- Australia
- Austria
- Bangladesh
- Belgium
- Brazil
- Bulgaria
- Canada
- China
- Croatia
- Cyprus
- Czech Republic
- Egypt
- Estonia
- Eswatini
- Ethiopia
- France
- Germany
- Greece
- Haiti
- Hong Kong
- Hungary
- India
- Iraq
- Ireland
- Indonesia
- Italy
- Japan
- Jordan
- Kazakhstan
- Kenya
- Kosovo
- Kuwait
- Latvia
- Luxembourg
- Malaysia
- Malta
- Mauritius
- Mexico
- Micronesia
- Moldova
- Montenegro
- Morocco
- Mozambique
- Myanmar
- Namibia
- Nauru
- Nepal
- Nigeria
- Nicaragua
- Niue
- Norway
- Netherlands
- New Zealand
- Oman
- Pakistan
- Palau
- Palestine
- Panama
- Papua New Guinea
- Paraguay
- Peru
- Puerto Rico
- Philippines
- Portugal
- Portugal
- Qatar
- Republic of Congo
- Romania
- Russia
- Rwanda
- Samoa
- San Marino
- Senegal
- Serbia
- Seychelles
- Sierra Leone
- Singapore
- Slovakia
- Slovenia
- Somalia
- South Africa
- South Korea
- South Sudan
- Spain
- Sri Lanka
- St Kitts and Nevis
- St Maarten
- St Lucia
- Sweden
- Switzerland `
- Syria
- Taiwan
- Tajikistan
- Tanzania
- Thailand
- Timor Leste
- Togo
- Tonga
- Trinidad and Tobago
- Turkey
- Turks and Caicos
- Turkmenistan
- Tunisia
- Tuvalu
- Uganda
- Ukraine
- UK
- Uruguay
- USA
- Uzbekistan
- Vatican City
- Vietnam
- Venezuela
- Vanuatu
GERMANY KYC, KYB AND AML
Scale Identity Verification and KYC Operations in Germany
Verify German customers and businesses through Germany’s notified eID, NFC, QES, identity documents, biometrics and KYB. Reduce manual review, maintain consistent audit evidence and run one connected workflow designed to support the GwG today and AMLR from 10 July 2027.
Operational Performance for Germany KYC
Our Numbers Speak Volumes
98.5%
First-Pass
Verification Rate
< 10 sec
Median
Verification Time
5+
German ID Methods
Supported
Germany IDV/KYC Challenges
The eID Gap
Every Personalausweis ships with an NFC eID function, but everyday consumer use stays limited, so firms fall back to manual uploads. Manual capture is slower and easier to spoof.
German Names Break Global Matching
Müller and Mueller, ß and ss, hyphenated and married surnames trigger false positives and manual review spikes when diacritics are lost in international databases.
Ownership Is Hard to See Through
GmbH and AG structures hide UBOs behind holding layers and nominees, and AMLR sets the line at 25% ownership, or control. Transparenzregister filings are often incomplete or outdated, which stalls KYB and delays revenue.
Registry Data Is Not Verification
Handelsregister and Unternehmensregister confirm a company exists, not who controls it or whether they are sanctioned. KYB needs screening layered on top of registry lookups.
Regulatory Update
What AMLR Changes for Identity Verification in Germany
The EU Anti-Money Laundering Regulation (EU) 2024/1624 applies directly in Germany from 10 July 2027, with no transposition period. It becomes the due diligence rulebook, with the GwG amended to fit it, and AMLA, the new EU-level supervisor, is established in Frankfurt.
