Germany sits at the center of European crypto supervision. Any business offering virtual-asset services to German clients – or operating a CASP (crypto-asset service provider) from German soil – must satisfy BaFin's KYC and onboarding framework before it touches a euro of German user funds. That framework draws simultaneously on MiCA, FATF Recommendation 15 and the domestic anti-money-laundering regime, which together create one of the most demanding compliance environments in the EU. For an exchange or custodian approaching Germany for the first time, the question is not whether to comply but how quickly the programme can be made examination-ready. This page maps the regulated basis, the onboarding process, the Travel Rule (the obligation to pass originator and beneficiary data with every qualifying transfer), and the cross-border interactions that catch operators off-guard.
What is the regulated perimeter in Germany for crypto KYC?
Germany is a MiCA jurisdiction regulated primarily by BaFin (Bundesanstalt für Finanzdienstleistungsaufsicht), the Federal Financial Supervisory Authority. Under the applicable MiCA provisions, a CASP authorised in any EU member state may passport across the EEA – but Germany's domestic AML law, the Geldwäschegesetz, imposes obligations that sit alongside and in some respects exceed the MiCA baseline. BaFin enforces both layers concurrently.
The perimeter is broad. Entities providing exchange, custody, transfer, brokerage or advisory services in relation to crypto assets are caught. The test is functional: if the economic activity is a regulated service, the label the operator assigns to itself is irrelevant. BaFin has demonstrated consistently that it will pursue unlicensed operators, including those based offshore who route transactions through German banking rails or market to German retail clients.
Operating without the right authorisation exposes the business to enforcement, frozen correspondent-banking rails and a near-permanent reputational difficulty with German credit institutions – which remain among the most conservative in Europe when onboarding crypto-related clients. The risk is not theoretical; in our cross-border practice we regularly see operators discover the German perimeter only after a banking partner terminates the relationship.
Which crypto businesses must build a formal KYC programme for Germany?
Any entity that falls within the CASP perimeter under MiCA, or within the domestic VASP definition under the Geldwäschegesetz, must operate a documented KYC (know-your-customer) programme meeting BaFin's expectations. The obligation extends to foreign operators with a material German user base, even where the entity itself is licensed elsewhere in the EU under the MiCA passport.
BaFin scrutinises four categories of operator most closely: spot-exchange operators, custody service providers, firms offering token transfer or settlement, and any platform that structures a lending or staking product in a manner that qualifies as a financial instrument under applicable German law. Decentralised or non-custodial structures are not automatically excluded – the authority applies a substance-over-form analysis to determine whether a natural or legal person exercises sufficient control to be captured.
For a business sitting between, say, a UAE-licensed entity and a German user base, the legal question turns on whether the German-facing activity is substantive enough to require a local authorisation or whether the MiCA passport of another EU hub suffices. That analysis is fact-specific and time-sensitive: BaFin does not wait for the operator to reach a threshold before opening a dialogue.
The process above describes the standard path. Your facts – the entity structure, the user base, the banking layer – change the analysis materially. For a scoped assessment of your German perimeter exposure, contact OBOLUS at info@oboluslaw.com or map your options with our team.
How does the KYC onboarding process work under BaFin supervision?
BaFin expects a risk-based onboarding process that is documented, proportionate, and auditable from day one of client acceptance. The process flows through four functional stages, each with its own evidentiary requirement.
Stage one is customer identification. For natural persons this means verifying legal name, date of birth, nationality and residential address using a government-issued document. For legal entities, the expectation extends to the full beneficial-ownership chain, typically requiring corporate registry extracts, shareholder registers and signed declarations. BaFin has signalled that for high-risk jurisdictions or complex structures it expects independent verification, not self-certification.
Stage two is risk classification. Each customer must be assigned a risk rating – simplified, standard or enhanced – based on factors including jurisdiction of residence, transaction type, product risk and the source of funds. The classification is not static: BaFin expects periodic re-evaluation and event-triggered reassessment when a customer's profile changes materially.
Stage three is enhanced due diligence for elevated-risk customers. Politically exposed persons (PEPs), customers from jurisdictions on the FATF grey or black list, and any counterparty presenting unusual transaction patterns trigger an enhanced diligence protocol. This includes senior management sign-off, documented source-of-wealth analysis and – in practice – ongoing transaction monitoring at a higher sensitivity threshold.
Stage four is ongoing monitoring and record retention. Germany's Geldwäschegesetz sets a minimum retention period for KYC records and transaction documentation. BaFin examiners routinely request documentary evidence of the monitoring programme, including alert logs, escalation records and the basis for any SAR (suspicious activity report) filed with the Financial Intelligence Unit, the FIU.
