Skip to content
BaFin · Germany

BaFin video identification — remote onboarding in Germany

Fintech Passport
August 20, 2026 · 11-min read
BaFin video identification — remote onboarding in Germany

German video identification is not a technology choice — it is a circular with a checklist, and BaFin calls it a bridging technology. The Geldwäschegesetz says identity must be verified either by properly examining a document presented in person or by a procedure of equivalent security. Circular 3/2017 (GW) is what fills in the second limb for video, and its requirements are unusually specific: three randomly chosen security features from different categories, an automated checksum calculation on the machine-readable zone, the serial number spoken aloud, a one-time number sent and returned, and the whole session recorded in vision and sound. Here is the procedure, what it cannot be used for, and where implementations drift.

1. Where video identification sits in the GwG

Three provisions frame it. § 11(1) GwG requires obliged entities to identify the contracting partner, any person acting for them and the beneficial owner before entering into a business relationship or carrying out a transaction. § 12 GwG lists what may be used to verify the identity of a natural person. And § 13(1) GwG governs the method: verification proceeds either through appropriate examination of the document presented on site, or through another procedure suitable for money-laundering-law identity verification that offers a security level equivalent to that first method.

Video identification lives entirely inside that second limb. It is not named in the statute; it is a way of meeting the equivalence test, and Circular 3/2017 (GW) is BaFin’s statement of what equivalence requires in practice.

§ 13(2) GwG also empowers the Federal Ministry of Finance to specify by ordinance, without Bundesrat consent, further requirements for these procedures, to determine which procedures are suitable under paragraph 1 no. 2, and to designate test procedures whose security standards are examined — with the Federal Office for Information Security confirming the required security level for electronic test procedures. That power matters for planning: the circular is the current basis, not a permanent one.

2. Video is one route among several

§ 12(1) GwG sets out the verification routes for natural persons, and video identification is a way of performing the first of them remotely rather than a route in itself. Firms designing a German onboarding stack should look at the whole list before assuming video is the answer.

RouteAnchorPractical note
Valid official ID bearing a photograph§ 12(1) no. 1 GwGThe baseline. Video identification is the remote way of examining it
Electronic proof of identity§ 18 PAuswG, § 12 eID-Karte-G, § 78(5) AufenthGThe eID chip route; strongest assurance, lowest adoption
Qualified electronic signatureArticle 3(12) of Regulation (EU) 910/2014, validated under Article 32(1)Requires the customer to already hold a qualified certificate
Notified electronic identification schemeArticle 9 and Article 8(2)(c) eIDASThe cross-border route; depends on which schemes are notified
Documents under the payment-account identity ordinance§ 1(1) Zahlungskonto-IdentitätsprüfungsverordnungNarrow route tied to payment-account access, including provisions for minors

3. Who may run it, and the sub-delegation ban

Video identification may be carried out only by appropriately trained and qualified staff — either employees of the obliged entity, or of a third party to which the identification duty has been outsourced. The circular then closes the chain: further sub-outsourcing, or a third party in turn relying on another third party, is not permitted.

Training is specified rather than assumed. Staff must know the checkable document features, the forgery methods in circulation, the applicable money-laundering and data-protection rules, and the procedural requirements themselves. Training must take place before the work begins and be refreshed at regular intervals, at least annually, plus on an ad-hoc basis when circumstances require.

Facts: a payment institution contracts an identity provider for German onboarding. The provider handles the technology and routes the live sessions to an operations partner in another country that supplies the agents.

What the rule says: that is a third party relying on a further third party, which the circular does not permit. It is not cured by contract quality, agent training or supervisory access.

What the practitioner does: restructures so the agents sit either inside the institution or inside the single outsourced third party — contracted directly by the institution, not sub-contracted — and pulls the annual training evidence for those agents into its own outsourcing control file, since the identification duty and its consequences remain with the institution.

4. The document, and the three-feature rule

Only documents carrying sufficiently forgery-proof security features that can be checked visually in white light during the video transmission qualify. The circular groups those features into categories — diffractive elements such as holograms and kinetographic structures; personalisation features such as tilted laser images; material features such as security threads and windows; and security printing such as microtext and guilloches.

The operative requirement is the count and the spread: the agent must check at least three security features, randomly selected for that identification, from different categories. Random selection is doing real work here — a fixed script of the same three features every time is predictable to anyone producing forgeries, and it is not what the circular describes.

A machine-readable zone is a mandatory component of an acceptable document, and the procedure must include an automated calculation of the check digits contained in that zone, plus a cross-comparison against the data in the visible fields. The person being identified must also state the full serial number of their document aloud during the transmission, and validity dates are checked.

5. The session: movement, encryption, and what the agent watches

The customer is instructed to tilt the document horizontally and vertically, and to perform further movements on instruction, so that the optical features behave as genuine features behave. The point is not the image; it is the behaviour of the document under changing angle and light.

The channel is specified. Only end-to-end encrypted video chats may be used, and the circular requires compliance with the Federal Office for Information Security’s Technical Guideline TR-02102. Image and sound quality must permit identification beyond doubt, which includes being good enough to assess the security features and detect manipulation.

Photographs or screenshots must capture the person and the front and reverse of the document, with all details clearly recognisable and at a quality supporting unambiguous identification.

6. The one-time number that closes the session

Identification does not end when the agent is satisfied. During the video transmission the person must be sent a sequence of digits valid only for this purpose and centrally generated, delivered by email or SMS, which they then enter and transmit back electronically. The identification is complete on successful system-side verification of that number.

