Anti-Money Laundering
19 Aug 2026

Proving GwG training: what the supervisory authority wants to see

Bridgly Editorial Team
Reading time:
7
minutes
Open binder with training documentation, next to it a laptop with an attendance overview
Table of contents

The obligation is set out in Section 6 (2) no. 6 GwG — and names no interval

The training obligation is part of the internal safeguards. Section 6 (2) no. 6 of the German Money Laundering Act (GwG) requires the initial and ongoing training of employees on typologies and current methods of money laundering and terrorist financing and on the relevant regulations and obligations, including the data protection provisions.

Two things are expressly not stated there. First, no interval: the law says ongoing, not annually. Nor does the Interpretation and Application Guidance of the federal states in the version of June 18, 2025 set an interval — older state versions still did, which is why it is worth checking the version status. An annual rhythm is good practice but not a legal obligation — anyone who presents it as such is misquoting the law. Second, no formal requirement for the proof. How often GwG training must take place and how the rhythm is derived in practice is broken down in GwG training: obligation and frequency under Section 6 GwG.

Section 8 GwG is the wrong reference

Section 8 GwG does not cover training documents. In practice, the five-year period of subsection 4 is nevertheless regularly applied to training documents. That does not hold up. Section 8 GwG is linked exclusively to the fulfillment of due diligence obligations: information on contracting parties and beneficial owners, on the business relationship and on transactions, the risk assessment in the individual case, evidence submitted under Section 16a (2) GwG, the investigation of conspicuous matters, the considerations regarding the reporting decision, and decisions on terminating cross-border correspondent relationships. Instruction, training, or internal safeguards do not appear in any of these items. The period of subsection 4, for its part, refers to the records and supporting documents under subsections 1 to 3.

This is not hair-splitting but has a practical consequence: anyone who bases their proof process solely on Section 8 GwG has not named any reliable basis for the training at all — and will be asked in the audit what they are relying on.

Where the obligation to provide proof actually comes from

The obligation to provide proof follows from Section 6 (1) GwG in conjunction with Section 52 (1) GwG, i.e. from the interaction of two provisions. Section 6 (1) GwG requires obliged entities to have appropriate internal safeguards, whose functionality they must monitor and which they must update as needed. Appropriateness and functionality can be neither monitored nor proven without records.

The second provision is the operational one: Section 52 (1) GwG requires obliged entities to provide the supervisory authority with information on business matters and to submit documents free of charge on request — as originals, copies, or in digital form. Added to this are the right of entry and inspection under the following subsections and the general supervisory power under Section 51 GwG, which allows the authority to issue suitable and necessary orders; the frequency of audits is based on the risk profile of the obliged entity.

The standard for proof of training is therefore not a retention period but the ability to produce it. The question is not How long do I have to keep this?, but Can I show it when the supervisory authority asks for it?

What belongs in the proof

The Interpretation Guidance of the Federal Chamber of Tax Advisers sums up the requirement in one line: document whom one trained when, how, and with what content. Translated into proof that holds up in an audit:

  • Person — name and function of the person trained, not just a department. The Interpretation Guidance of the federal states focuses on the relevant employees; who counts as relevant should be derivable from the risk analysis.
  • Timing — date; for an initial induction, also the reference to the date of joining, so that the initial training demonstrably took place before the first customer contact.
  • Content — not the course title, but the topics covered with version status. This is exactly where viable proof differs from an attendance list.
  • Form and scope — classroom, e-learning, or a combination, duration, trainer or provider. Which format makes sense when is compared in e-learning versus classroom training for GwG training.
  • Assessment — whether and how it was checked that the content got through, and with what result.
  • Confirmation — acknowledgment by the person trained, signed or as a logged electronic confirmation.
  • Responsibility — the assignment to the AML officer, to whom the Interpretation Guidance of the federal states assigns the training concept.

The formal requirements for proof apply similarly across areas of law; the generic standard, including questions of burden of proof, is described in Proving mandatory training. This article is limited to where the GwG deviates from it.

Who counts as a relevant employee

The law simply speaks of employees. In the section on the duties of the AML officer, the Interpretation Guidance of the federal states focuses on relevant employees and assigns the AML officer responsibility for a training concept. BaFin phrases it more broadly for its area of supervision and, in principle, focuses on all employees — anyone who is supervised should therefore consult the guidance applicable to them instead of relying on the narrower wording. This shifts the actual work forward: before the first proof is created, it must be justified who belongs in the group.

The risk analysis provides this justification. Section 5 GwG requires obliged entities to identify, assess, document, and regularly review the risks relevant to them and to submit them to the supervisory authority on request in the current version. Anyone who derives from this analysis which functions touch on customer contact, payment transactions, or contract initiation has an argument for delimiting the training group that will outlast an audit.

