Startseite Themen Brennpunkt INNOVATIONSPREIS-IT IT-Bestenliste INDUSTRIEPREIS INDUSTRIE-Bestenliste TrafficGenerator
INNOVATIONSPREIS-IT 2017

Drucken
Mittelstandspresse

05.08.2026

AI use for combating money laundering

Are you underestimating the legal risk of sanctions under Article 6(2) of the AI ​​Regulation?

Using AI for AML? FATF updates, audit readiness and AML/scoring separation decide your sanction risk under Art. 6 (2) AI Act, GwG and KWG.
Using AI for AML? FATF updates, audit readiness and AML/scoring separation decide your sanction risk under Art. 6 (2) AI Act, GwG and KWG.

Unterföhring bei München, 05.08.2026 (PresseBox) -  

I. Practical and legal relevance

As an anti-money laundering officer, this text is essential reading: it summarizes current regulatory and supervisory developments. It gives you the new FATF country risks that must be incorporated into your risk assessment immediately, legal clarity on direct AMLA supervision, strategic insight into BaFin's stricter auditing practices, and — through the explanations on the AI Regulation — legal support for your future decisions on monitoring systems.

II. Key Data 1.) Data to be implemented immediately / Deadline-related

June 17–19, 2026 (FATF Decisions): The country list changes have been active since the plenary meeting. The inclusion of Bosnia and Herzegovina and Iraq (Enhanced Monitoring) and the removal of Algeria and Namibia should be assessed promptly in the institution-specific risk analysis and, where appropriate, reflected in KYC processes.

July 1, 2026 (BaFin Restructuring): BaFin's new organizational structure came into effect. The resolution function was integrated into the SPS business unit, and Division A now operates with a focused "Anti-Financial Crime" function. From this point on, audits are conducted under the new personnel and organizational structure.

2.) Relevant time periods and events

July 1, 2026 to June 30, 2028 (UK FATF Chairmanship): International audit priorities will increasingly focus on combating fraud rings, optimizing risk-based supervision, and public-private information exchange. Compliance departments should align their long-term strategy accordingly.

June 10/16, 2026 (AMLA webinar materials): The complete criteria for identifying institutions to be directly supervised have been available since June 16. Important for deadline monitoring: a specific obligation to provide data or cooperate arises only upon a corresponding official request; content and scope depend on the specific letter.

Note on draft legislation (EUDI Wallet & AI Regulation): The national law on the European Wallet (EBDIG / amendment to the Money Laundering Act) and the final AI guidelines following the consultation of May 19, 2026, do not yet specify concrete entry into force or transitional periods. These must continue to be monitored as part of regulatory oversight.

III. Duties for money laundering officers, C-level executives and compliance

Update on country risks and KYC processes — Mandatory: Internal country risk models and IT systems must be adapted immediately. For business relationships involving newly added countries, assess whether enhanced due diligence is required based on the FATF classification and other risk factors. For removed countries, conduct a documented risk-based reassessment; a reduction in additional measures is only permissible if no other elevated risk factors (e.g., sanctions, corruption, terrorist financing) are present. Relevant for: Money Laundering Officer (operational implementation), Compliance (adaptation of internal guidelines).

Examination of the AMLA reporting obligation — Obligation: Verify internally whether the institution has received an official letter from BaFin regarding direct supervision by the EU authority (AMLA), and whether it has been contacted by BaFin or another competent authority in connection with the AMLA selection process. Information and data submission obligations specified in the respective letter must be fulfilled within the given timeframe. Such a request does not necessarily mean the institution is already under direct AMLA supervision. Regardless, the general obligations under the German Money Laundering Act (GwG) and the relevant BaFin regulations remain fully in effect. Relevant for: Money Laundering Officer (data provision), Compliance, C-Level (awareness of a possible change to direct EU supervision).

Resource planning and preparation for BaFin special audits — Obligation: The reorganization and personnel increase at BaFin give cause to critically review the adequacy of your own money laundering and compliance resources as well as the institution's auditing capabilities. Relevant for: C-Level (budget/personnel), Compliance & Money Laundering Officer (ensuring audit capability).

Preparation for new digital identification procedures (EUDI wallet) — Obligation: Monitor the upcoming amendments to the Money Laundering Act (GwG) through the EBDI Act. IT and onboarding processes must be designed so that electronic identification methods (e.g., the national eID function and future EUDI wallets) can be integrated into customer identification in compliance with the law. The requirements of the GwG, the eIDAS Regulation (including eIDAS 2.0), and the relevant technical and data protection regulations must be taken into account. Relevant for: C-Level (budget and resources for a modular, API-centric KYC architecture), Compliance & Money Laundering Officer (technical requirements, adaptation of guidelines and risk analysis), IT (interfaces and logging).

