IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

With the Indicium report, you transfer the documented rigour of your customer due diligence to your own workforce — audit-proof and with dated sources.

Know Your Employee: The Blind Spot in Anti-Money-Laundering

KYC is standard, Know Your Employee often is not: why employee vetting under § 6(2) no. 5 GwG ranks equally and how to implement it.

Know Your Employee (KYE) denotes the systematic vetting of your own employees according to the same core principles that have long been standard in customer due diligence (Know Your Customer, KYC): risk-based, event-driven and documented. Legally, KYE is not optional for entities obliged under the GwG (German Anti-Money-Laundering Act): § 6(2) no. 5 GwG anchors it as an internal safeguard ranking equally alongside the customer-facing duties. In practice, a gap nonetheless persists: while considerable investment flows into KYC processes, employee vetting in many organisations is reduced to a Führungszeugnis (German police clearance certificate) at hiring.

KYC and KYE: same logic, unequal implementation

Customer due diligence follows an established methodology: identification, risk classification, enhanced review where risk is elevated, ongoing monitoring, complete documentation. For the workforce, the law prescribes the same idea — § 6(2) no. 5 GwG requires verifying the reliability of employees through suitable measures, and § 1(20) GwG defines what reliability means: the assurance that the person observes anti-money-laundering duties, reports suspicions and does not personally participate in dubious transactions. The details of this duty are covered in our article on the reliability check under § 6 GwG.

For credit institutions, § 25h(1) KWG (German Banking Act) adds a further layer: institutions must maintain adequate internal safeguards that also prevent criminal acts to the detriment of the institution. Personnel-related precautions are a self-evident part of this safeguard system — because safeguard systems are operated by people.

Why the blind spot can become expensive

Internal offenders differ structurally from external ones: they know the controls that outsiders would first have to overcome, and they act with legitimate access rights. A KYC process that scrutinises every customer helps little if the person operating it was never vetted beyond a basic document. In more detail: Insider risk in banks.

The Führungszeugnis customarily relied on in practice changes little: it is a register extract with limited content — it reveals neither falsified CV entries nor economic entanglements, neither foreign matters nor current media coverage. As the sole “suitable measure” within the meaning of § 6(2) no. 5 GwG, it therefore regularly falls short of the breadth of the statutory definition in § 1(20) GwG, particularly for positions with elevated risk.

Add to this the evidentiary dimension: what counts vis-à-vis internal audit and the supervisory authority is not the assertion that you vet your employees, but the documentation of who was vetted when, to what extent and with what result. Precisely this documentation discipline is taken for granted on the KYC side — and is often entirely absent on the employee side.

The KYC methodology mirrored onto the workforce

Anyone setting up KYE in earnest can transfer the familiar KYC logic almost one to one:

  • Risk classification: rate positions instead of customers — payments, trading, IT administration and management functions carry a different risk than roles without access to money flows or customer data.
  • Tiered screening depth: baseline check for the broad base, enhanced research across several categories (register data, sanctions lists, adverse media, conflicts of interest) for sensitive functions.
  • Event-driven checks: not only at hiring, but also on moves into risk-relevant roles and upon concrete indications.
  • Ongoing component: reliability is a snapshot; appropriate repetition cycles close the gap between two checks.
  • Documentation: record every result in audit-proof form — with sources and date, not as an informal note.

Begin with an honest stocktake: compare the documented effort of your customer due diligence with that of your employee vetting. If the answer is markedly asymmetrical, first prioritise the positions with the greatest damage potential and define screening scope, cycle and documentation format there. Use the structures that already exist: the risk analysis underlying your customer classification can be extended by a position dimension with manageable effort, and the documentation standards of the KYC domain already provide the format for the employee side. A category-based software report with dated sources and human final review (Art. 22 GDPR) maps this process in audit-proof form; details on sector-specific implementation are available under Industries, key terms in the Glossary.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report