Operating a crypto business in Germany without a properly constituted Money Laundering Reporting Officer (MLRO) – also called a Geldwäschebeauftragter – and a functioning compliance officer structure is one of the fastest routes to BaFin enforcement. The Bundesnetzagentur für Finanzdienstleistungsaufsicht, known universally as BaFin, has made clear that for any entity holding a crypto custody licence (Kryptoverwahrgeschäft) or a broader payments or investment services authorisation under German law, the AML compliance function is not a formality. It is a supervised structural requirement. As VASP supervision tightens across every leading hub, Germany stands out for the depth of its personal-accountability expectations – particularly for cross-border operators whose legal entity sits in Frankfurt but whose users, banking partners and counterparties span multiple time zones.
This page sets out the regulated basis for the MLRO and compliance officer function under the BaFin regime, the practical steps for assembling and evidencing that function, how it interacts with the Travel Rule (the obligation to pass originator and beneficiary data with a transfer), and where the most common structural mistakes arise for inbound operators.
What triggers the MLRO obligation under BaFin supervision?
Any entity authorised or registered in Germany as a virtual asset service provider (VASP) – whether under the Kryptoverwahrgeschäft licence, an investment services authorisation, a payment institution licence or the transitional crypto-asset operator framework – is subject to the German Anti-Money Laundering Act (the Geldwäschegesetz, known as the GwG) and is required by BaFin to appoint a dedicated MLRO and a deputy. The trigger is the regulated activity, not the volume of business. A new entrant processing a modest number of transactions each month is subject to the same structural obligation as an established exchange. BaFin examines the function before and after authorisation.
The obligation extends to firms passporting into Germany under MiCA (the EU's Markets in Crypto-Assets Regulation) once the CASP authorisation framework is fully operative across the EU. A firm authorised in, say, Ireland or Malta may conduct business in Germany on a passport basis, but the host-state AML obligations – including the expectation of a locally accessible compliance contact and an effective AML program – apply on day one of cross-border service. BaFin has stated publicly that passporting does not eliminate German AML requirements at the point of customer relationship.
In our practice, we see inbound operators consistently underestimate this point. They assume the home-state licence handles everything. It does not handle the German AML layer.
BaFin's personal-accountability model means that the MLRO is not merely a title. The individual carries direct regulatory exposure for failures in the AML program. That exposure includes formal measures up to and including prohibition from holding the role.
CTA #1 — The standard path above describes a clean authorisation scenario. Your facts – the entity structure, the user base geography, the banking relationships – change the analysis in ways that matter before you apply. Map your options with an OBOLUS assessment before you commit to the structure.
What must the MLRO function actually do?
The MLRO function under the BaFin regime has four operational pillars: internal suspicious transaction reporting, staff training and awareness, risk-based customer due diligence oversight, and interface with the German Financial Intelligence Unit (Financial Intelligence Unit Deutschland, the FIU). Each pillar must be evidenced, not merely asserted. BaFin expects documented policies, training records, SAR (Suspicious Activity Report) logs, and a demonstrable risk-assessment methodology that is updated when the business model or customer profile changes.
The compliance officer function – which may be held by the same individual as the MLRO in smaller firms, but must be structurally distinct for larger or higher-risk entities – carries responsibility for ongoing regulatory monitoring, breach identification and escalation to the management board. BaFin's supervisory practice is to assess whether the compliance officer has sufficient seniority, independence from commercial pressure and access to management to be effective. A compliance officer who reports to the head of sales, rather than directly to the board, will draw scrutiny.
Key operational requirements BaFin assesses:
- A written AML risk assessment covering customer types, geographies, products and delivery channels – reviewed at least annually.
- A KYC framework (know-your-customer) that is risk-stratified: enhanced due diligence for higher-risk customers, simplified procedures only where the GwG permits.
- Transaction monitoring with documented alert-handling and escalation procedures. BaFin expects the monitoring system to be calibrated to the firm's actual risk profile, not a default vendor configuration.
- A SAR reporting process connected to the FIU's goAML system, with timelines for reporting met consistently.
- A deputy MLRO who can act in the absence of the primary appointee without a gap in the function.
In a recent compliance review matter, a payment institution with a German authorisation discovered during an internal audit that its transaction monitoring rules had not been updated since initial deployment. The calibration missed a category of high-risk counterparty that had emerged following a change in product mix. We assisted the firm in preparing a remediation plan and a voluntary disclosure to BaFin that pre-empted a formal supervisory measure. The remediation involved recalibrating monitoring parameters, retraining staff and updating the risk assessment – a process completed over several weeks rather than months, in part because the documentation structure was already sound.
How does the Travel Rule apply to a German-licensed VASP?