In our practice, the stage that most frequently causes programme failure at examination is stage two – specifically the absence of a documented, consistently applied risk-classification methodology. An operator may onboard correctly but classify incorrectly, producing a misalignment between actual risk and the diligence applied.
What does the Travel Rule require for transfers in Germany?
Under the applicable FATF and EU transfer-funds regulation provisions, a VASP operating in Germany must collect, verify and transmit originator and beneficiary information alongside every qualifying virtual-asset transfer – this is the Travel Rule. BaFin expects full operational readiness, not a roadmap commitment.
The data fields required include originator name, originator account identifier (the wallet or address), originator address or identification number, and the equivalent beneficiary data. For transfers between VASPs the obligation runs to both the sending and receiving entity. Where the counterparty VASP is domiciled in a jurisdiction without an equivalent Travel Rule regime, BaFin expects documented risk management of that gap rather than a simple data omission.
The technical implementation challenge is significant. A business must be able to identify whether a counterparty address belongs to a hosted or unhosted wallet, apply the correct data protocol to the transfer, and demonstrate to BaFin that its VASP-to-VASP messaging layer is functional and tested. Several interoperability protocols are in market use; the choice of protocol is a compliance decision as much as a technical one, since BaFin examines the completeness and accuracy of transmitted data rather than the protocol chosen.
For a cross-border operator – for instance, a Singapore-licensed exchange clearing euro transactions for German clients through a German IBAN – the Travel Rule applies at the point the transfer enters or exits the German-regulated perimeter. Failure to transmit compliant data is a direct AML breach in BaFin's view and will appear in the examination findings.
Who runs AML governance for a crypto firm in Germany?
BaFin requires every CASP or VASP operating in Germany to designate a Geldwäschebeauftragter – the German statutory equivalent of a MLRO (Money Laundering Reporting Officer) – who holds personal responsibility for the AML programme. The appointment must be notified to BaFin and the individual must be fit and proper: demonstrable AML expertise, seniority within the organisational hierarchy, and genuine decision-making authority.
For foreign operators relying on a MiCA passport from another EU member state, the question of where the MLRO function must be physically located is material. BaFin has been clear that the compliance function must be effective, not nominal. An MLRO based in a different jurisdiction who cannot access German transaction data in real time, or who lacks authority to file an FIU report independently, will not satisfy the examination standard.
The governance structure must also include a documented deputy designation, a written AML manual approved by senior management, and a training programme with records showing staff have completed it. BaFin examiners have in past inspection cycles focused heavily on the training documentation – specifically whether staff can demonstrate understanding of the product-specific risk typologies relevant to the firm's crypto service lines.
If a prior compliance programme has stalled or a BaFin correspondence has gone unanswered, a structured legal review can surface the gap and map the remediation path. To pressure-test your AML governance structure before the next examination cycle, message us via t.me/oboluslaw or map your options.
How does Germany's KYC regime interact with cross-border banking and tax obligations?
For a crypto business with German regulatory exposure, KYC compliance and banking access are inseparable. German correspondent banks and neo-bank providers will not open or maintain accounts for a CASP unless they can inspect the AML programme, the MLRO appointment and the BaFin authorisation status. In practice, a BaFin-supervised entity with a documented, examined AML programme has a materially better prospect of maintaining German banking rails than an offshore entity relying solely on a third-country licence.
The cross-border structuring decision is more complex than the licence question alone. An operator domiciled in the BVI or Cayman Islands, holding a local registration, but routing euro clearing through a German IBAN or marketing to German users, faces a tripartite analysis: the German regulatory perimeter question, the German tax nexus question, and the banking relationship question. These three do not always produce the same answer, and an optimised structure addresses all three before the first user is onboarded.
Germany's corporate tax treatment of crypto transactions – particularly the VAT status of exchange services, the income characterisation of staking and lending, and the transfer-pricing implications of intra-group arrangements – interacts directly with the KYC and AML documentation obligation. BaFin examiners and the tax authority operate with growing co-ordination; an AML file that documents source-of-funds analysis in detail will also generate a factual record that has tax implications. We flag this interaction routinely in our advisory work because operators often treat compliance and tax as separate workstreams until an examination or audit reveals they are not.
Where a business has an entity in one EU hub passporting into Germany and a holding structure offshore, the MiCA passport simplifies the regulatory position but does not eliminate the German AML and Travel Rule obligations. Allied counsel in the relevant jurisdictions – covering the holding company's home rules alongside BaFin's expectations – is the standard configuration for this type of structure.
What are the most common KYC compliance mistakes in Germany?
