- Aug 26, 2026
- 14 min read
BaFin Compliance Guide: AML & KYC Requirements in Germany 2026
What BaFin requires on AML and KYC in Germany, what it fines firms for, and how the EU AMLR changes the rulebook in July 2027.

Germany runs a €4.53 trillioneconomy with a financial sector stacked on top of it. Eurostat puts total consolidated financial sector liabilities at 450.2% of GDP as of December 2025. Banks, payment firms, and crypto asset service providers (CASPs) keep arriving to do business in the country.
The regulator attached to that market bites. German AML rules sit with the Federal Financial Supervisory Authority, the Bundesanstalt für Finanzdienstleistungsaufsicht, known as BaFin. Financial institutions and CASPs both fall under its AML regulations, and non-compliance gets expensive fast.
In January 2026, BaFin fined VR-Bank Bad Salzungen Schmalkalden eG €325,000 (approx. $380,000) for anti-money laundering failings.
BaFin will not be the only authority in the picture for much longer. The EU Anti-Money Laundering Regulation (EU AMLR) applies from July 2027 and makes the substantive rulebook directly applicable across all 27 Member States, while the new EU Anti-Money Laundering Authority (AMLA), headquartered in Frankfurt, takes direct supervision of a limited group of high-risk cross-border firms. Firms operating in Germany need to know which obligations sit where.
Here is how BaFin works today, what changes in 2027, and how the two regimes split the work.
What is Germany's Money Laundering Act GwG?
The Geldwäschegesetz (GwG), the German Anti-Money Laundering Act, is the country’s primary AML legislation. The GwG implements the EU’s Anti-Money Laundering Directives (AMLDs) within the German legal framework. It encompasses identifying suspicious activities, Customer Due Diligence, and reporting cases of potential money laundering or terrorist financing.
Highlights of the GwG include:
- Companies at risk of money laundering (such as financial institutions, real estate agents, and casinos) are obligated to verify customer identities, conduct risk assessments, and monitor transactions as part of CDD.
- Obliged entities must report any suspicion of money laundering via a Financial Intelligence Unit (FIU) report (such as a Suspicious Transaction Report, or an STR).
- Obliged entities have to store customer and transaction data for a set period.
- Penalties for companies that fail to comply include heavy fines or criminal charges.
What is BaFin and what does it regulate?
The Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht – ‘BaFin’) is the German financial regulator.
BaFin’s functions can be divided into two broad categories:
- Protection of consumers. Ensuring that the market is stable, fair, and transparent to protect consumers from harm.
- Control over organizations. Authorizing banks, financial service providers, insurance companies, and payment and e-money services to operate in Germany.
The scope of BaFin’s supervision is vast and covers these key responsibilities:
- Licensing
- Conducting audits
- AML compliance supervision
- Gathering financial statements
- Making sure that the obliged entities meet their payment requirements
- Enforcement.
In addition to more traditional financial sectors, BaFin now also supervises the regulation of virtual assets under the EU’s Markets in Crypto-Assets (MiCA) framework.
Other agencies combating financial crime in Germany
In 2023, Germany announced plans to create a new body to combat money laundering and other forms of financial crime, the Federal Office for Combating Financial Crime (Bundesamt zur Bekämpfung von Finanzkriminalität or ‘BBF’). However, the agency has not yet been established and is currently unfunded. If and when the BBF is up and running, it will need to work closely with BaFin and may issue its own guidelines for combatting financial crime.
Germany is also home to the new EU Anti-Money Laundering Authority (AMLA). Based in Frankfurt, it began operations on July 1, 2025. The AMLA’s role is to work with national authorities to “ensure the uniform application of anti-money laundering legislation and to strengthen cooperation between national Financial Intelligence Units”.
Germany's AML requirements under BaFin
BaFin requires a risk-based approach to AML and prevention of other financial crimes.
According to the FATF, a risk-based approach means identifying, assessing, and understanding the money laundering and terrorist financing risk to which an entity is exposed, as well as taking the appropriate mitigation measures in accordance with the level of risk.
When designing a risk management system, companies must consider their business type, the products they offer, and the potential risks involved. For instance, the gambling sector is considered vulnerable to money laundering and the use of gambling services to launder proceeds of crime, so gambling operators should apply risk-based KYC and AML measures that reflect the specific risks they face.
