Skip to main content

Janina Schwarz

Senior Compliance & AML Expert for Banks and Financial Services KYC · AML/AFC · AMLR · ICS & Control Frameworks · Audit Support

Anyone responsible for anti-money laundering within a banking group asks themselves the same question over and over again: Does a company even belong to the “group”? Is it an obliged entity itself? And who is responsible for implementing what—directly, indirectly, in the EU, or in a third country? With the implementation of the EU Anti-Money Laundering Regulation (AMLR, Regulation (EU) 2024/1624) effective July 10, 2027, this classification takes on greater significance. This article outlines the criteria that are helpful in practice and compares the current legal situation under Section 9 of the German Anti-Money Laundering Act (Geldwäschegesetz, GwG) with the future framework.

1. Why the group question is becoming relevant now

Until the AMLR takes effect, Section 9 GwG will continue to apply to group-wide obligations. The AMLR is directly applicable and will make group governance more uniform across Europe in the future. For major banks, this is no minor matter: guidelines, agreements with subsidiaries, data flows, and risk methodologies all require lead time. Those who wait until 2027 to begin properly classifying their group structure will lose valuable time.

Added to this is the European supervisory perspective. The AMLA will directly supervise certain credit and financial institutions, as well as groups, that operate in a minimum number of Member States (according to Article 12 of Regulation (EU) 2024/1620: at least six). If an obliged entity is part of such a group, the risk profile is assessed on a group-wide basis. Clearly defining the boundaries of the group is therefore also relevant from a supervisory perspective.

In addition, the AMLA provides further detail on group-related matters through regulatory technical standards (RTS) and guidelines. On October 1, 2026, it submitted the final drafts of the RTS regarding Art. 16(4) AMLR (minimum requirements for group-wide strategies, procedures, and controls, including the exchange of information within the group) and Article 17(3) of the AMLR (additional measures for branches and subsidiaries in third countries) to the European Commission. The guidelines on the business-wide risk assessment pursuant to Article 10(4) of the AMLR, upon which the group-wide risk assessment is based, are currently being finalized following the conclusion of the consultation. Project managers should keep an eye on both instruments, as they may affect systems and processes.

2. Starting Point: What Is a “Group”?

According to Section 1(16) GwG, a group is an association of companies consisting of

  1. a parent company,
  2. the parent company’s subsidiaries,
  3. the companies in which the parent company or its subsidiaries hold an interest, and
  4. Companies that are affiliated with one another through a relationship as defined in Article 22(1) of Directive 2013/34/EU.

Pursuant to Section 1(25) GwG, a parent company is an entity to which at least one other entity is subordinate pursuant to Section 1(16), items 2 through 4 of the GwG, and to which no other entity is superior.

In its Interpretation and Application Guidance (Auslegungs- und Anwendungshinweise, AuA; as of July 2025, Chapter 11), BaFin specifies the criteria for determining when an entity qualifies as a subsidiary. Examples include a majority of voting rights, the right to appoint or remove members of the governing bodies, a controlling influence based on a control agreement, a profit transfer agreement, or the articles of incorporation, as well as unified management in conjunction with a holding within the meaning of Section 271(1) of the German Commercial Code (HGB). According to the AuA, the obligations under § 9(1) GwG apply to obliged entities under § 2(1) of the GwG that are parent companies and have their principal place of business in Germany.

3. Three distinctions that make all the difference in practice

3.1 Group membership does not make an entity an obliged entity

The group-wide risk analysis pursuant to Section 9(1), first sentence, of the GwG applies to branch offices, branches and group companies that are subject to anti-money laundering obligations. BaFin clarifies that the group-wide risk analysis can only apply to entities that are subject to anti-money laundering obligations at their place of incorporation. If entities are not included, this must be justified separately and documented in a transparent manner.

Practical implication: The group structure requires a classification by unit, not just a list of shareholdings. A company can be part of the group without being an obliged entity itself—for example, a service company. It is crucial that the rationale for exclusion from the scope be clearly documented and supported by senior management.

3.2 Direct is not the same as indirect

Group structures are rarely flat. Intermediate companies and multi-tiered ownership structures are the norm. Several points help with the classification:

  • Subordination: The decisive factor is whether a company is subordinate to the parent company, directly or indirectly, pursuant to § 1(16)(2) through (4) GwG.
  • Controlling Influence: Pursuant to Section 9(1), third sentence, of the GwG, the parent company must ensure the effective implementation of measures at entities that are subject to anti-money laundering obligations and to the parent company’s controlling influence. BaFin adds that measures must be taken where the parent company has the legal ability to ensure effective implementation based on its ownership interest or other agreements. In the case of minority interests, this is a typical point requiring clarification.
  • Subgroups: Section 9(4) GwG extends the obligations to obliged entities that are group companies if at least one other company is subordinate to them and subject to their controlling influence, and if their parent company is not required to take group-wide measures either under Section 9(1) GwG or under the law of the country where it is headquartered. This applies in particular to German intermediate holding companies or subgroups within international groups.
  • Implementation at the Subsidiary Level: Pursuant to Section 9(5) GwG, obliged subsidiaries of a parent company, as defined in paragraph 1, shall implement the measures specified in paragraph 1, sentence 2, items 1, 3, and 4; all other obliged entities within the group shall implement at least the provisions regarding information exchange and data protection (Nos. 3 and 4). Their own statutory obligations remain unaffected.