Timeline
- End of 2026 Member State deadline to issue EU Digital Identity Wallets (eIDAS 2.0)
- 10 July 2027 AMLR applies, no transposition
- December 2027 Wallet acceptance by defined relying parties under eIDAS 2.0 Article 5f
- 2028 AMLA direct supervision begins
eIDAS Routes Become Expressly Recognised
Article 22(6) sets out two routes to identity verification. One is an identity document, passport or equivalent supported where relevant by reliable and independent sources. The other is eIDAS electronic identification at assurance level substantial or high, together with relevant qualified trust services. Both routes remain valid. Germany's video identification and QES under Section 12 GwG (§ 12 GwG) stay usable, and firms should document which route they use and why
The Ownership Test Tightens
AMLR harmonises the beneficial-ownership test at 25% or more, or control, so Transparenzregister and KYB checks must cover holdings and control.
Existing Customers Get Re-Checked
AMLR expects existing customer records to be brought up to standard on a risk basis, not just new onboarding. Continuous monitoring keeps back-book files current between reviews.
Accountability Stays With You
Article 18 keeps customer due diligence accountable with the obliged entity even when verification is outsourced, so vendor evidence and clean audit trails matter more under AMLR.
FOR BAFIN-SUPERVISED BUSINESSES
Streamline BaFin-Supervised Onboarding in Germany
Connect identity verification, QES, Penny Drop and compliance evidence in one configurable workflow for businesses operating within BaFin’s supervisory remit. Reduce customer drop-off and manual handovers while giving compliance teams a consistent, review-ready record of every decision.
Verify the Customer
Verify identity using the configured route, such as Germany’s notified eID, NFC document reading or document and biometric checks.
Complete Qualified Signing
Apply and validate the QES within the same journey, keeping the signed document, verification result and supporting evidence together.
Confirm the Payment Account
Use Penny Drop Verification to confirm account ownership and capture the account evidence Section 12(1) no. 3 GwG requires for QES identification.
Shufti’s IDV/KYC Solutions for Germany
KYC Solutions
Onboarding that supports GwG duties for German customers, with age and address checked in the same flow as identity, each check completing in seconds.
Explore MoreFace Verification
Face verification binds the live person to the document with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness, stopping spoofs, masks and deepfakes.
.Age Verification
Selfie-based age estimation combined with document verification where required, supporting operators' youth-protection obligations in sectors such as gaming and e-commerce.
.Bank Account Verification
Confirms a German bank account (DE IBAN) belongs to the customer, returning the registered account holder name for matching against the verified identity.
.Address Verification
Shufti verifies German address-bearing documents, including utility invoices, telecom bills and bank statements from major German issuers. Proof-of-address checks remain common in regulated onboarding.
.Document Verification
Verification of Personalausweis, eAT residence permits and German ePassports, including NFC chip reading and German-language OCR extraction. Remains a permitted route for remote verification under AMLR.
.Identity Verification
Shufti confirms every customer is real and present, not a spoofed or synthetic identity. Biometric face matching and liveness detection run against 10,000+ actively processed document types.
.KYB Solutions
Under the GwG, every business you onboard needs the same scrutiny as the people behind it. Shufti checks registry records, beneficial ownership, and VAT details in real time, then screens UBOs against 4,000+ global watchlists for sanctions and adverse media exposure.
Explore MoreBusiness Verification
Automated validation of Handelsregister data, VAT ID (USt-IdNr.), tax numbers, and managing directors. Reduces manual registry lookups and onboarding delays.
.Enhanced Due Diligence (EDD)
Structured risk profiling for complex ownership chains, cross-border entities, and high-risk sectors, built to support Germany’s risk-based AML obligations under the GwG.
.AML Screening
Shufti screens customers and transactions in 240+ countries and territories, flagging sanctions, PEP, and adverse media matches as they happen. Ongoing monitoring surfaces suspicious activity in time to meet local reporting obligations.
Explore More
AI Compliance Copilot
Helps compliance teams review verification and AML data, investigate alerts, and understand the reasoning behind risk signals. It brings relevant case information together to support faster, more consistent compliance decisions.
.
Transaction Monitoring
Ongoing transaction monitoring calibrated to German financial flows flags anomalies against AML rules, supporting the risk-based controls expected by BaFin and the German FIU.