BaFin requires entities to develop strict principles for detecting and preventing criminal activity. These include:
- Applying general due diligence requirements. Due diligence measures must be undertaken before establishing any business relationship or implementing a transaction. BaFin sets three levels of due diligence checks:
- Simplified Due Diligence (SDD)
- General Customer Due Diligence (CDD)
- Enhanced Due Diligence (EDD).
Although CDD requirements differ for natural and legal persons, SDD and EDD do not have this differentiation. A business must have a precise understanding of how it assesses clients as either “high-risk” or “low-risk” based on the high- and low-risk factors set out in the Annexes to the GwG. If a company is not sure how to assess a client, it can ask BaFin for help.
- Appointing an AML officer. BaFin requires businesses to appoint an AML officer and a deputy as contact persons for the regulator. Essentially, the officer is responsible for compliance with BaFin. Ongoing monitoring and reporting are also among their duties.
- Conducting employee training. Companies under BaFin must instruct all their employees on financial crimes and their prevention. Companies can decide on the form and timing of such training, but it is always recommended that the instructions be provided whenever there are any changes in BaFin’s practices or a new form of money laundering emerges.
- Recording and retention. BaFin requires companies to record and store the results of due diligence checks (as well as other reports) for at least 5 years, and to provide them to the regulator if needed.
- Reporting. This includes reporting of suspicious activity and transactions.
The obliged entity may engage third parties in order to fulfill the general due diligence requirements. Delegation requires a contractual agreement.
Since January 1, 2020, BaFin has considered crypto assets financial instruments. Crypto businesses now fall under BaFin’s supervision and must comply with all AML and KYC requirements. BaFin cryptocurrency regulations can be found on the official website here.
Suggested read: The Three Stages of Money Laundering and How Money Laundering Impacts Business
The legal framework behind BaFin AML rules
This is a breakdown of the main acts and regulations that BaFin enforces:
- The Money Laundering Act in Germany (Geldwäschegesetz – GwG). All BaFin AML requirements, as well as administrative fines for non-compliance, stem from this law. It aligns with the 4th, 5th, and 6th Anti-Money Laundering Directives, which regulate AML compliance across the European Union. Recent updates to this Act reflect stricter AML enforcement and greater consideration of virtual assets.
- The Banking Act supervises financial institutions in the country.
- The Insurance Supervision Act controls the activity of insurance companies. The law primarily protects the interests of insured persons and makes sure that both the companies and clients fulfill their contractual obligations.
- The Payment Services Supervision Act oversees payment service companies, such as credit and electronic money institutions.
- The Investment Code controls the investment sphere – mainly investment funds offered by asset management companies.
- The Criminal Code addresses various criminal offenses, defines money laundering and establishes penalties for crimes.
- The Securities Trading Act oversees a broad scope of activities, from provision of investment services to financial reporting.
Here is a list of other regulations related to BaFin’s activity.
The EU AML Package and its impact on Germany
In 2024 the EU overhauled its anti-money laundering and counter-terrorist financing framework. The old system was directive-based and fragmented across AMLD4 and AMLD5. The replacement combines directly applicable regulation with a new supervisory authority, and it is the most significant structural change to EU AML law since AMLD4.
The package consists of three legislative instruments, all adopted May 31, 2024:
| Instrument | Type | Official reference | Role |
|---|---|---|---|
| AMLR (AML Regulation) | Regulation – directly applicable | (EU) 2024/1624 | Substantive rulebook: CDD, beneficial ownership, internal controls, obliged entities |
| AMLD6 (6th AML Directive) | Directive – requires national transposition | (EU) 2024/1640 | Institutional/supervisory framework: FIUs, national supervisors, sanctions regime, beneficial ownership registers |
| AMLA Regulation | Regulation – directly applicable | (EU) 2024/1620 | Establishes the EU AML Authority (AMLA), its supervisory and enforcement powers |
Read them as one system with three layers, not as three independent reforms.
AMLR is the substantive layer. It sets out what obliged entities actually have to do: CDD, beneficial ownership identification, internal controls, suspicious transaction reporting. Identical terms across all 27 Member States, no transposition needed. It applies from July 10, 2027.
