Skip to content
BaFin · Germany

§43 GwG — filing SARs in Germany via goAML

Fintech Passport
April 30, 2026 · 10-min read
§43 GwG — filing SARs in Germany via goAML

§43 of Germany’s Geldwäschegesetz is the SAR-filing rule — and the German specificities around it are the ones cross-border payment firms build wrong. There is no reporting threshold. Registration with the financial intelligence unit is owed whether or not you ever file. A reported transaction cannot simply be executed once the report is sent. And the liability shield AML teams cite is not the provision they usually name. This is §43 read alongside the four sections that make it operational — §45, §46, §47 and §48.

1. Who receives the report

Reports go to the Zentralstelle für Finanztransaktionsuntersuchungen — FIU Germany — which sits administratively at the Generalzolldirektion, the federal customs authority, rather than under a finance or justice ministry as in most member states. The distinction that matters in practice is that the FIU is not the supervisor. BaFin supervises AML compliance for credit institutions, e-money and payment institutions, investment firms, insurers and crypto-asset service providers; the Länder authorities supervise non-financial obliged entities. FIU Germany assesses your reports; BaFin assesses whether your framework produces them.

2. Who must file

§2 GwG lists the obliged entities (Verpflichtete). The fintech-relevant categories are credit institutions and branches of foreign credit institutions, e-money and payment institutions including passporting ones, MiFID investment firms, crypto-asset service providers, crowdfunding service providers and insurers.

For a group operating through a German branch there is a provision that is easy to miss: §43(3) places the reporting duty on a member of the management level of the obliged entity where the facts relate to an activity of the German branch. The report is not a back-office act that can be pushed entirely to a group hub — see our AML representative across the EU piece for how the named-person duties interact.

3. The three triggers, and the absence of a threshold

§43(1) requires a report where Tatsachen — facts — indicate that:

  • an asset stems from a criminal act capable of being a money-laundering predicate offence;
  • a business transaction or business relationship is connected to terrorist financing; or
  • the contracting party has failed to comply with the disclosure duty in §11(6) sentence 3 — the duty to disclose to the obliged entity whether they are establishing, continuing or carrying out the relationship or transaction for a beneficial owner.

That third limb is a self-standing trigger, not a due-diligence failure to be logged and closed. A refusal to answer the beneficial-owner question is the reportable fact.

The report is owed unverzüglich: without culpable delay, measured from the point the facts are known, not from the close of an internal investigation. Two further paragraphs are worth knowing. §43(4) provides that a report meeting the requirements of §261(8) of the Strafgesetzbuch counts at the same time as a self-report under that criminal provision. And §43(5) lets the FIU designate typified transactions that must always, or need never, be reported — so the German reporting perimeter can move without the statute changing.

4. Registration is a standing duty, not a consequence of filing

§45 carries the mechanics, and one obligation that catches firms with no filing history at all. Reports under §43(1) must be transmitted electronically; and obliged entities must register electronically with the FIU independently of the submission of any suspicious transaction report. Under the transitional rule in §59, that registration duty applies from the commissioning of the FIU’s new information network and in any event from 1 January 2024 — with a later date, 1 January 2027, only for goods dealers outside the high-value categories.

The postal channel survives but narrowly: §45(1) permits post where electronic transmission is disrupted, §45(2) lets the FIU allow it to avoid undue hardship, and §45(3) requires the official forms. §45 was itself amended with effect from the end of December 2024 by the Finanzmarktdigitalisierungsgesetz, so a policy citing an older version should be re-checked.

5. Worked example — the passporting EMI with nothing to report

Facts: an e-money institution passports into Germany, opens a German customer base in 2023, and files no Verdachtsmeldung in its first two years — genuinely, because nothing met the threshold it applied. It has no goAML account. Its AML manual says an account will be opened “when the first report arises”.

Applicable rule: §45(1) sentence 2 requires registration independently of filing, and §59 fixes the outer date at 1 January 2024. The firm has been in breach since then, entirely separately from any question about reportable facts. And because §43(1) has no threshold, the internal threshold that produced the empty filing history is itself a finding.

What the analyst does: registers immediately rather than waiting for a case — a registration completed under an unverzüglich deadline is how late reports happen — names the submitter and a deputy, and re-runs the closed-alert population for cases suppressed on value alone.

Outcome: two findings avoided, and the first genuine report goes through a channel that already works.

6. §46 — when the transaction may actually be executed

This is the provision that most EU-wide payment platforms do not implement natively. Where a transaction has been reported under §43(1), it may be executed only if the FIU or the public prosecutor’s office has consented, or if the third business day after the day the report was sent has elapsed without the transaction being prohibited. For the purpose of that period, §46(1) states that Saturday does not count as a business day — so a Thursday report can push the earliest execution into the following week.

§46(2) is the carve-out. Where postponing the transaction is not possible, or where postponing it would obstruct the investigation of the facts, the transaction may be executed — and the report must then be made immediately afterwards. That is a decision with a documented rationale, not a fallback for a system that cannot hold a payment.

7. Worked example — the instant payment that cannot be held

Facts: an inbound instant credit transfer triggers a real-time alert with facts pointing at a money-mule pattern. The payment rails settle in seconds; the operations team cannot stop it. The AML officer files the report the same morning.

Applicable rule: §46(1) presumes a transaction still capable of being withheld. Where execution has already happened or cannot be postponed, §46(2) governs: execution is permitted and the report follows immediately. What §46 does not do is convert an unstoppable payment into a compliant one automatically — the firm has to be able to show which limb it relied on.

