Virtual IBANs under BaFin scrutiny: New AML expectations for banks and payment service providers

Virtuelle IBANs im Visier Was die neue Bafin-Aufsichtsmitteilung für Banken und Zahlungsdienstleister bedeutet Virtual IBANs under BaFin scrutiny: New AML expectations for banks and payment service providers

Virtual IBANs (“vIBANs”) have long been a standard building block of modern payment products. They facilitate the automated allocation of incoming payments, enable efficient reconciliation of receivables and are used, among other things, in platform, marketplace, e-commerce and treasury models. Technically, they are individual identifiers assigned to a customer or a specific payment transaction without necessarily being linked to a separate payment account. Incoming payments are allocated to and managed through a central master or omnibus account (“master account”).

Credit institutions may provide payment service providers with master accounts together with associated vIBANs. The payment service providers, in turn, assign these vIBANs to their own customers for the individual allocation of payment transactions. Maintaining an account within the meaning of Section 17 of the German Payment Services Supervision Act (ZAG) is possible within the framework of a correspondent relationship.

With its Supervisory Notice 06/2026 of 27 July 2026, BaFin has now placed the anti-money laundering risks of such structures firmly in focus. The notice is based on joint findings by BaFin and the Financial Intelligence Unit (FIU). According to supervisory experience, virtual IBANs may, particularly in complex cross-border structures, be used to obscure the persons actually involved in transactions and the economic background of payments.

The notice applies with immediate effect and is limited until 10 July 2027, i.e. until the European Anti-Money Laundering Regulation (AMLR) becomes applicable. It applies to all obliged entities in the financial sector but is of particular practical relevance to two groups:

  • Credit institutions providing payment service providers with master accounts and vIBAN structures; and
  • Payment service providers assigning such vIBANs to their own customers.

The central risk: Lack of transparency

The core issue is not the virtual IBAN itself but a potential information asymmetry throughout the payment chain. Multi-layered structures are particularly critical: the account-holding credit institution often knows only the payment service provider as its direct contractual partner. However, the vIBAN is used by an end customer of that payment service provider. If the bank lacks sufficient information about this end customer, its beneficial owners or the underlying business activity, its ability to assess payment flows from an economic perspective is significantly limited.

BaFin therefore describes a structural tension: the institution maintaining the master account and processing the transactions may not possess the information required for a robust risk assessment, while the institution maintaining the relationship with the end customer is not necessarily the institution through which the payment flows are technically processed.

This issue becomes even more pronounced in cross-border models. A vIBAN with a German country code may be linked to a master account maintained abroad. To payers and other parties involved, this may create the impression that the account is located in Germany, even though the account-holding institution, the payment service provider and the end customer are situated in different jurisdictions. The country code alone therefore does not provide reliable information regarding the actual location of the account or the institutions involved.

Underground banking

The supervisory authority pays particular attention to so-called “underground banking”. BaFin uses this term to describe informal financial transfer systems that move assets outside regulated banking and payment infrastructures, often involving intermediaries, trade transactions or alternative payment mechanisms. Such arrangements may be designed to circumvent regulatory controls, capital restrictions or transparency requirements. They are characterised by fragmented, frequently cross-border payment structures intended to conceal the origin, recipient and economic purpose of assets.

Within such systems, vIBANs may serve as a technical or organisational intermediary layer. The separation between the formal account holder, the intermediary payment service provider and the actual end customer makes it more difficult to identify payers, recipients and the underlying economic purpose of payments.

Particularly noteworthy is one specific finding highlighted by BaFin: according to FIU analyses, substantial payment flows have previously been identified involving international companies, intermediary payment service providers based in Hong Kong, China, and generic payment references. These findings support the assumption of increased fraud and money laundering risks associated with complex vIBAN structures operated by foreign payment service providers.

It should be emphasised that the Supervisory Notice does not generally regard vIBAN models as constituting underground banking. Rather, it identifies circumstances in which existing transparency deficits may be exploited. A blanket withdrawal from vIBAN products is therefore neither required nor proportionate from a risk perspective. Instead, BaFin expects governance structures in which information flows, responsibilities and control mechanisms appropriately reflect the actual complexity of the business model.

Supervisory red flags

In its new Supervisory Notice, BaFin identifies a number of typical risk indicators. These provide institutions with a concrete basis for reviewing transaction monitoring scenarios and customer risk classification criteria. According to the supervisory authority, particular attention should be paid to the following triggers:

  • Numerous vIBANs linked to a master account maintained by a foreign payment service provider, particularly one established in a third country;
  • Incomplete information regarding end customers, address details or beneficial owners;
  • High transaction volumes without any identifiable underlying economic activity;
  • Incoming payments from potential shell companies (for example, newly established companies, companies sharing the same or unusual business address, or companies without a meaningful online presence) or payments to recipients with similar characteristics;
  • Generic or unclear payment references (examples include “saldo invoice”, “saldo fattura” or “payment for goods”);
  • Short periods of use of individual vIBANs and unusually rapid turnover of funds;
  • Complex international payment routes or the involvement of multiple payment service providers;
  • Fragmented transaction patterns lacking economic plausibility; and
  • Combinations of trade transactions and payment flows without an identifiable economic rationale.