AMLD6 is the enforcement layer. It does not restate AMLR's substantive obligations. It defines how breaches get policed and punished, covering sanctions ceilings, national supervisors' powers, FIU structures, and cross-authority cooperation. Because it is a directive, each Member State transposes it into national law, so enforcement detail can still vary across jurisdictions until transposition is complete. The underlying substantive standard does not vary.
AMLA is the supervisory layer above both. It applies AMLR's substantive rules within the sanctions and cooperation framework AMLD6 establishes, directly supervises a limited cohort of high-risk cross-border entities, and coordinates with national supervisors on everything else.
One compliance failure can pull in all three at once. An AMLR breach, inadequate CDD for example, is what creates the liability. AMLD6 supplies the penalty ceiling and the procedural mechanics that a national supervisor, or AMLA where it has direct authority, will apply. AMLA is the body that may ultimately investigate, impose binding decisions, or apply sanctions in the highest-risk cases, while national supervisors handle everything else under AMLD6-derived domestic law.
For compliance teams the working recommendation is to treat AMLR as the fixed substantive baseline that will not vary by jurisdiction, and monitor two moving parts: AMLD6 transposition and AMLA's Regulatory Technical Standards. Those two determine how strictly, and by whom, that baseline is enforced in each market the business operates in.
Key changes to German AML rules under the AMLR
The list of obliged entities expands to include:
- Crypto-asset service providers, or CASPs, the EU term for VASPs
- Luxury goods traders
- Real estate professionals
- Corporate service providers
- Professional football clubs, applicable from 2029
Crypto was not entirely new to EU AML law, but AMLR significantly widens which crypto businesses count as obliged entities. That now covers:
- Placing crypto-assets
- Providing transfer services for crypto-assets
- Operating a trading platform for crypto-assets
- Advising on crypto-assets
- Portfolio management of crypto-assets
Two further changes:
- Obliged entities must appoint a member of their management body as a compliance manager, with responsibilities including identifying significant or material weaknesses in financial crime guidelines, procedures, controls, and reporting obligations.
- The threshold for identifying beneficial owners drops from over 25% ownership to 25% and above, with a lower 15% threshold in certain circumstances.
AMLR: Ongoing monitoring and screening duties
Obliged entities must screen customers against sanctions lists so they are not doing business with sanctioned parties. AMLA sets the technical standards and guidelines for that screening.
Ongoing monitoring is a core AMLR requirement. Entities are expected to continuously review customer relationships to identify signs of unusual or suspicious activity, and AMLA's draft guidelines address this under Article 26(5) of the AMLR.
Transaction monitoring is the main practical tool for meeting that duty. Businesses are expected to watch the payments and transactions moving through a customer relationship for as long as the relationship lasts, looking for what does not fit: a transaction that is unusually large, a sudden change in behavior, payments to or from a high-risk country, activity that does not match what you know about that customer and their normal patterns. Anything that looks off should prompt a closer look, and an STR to the relevant national authority if warranted.
Article 26 of the AMLR makes this a formal, harmonized obligation across the EU. The monitoring framework has to fit the size, risk, and complexity of your business, built from manual checks, automated tools, or a mix of the two. AMLA is finalizing detailed guidelines on what a good monitoring setup looks like in practice, covering both how to keep customer information up to date and how to design a system that spots unusual transactions.
AMLR implementation timeline in Germany
- July 10, 2027: The AMLR starts to apply. The deadline for full transposition of AMLD6 falls on the same date, as does the EU-wide €10,000 limit on cash payments under the AML Regulation.
- 2027: AMLA selects the entities that will come under its direct supervision.
- 2028: AMLA begins direct supervision of selected high-risk, cross-border financial institutions.
Customer Due Diligence requirements in Germany
Due diligence requirements are recorded in the GwG. They are Customer Due Diligence, Simplified Due Diligence, and Enhanced Due Diligence.
There are several circumstances when a company needs to apply CDD:
- Starting a new business relationship with a natural or legal person
- Completing transactions that fall outside an established contract when the transfer of funds involves an amount of €1000 or more
- Other transactions with a value greater than €15,000
- Suspicious transactions potentially connected to money laundering or other crimes
- Regular CDD for existing clients, if something has changed in the client’s circumstances (e.g., a change in ownership)
Detailed BaFin's CDD requirements may be found on the official website.