The Travel Rule – the obligation requiring a VASP to collect and transmit originator and beneficiary information alongside a virtual-asset transfer – applies to German-licensed VASPs under both the GwG and the EU's Transfer of Funds Regulation (TFR), which in its revised form brings crypto-asset transfers expressly within scope. A VASP authorised under BaFin supervision must, for transfers above the applicable threshold, pass name, address, account number or wallet identifier, and date of birth of the originator to the receiving VASP or financial institution, and obtain the corresponding beneficiary data on the receiving side.
For cross-border operators, the Travel Rule creates an immediate practical tension. The technical standards for data exchange – the formats, the messaging protocols, the confirmation mechanisms – are not yet fully harmonised across all counterparty jurisdictions. A German VASP sending to a counterparty in Singapore, Hong Kong or Switzerland will encounter different implementation states depending on the counterparty's own supervisory environment. The FATF (Financial Action Task Force) Recommendation 15 framework provides the global baseline, but the operational reality is that bilateral solutions are often required for non-EU corridor transfers.
BaFin expects the MLRO to have mapped Travel Rule compliance not only for inbound and outbound EU transfers but also for transfers to and from third-country VASPs. Where a third-country VASP cannot or will not provide compliant Travel Rule data, the German VASP must apply enhanced due diligence and, in some cases, decline the transaction. The MLRO is accountable for the policy that governs this decision.
Operators we advise routinely underestimate the volume of operational decisions the Travel Rule generates. It is not a one-time technical integration. It is an ongoing compliance process requiring MLRO oversight, vendor management and regular policy review.
What additional obligations apply to cross-border operators serving German clients?
A business domiciled outside Germany but serving German retail or institutional clients faces a layered set of obligations that the MLRO must account for. The first layer is jurisdictional: BaFin has historically taken the position that soliciting German customers from outside Germany, without a German authorisation or a valid EU passport, constitutes unauthorised conduct under the applicable financial services provisions. The second layer is the AML layer: even where an entity holds a valid authorisation in another EU member state, the German AML requirements attach at the customer-relationship level.
For a business sitting between a UAE VARA licence and German MiCA passporting, the legal question turns on which activity is being conducted, for whom, and on what legal basis. VARA in Dubai and BaFin in Germany operate entirely separate regimes. A VARA-licensed operator does not carry any authorisation entitlement in Germany. If that operator wishes to engage German institutional clients, it will need either a MiCA CASP authorisation (accessed via any EU member state) or, for activities outside MiCA scope, a separate BaFin authorisation. The MLRO of a multi-licensed group must understand which entity is acting, under which licence, for which client, at all times.
Banking interaction compounds this. German banks and payment service providers have their own AML obligations and conduct their own onboarding reviews of VASP clients. A German bank will typically require sight of the VASP's AML program, its MLRO appointment documentation, its risk assessment and its transaction monitoring policy before opening a business account. A well-prepared MLRO file is, in practice, as important for banking access as it is for regulatory compliance. We have seen firms lose banking relationships not because of a compliance failure but because the documentation was not organised in a form that a bank's compliance team could efficiently review.
Who qualifies as MLRO under the German regime?
BaFin requires that the MLRO be a natural person – not a corporate entity or an outsourced service – who is resident in Germany or at minimum readily accessible to BaFin and the FIU. The individual must be at management level within the firm, with sufficient authority to implement measures and a direct reporting line to the board or managing directors. BaFin assesses the individual's suitability as part of the authorisation process and may require an interview or written representations regarding the candidate's AML experience and knowledge of the German regulatory environment.
For smaller firms, particularly those in the early stages of building out a German operation, the MLRO role is sometimes filled by a founder or senior executive on a temporary basis pending a dedicated hire. BaFin tolerates this in early-stage scenarios but expects a road map to a permanent appointment. Indefinitely combining MLRO, compliance officer and commercial management responsibilities in one person is a structural risk that BaFin will flag.
Outsourcing the MLRO function to an external provider is not straightforwardly permitted under the GwG model. The MLRO must be an employee or a person with an equivalent level of commitment and accountability to the firm. External consultants can support the function – preparing risk assessments, reviewing policies, providing training – but they cannot serve as the appointed MLRO. This distinction matters particularly for foreign operators who attempt to use a German consultancy firm as a substitute for a proper appointment.
In our cross-border practice, we assist clients in identifying suitable MLRO candidates, preparing the BaFin suitability file, and structuring the reporting lines so that the function is defensible from day one.
CTA #2 — If a prior BaFin application stalled on the compliance function requirements, or a banking relationship was lost because the AML documentation did not satisfy the bank's review, a second read of the structure can identify the specific gap and the route to resolution. Map your options with the OBOLUS compliance team.
How does BaFin supervise the compliance function after authorisation?