Classification of AI systems (AI Act) — Obligation: When procuring or using AI systems for anti-money laundering purposes, ensure and document that they are correctly classified in accordance with Annex III of the AI Regulation. Document in particular the purposes for which the systems are used and whether they perform additional functions (e.g., creditworthiness or solvency checks). Such functions can constitute independent high-risk use cases under Annex III and trigger additional regulatory obligations. Relevant for: Money Laundering Officer (classification of AML-related AI use cases and their integration into the internal security organization), Compliance & Risk Management (AI register, assessing high-risk systems, implementing regulatory requirements), C-Level (overall responsibility for AI governance and proper business organization).

Strategic focus on fraud prevention (FATF objectives) — Supervisory expectation / strategic best practice: Internal risk models and preventive measures should focus more strongly on the overlaps between money laundering and fraud rings, in line with the priorities of the UK's FATF chairmanship (combating fraud rings, optimizing risk-based supervision, promoting public-private information exchange). Relevant for: Money Laundering Officer (expansion of risk analysis), Compliance.

IV. Pain Points

Institutions face operational and technical hurdles. If these are not overcome in time, significant violations of specific legal standards are likely.

1. The pain points in implementation

The IT bottleneck (country risk & KYC): Immediate adjustment of country lists in KYC and transaction monitoring systems often fails in practice due to rigid IT release cycles. A delayed system change means alert systems do not immediately trigger for transactions originating from Iraq or Bosnia and Herzegovina.

Demarcation issues in AI use: Clearly separating money laundering detection (transaction patterns) from creditworthiness assessment/credit scoring within the IT infrastructure is complex. If a system serves both purposes, the entire system can be classified as high-risk AI under the AI Regulation, triggering additional documentation, governance, and compliance requirements.

Resource shortage vs. BaFin expansion: The consolidation of personnel and organizational resources indicates a stronger supervisory focus on anti-financial crime. However, the market for qualified anti-financial crime personnel is completely depleted. The biggest pain point is meeting BaFin's expected audit readiness and documentation depth with existing staff.

Technical integration of the EUDI wallet: Connecting systems to electronic identification means (e.g., national eID function and future EUDI wallets) requires fundamental changes to the digital onboarding process.

2. Which specific norms may be violated?

Delay or error in implementation could, in the worst case, lead to direct violations of the Money Laundering Act (GwG), the Banking Act (KWG) and the European AI Regulation:

a.) Violations of the GwG (Money Laundering Act)

Section 15 Paragraph 3 No. 1 GwG (Enhanced Due Diligence): If the newly added FATF countries (Iraq, Bosnia) are not immediately entered into the system, the mandatory enhanced due diligence for these customers is not performed. This may constitute an administrative offense.

Section 4 Paragraph 3 GwG (Risk Analysis): Failure to assess new relevant country and fraud risks, or delayed assessment, may result in the risk analysis no longer reflecting the current risk situation.

Section 6 GwG (Internal Safeguards): Inadequate or insufficiently updated monitoring systems may impair the effectiveness of internal safeguards and lead to supervisory complaints.

b.) Violations of the German Banking Act (KWG) / Minimum Requirements for Risk Management (MaRisk)

Section 25a Paragraph 1 KWG (Proper Business Organization): Inadequate personnel or organizational resources may constitute a violation of the requirements for proper business organization.

c.) Violations of Regulation (EU) 2024/1689 (AI Regulation / AI Act)

Article 6(2) in conjunction with Annex III, point 5(b) of the AI Regulation: If an AI system performs creditworthiness assessment tasks in addition to AML functions, it must be examined whether this constitutes a high-risk use case under Annex III. Failure to comply with the resulting obligations may render the system incompatible with the AI Regulation, which provides for substantial fines.

V. Concrete solutions 1.) Agility in FATF Updates (The IT Bottleneck)

Automated data feeds (APIs): Connect sanctions and country list providers (e.g., Dow Jones, Refinitiv, LexisNexis) directly to your core systems so changes are incorporated promptly and with less manual effort.

Fast-Track Releases: Establish an "Emergency Change Process" with IT for urgent regulatory parameter changes — accelerated adjustments while maintaining the necessary release, testing, and documentation controls.