In 2025, BaFin updated interpretation and application instructions on the GwG (official Auslegungs- und Anwendungshinweise (AuA). Among the changes, the regulator highlighted new guidance on Enhanced Due Diligence obligations for crypto-asset transfers to or from self-hosted addresses, i.e., transfers involving private, unhosted wallets.
For CDD, BaFin distinguishes between natural persons and legal persons.
For natural persons, the following should be collected
- Name
- Date of birth
- Place of birth
- Residential address (or postal address in certain cases)
- Type, number, and issuing authority of a submitted ID document.
The client’s data can be extracted from a valid official document (such as a passport or identity card) or from electronic proof of identity. An electronic scan of the presented ID document is enough to comply with recording and retention requirements.
Here are the requirements for legal persons:
- Name of the company or trading name
- Legal form
- Commercial register number (if available)
- Address of the registered office
- Ownership, including the beneficial owner, and control structure
- Purpose of business (if not explicit)
The company’s commercial register or its equivalent can be used to gather information about the company. For due diligence checks, BaFin requires entities to refer to the FATF's list of high-risk countries and the EU Commission Delegated Regulation. Information on financial sanctions is available on the Deutsche Bundesbank’s website.
Simplified and Enhanced Due Diligence explained
Simplified Due Diligence
BaFin does not provide a specific list of information to be collected in the event of an SDD. Instead, the regulator permits companies to reduce general due diligence requirements to whatever extent the company thinks is reasonable. In practice, the simplified check only applies when all the lower-risk factors coalesce. Annex 1 of the GwG lists them.
Enhanced Due Diligence
BaFin distinguishes the three red flags of money laundering and terrorist financing.
- PEP. If a beneficial owner of the client company is a Politically Exposed Person or a close acquaintance, EDD must be applied.
- Complex or suspicious transactions. Businesses are to conduct EDD if the transactions their clients want to make are:
a) significantly large or complex
b) follow an unusual pattern
c) have no apparent economic purpose
- Partnerships with EU businesses that pose high risk or businesses located in third countries
EDD must be conducted when obliged entities, such as financial institutions, correspond with companies within the EU that pose a high risk of money laundering and terrorist financing, or with companies outside the EU.
Annex 2 of the GwG carries the full list of higher-risk factors.
These are the requirements for EDD that BaFin sets for the three high-risk factors above:
- PEP:
a) A member of senior management has to approve a business relationship with the client company
b) The source of funds has to be checked
c) Enhanced ongoing monitoring is needed
- Complex or suspicious transactions:
a) The company must conduct a thorough check of suspicious transactions with regard to financial crimes
b) Enhanced ongoing monitoring must be set up
- Partnerships with businesses in the EU that pose a risk, or businesses located in third countries:
a) A full check of the client company is to be conducted (including the nature of the business, reputation, established measures for preventing financial crimes, etc.)
b) A member of senior management must approve the business relationship with the company
c) Both sides must document their responsibilities for the fulfillment of EDD before establishing the business relationship
d) The client company cannot have an account in a shell bank
e) The client company cannot make transactions via payable-through accounts. For information on checking PEPs, BaFin recommends referring to the FATF’s guidance.
Suggested read: What Is Crypto KYC and Why Do Exchanges Need It?
Identity verification methods for German KYC
German AML rules allow several methods for verifying a person's identity. These include physical document checks, electronic identification, qualified electronic signatures, and video identification, which is subject to specific BaFin requirements.
- Video identification procedure. Video identification, or VideoIdent, is a distinctive feature of ID verification in Germany and requires special attention. BaFin provides full details on the video identification procedure here.
- On-the-spot check of a qualified identification document. This is when an individual presents a physical identity document for verification, usually a passport or birth certificate (for persons younger than 16 years old).
- Electronic proof of identity. Holders of a German identity card aged 16 or over can use it for verification purposes. Please refer to the Act on Identity Cards and Electronic Identification or the Residence Act for detailed information.
- Qualified electronic signature. When a person conducts a digital transaction, a qualified electronic signature can be used for identity verification purposes. The e-signature must be validated.