3.3 EU is not the same as third country

The law makes a clear distinction here:

  • Headquarters in another EU member state (Section 9(2) GwG): The parent company must ensure that entities in which it holds a majority stake comply with the national regulations in that country implementing the Anti-Money Laundering Directive.
  • Headquarters in a third country (Section 9(3) GwG): According to Section 1(17) GwG, a third country is a country that is neither an EU member state nor a signatory to the EEA Agreement. If the minimum requirements there are lower than in Germany, majority-owned entities must comply with the requirements of the GwG to the extent permitted by the law of the third country. If the implementation of the measures under Section 9(1), second sentence, nos. 1, 3, and 4 is not permitted under the law of the third country, additional measures must be taken to effectively mitigate risks, and the competent supervisory authority must be informed. If the measures are insufficient, the supervisory authority may order that no business relationship be established or continued in that third country and that no transaction be carried out.

This leads to a topic that is often oversimplified: The principle that “the stricter law applies” is explicitly established in the GwG only for third-country scenarios. For EU entities, the law of the country of incorporation applies. This should be precisely reflected in corporate guidelines so that neither too much nor too little is mandated.

4. What changes will the AMLR bring?

  • Legal Form: The AMLR will take effect directly as a regulation as of July 10, 2027. The extent to which the national group rules under the GwG will then be replaced, supplemented, or amended depends on the national legislative bodies responsible for implementing the regulation. A comparison of the regulations should therefore be conducted at an early stage and updated on an ongoing basis.
  • Definition of a group: According to Article 2(1)(41) of the AMLR, a group consists of a parent company and its subsidiaries, as well as companies that are linked by a relationship within the meaning of Article 22 of Directive 2013/34/EU. Entities in which only a holding is held (see § 1(16)(3) GwG) are not expressly mentioned there. For shareholding portfolios, a careful comparison is therefore warranted. Article 2(1)(42) of the AMLR also redefines the parent company, including for groups headquartered outside the Union.
  • Group-wide Risk Assessment: Pursuant to Art. 16(1) of the AMLR, the parent company shall conduct a group-wide risk assessment, taking into account the business-wide risk assessments of all branches and subsidiaries. According to the final draft RTS, this assessment must be commensurate with the group’s complexity and risk profile and take a holistic view of the risks.
  • Exchange of Information: Article 16(3) of the AMLR specifically lists the identity and characteristics of the customer, beneficial owners, the nature and purpose of the business relationship, and reported suspicious cases along with the underlying analyses, unless the Financial Intelligence Unit directs otherwise. The draft RTS specifies that the exchange of information must be on a need-to-know basis. This requires robust processes and a clear legal framework for data protection.
  • Subsidiaries and Branches Outside the EU: Pursuant to Article 17 of the AMLR, the parent company must ensure that entities in third countries with less stringent requirements comply with the requirements of the AMLR; if the law of the third country does not permit this, additional measures must be taken and the supervisors must be notified. The final draft RTS on Article 17(3) of the AMLR specifies these additional measures.
  • Continuity with Nuances: Much remains familiar, such as group-level audits and harmonized guidelines. Under Art. 16(2) of the AMLR, compliance functions are established at the group level: a group-level compliance manager and, if group-level activities warrant it, a compliance officer. The decision regarding the scope must be documented.

Important: The RTS on Art. 16(4) and Art. 17(3) of the AMLR have been submitted to the Commission as final drafts. They will not become binding until they are adopted by the Commission and published in the Official Journal of the EU; according to the AMLA, they are scheduled to take effect six months after their entry into force.

5. Common Practical Problems

  1. Maintaining the Scope List: Shareholdings change. Without a process for ongoing updates (additions, removals, structural changes), every classification becomes outdated.
  2. Ownership of the Risk Analysis: In practice, obliged subsidiaries prepare their own risk analyses, which are then consolidated at the group level. According to the AuA, the group-wide risk analysis and group-wide safeguards must be approved by the designated member of the parent company’s management.
  3. “Uniform” does not mean “identical”: According to the AuA, the safeguards applicable to the respective category of obliged entities must be applied in the same manner throughout the group, regardless of location. The same measures are not required for all sectors.
  4. Enforcement through contracts and instructions: The Group Anti-Money Laundering Officer must have the authority to issue directives, access to audit reports from Internal Audit and external auditors, and access to relevant customer, account, and transaction information. This must be ensured through contractual and organizational measures.
  5. Information Exchange vs. Local Law: According to the AuA, information regarding intended or filed suspicious activity reports must also be made available, and it must be possible to determine whether a customer has relationships with other group entities. In third countries, this sometimes conflicts with data protection or confidentiality regulations; in such cases, the additional measures and the obligation to provide information to the supervisory authority apply.
  6. Documentation of Exceptions: Any entities not included must be justified and documented in a way that is transparent. Missing justifications are a classic audit finding.