What the analyst does: records in the case file that execution fell under §46(2) and why, with the alert and report timestamps; separates the outbound leg, which usually can be held, from the inbound leg that could not; and checks that the restriction applied afterwards does not communicate its reason to the customer, because §47 continues to apply.

Outcome: a defensible file. The failure mode is the opposite — treating §46 as inapplicable to instant payments generally, and never documenting the reliance on §46(2).

8. Who files in a BaaS stack

Where a fintech distributes regulated payment services through a partner credit institution, both are frequently obliged entities in their own right, each with its own §43 duty on the facts it holds. The statute does allow the work to move, and the provision that does it is §45(4): an obliged entity may have the §43(1) obligation performed by a third party in accordance with §6(7) — which permits internal safeguards to be performed under contract subject to prior notification to the supervisory authority, allows the authority to prohibit the arrangement where proper performance or the entity’s steering and control would be impaired, and states expressly that responsibility for fulfilling the measures remains with the obliged entity.

ElementStatutory basisCan it be performed by another entity?Who remains answerable
Deciding that facts trigger a report§43(1)No — it attaches to the obliged entity holding the factsThe obliged entity; for German branch activity, its management level under §43(3)
Submitting the report§45(1) and §45(4) with §6(7)Yes, by contract, after prior notification to the supervisorThe obliged entity — §6(7) leaves responsibility with it
Holding the transaction§46(1)Only as an operational capability; the duty is not transferredThe obliged entity that filed
Confidentiality§47NoBoth entities and their staff

The practical consequence is that a partnership contract can allocate the submission and the alert handling, but not the accountability. It also has to be notified. The ICT-contract clauses required under DORA sit in the same agreement, and drafting the two in isolation produces inconsistencies BaFin will read side by side.

9. Confidentiality, the liability shield and the sanction

§47 prohibits disclosing to the customer or to third parties that a report has been filed or that an investigation is under way. It applies to customer-facing tooling as much as to conversations: a status message that explains an unusual hold is a §47 problem.

The protection sits in §48, not in §44 — §44 is the reporting duty of the supervisory authorities. Under §48(1), a person who reports facts under §43 or files a criminal complaint under §158 of the Strafprozessordnung may not be held responsible under civil or criminal law, or pursued in disciplinary proceedings, unless the report was made untruthfully intentionally or with gross negligence. §48(2) extends the shield to an employee who reports internally to a superior or to the unit designated to receive such reports, and to compliance with an FIU information request under §30(3).

Breaches are administrative offences rather than crimes: failure to report under §43(1) and breach of §47 are both listed in §56 GwG. The escalation in §56(3) is the number to plan against — for serious, repeated or systematic breaches, up to EUR 1 million or twice the economic benefit, and for credit and financial institutions up to EUR 5 million or 10 % of total annual turnover. The named Geldwäschebeauftragter under §7 can be addressed personally.

10. Frequently asked questions

Which provision protects a firm that files in good faith?

§48 GwG. It covers reports under §43 and criminal complaints under §158 StPO, internal reports by employees, and responses to FIU information requests under §30(3) — with the exception of reports made untruthfully intentionally or through gross negligence. §44 is a different rule: the reporting duty of supervisory authorities.

Is there a minimum amount below which no report is needed?

No. §43(1) requires the report irrespective of the value of the asset or the size of the transaction. Value can inform how an alert is triaged; it cannot decide whether a report is owed once the facts are there.

Do we have to register with the FIU if we have never filed?

Yes. §45(1) sentence 2 requires electronic registration independently of filing, and §59 sets the outer date at 1 January 2024 for financial-sector obliged entities. Absence of reports is not a defence to absence of registration.

Is tipping-off a criminal offence in Germany?

Breach of the §47 prohibition is listed among the administrative offences in §56 GwG rather than as a GwG crime. The exposure is a fine — with the §56(3) ceilings for serious, repeated or systematic breaches — plus the supervisory consequences.

Can a partner bank file on our behalf?

The submission can be performed by a third party under §45(4) with §6(7), by contract and after prior notification to the supervisory authority, which may prohibit it. Responsibility for the obligation stays with the obliged entity, and the §43(1) assessment stays with whoever holds the facts.

How long must the records be kept?

Five years under §8 GwG, and not longer than ten. Records of investigations that produced no report follow the general AML retention rule running from the end of the relationship.

11. What to do, today

  • Confirm the goAML registration exists — not the ability to register. If it does not, this is the first thing to fix, and it is independent of any case.
  • Remove value floors from the reporting decision. §43(1) has no threshold; keep value in triage, out of the reporting gate.
  • Make the §11(6) disclosure failure a reporting trigger, not a due-diligence exception queue.
  • Implement the §46 clock properly — third business day after the day of dispatch, Saturday excluded — and give operations a documented §46(2) path for payments that cannot be held.
  • Fix the citation in your policy. The liability shield is §48; a manual citing §44 is citing the supervisors’ duty.
  • Notify the supervisor before delegating submission, and record that responsibility remains with the obliged entity under §6(7).
  • Name the management-level owner for German branch activity under §43(3), with a deputy.

Related: AMLA’s harmonised STR format · EMI licence in Germany · FIU-Nederland UTR via goAML · TRACFIN — filing in France · Sanctions screening at instant-payment speed · Germany’s Transparenzregister · The EU AML package — AMLR, AMLD6 and AMLA

Related reads.