2026, Article 50 of the EU AI Act requires providers and deployers of certain AI systems to disclose AI-generated and AI-manipulated content. This article explains the European Commission's newly introduced transparency icons, the respective obligations for providers and deployers, and the practical steps organisations should take to ensure compliance.
Read More
The EU's 21st Sanctions Package against Russia
Read More

The EU’s 21st Sanctions Package against Russia

With its 21st sanctions package, the European Union has significantly tightened its restrictive measures against Russia. Financial institutions and crypto-asset service providers, in particular, will need to strengthen their sanctions compliance by focusing on third countries, alternative payment channels and increasingly complex transaction structures.
Read More