IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

With the Indicium report, you receive a documented, dated review basis per employee that you can present to internal audit and the supervisor unchanged.

The AML Officer: Setting Up Employee Screening Operationally

How the anti-money laundering officer sets up employee screening under § 6 (2) no. 5 GwG: risk classes, review cycles and audit-proof documentation.

The anti-money laundering officer is responsible under § 7 (1) sentence 1 GwG (the German Anti-Money Laundering Act) for compliance with anti-money laundering rules — and thereby also for the internal safeguards, among which § 6 (2) no. 5 GwG explicitly counts the reliability check of employees. The officer can rarely carry out the screening operationally in person; they remain accountable for it nonetheless. What they need is not case-by-case activism but a documented process: risk-based position classification, defined review depth per risk class, a fixed cycle, a clear escalation path and documentation that withstands a BaFin special audit.

Why Employee Screening Lands on the AML Officer’s Desk

The reliability of employees is legally defined in § 1 (20) GwG — it is therefore not a soft HR criterion but a statutory review standard. For institutions, § 25h (1) KWG (the German Banking Act) adds a requirement for internal safeguards against criminal acts to the detriment of the institution. In practice, this means: HR conducts interviews and collects documents, but the questions of whether screening is done systematically, how deep and how often belong in the AML officer’s remit. Anyone who leaves them unanswered has no response at the next audit to the supervisor’s most obvious question: “Show us your concept.”

The Process Blueprint in Five Steps

A sound employee screening programme can be set up along five building blocks:

  • 1. Risk-based position classification: classify all functions in the organisation by money laundering and abuse risk — payments, client onboarding, compliance functions and IT administration naturally rank higher than roles without client or system access.
  • 2. Review depth per risk class: assign each class a fixed catalogue of review categories — from identity and CV verification through register and sanctions-list screening to adverse media research for exposed positions.
  • 3. Define the cycle: the check is not a mere hiring formality. Alongside onboarding, the concept must include event-driven checks (role changes, red flags) and a recurring cycle for high-risk functions.
  • 4. Set the escalation path: who assesses a hit, who decides on consequences, when is management involved? Without a defined path, every finding remains an ad hoc risk.
  • 5. Documentation: file every check with date, sources, result and assessment — such that a third party can retrace the decision years later.

Audit-Proof Means: Traceable for Third Parties

Internal audit and the supervisor are not interested in whether checks were done, but in whether they can be evidenced. Audit-proof documentation answers three questions: what was checked, when, and in which sources? What was the result? Who assessed it, and on what grounds? The same documentation also protects the AML officer personally: anyone who can prove that the concept existed and was applied has a robust answer, if it comes to it, to the question of their own fulfilment of duties. Screenshots in an HR folder rarely meet this standard; a standardised report format with dated source references meets it structurally. Indicium provides audit-proof reports with dated sources and final human review (Art. 22 GDPR) — from €79 per report, details in the software report.

Typical Gaps in Existing Processes

Recurring weaknesses from a special-audit perspective: the check exists only as a copy of the certificate of conduct at onboarding; existing employees in critical functions have never been re-screened; external staff fall through the cracks entirely; and the risk analysis mentions employee risks without any review process following from it. None of these gaps is bad faith — they arise because responsibility between HR and compliance was never clarified. That is exactly why the screening concept belongs, in writing, in the AML officer’s responsibility, with HR as the operational partner. Why the workforce deserves the same systematic scrutiny as clients is argued in KYC vs. Know Your Employee; the legal foundations are covered in depth in the overview of the reliability check under § 6 (2) no. 5 GwG.

Do not start with the tool, start with the classification: first classify all positions by risk, define review scope and cycle per class, and set the escalation path down in writing. Only then does the implementation question arise — we have compiled the requirements a screening tool should meet in the requirements catalogue for screening software. If you would like to walk through the process once: book a demo.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report