For obliged entities under the German Anti-Money Laundering Act (GwG), the reliability screening of employees is not a voluntary add-on but a statutorily defined internal safeguard: § 6 (2) no. 5 GwG requires “the verification of the reliability of employees through appropriate measures”. What reliability means is defined by the statute itself — in § 1 (20) GwG. Banks and insurers must carry out the screening at hiring and on an ongoing basis, and must be able to document its implementation.
The Legal Basis: Employee Screening as an Internal Safeguard
§ 6 GwG obliges all entities within the meaning of the Act — including credit institutions under § 2 (1) no. 1 GwG — to implement appropriate internal safeguards. Within § 6 (2) no. 5 GwG, employee screening ranks equally alongside better-known duties such as training or the appointment of an anti-money-laundering officer. In practice, it is nonetheless frequently neglected: while customer due diligence (KYC) is conducted with considerable effort, the employee side is often limited to a criminal-record certificate at hiring. Why this falls short is explained in the article KYC vs. Know Your Employee.
What “Reliability” Means Under § 1 (20) GwG
Many obliged entities are unaware that the GwG contains its own statutory definition. Under § 1 (20) GwG, a person is reliable if they offer assurance that they
- carefully observe the anti-money-laundering obligations and the company’s internal principles,
- report facts relating to money laundering or terrorist financing to their superior or the anti-money-laundering officer, and
- do not themselves participate, actively or passively, in questionable transactions or dealings.
The screening therefore does not target criminal convictions alone, but a prognosis: does the person offer assurance that they will carry their share of the prevention duties — or are there indications to the contrary? A clean criminal-record certificate answers this question only in small part.
When Screening Is Required: Hiring and Ongoing Operations
The provision does not distinguish between new hires and existing staff. Essentially, two screening triggers are recognised:
- At hiring: before the person takes up their duties, with a screening depth calibrated to the risk of the position — anyone who can approve transactions or circumvent controls must be screened more intensively than a role with no contact with monetary flows.
- Ongoing: reliability is not a one-time determination. Event-driven screenings (for instance upon role changes or concrete indications) and appropriate repeat cycles are part of a complete implementation. On distinguishing the models, see One-Time Screening or Continuous Monitoring.
Typical Implementation Gaps
In practice, we encounter recurring weaknesses that surface during a review by internal audit or the supervisory authority:
- The screening exists only on paper — a clause in the onboarding process without a defined screening scope.
- There is no risk-based tiering: all positions are screened identically (or identically little).
- Existing employees and internal movers into sensitive functions are not covered.
- Results are not documented — in case of doubt, there is no way to prove that any screening took place at all.
- External staff with comparable access fall through the net entirely.
The last point weighs particularly heavily, because data protection law demands a structured approach here; details for the application context are covered in the article Pre-Employment Screening in Banks.
Recommended Course of Action: How to Set Up the Screening
A robust concept can be built in four steps. First: classify positions on a risk basis — which roles could undermine money-laundering prevention? Second: define screening depth and cycle per risk class, from a basic check to in-depth research across multiple categories (registers, sanctions lists, adverse media). Third: define responsibilities and escalation paths — operational implementation usually sits with the anti-money-laundering officer, see The AML Officer’s Duty Specification. Fourth: document each screening so that internal audit and the supervisory authority can trace trigger, scope, sources and result.
For practical implementation, Indicium delivers reviewable software reports with dated sources and human final review (Art. 22 GDPR) — from €79 per report. We are happy to show you what this looks like in your industry in a demo.
This article provides general information and does not constitute legal advice.