6. Classification Checklist

StepKey QuestionLegal basisConsequence
1. Group AffiliationDoes a relationship exist as defined in § 1(16)(2) through (4) GwG (subsidiary, equity interest, affiliated company)?§ 1, paras. 16, 25 GwG; AuA, Chapter 11.1Company is part of the group: yes/no
2. Obliged-entity statusIs the entity subject to money laundering regulations at its place of business?§ 9(1), sentence 1, of the GwG; AuA, Chapter 11.3.1Inclusion in the group-wide risk analysis; otherwise, documented justification
3. Position within the structureDirectly or indirectly subordinate? Are there intermediate companies with their own subsidiaries?Section 1, paragraph 25; Section 9, paragraph 4 GwGReview of Subgroup Responsibilities
4. InfluenceIs there a controlling influence or the legal capacity to effectively implement this?§ 9(1), sentence 3, GwG; AuA, Chapter 11.3.2Scope of enforcement; structuring through shareholdings or agreements
5. Size of shareholdingMajority ownership?§ 9, paras. 2 and 3 GwGApplicability of the rules for foreign entities
6. Country of IncorporationDomestic, another EU/EEA country, or a third country?Section 1, paragraph 17; Section 9, paragraphs 2 and 3, GwGEU: Law of the country of incorporation; third country: stricter law, to the extent permitted
7. Conflict of LawsDo local laws prohibit certain measures (data protection, confidentiality)?§ 9, para. 3, sentences 2 and 3 GwGAdditional measures, notification of the regulatory authority, and, if necessary, a ban on conducting business
8. Future Legal SituationHow will the AMLR, effective July 10, 2027, affect this classification?Regulation (EU) 2024/1624; RTS regarding Art. 16(4) and Art. 17(3) of the AMLRGap Analysis and Adjustment of Group Policies

7. Recommendations for Action

  • Establish a scope register: For each entity, document and regularly update the following information: obliged-entity status, country of incorporation, ownership percentage, degree of influence, and rationale for classification.
  • Incorporate the decision tree into policies: Define the assessment criteria in the group policy so that new entities are assessed consistently.
  • Gap Analysis: GwG vs. AMLR—Compare group-relevant requirements and prioritize the need for adjustments to policies, contracts, and systems.
  • Secure enforcement rights: Establish the group anti-money laundering officer’s rights to issue instructions, obtain information, and conduct audits through contractual and organizational measures.
  • Assess third countries separately: Obtain a legal assessment of data protection and confidentiality limits, define additional measures, and prepare communications with supervisory authorities.
  • Monitor RTS and guidelines: Track the Commission’s adoption of the RTS, publication in the Official Journal, and final guidelines on risk assessment, and align project plans accordingly.

8. Frequently Asked Questions (FAQ)

Does Section 9 GwG also apply to companies that are not themselves obliged entities?

The group-wide risk analysis applies to entities that are subject to anti-money laundering obligations at their place of business. Entities not included in the analysis must be specifically justified and documented in a transparent manner.

Does the stricter law apply to subsidiaries in other EU member states?

Pursuant to Section 9(2) GwG, entities in which a majority stake is held in another EU member state must comply with the national law of that state. Pursuant to Section 9(3) of the GwG, there is an express obligation to apply German requirements, to the extent permitted, to third countries.

What happens if the laws of the third country prohibit the exchange of information?

In that case, additional measures must be taken to effectively mitigate the risk, and the competent supervisory authority must be notified (Section 9(3), second sentence, GwG). If these measures are insufficient, the supervisory authority may impose restrictions on business operations.

When does the AMLR take effect?

The EU Anti-Money Laundering Regulation (Regulation (EU) 2024/1624) will take effect on July 10, 2027.

Conclusion

Classifying companies that are part of a group is less a matter of definition than a task involving structure and documentation. Those who separately examine group affiliation, obliged-entity status, position within the structure, scope of influence, and country of domicile—and document their reasoning—create a solid foundation for compliance with § 9 GwG and for the transition to the AMLR.


Need to classify your group structure?

As a consultant in the Compliance/AML practice area, I assist with the classification of corporate structures, GwG/AMLR gap analysis, and the development of group-wide policies.

Note: This article is intended to provide general technical information and does not constitute legal advice. It reflects the status as of the publication date, October 9, 2026, and takes into account the German GwG as amended effective February 10, 2026, as well as BaFin’s Interpretation and Application Guidance (as of July 2025). Draft RTS and AMLA guidelines are subject to change until they are adopted or published. This article does not contain any information regarding specific institutions or client matters.