.Supported Verification Methods for Germany
Every Verification Route Germany Uses, in One Platform
Shufti supports the full range of remote verification routes used in Germany, from the EUDI Wallet and the notified eID to document and biometric checks. Each method below shows what is live today and what is ready for the 2027 rollout.
EUDI Wallet
Wallet-ready · from 2027AMLR Article 22(6) recognises eIDAS electronic identification, including the EUDI Wallet. Germany is developing its wallet under the eIDAS 2.0 rollout. Shufti is built to accept wallet-based verification as the German wallet goes live.
Notified eID
LiveeIDAS HighThe Online-Ausweisfunktion, the eID function of the Personalausweis and the eAT residence permit, is Germany’s notified eID at the highest eIDAS assurance level, used through AusweisApp. Shufti verifies it today, alongside supported commercial and bank eIDs that are not eIDAS-notified.
Docless Database (eIDV)
LiveDatabase-driven verification against permitted German reference data sources confirms identity in seconds for low-risk onboarding, with no document upload needed. Shufti escalates to stronger checks as risk rises.
NFC Chip Verification
LiveShufti reads the secure chip in the Personalausweis, the eAT residence permit and the German ePassport. This is the high-assurance capture route where eID use is still limited.
Document and Face Biometric
LiveA route permitted under AMLR Article 22(6)(a). Document authentication of the Personalausweis, eAT and ePassport, paired with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness to confirm a real, present person.
Video Identification
LiveSection 13 GwG and BaFin Circular 3/2017 set the rules for attended video identification, and that circular stays the binding standard while the GwVideoIdentV ordinance remains in draft (as at August 2026). A guided real-time video session checks the document's security features live, runs a face match and liveness check, and closes with a one-time code.
Qualified Electronic Signature
LiveSection 12(1) no. 3 GwG permits identification by a validated QES plus a transfer from a payment account in the customer’s name. Shufti runs eIDAS-qualified signing through an EU qualified trust service provider, producing PAdES-LTV signatures. For Germany, the signing identity check runs through NFC and face biometrics.
Independent Validation
Shufti's Recognition Across Independent Evaluations

Ranked Exceptional in the Liminal Index 2026 for age estimation
View Report
Differentiated by Gartner on document diversity and country coverage
Read more
Certified at iBeta Level 3 PAD with 0% APCER
Read Blog
Broadest global reach in the 2025 KuppingerCole Extended IDV report
Download Report
Ranked Top 5 in the DHS RIVR 2025 for identity validation
Read Blog
Ranked Exceptional for age verification by Liminal Index 2026
View Report
Recognised as a Leader across four G2 Summer 2026 reports
View ReportEvidence-Ready Checks Across People & Businesses
Verifications with robust evidentiary support
Individual Documents We Verify
Shufti verifies 20+ individual German documents.
View All Supported DocumentsPersonalausweis (German National Identity Card)
Primary identity document under Section 12 GwG for German citizens. Biometric, ICAO-compliant, with an NFC chip and Online-Ausweisfunktion eID for high assurance.
Elektronischer Aufenthaltstitel (eAT – Electronic Residence Permit)
Electronic residence permit for non-EU nationals in Germany. Carries a biometric NFC chip and the eID function for remote, high-assurance identity verification.
Reisepass (German ePassport)
Machine-readable German passport under Section 12 GwG. Biometric and ICAO-compliant, with an NFC chip that supports chip-based checks for cross-border onboarding.
EU/EEA National ID Cards & Passports
National identity cards from EU and EEA states, accepted for German onboarding. Verified against ICAO standards with document, biometric and chip-based checks.
German Driving Licence (Führerschein)
German driving licence, accepted as a supporting document where GwG permits. Verified for authenticity through document checks, though it carries no NFC chip.
Online-Ausweisfunktion (eID Function)
NFC-enabled digital identity verification tied to the Personalausweis, an eIDAS-notified eID. Recognised for identity verification under AMLR Article 22(6)(b).