The most common failure we see is a KYC policy that was written for a different jurisdiction and adopted for Germany without localisation. A policy calibrated to the FCA's MLR registration standard or to MAS's Payment Services Act requirements will not automatically satisfy BaFin's expectations on risk classification, FIU filing obligations or beneficial-ownership verification depth.
A second recurring problem is the unhosted wallet gap. Many operators have a credible KYC process for their direct customers but have not built a documented procedure for transactions involving unhosted wallets. BaFin explicitly expects a risk-based approach to those transfers, with documented justification for the risk rating applied and the level of due diligence conducted on the counterparty address.
Third is the MLRO appointment in name only. A compliance officer who lacks real authority, who is shared across multiple entities, or whose appointment has not been notified to BaFin will produce a finding at examination – and in serious cases, a supervisory measure against the individual as well as the firm.
The fourth mistake is underinvestment in transaction-monitoring calibration. An out-of-the-box monitoring tool with default thresholds is not examination-ready for a BaFin-supervised entity. The regulator expects evidence that the firm has tuned its rules to its specific product set, user base and risk classification, and that it reviews the effectiveness of those rules periodically.
Practice insight: remediation in a cross-border context
In a recent compliance matter, a custodian operating under an EU passport encountered a BaFin inquiry regarding the completeness of its Travel Rule implementation for transfers involving unhosted wallets. The firm's MLRO function was centrally located in a different member state, and its monitoring rules had not been localised for the German product offering. We conducted a gap analysis against BaFin's published supervisory expectations, restructured the MLRO reporting line to create a dedicated German-facing compliance function, and produced a revised Travel Rule operating procedure with documented justification for the risk classifications applied to unhosted wallet transfers. The firm responded to BaFin within the inquiry period with a complete remediation package. The inquiry was closed without escalation to a formal supervisory measure.
A common assumption: one offshore licence covers the world
A common assumption among early-stage crypto businesses is that a single offshore licence – BVI, Cayman or a jurisdiction outside the EU – is sufficient to serve clients globally, including in Germany. This is incorrect and the consequences of acting on it in the German market are significant.
MiCA creates a passporting regime, but the passport runs between EU member states. A BVI-registered entity does not hold an MiCA authorisation and cannot use the passport. For that entity to serve German clients lawfully, it must either obtain a CASP authorisation in an EU member state and passport in, or satisfy BaFin that an exemption applies. BaFin's approach to reverse-solicitation exemptions is restrictive: if the operator has placed advertising visible to German residents, the burden of proving true reverse solicitation is high.
Beyond the regulatory question, German banks will not provide correspondent services to an unlicensed or improperly structured entity regardless of its offshore registration. The practical consequence is the one operators feel first: the banking relationship fails before the regulatory enforcement arrives.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – the full compliance practice overview across all major regimes
- MLRO and compliance officer function – legal counsel – structuring and appointing the MLRO function for regulated entities
- Exchange disclosure orders for regulated entities – pursuing or responding to disclosure orders across common-law forums
FAQ
What does the Travel Rule require from a VASP?
Under the applicable FATF and EU provisions, a VASP must collect, verify and transmit originator and beneficiary information – name, account identifier and address or identification data – alongside every qualifying virtual-asset transfer. The obligation runs to both the sending and receiving VASP. Where the counterparty is in a jurisdiction without an equivalent regime, BaFin expects documented risk management of that gap rather than omission of the required data fields.
Who must act as MLRO for a crypto firm?
BaFin requires a designated Geldwäschebeauftragter – the MLRO equivalent – who is notified to the regulator, holds genuine seniority within the firm and has independent authority to file FIU reports. The individual must demonstrate documented AML expertise appropriate to the firm's product set. A nominal appointment, a shared function across multiple entities, or an MLRO without real access to German transaction data will not satisfy the examination standard.
How do regulators audit crypto AML programs?
BaFin examinations for crypto AML programmes typically review the risk classification methodology, customer identification records, beneficial-ownership documentation, Travel Rule implementation, transaction-monitoring calibration, alert and escalation logs, FIU filing history, staff training records and the MLRO appointment and governance documentation. Examiners focus on the consistency between the written programme and actual operational practice – a policy document that does not match the firm's real workflow is a primary finding trigger.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and Travel Rule programmes that regulators such as BaFin increasingly scrutinise at examination. We map the licence stack across operating, custody and payment layers before you commit, and we advise on the cross-border interactions between regulatory, banking and tax obligations that a single-jurisdiction view misses. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in BaFin and MiCA compliance programme design, Travel Rule implementation and cross-border VASP regulatory analysis.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.