None of these indicators alone proves money laundering or unlawful underground banking. What matters is the overall assessment. However, the combination of several indicators (for example, a third-country connection, short transaction cycles, generic payment references and implausible trade flows) may justify enhanced scrutiny and, where appropriate, the filing of a suspicious activity report.

Expected risk-based measures

Based on the risks identified, BaFin derives specific expectations for both credit institutions and payment service providers. The new Supervisory Notice clarifies how BaFin expects existing obligations under the German Anti-Money Laundering Act (GwG) and the relevant sector-specific legislation to be applied to vIBAN structures. It is therefore likely to become an important benchmark in future supervisory reviews and ongoing supervision.

The identified risks may, in particular, require account-holding credit institutions to adjust their anti-money laundering due diligence, control and monitoring measures. These measures should be risk-based and tailored to the specific characteristics of vIBAN structures. Obliged entities are expected to address the identified risks through appropriate preventive measures—this applies equally to credit institutions and payment service providers.
For determining the appropriate level of effort, BaFin sets out a clear benchmark: the nature, scope and intensity of the measures should be based in particular on the complexity of the respective vIBAN structures, the number of payment service providers involved and the degree of transparency regarding end customers and their beneficial owners.

In practice, this results in a graduated due diligence approach. Where vIBAN structures make it more difficult to clearly attribute payment flows to the actual end customers, institutions are expected, on a risk-based basis, to apply enhanced requirements with respect to information gathering, documentation and the ongoing monitoring of the business relationship. This applies in particular to multi-layered models, cross-border payment structures and the involvement of foreign payment service providers. Given the complexity of such structures, institutions should regularly assess whether enhanced due diligence measures pursuant to Section 15 of the German Anti-Money Laundering Act (GwG) are required.

BaFin identifies the following mitigation measures:

1. Ensure sufficient transparency regarding end customers, beneficial owners and roles

Institutions must understand and document the roles of all parties involved in the payment process: Who maintains the master account? Who issues or allocates the vIBAN? Who performs customer due diligence? Who identifies the beneficial owner? Who monitors which transactions, and who decides whether unusual activity should be investigated or a suspicious activity report should be filed?

However, the Supervisory Notice does not automatically require the account-holding institution to identify every end customer as its own customer under Section 10 of the German Anti-Money Laundering Act (GwG). It must, however, have access to a sufficient level of information and contractually secured access rights to enable it to adequately assess and monitor its own business relationship. Simply relying on the intermediary payment service provider’s assurance that it knows its end customers is unlikely to be sufficient where an elevated risk exists.

2. Assess the need for enhanced due diligence

According to BaFin, institutions should regularly assess whether enhanced due diligence measures pursuant to Section 15 GwG are appropriate where multi-layered models, cross-border payment structures, foreign payment service providers or significant transparency deficits exist.

“Regular assessment” does not mean that every vIBAN structure automatically represents a higher risk. Rather, the decision must be based on a documented case-by-case assessment. However, the more complex and less transparent the structure, the greater the justification required where an institution concludes that no increased risk exists.

3. Validate customer and transaction profiles

Ongoing monitoring pursuant to Section 10(1) No. 5 GwG must reflect the specific vIBAN model. Expected transaction volumes, countries of origin and destination, typical payer and beneficiary groups, payment purposes, transaction durations and settlement speeds should already be identified during onboarding and subsequently compared with actual transaction behaviour.

Deviations should not only be detected technically but also investigated from an economic perspective and documented in a comprehensible manner.

4. Enhance transaction monitoring

Generic monitoring scenarios are often insufficient for complex vIBAN models. Institutions require monitoring rules that, where technically and legally feasible, analyse payment activity not only at the aggregated master account level but also at the level of individual vIBANs and their assigned end customers.

Particular attention should be paid to:

rapid incoming and outgoing payments;
fragmented, multi-layered or cross-border transaction chains;
unusual counterparties;
third-country connections;
changing vIBANs; and
deviations from the documented business model.

5. Account retrieval database pursuant to Section 24c KWG

Particular practical importance is attached to BaFin’s General Administrative Act of 8 December 2020. According to this guidance, credit institutions must, for certain vIBAN structures using a German country code, record the relevant end customer data in the account retrieval database pursuant to Section 24c(1) of the German Banking Act (KWG).

The new Supervisory Notice expressly reiterates this expectation. Institutions should therefore verify that all relevant vIBANs are recorded completely, accurately and up to date and that the data supplied by participating payment service providers is contractually and technically safeguarded.

6. Governance, contracts and training

The control framework does not end with transaction monitoring. Agreements with participating payment service providers should contain clear obligations regarding the provision, updating and quality assurance of data. They should also provide for information rights, audit rights, escalation procedures and rules governing subcontractors and additional payment service providers within the payment chain.