Entity Identity
Handelsregisterauszug (Commercial Register Extract)
Commercial register extract from the Handelsregister. Confirms a company's legal existence, registered office, legal form and appointed directors for KYB.
Unternehmensregister Profile
Consolidated Unternehmensregister profile pulling a company's official filings, financial disclosures and register entries together in one KYB source.
Gewerbeanmeldung (Trade Registration)
Trade registration required for sole traders and small businesses in Germany. Evidences a lawfully registered commercial activity during KYB onboarding.
Tax Identity
Steuernummer (Tax Number)
Tax number issued by the local Finanzamt. Confirms a person or business is registered for tax and supports KYB and fiscal identity checks for onboarding.
USt-IdNr. (VAT ID)
VAT identification number issued by the Bundeszentralamt für Steuern. Verified for EU VAT reporting and to confirm a business is trading legitimately.
Ownership & Control (UBO)
Transparenzregister Extract
Mandatory beneficial ownership record under the GwG. Shufti checks control data against it, with the AMLR test of 25% or more ownership, or control, for entities.
Gesellschafterliste (Shareholder List)
Shareholder list filed with the commercial register. Shufti uses it to map shareholdings and identify the people behind a German company for UBO checks.
Geschäftsführer/Vorstand Listing
Listing of managing directors and board members as a company's legal representatives. Screened against sanctions, PEP and adverse media lists during KYB.
Languages We Cover
German-language document parsing
Native German-language parsing and matching keep umlauts, ß and compound names intact across the Personalausweis, eAT, Handelsregister and Transparenzregister, so checks stay accurate against official sources.
Name matching logic
Name and address matching handles German formatting, umlauts and compound names, cutting false mismatches when records are checked against official sources.
Cross-document consistency checks
Cross-document consistency checks reconcile names and identifiers across the Personalausweis, eAT, Handelsregister and Transparenzregister to catch mismatches.
Governance & Controls
Audit-Ready Decisions, Lower Operational Drag
Fewer Avoidable Re-submissions
Optimised capture for German ID formats and the NFC-enabled Personalausweis cuts avoidable re-submissions and manual review.
Cleaner Audit Trails
Structured logs aligned to GwG record retention and FIU reporting obligations keep every onboarding decision audit-ready.
Better Name Matching Outcomes
Matching handles umlauts, ß conversion and compound surnames common in Germany, reducing false positives and manual review.
One Workflow, One Back Office
KYC, KYB and AML screening are consolidated in one operational case view, so one back office team works on every customer file.
National ID-First Flow Design
Personalausweis and eAT-first onboarding reflects Germany's national identity ecosystem and the way customers actually verify.
Continuous Compliance
Compliance that does not stop at onboarding
AMLR treats customer due diligence as a continuing obligation. Perpetual monitoring keeps the customer picture current between reviews, so risk is caught when it appears, not at the next annual check.
Surface Changes as it happens
DetectPerpetual monitoring flags risk when it appears, not at the next annual review. Behavioural biometrics, background fraud signals, and ongoing sanctions and PEP screening watch every active relationship.
Step up when the signal fires
VerifyWhen a signal fires, re-verification confirms the person or the ownership change using the same live methods above, so a flag turns into a resolved decision.
Keep the file audit-ready
ComplyEvery check and decision is logged to GwG record-keeping standards, so the file is organised and retrievable for internal audit and supervisory review.
Perpetual KYC
pKYCKeeps individual customer risk current with behavioural biometrics, background fraud signals and ongoing AML screening, so back-book records stay standard-ready.
Perpetual KYB
pKYBMonitors the Transparenzregister and Handelsregister for shareholding and control changes, so a shift past the 25% line or a change of control is caught between reviews.
Built To Fit Germany's Regulatory Landscape
BaFin (Federal Financial Supervisory Authority)
Supervises banks, financial services institutions, crypto custody providers and fintechs. Shufti supports BaFin AML guidance with structured identity evidence, risk classification logs and ongoing monitoring controls.
