ZahlPrüfbV — the German payment institution audit report
The ZahlPrüfbV decides what BaFin and the Bundesbank read about a German payment or e-money institution every year, and it is written for the auditor, not the institution. The Zahlungsinstituts-Prüfungsberichtsverordnung of 15 October 2009 sets the subject, timing and content of the long-form audit report (Prüfungsbericht) that accompanies the annual accounts of every institution under the ZAG. Its sections turn into a checklist of what the auditor will ask for: safeguarding, outsourcing, agents, IT, AML, SEPA, instant payments, verification of payee and the Payment Accounts Act. This guide walks through the structure, the annexes, the AML audit cycle, and three situations where institutions lose findings they could have avoided.
1. Legal basis and scope
The ordinance implements the audit provisions of the Zahlungsdiensteaufsichtsgesetz (ZAG). Under § 22 ZAG an institution prepares its annual accounts within the first three months of the financial year and submits the prepared, and later the adopted, accounts and management report to BaFin and the Deutsche Bundesbank without delay. The auditor then files the Prüfungsbericht with both authorities as soon as the audit ends. § 24 ZAG sets the auditor’s special duties: examine the institution’s economic situation, whether it met its notification duties, its compliance with the Geldwäschegesetz and Regulation (EU) 2023/1113, and a long list of ZAG and EU obligations including Regulations (EU) 2021/1230, 260/2012, 2015/751 and 2022/2554. The auditor must also tell BaFin and the Bundesbank without delay about facts that could lead to a qualified opinion, endanger the institution, or amount to serious breaches. BaFin can set audit priorities (Prüfungsschwerpunkte) of its own.
§ 1 ZahlPrüfbV applies the ordinance to institutions within the meaning of § 1(3) ZAG, which covers payment institutions and e-money institutions. An institution that is also a credit institution under the KWG applies the ZahlPrüfbV only where it goes beyond the PrüfbV for banks, and receives one combined report. The current text was last amended by Article 10 of the Gesetz für dringliche Änderungen im Finanzmarkt- und Steuerbereich of 28 February 2025 (BGBl. 2025 I Nr. 69), which updated §§ 16a and 16b.
2. What the report must contain
| Part | Sections | What the auditor reports and assesses |
|---|---|---|
| General rules | §§ 1–7 | Risk-based scope, reporting period (normally the financial year), how prior findings were remediated, a summary conclusion, signature with place and date |
| The institution | §§ 8–9 | Use of the licence or registration, changes in legal form, owners, management, services, IT, organisation chart, outsourcing (Anlage 1), agents and e-money agents, branches |
| Supervisory requirements | §§ 10–16d | Proper business organisation, IT systems, own funds and solvency, PII cover for PIS and AIS providers, notifications, AML, and compliance with Regulations 2021/1230, 260/2012, 2015/751 and the Zahlungskontengesetz |
| Payment services and e-money | § 17 | Accounts used for settlement, payment-system participation, safeguarding under §§ 17 and 18 ZAG, funding and term of any credit |
| Accounts-based reporting | §§ 18–22 | Business development, assets, earnings, risk position, explanations of the accounts |
| Data overview | § 23 | Anlagen 1–3 filled in with current and prior-year figures |
The summary conclusion in § 6 matters most, because it is what supervisors read first. It must allow an overall judgement on the economic position, the business organisation and risk management, and compliance with the other supervisory requirements, in particular the safeguarding requirements and the liability cover for payment initiation and account information services. It must also state whether the AML rules and notification rules were observed.
3. The three annexes
Anlage 1 is the data overview for institutions that have outsourced activities. § 8(3) requires the auditor to report separately on outsourcing of material activities and processes, judge whether the institution’s classification of each outsourcing as material or not is traceable, and use the Anlage 1 form.
Anlage 2 is the AML Erfassungsbogen. Under § 16(9) the auditor enters the main AML results and grades each item using the classification the form prescribes; obligations that are not relevant to the business are marked F 5. The form is part of the report and must be complete.
Anlage 3 is the data overview for payment and e-money institutions: headcount, reserves, liquidity and funding concentrations, interest and fee income, administrative costs and similar figures, each with the prior year alongside.
4. The AML audit and its own cycle
§ 15 gives the AML audit a separate rhythm. It takes place once a year, the auditor fixes the start date and period, the period runs from the last audit’s cut-off date to the next, and the audit must start no later than 15 months after the beginning of its period. Payment institutions whose payment volume did not exceed EUR 36 million in the previous financial year are audited on AML only every two years, starting with the first full year of payment services, unless their risk position calls for a shorter cycle. The relief is written for Zahlungsinstitute; e-money institutions are not named in it.
§ 16 sets the content. The auditor describes the institution’s AML arrangements across every relevant item in Anlage 2, assesses their adequacy, and, for the transfer-of-funds rules, their effectiveness. For group parents the auditor also assesses the group-wide risk analysis and measures under § 9 GwG. The auditor must check that the institution’s risk analysis under § 5 GwG matches its actual risk, account for all internal-audit work in the period, and report any BaFin orders and whether they were followed.