That step binds the identified person to a contact channel already recorded in the file, and it is the reason the address or number used must be captured before the session rather than collected during it.

7. Recording and retention

The entire identification process, in all its individual steps, must be recorded, in vision and sound, with the person’s consent obtained. This is a full-session recording, not a set of stills plus a log.

Retention runs under § 8(4) GwG: records and other supporting documents are kept for five years, subject to longer periods where other statutory duties require, and subject to a ten-year outer limit. The clock is a calendar-year clock — it begins at the end of the calendar year in which the business relationship ends, or, in other cases, at the end of the calendar year in which the information was established.

Facts: a firm onboards a customer in March 2026 and the relationship ends in July 2027. Its archive is configured to delete identification recordings five years after the recording date.

What the rule says: the period does not run from March 2026. It starts at the close of the calendar year in which the relationship ended — 31 December 2027 — so the five years run to the end of 2032.

What the practitioner does: re-keys the retention rule to the relationship-end date rather than the capture date, and adds the outer ten-year limit as a hard ceiling so nothing is held indefinitely by an inherited legal hold. Deleting a recording early is as much a finding as keeping it too long.

8. When the process must be aborted

The circular treats several situations as terminating rather than as risks to weigh. The process is aborted where visual verification or the communication itself is not possible — because of poor lighting, inadequate image quality, or problems with signal transmission — and where there is any other discrepancy or uncertainty that is not resolved.

Operationally that means an abort has to be a defined outcome in the workflow with its own disposition, not a silent retry. A customer who fails on lighting and is immediately re-queued into a fresh session with no record of the first attempt leaves an evidence gap exactly where a supervisor will look, and it removes the pattern data that repeated aborts against the same document would otherwise reveal.

The circular is explicit: identification of legal persons or partnerships by way of video identification is not possible. What the procedure can do is verify the identity of the natural person acting as legal or authorised representative.

The legal person itself is identified on documents and register data under § 12(2) GwG — an extract from the commercial or cooperative register or a comparable official register, founding documents or equivalent authoritative documentation, or the obliged entity’s own documented inspection of the register data.

Facts: an EMI onboards a German GmbH remotely. The managing director completes a video identification, and the file is closed on that basis.

What the rule says: the video session verifies the managing director as a natural person acting for the customer. It does not identify the GmbH, and it does not address the beneficial owners, whose identification is required by § 11(1) alongside that of the contracting partner.

What the practitioner does: keeps the video session for the representative, adds the register-based identification of the company under § 12(2), documents the authority under which the representative acts, and runs beneficial-ownership identification as a separate strand — including the German transparency register position.

FAQ

Is video identification still permitted in Germany?

Yes, on the basis of Circular 3/2017 (GW). BaFin’s evaluation published on 9 May 2022 continued it as a bridging technology and said it would keep monitoring whether the requirements remain adequate as technology develops, including whether to move to an ordinance under § 13(2) GwG or retain the circular.

Can we use a provider that subcontracts the agent function?

No. The circular prohibits further sub-outsourcing and prohibits a third party relying on a further third party. The agents must sit within the obliged entity or within the single third party to which the identification duty is outsourced.

How many security features must the agent check?

At least three, randomly selected for that identification, and from different categories — diffractive, personalisation, material and security-printing features are the groups the circular describes.

Do we need the machine-readable zone?

Yes. A machine-readable zone is a mandatory component of an acceptable document, and the procedure must automatically calculate its check digits and cross-compare them with the data in the visible fields.

How long must the recording be kept?

Five years under § 8(4) GwG, with the period beginning at the end of the calendar year in which the business relationship ends — or, in other cases, in which the information was established — and subject to a ten-year outer limit.

Can we identify a company by video?

No. Legal persons and partnerships cannot be identified by video identification. The procedure can verify the natural person representing them; the entity itself is identified under § 12(2) GwG on register extracts, founding documents or a documented register inspection.

How does this compare with the Spanish approach?

The mechanism is different. Germany works through an equivalence test in § 13(1) no. 2 GwG that BaFin fills in by circular; Spain requires the procedure to have been previously authorised by SEPBLAC under Article 21(1)(d) of the Regulation of Ley 10/2010, and publishes the authorisations. Passporting a single onboarding flow across both needs the union of the two requirement sets, not the intersection.

What to do, today

  • Compliance officers: confirm the three-feature check is randomised per session rather than scripted, and that check-digit calculation on the machine-readable zone is automated and cross-compared, not eyeballed.
  • Vendor and outsourcing managers: trace the contracting chain to the individuals performing sessions. If any link is a subcontract, the arrangement does not meet the circular however the paperwork reads.
  • Operations: make abort a recorded disposition with its own reason code, and monitor repeat aborts against the same document — that pattern is the reason the record exists.
  • Records and IT: re-key retention to the relationship-end calendar year, not the capture date, and set the ten-year ceiling explicitly.
  • Onboarding product: for corporate customers, separate the three strands — representative by video, entity by register, beneficial owners on their own path — and stop treating a completed video session as a completed corporate file.

Related: EBA remote customer onboarding guidelines · Transparenzregister and beneficial owners · EMI licence in Germany · Filing a SAR in Germany under § 43 GwG · SEPBLAC video-identification — remote onboarding in Spain · Remote onboarding compared across the EU

Related reads.