German Financial Intelligence Unit (FIU)
Receives Suspicious Activity Reports under Section 43 GwG. Decision audit trails, structured risk indicators and escalation logs support STR documentation.
Bundesministerium der Finanzen (BMF)
Oversees the AML framework and GwG implementation. Shufti supports risk-based-approach documentation and mandatory record retention (5 years minimum under GwG).
Transparenzregister (Transparency Register)
Maintains beneficial ownership information. Shufti captures UBO data and screens controlling persons against sanctions and PEP lists. Where your findings diverge from the register, Shufti flags the gap so you can file the Unstimmigkeitsmeldung to Bundesanzeiger Verlag GmbH under Section 23a GwG, and within 14 calendar days under Article 24 AMLR from 10 July 2027.
Handelsregister / Unternehmensregister
Official company registration and disclosure system. KYB workflows verify legal status, directors and shareholder filings against Handelsregister records.
Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
Supervises GDPR enforcement at federal level. Data minimisation, lawful-basis processing and EU-region hosting support compliant handling of German personal data.
Bundesnetzagentur
Supervises qualified trust services (e.g. QTSPs, QES and the trusted list) and regulates telecom and certain digital infrastructure. Shufti’s QES route runs on an EU qualified trust service provider on this trusted-list basis. Identity verification also supports SIM registration and telecom onboarding.
AMLA (EU Anti-Money Laundering Authority)
The new EU-level supervisor has been established in Frankfurt since July 2025. Begins direct supervision of selected high-risk cross-border entities from 2028 and shapes technical standards under AMLR.
Deployment Option
Cloud in EU and Germany regions such as Frankfurt, or on-premise, hosts German customer data in-region and supports GDPR accountability and BaFin expectations.
Regulatory Alignment
Built to support GwG due diligence obligations, UBO verification, and recordkeeping duties, as well as GDPR principles and AMLR requirements applying from 10 July 2027.
Retention Controls
GwG records are kept for five years from the end of the calendar year in which the relationship ends or the data is captured, and are destroyed at the latest after ten years under Section 8(4) GwG. From 10 July 2027, Article 77 AMLR sets five years, extendable by competent authorities case by case.
Encryption & Security
Encryption in transit and at rest, with access controls and audit logging, supports Article 32 GDPR and BDSG duties, backed by ISO 27001 certification and SOC 2 Type II attestation.
Scope of Our Role
Shufti acts as a data processor and provides verification technology, not legal or regulatory advice. Responsibility for customer due diligence and for the choice of verification method remains with the obliged entity, documented in its own risk assessment.
Automated Decisions and Biometric Data
The lawful basis for processing is set by the controller. Biometric data used to uniquely identify a person engages Article 9 GDPR, and human review is available in the workflow.
AI Act Position
Article 50 transparency obligations have applied since 2 August 2026, and Annex III high-risk obligations apply from 2 December 2027 under Regulation (EU) 2026/1744. Shufti documents its classification position for facial biometric matching, liveness detection and age estimation.
Data and Privacy Controls in Germany
Germany AML Sources That Strengthen Decisions
We screen against 215+ sanction regimes, 4,000+ watchlists, 100,000+ adverse-media sources, and 6M+ PEPs across Germany and globally. A few of them are:
BaFin
FIU Deutschland
Deutsche Bundesbank
Bundesministerium der Finanzen (BMF)
Transparenzregister
Handelsregister / Unternehmensregister
Bundeszentralamt für Steuern (BZSt)
Bundeskriminalamt (BKA)
Bundesamt für Wirtschaft und Ausfuhrkontrolle (BAFA)
Generalzolldirektion / German Customs (Zoll)
FATF
EU Consolidated Financial Sanctions List
UN Security Council Consolidated List
European Banking Authority (EBA)
EU AMLA (Anti-Money Laundering Authority)
SEE SHUFTI IN YOUR GERMANY WORKFLOW
Turn German Verification Requirements into a Smoother Customer Journey
Share your customer types, risk rules and current onboarding process. A Shufti specialist will show you how to connect identity verification, KYB, QES, Penny Drop and ongoing monitoring, reducing operational hand-offs while keeping decision evidence organised for compliance review.