Two points are specific to payment firms. For the § 24c KWG account-retrieval system, the auditor checks that identification data are captured correctly and mapped to the right account. For e-money due diligence under § 25i KWG, the assessment is made separately for each e-money product. § 16(8) also requires figures in Anlage 2 from the risk analysis: high-risk products, total customers with low-risk and high-risk shares, the number of PEPs, correspondent relationships split by EEA, third country and high-risk country, branches and subsidiaries by location, and the number of agents and e-money agents in Germany and elsewhere in the EEA.
One drafting point: §§ 15(4) and 16(2) still refer to Regulation (EU) 2015/847, while § 24(1) ZAG now refers to its replacement, Regulation (EU) 2023/1113. Expect the auditor to test the current regulation.
5. Payments regulation: §§ 16a to 16d
These sections are where the 2025 amendment landed. § 16b asks the auditor to assess compliance with Regulation (EU) No 260/2012 as amended by Regulation (EU) 2024/886: reachability for credit transfers and direct debits, the technical requirements, sending and receiving instant credit transfers under Article 5a, the charges rule in Article 5b, verification of payee under Article 5c, and direct-debit interchange fees. § 16a covers cross-border payment charges under Regulation (EU) 2021/1230, § 16c card interchange under Regulation (EU) 2015/751, and § 16d the Zahlungskontengesetz: information duties, account-switching assistance, cross-border account opening and internal organisation. Each section also asks what the institution did to comply, and whether it outsourced those arrangements.
6. Worked example: safeguarding in a fast-growing EMI
Facts: A German EMI doubles its customer balances in a year. It safeguards through segregated accounts at a credit institution (method 1), but reconciliation runs weekly and its end-of-day cut-off differs from the account bank’s.
What the auditor applies: § 17(2) requires the auditor to describe the safeguarding under §§ 17 and 18 ZAG, assess its effectiveness, and explain the method used. § 6 then carries the conclusion into the summary.
What the practitioner does: The head of finance moves to daily reconciliation months before year-end, documents the cut-off logic, and keeps a file of reconciliations and breaks with their resolution. The safeguarding comparison helps if the group safeguards differently in other markets.
Outcome: The auditor can assess effectiveness on evidence instead of recording a weakness that appears on page one.
7. Worked example: agents that do not match the notifications
Facts: A payment institution uses 60 agents in Germany and another EEA state. Its agent register in the CRM shows 64 active agents; BaFin’s notifications show 58.
What the auditor applies: § 8(4) requires the auditor to report on how agents and e-money agents are integrated into risk management, whether the notifications agree with the institution’s own records, and how the institution ensures agents’ fitness and reliability. § 14 requires an assessment of the notification process, and § 16(8) puts agent numbers in Anlage 2.
What the practitioner does: Compliance reconciles the CRM with the notifications before the audit, files the missing notifications or deactivates agents that should not be active, and keeps the fit-and-proper files current. The agent register rules set out what must be notified.
Outcome: A notification finding avoided, and one consistent agent count across §§ 8, 14 and Anlage 2.
8. Worked example: the small PI and the two-year AML cycle
Facts: A payment institution processed EUR 28 million in its previous financial year and assumes its AML audit can wait another year.
What the auditor applies: § 15(4) allows a two-year AML cycle for payment institutions under EUR 36 million, but only if their risk position does not require a shorter one. The institution recently added cross-border payouts to higher-risk corridors.
What the practitioner does: The MLRO updates the § 5 GwG risk analysis to reflect the new corridors and discusses the cycle with the auditor early. If the risk analysis shows higher risk, the institution plans for an annual audit instead of discovering the point in the report.
Outcome: The audit cycle follows the risk, which is what § 15(4) requires.
FAQ
What is the ZahlPrüfbV?
The Zahlungsinstituts-Prüfungsberichtsverordnung of 15 October 2009, which governs the audit of payment and e-money institutions’ annual accounts under the ZAG and the content of the auditor’s report.
Who submits the audit report?
The auditor submits the Prüfungsbericht to BaFin and the Deutsche Bundesbank as soon as the audit ends, under § 22 ZAG.
Does it apply to e-money institutions?
Yes. It applies to all institutions under § 1(3) ZAG, and § 16(5) adds a per-product AML assessment for e-money.
What is Anlage 2?
The AML Erfassungsbogen: the auditor records and grades the main AML findings on it, marking non-relevant items F 5. It is part of the report.
How often is AML audited?
Annually, starting within 15 months of the start of the period. Payment institutions under EUR 36 million in payment volume may be audited every two years unless their risk requires more often.
Are instant payments and verification of payee in scope?
Yes. Since the 2025 amendment, § 16b covers Articles 5a and 5c of Regulation (EU) No 260/2012 as amended by Regulation (EU) 2024/886.
What to do, today
- CFO: run daily safeguarding reconciliations and keep the break log audit-ready.
- MLRO: pre-fill Anlage 2 figures from the § 5 GwG risk analysis, and check each e-money product separately.
- Compliance: reconcile agents and outsourcing registers with BaFin notifications before fieldwork.
- Payments operations: document instant-payment and verification-of-payee compliance for § 16b.
Related: The German reporting calendar · ZAIT and DORA for German payment institutions · BaFin’s MVP portal