Suggested read: Types of Electronic Signatures Explained: Complete Guide
Key MiCA changes for crypto businesses in Germany
MiCA (the Markets in Crypto-Assets Regulation) is an EU-wide regulation that creates a comprehensive legal framework governing crypto-assets, stablecoins, and crypto-asset service providers. It came into effect in June 2023 across all EU member states, with most of its provisions for CASPs applying from December 30, 2024.
Key changes for crypto regulation in Germany under the MiCA regulation include:
- CASP licenses replacing BaFin's crypto-custody permits. The new licenses are still overseen by BaFin.
- New EDD requirements introduced for unhosted/self-hosted crypto wallets. This includes verifying wallet ownership.
- Expectation set for firms to use blockchain analytics tools. Required for enhanced scrutiny of transactions involving unhosted wallets.
Suggested read: MiCA Regulation and EU Crypto Rules: What Changes in 2026
BaFin reporting requirements explained
BaFin aligns with European Union reporting guidelines. Submitting Suspicious Transaction Reports is the cornerstone of German AML reporting, and companies must report any transaction suspected of ties to money laundering or terrorist financing. Sector-specific reports also apply to the finance and insurance sectors.
Filing a Suspicious Transaction Report in Germany
Businesses have to report any suspicious activities or transactions when:
- They detect any malicious activity
- The contracting party does not want to disclose whether it conducts business on behalf of a beneficial owner
The company must submit an STR even if it is unsure whether the contracting party’s activity is suspicious. Besides, the company does not have to conduct any investigation – it has to provide BaFin with an explanation of why it believes the activity is abnormal. It is not recommended to contact and question the contracting party to avoid alerting it to any arising suspicions.
Here’s what to keep in mind when submitting an STR:
Person in charge of the submission: the AML officer.
Authority to submit to: the Financial Intelligence Unit for detection and prevention of money laundering and terrorist financing (businesses should not ask the FIU for any preliminary review of the report).
Means of submission: electronically, through the “goAML” system (companies need to register on the “goAML” web portal to access the system and file the report).
Time: as soon as the suspicious activity has been detected.
Other BaFin reports for financial institutions
Financial institutions also submit:
- Annual reports
- External audit reports
- Financial statements
- Major changes reports, covering significant changes such as those to the management board
- Exposures and loans of more than €1 million
Some entities, including investment service companies, must report all on-exchange and off-exchange dealings in financial instruments. The Banking Act has the detail.
Recording and retention rules under BaFin
Entities should not underestimate the importance of recording and storing data, since they often face external audits.
Data to record:
a) Information collected through due diligence checks, including results of risk assessment. Records may include video and audio recordings made to fulfill due diligence requirements
Video Interview recordings should also be retained in full
b) Detailed transaction information, which includes CDD data and transaction date/time, amount, currency type, account numbers, and payment method
c) STR and other reports
Recording requirements: BaFin permits making copies of checked documents (and storing them in digital form
Retention period: The entire video identification process must be recorded and retained by the obliged entity for at least 5 years and no longer than 10 years. After this period, all records, including video identification records, must be destroyed.
Obliged entities may use personal data solely for the prevention of money laundering and terrorist financing. Entities must also make sure the security of any stored data.
Penalties for non-compliance with BaFin requirements
BaFin makes sure that businesses use appropriate preventive measures to protect themselves against money laundering and terrorist financing. Failing to comply with BaFin may result in AML penalties, including:
- Fines
- License termination
- Seizure of assets
- Criminal liability
The regulator imposes administrative fines for breaches of compliance, such as failures to establish a risk management system, retain records, and meet reporting requirements. For serious or systematic violations, a company can receive a fine of up to €1 million or up to twice the economic benefit derived from the breach. In particularly serious cases, penalties of up to €5 million can be imposed.
As more and more businesses move online, BaFin now focuses on information security and compliance with BAIT (Supervisory Requirements for IT in Financial Institutions).
Recent BaFin fines and enforcement actions
- Norddeutsche Landesbank ordered to “eliminate serious deficiencies in its money laundering and terrorist financing prevention measures” on August 3, 2026.
- CRONBANK AG ordered to “establish a proper business organization and effective anti-money laundering measures” on May 29, 2026.