Manual fallback processes: While system-side adjustment is pending, instruct the 1st line of defense (e.g., account managers) via "Compliance Flash" to temporarily escalate new business with the affected countries (Iraq, Bosnia and Herzegovina) manually for compliance approval.

2.) AI Architecture and AI Act Compliance

Strict data siloing: Keep databases and AI models for transaction monitoring (AML) strictly separate from those for credit scoring. An AI model must not access both data sources simultaneously.

Use-case inventory: Maintain a central register for all AI systems used in-house. Explicitly document the purpose of each AML tool ("Fraud prevention/money laundering exclusively, no credit checks") to demonstrate exemption from high-risk classification during audits.

Compliance by Design: Integrate compliance into the procurement and proof-of-concept phases of new software to prevent incorrect classification from the outset.

3.) Resource shortage vs. BaFin audit pressure

Outsourcing Level 1 alerts: Outsource the initial review of transaction alerts (triage/false positive handling) to specialized managed service providers, freeing your internal core team for complex suspicious cases.

Robotic Process Automation (RPA): Automate recurring manual research tasks in the KYC process (e.g., commercial register extracts, negative media coverage) to free up analyst time.

Mock audits: Conduct a simulated BaFin special audit by external auditors to identify gaps in organization and documentation before the newly consolidated BaFin "Anti-Financial Crime" unit conducts an unannounced audit.

4.) Preparation for the EUDI wallet

Modular KYC architecture: Don't build digital onboarding as a monolithic system. Use an API-centric architecture into which new identification methods (such as the EUDI wallet) can be integrated via "plug and play" without reprogramming the entire process.

Legislative monitoring: Establish a monitoring process to track the adoption of the EBDI Act, so the technical interface requirements of the Federal Office for Information Security (BSI) can be adapted in time.

VI. Conclusion

Regulatory and supervisory requirements continue to increase. The increased staffing at BaFin, new FATF risk countries, and the substantive requirements of the AI Regulation necessitate timely action. To proactively avoid fines and sanctions, you must now make your IT processes more flexible, modify your KYC systems, and ensure your AI tools are legally compliant. Only through proactive preparation can your institution remain protected from these intensified audits.

Author: Predrag Savic

Predrag Savic drives the topics of regulatory compliance, governance, and risk management at S+P Compliance Services. His goal: to translate complex regulatory requirements into pragmatic solutions so that companies remain operationally excellent and legally compliant, even with new standards such as DORA or ESG.

Ansprechpartner

Cassedy Brose

Anna Tatar
+49 89 452 429 70 113
Zuständigkeitsbereich: Online Marketing Managerin

Über S&P Unternehmerforum GmbH:

Über S+P Seminare

S+P Unternehmerforum GmbH mit Sitz in München ist ein führender Anbieter für praxisnahe, rollenbasierte Weiterbildung im deutschsprachigen Raum. Seit der Gründung im Jahr 2004 unterstützt S+P Fach- und Führungskräfte sowie C-Level-Manager:innen aus der Finanzwirtschaft und Industrie dabei, sich gezielt weiterzuentwickeln und regulatorisch sowie strategisch sicher zu handeln.

S+P bietet ein breites Portfolio an Online-Seminaren, E-Learnings, Zertifikatslehrgängen und Executive Education Programmen. Themenschwerpunkte sind unter anderem Compliance, Geldwäscheprävention, Risikomanagement, Projektmanagement, Finance, Leadership und digitale Transformation.

Ein Alleinstellungsmerkmal ist die S+P Tool Box – mit sofort einsetzbaren Arbeitshilfen wie Leitfäden, Checklisten, Gantt-Plänen und Risikochecks. Zusätzlich steht allen Teilnehmer:innen die digitale Lernplattform S+P Lounge zur Verfügung.

Mit dem Zertifikat S+P Certified und dem digitalen Karriere-Badge dokumentieren Absolvent:innen ihre Kompetenz sichtbar – für Arbeitgeber, Kunden und Netzwerke.

Teilnehmer bewerten S+P Seminare auf ProvenExpert mit 4,65 von 5 Sternen. Für jedes gebuchte Seminar pflanzt S+P im Rahmen des ESG-Projekts „Dein Seminar, dein Baum, deine Zukunft“ einen Baum in Deutschland.

Mehr Informationen unter: www.sp-unternehmerforum.de

Datei-Anlagen:


(53 kB)
1621592.attachment

Using AI for AML? FATF updates, audit readiness and AML/scoring separation decide your sanction risk under Art. 6 (2) AI Act, GwG and KWG.