A three-tier delimitation has proven itself in practice. First, the functions with direct customer contact and decision-making authority over establishing business relationships — they need the full training. Second, functions that are only indirectly affected, for example in accounting or contract management; for them, a reduced scope is as a rule sufficient, but it also needs to be documented. Third, senior management, which rarely carries out operational checks but is responsible for the appropriateness of the safeguards.

The most common mistake is not training too few people but not justifying the group at all. A list of participants without any recognizable selection logic does not answer the supervisory authority's question as to why exactly these people were trained and others were not.

How long to retain if Section 8 GwG does not apply?

Because the five-year period is not directly applicable, there is no statutory period for proof of training. In practice, no one who follows the five years will be worse off: they correspond to the period the supervisory authority finds in the rest of the audit material and cover the usual audit cycle. The only important thing is that these five years appear in your own documentation as a deliberate determination — as a derivation, not as a quotation of a provision that regulates something else.

Content status has been a separate audit point since March 2026

Since March 1, 2026, the GwG-Meldeverordnung has applied, promulgated on September 1, 2025 as BGBl. 2025 I no. 200. It reorganizes the form and mandatory information of reports under Section 43 (1) and Section 44 GwG: transmission exclusively electronically via the reporting system of the Financial Intelligence Unit (FIU), additional mandatory fields, machine-readable attachments, format validation before sending.

For proof of training, this means two things. First, a training status from before March 2026 is outdated in terms of content on the topic of suspicious activity reporting — exactly the case for which Section 6 (2) no. 6 GwG provides for ongoing training. Second, the version status in the proof thereby becomes a reliable argument: anyone who has documented that the new reporting channel via the FIU's goAML portal was trained from March 2026 can show this. Anyone who has only noted basic GwG training cannot.

How much pressure there is on the reporting process is shown by the annual report of the Financial Intelligence Unit: for the 2025 reporting year, it shows 374,693 suspicious activity reports, around 41 percent more than in the previous year (published on July 21, 2026). Which circumstances trigger a report in the first place is compiled under red flags in everyday business; the conceptual basics of customer due diligence are covered in What does KYC mean?.

What the proof cannot achieve

Proof of training shows that training took place — not that the internal safeguard as a whole is appropriate. Section 6 (1) GwG focuses on the risk situation of the individual obliged entity. A complete attendance list for content that does not match your own risk analysis is a well-documented deficiency. The proof must therefore be linked to the risk analysis under Section 5 GwG, which in any case has to be documented, regularly reviewed, and submitted to the supervisory authority on request.

Nor does it prove effectiveness. Whether the people trained recognize a conspicuous constellation when it matters shows up elsewhere — in the number and quality of internal reports, in the processing time, and in whether questions are asked at all. These signals do not belong in the proof of training, but they do belong in the monitoring of functionality under Section 6 (1) sentence 3 GwG. Anyone who keeps the two cleanly separate has two reliable answers in the audit interview instead of one.

FAQ

Do GwG training records have to be kept for five years?

Not on the basis of Section 8 GwG. Its catalog covers records on due diligence obligations, transactions, and the assessment of suspicions, not the training under Section 6 (2) no. 6 GwG. Five years is a sensible orientation based on the rest of the audit material, but it is the obliged entity's own determination and not a statutory period.

How often must GwG training take place?

The law requires initial and ongoing training but does not name an interval. The Interpretation and Application Guidance of the federal states does not set an interval either. The rhythm follows from your own risk analysis and from changes in the legal situation — the GwG-Meldeverordnung from March 2026 is one such occasion.

Who has to be trained?

The law speaks of employees. The Interpretation Guidance of the federal states focuses on the relevant employees and assigns the training concept to the AML officer. Who counts as relevant should be justifiable on the basis of the risk analysis under Section 5 GwG, not on the organizational chart alone.

What happens if proof is missing?

The supervisory authority can demand the submission of documents under Section 52 (1) GwG and issue orders under Section 51 GwG. Missing proof is ultimately treated as a deficiency in the internal safeguards under Section 6 (1) GwG. Which legal consequences follow from this in the individual case depends on the facts and is not a question that can be answered across the board.

Is a digital confirmation in the learning system sufficient?

The GwG does not prescribe any form for proof of training. What is decisive is the ability to produce it under Section 52 (1) GwG: the proof must be presentable on request and show the person, timing, content, and confirmation. A logged electronic confirmation meets this if it is assigned in an unalterable way and can be exported.

Sources

All sources accessed on 6 Aug 2026 unless otherwise stated in the entry. For provisions on gesetze-im-internet.de, the legal status as of 6 Aug 2026 applies; retrieval there was not technically possible.

More blog posts

Insights into the future of digital learning, with a focus on AI, compliance, and modern training solutions. Discover the latest posts and articles to gain practical insights into legally compliant, efficient, and automated corporate training.

Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.