Relevant business functions—particularly Sales, Onboarding, Compliance, Anti-Money Laundering, Operations and Transaction Monitoring—should receive targeted training on the specific misuse risks associated with vIBANs. In this respect, BaFin expressly refers to Section 6(2) No. 6 GwG.

Not only an issue for the account-holding bank

Although many of the measures primarily address the perspective of account-holding credit institutions, BaFin expressly places obligations on payment service providers as well. They are often the only parties with direct access to end customer information and business model data. Consequently, the quality of their KYC processes, transaction monitoring and data management becomes a key risk factor for the entire payment chain.

In practice, this may result in stricter requirements arising from banking relationships. Banks are expected to expand their due diligence questionnaires, contractual information rights and ongoing monitoring activities. Payment service providers should therefore be prepared to demonstrate in greater detail how they identify end customers, determine beneficial owners, classify risks and investigate unusual activities. Equally important is the ability to provide the required information promptly and in a technically usable format.

A preview of the AML Regulation

The German Supervisory Notice does not stand in isolation. As early as 2024, the European Banking Authority (EBA), in its report on virtual IBANs, identified significant differences across the EU regarding definitions, regulatory treatment and supervisory practices. Among the identified risks were unclear responsibilities, shortcomings in anti-money laundering controls and the possibility that end customers or public authorities might misunderstand the actual geographical location of a vIBAN.

The fact that BaFin has limited the validity of its Supervisory Notice until 10 July 2027 does not indicate that the identified risks will diminish thereafter. Rather, this is the date on which the European Anti-Money Laundering Regulation (AMLR) becomes directly applicable. Institutions should therefore expect the AMLR to contain similar or even more stringent transparency requirements for vIBAN structures. The Supervisory Notice already provides valuable guidance on how future harmonised EU-wide compliance processes are likely to be designed.

What institutions should do now

  • Create a product inventory: Record all vIBAN offerings, master accounts, country codes, participating entities and intermediaries.
  • Update the risk assessment: Assess product, customer, country, distribution and transaction risks and incorporate the supervisory red flags.
  • Document the operating model: Clearly assign responsibilities for KYC, beneficial ownership, monitoring, investigations, suspicious activity reporting and regulatory enquiries.
  • Test data availability: Verify which end customer and transaction data is actually available, how quickly it can be retrieved and whether it covers the entire payment chain.
  • Validate Section 24c KWG implementation: Review the completeness, accuracy and currency of stored end customer data for relevant German vIBANs.
  • Calibrate transaction monitoring: Adapt monitoring scenarios and thresholds to vIBAN-specific transaction patterns and ensure that analyses extend beyond the aggregated master account level.
  • Strengthen contractual arrangements: Secure obligations regarding data provision, updates, audit rights, escalation procedures and cooperation throughout the payment service provider chain.
  • Evidence controls: Document decisions, sampling activities, alerts, investigations and mitigation measures so that their appropriateness can be demonstrated during supervisory reviews.
  • Train employees: Raise awareness among relevant business functions regarding the specific risks associated with vIBANs and underground banking.

Conclusion

The new Supervisory Notice is not a rejection of virtual IBANs. It is, however, a clear warning against business models in which technical efficiency comes at the expense of regulatory transparency. The more layers, jurisdictions and payment service providers exist between the master account and the actual end customer, the more robust the institution’s information access, data quality, transaction monitoring and allocation of responsibilities must be.

Banks and payment service providers therefore face an immediate need for action. Institutions operating or facilitating vIBAN structures should not wait until the next supervisory inspection or the application of the AML Regulation. The Supervisory Notice already provides a concrete benchmark against which the adequacy of existing anti-money laundering controls and preventive measures is likely to be assessed.



By continuing, you accept our privacy policy.
You May Also Like
EuGH schafft Klarheit: Nicht jede Weiterleitung von Geldern Dritter ist ein Zahlungsdienst im Sinne der PSD2 ECJ Clarifies the Scope of PSD2: Not Every Transfer of Third-Party Funds Constitutes a Payment Service
Read More

ECJ Clarifies the Scope of PSD2: Not Every Transfer of Third-Party Funds Constitutes a Payment Service

The ECJ has further clarified the distinction between payment services and other business models. The judgment confirms that merely receiving and forwarding third-party funds does not automatically trigger licensing requirements under PSD2. The decision provides greater legal certainty for FinTechs, platform operators and other businesses handling payment flows, while emphasising that the specific business model remains decisive.
Read More
Neues Listungspaket und 21. EU-Sanktionspaket gegen Russland: Auswirkungen auf den Finanzsektor EU expands Russia sanctions lists and prepares 21st sanctions package
Read More

EU expands Russia sanctions lists and prepares 21st sanctions package

The EU's listing package of 15 June 2026 and the proposed 21st sanctions package significantly expand sanctions against Russia. Financial institutions will increasingly need to address indirect risks, third-country involvement and complex payment structures within their sanctions compliance frameworks.
Read More