Frequently Asked Questions
Which identity documents can be used for German onboarding?
Customers can use the German Personalausweis, including its notified eID and NFC capabilities. Eligible EU and EEA identity cards, passports and residence permits can also be accepted when they meet the applicable GwG requirements. Shufti supports document, eID, NFC and biometric verification within one configurable workflow.
How does Shufti support BaFin-supervised businesses in Germany?
Shufti connects identity verification, KYB, AML screening, QES, account verification and decision evidence in one configurable workflow. This helps businesses within BaFin’s supervisory remit reduce manual hand-offs, standardise compliance records and prepare clearer evidence for internal audit and applicable supervisory review.
What documents are required for KYB in Germany?
Typically a Handelsregister extract, VAT ID (USt-IdNr.), shareholder list and beneficial ownership details from the Transparenzregister. Shufti verifies these in real time and screens the UBOs behind them against sanctions and PEP lists.
How are German name variants handled in screening?
Matching accounts for umlauts, ß and ss equivalence, and hyphenated or married surnames, so variants such as Müller and Mueller resolve correctly and false positives on German names stay low.
How long must AML records be retained?
Under GwG, identification and transaction records are kept for at least five years from the end of the calendar year in which the relationship ends or the data is captured, and are destroyed at the latest after ten years under Section 8(4) GwG. From 10 July 2027, Article 77 AMLR applies: five years, extendable by competent authorities case by case.
Is EU-region data hosting available?
Yes. Shufti offers EU-based cloud regions, including Germany, so German customer data is hosted in-region in line with GDPR and BDSG. On-premise deployment is available where residency requirements are stricter.
What changes for Germany under AMLR from July 2027?
AMLR applies directly, so no German transposition law is needed. It permits two verification routes, document-based and eIDAS-based, so notified eIDs, the EUDI Wallet and qualified trust services sit beside document and biometric checks, and sets the UBO test at 25% or more, or control by other means.
How do QES and account verification work together under Germany’s GwG?
Under Section 12(1) no. 3 GwG, the qualified signature must be validated under Article 32(1) eIDAS, and a transfer must come from a payment account in the customer’s name at a qualifying credit institution. Shufti connects QES, account verification and supporting evidence in one workflow.
When will the EUDI Wallet be usable for onboarding in Germany?
Under eIDAS 2.0, Member States must issue wallets by the end of 2026, and from December 2027 Article 5f requires defined relying parties, including banks, to accept them. Germany is developing its wallet under this rollout. Shufti is built to accept wallet-based verification as the German wallet goes live, so onboarding flows will not need to be rebuilt.
Can we keep using video identification after July 2027?
In principle yes, subject to national rules and AMLA’s pending technical standards. Video identification remains usable where national rules permit it, with a documented justification for the method choice. Shufti supports video identification alongside eIDAS-based routes, so firms can shift the mix over time without changing platforms.
Let’s Build Trust Into Your Business
1B+Verifications Processed
240+Regions Actively Processed
99.7%Accuracy Rate
Samer Al Tamimi
CEO of Safwa Bank
“We take our client’s privacy very seriously and always look for new innovative solutions to ensure a safe banking experience. Working with Shufti feels like a breath of fresh air, as their 100% in-house tech keeps our customer’s data free from vulnerabilities and fully safe and protected.”
Trusted. Compliant. Certified
Explore Shufti For Your Business
Get a personalised demo from our experts.
PROVEN PLAYBOOKS
Explore Practical KYC & AML Resources
10 July, 2026
Identity Verification in Europe: eIDAS 2.0 & EUDI Wallet
A practitioner's guide to verifying identity in Europe, covering eIDAS 2.0, the EUDI Wallet, docless eIDV and how to choose an eID provider for onboarding in the EU.
Product Guide