BaFin supervises the MLRO and compliance officer function on a continuous basis, not merely at the point of authorisation. Supervision takes several forms: scheduled and unannounced on-site inspections, document requests, interviews with the MLRO and senior management, and review of SAR filing patterns. BaFin also monitors for changes in business model, ownership structure or product offering that may affect the adequacy of the existing AML program – and expects the firm to self-report material changes.
One of the most common post-authorisation failures we observe is the static AML program: a program that was well-designed at the time of authorisation but was not updated as the business scaled or changed direction. A firm that launches as a simple exchange and then adds custody, staking or lending products without updating its risk assessment, its transaction monitoring rules and its KYC framework is operating with a mismatch between its actual risk profile and its documented controls. BaFin treats this as a compliance failure regardless of intent.
BaFin's expectations for transaction monitoring have become more detailed as supervisory experience with the crypto sector has deepened. Examiners will ask about the data sources feeding the monitoring system, the rule logic, the alert volumes, the disposition rates and the escalation records. A firm that cannot produce this information in an organised form during an inspection creates a supervisory problem that a well-maintained compliance program would have avoided.
Operators we advise in Germany are increasingly engaging in periodic self-assessments – internal mock audits, policy gap analyses and monitoring recalibrations – ahead of scheduled BaFin reviews. The cost of that preparation is a fraction of the cost of a formal supervisory measure.
Which operator profile most needs to prioritise the German compliance function?
Not every operator has the same exposure. The decision as to how urgently and how deeply to invest in the German compliance function depends on the business profile.
Profile A – German-licensed entity, primary market Germany: The highest obligation level. The MLRO must be properly appointed, the compliance officer structurally independent, the AML program current and the FIU reporting active. BaFin is the primary supervisor. The firm should plan for periodic inspections and invest in a compliance program that can withstand scrutiny at any point. Indicative timeline to a defensible program from scratch is several months, depending on the complexity of the product offering and the quality of incoming documentation.
Profile B – EU-passporting CASP using Germany as a key market: The home-state authorisation (Ireland, Malta, Lithuania or another EU member state under MiCA) carries the CASP licence. But the German AML overlay applies at the customer level. The firm's MLRO must understand and document the interface between the home-state AML program and the German-specific requirements. BaFin can engage the home-state authority if it identifies deficiencies in the German market AML posture. The key risk is assuming the home-state program is sufficient without German-specific adaptation.
Profile C – Third-country operator with institutional German clients only: Typically lower direct BaFin exposure than profiles A or B, but not zero. The AML obligations on the German institutional client to conduct due diligence on its VASP counterparty create indirect pressure on the third-country operator's compliance program. If the operator cannot produce satisfactory AML documentation, the German institutional client will restrict or terminate the relationship. The practical incentive to maintain a strong compliance function is therefore commercial as well as regulatory.
Related at OBOLUS
Related at OBOLUS
- AML, Travel Rule and KYC compliance for digital-asset businesses – full-service compliance program design, MLRO support and Travel Rule implementation.
- The compliance burden in practice – a detailed look at how MLRO obligations interact with the operational reality of a growing crypto firm.
- What recent enforcement tells crypto exchange operators – analysis of BaFin and EU enforcement patterns and what they signal for licensing and compliance strategy.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, rooted in the FATF Recommendation 15 framework and implemented in the EU through the revised Transfer of Funds Regulation, requires a VASP to collect and transmit originator and beneficiary identifying information alongside a virtual-asset transfer. The data typically includes name, account or wallet identifier, address and date of birth. For a German-licensed VASP supervised by BaFin, the obligation applies to transfers above the applicable threshold and to both inbound and outbound transactions. The MLRO is responsible for the policy and the operational implementation.
Who must act as MLRO for a crypto firm?
Under the German GwG and BaFin's supervisory expectations, the MLRO must be a natural person at management level within the firm – not an external consultant or a corporate service provider. The individual must have direct access to the board, sufficient authority to implement measures, and demonstrable knowledge of the German AML environment. BaFin assesses suitability at the point of authorisation and may require written representations or an interview. A deputy must also be appointed to cover absence. The function cannot be effectively outsourced, though external advisers can support it.
How do regulators audit crypto AML programs?
BaFin supervises AML programs through scheduled and unannounced inspections, document requests and interviews with the MLRO and senior management. Examiners review the written risk assessment, KYC policies, transaction monitoring rule logic and alert-handling records, SAR filing patterns and staff training documentation. A well-maintained program should be auditable on short notice. The most common finding in crypto sector reviews is a gap between the documented program and the operational reality – particularly where the business has evolved since the program was last updated.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the tax, banking and compliance work that surrounds them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your situation, contact info@oboluslaw.com or reach us on Telegram at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in BaFin supervisory requirements, AML program design and cross-border VASP compliance obligations.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.