For obliged entities under the German Anti-Money Laundering Act (GwG), the reliability screening of employees is not a voluntary add-on but a statutorily defined internal safeguard: § 6 (2) no. 5 GwG requires “the verification of the reliability of employees through appropriate measures”. What reliability means is defined by the statute itself — in § 1 (20) GwG. Banks and insurers must carry out the screening at hiring and on an ongoing basis, and must be able to document its implementation.
The Legal Basis: Employee Screening as an Internal Safeguard
§ 6 GwG obliges all entities within the meaning of the Act — including credit institutions under § 2 (1) no. 1 GwG — to implement appropriate internal safeguards. Within § 6 (2) no. 5 GwG, employee screening ranks equally alongside better-known duties such as training or the appointment of an anti-money-laundering officer. In practice, it is nonetheless frequently neglected: while customer due diligence (KYC) is conducted with considerable effort, the employee side is often limited to a criminal-record certificate at hiring. Why this falls short is explained in the article KYC vs. Know Your Employee.
What “Reliability” Means Under § 1 (20) GwG
Many obliged entities are unaware that the GwG contains its own statutory definition. Under § 1 (20) GwG, a person is reliable if they offer assurance that they
- carefully observe the anti-money-laundering obligations and the company’s internal principles,
- report facts relating to money laundering or terrorist financing to their superior or the anti-money-laundering officer, and
- do not themselves participate, actively or passively, in questionable transactions or dealings.
The screening therefore does not target criminal convictions alone, but a prognosis: does the person offer assurance that they will carry their share of the prevention duties — or are there indications to the contrary? A clean criminal-record certificate answers this question only in small part.
When Screening Is Required: Hiring and Ongoing Operations
The provision does not distinguish between new hires and existing staff. Essentially, two screening triggers are recognised:
- At hiring: before the person takes up their duties, with a screening depth calibrated to the risk of the position — anyone who can approve transactions or circumvent controls must be screened more intensively than a role with no contact with monetary flows.
- Ongoing: reliability is not a one-time determination. Event-driven screenings (for instance upon role changes or concrete indications) and appropriate repeat cycles are part of a complete implementation. On distinguishing the models, see One-Time Screening or Continuous Monitoring.
Typical Implementation Gaps
In practice, we encounter recurring weaknesses that surface during a review by internal audit or the supervisory authority:
- The screening exists only on paper — a clause in the onboarding process without a defined screening scope.
- There is no risk-based tiering: all positions are screened identically (or identically little).
- Existing employees and internal movers into sensitive functions are not covered.
- Results are not documented — in case of doubt, there is no way to prove that any screening took place at all.
- External staff with comparable access fall through the net entirely.
The last point weighs particularly heavily, because data protection law demands a structured approach here; details for the application context are covered in the article Pre-Employment Screening in Banks.
Recommended Course of Action: How to Set Up the Screening
A robust concept can be built in four steps. First: classify positions on a risk basis — which roles could undermine money-laundering prevention? Second: define screening depth and cycle per risk class, from a basic check to in-depth research across multiple categories (registers, sanctions lists, adverse media). Third: define responsibilities and escalation paths — operational implementation usually sits with the anti-money-laundering officer, see The AML Officer’s Duty Specification. Fourth: document each screening so that internal audit and the supervisory authority can trace trigger, scope, sources and result.
For practical implementation, Indicium delivers audit-proof software reports with dated sources and human final review (Art. 22 GDPR) — from €79 per report. We are happy to show you what this looks like in your industry in a demo.
This article provides general information and does not constitute legal advice.