- DLT Securities GmbH fined €140,000 (approx. $162,000) on March 19, 2026 for violations of the Money Laundering Act.
- VR-Bank Bad Salzungen Schmalkalden eG fined €325,000 (approx. $380,000) on January 20, 2026, for “deficiencies in money laundering prevention measures that occurred during the tenure of the bank's management in the 2023 financial year”.
Two of these are orders to remediate, and two are fines, and the pattern across all four is the same. BaFin's expectations run past having AML policies on paper. Firms have to maintain effective controls and be able to demonstrate that those controls work in practice.
Building a BaFin-compliant AML program
Here are the steps to establish a BaFin-compliant AML program:
- Conduct a company-wide risk assessment to identify compliance gaps and determine where controls need to be strengthened.
- Appoint an AML Officer and deputy who are reported to and approved by BaFin and have direct access to the board.
- Implement a risk-based approach with risk scoring for all customers, and tailor KYC and ongoing monitoring requirements to each customer’s risk profile.
- Build a compliant KYC process that covers CDD, sanctions and PEP screening, UBO verification, and risk-based ongoing monitoring.
- Implement automated transaction monitoring to identify unusual or suspicious transactions based on predefined rules, risk indicators, and customer behavior.
- Carry out ongoing transaction monitoring, with the scope and intensity calibrated to customers’ risk profiles, and make sure that alerts are reviewed and escalated when necessary.
- Set up rigorous case management processes that use automation where appropriate so that cases are opened and investigated promptly, and that necessary action is taken within regulatory deadlines.
- Establish robust reporting processes to ensure the timely filing of suspicious transaction reports with the FIU.
- Create clear written documentation covering internal controls, case management, escalation, transaction monitoring, and record-keeping procedures.
- Deliver ongoing staff training with regular, role-specific AML training that is documented for audit purposes.
- Commission independent audits through regular internal and external reviews that test the effectiveness of AML controls and identify gaps for remediation.
- Develop effective record-retention policies and processes to maintain required records for at least five years in accordance with statutory requirements.
Please note that these steps provide a general overview of key AML compliance measures and are not exhaustive. Businesses should assess their specific obligations based on their activities, risk profile, and applicable regulatory requirements.
Useful BaFin and AML resources
These are some helpful materials for a better understanding of BaFin AML requirements:
- BaFin’s official website not only provides insights into the regulator’s work but also contains articles and guidelines on compliance as well as full texts of all relevant legislation.
- Interpretation and Application Guidance (AuA) describes AML obligations under BaFin in relation to the GwG and other laws.
- The FATF Recommendations on AML/CFT may also be useful since Germany is a member of the Financial Action Task Force.
FAQ on BaFin and German AML compliance
-
What is considered money laundering in Germany?
Under Section 261 of the German Criminal Code (StGB), money laundering means disguising assets derived from unlawful activity such as fraud and drug trafficking. It is the act of integrating criminal money into the legitimate financial system so that it appears clean.
-
Does Germany require KYC?
Yes. German Know Your Customer requirements are based on European and national AML provisions. Financial institutions and CASPs operating in Germany must run KYC procedures on their customers, identity verification included. For remote onboarding, BaFin permits VideoIdent, subject to specific regulatory requirements.
-
Is BaFin like the SEC?
Not exactly. BaFin is an integrated financial supervisory authority covering banking, insurance, financial services, and securities. The US Securities and Exchange Commission regulates the securities industry specifically, protecting investors and the integrity of US securities markets.
-
What is Enhanced Due Diligence in Germany?
EDD in Germany means more comprehensive checks on new and existing customers where the risk of financial crime is considered higher. Section 15 of the Geldwäschegesetz sets out the specific requirements.
-
Who supervises crypto firms in Germany now?
BaFin supervises crypto-asset service providers in Germany under MiCA, in cooperation with the Deutsche Bundesbank. Significant asset-referenced and e-money token issuers fall under the European Banking Authority's direct supervision.
-
Does the GwG still apply after the AMLR takes effect?
Yes, though not in its current role. From July 10, 2027, the AMLR directly governs most substantive AML obligations and replaces many corresponding GwG provisions. The GwG continues to apply to areas that remain under German national law, including matters covered by AMLD6.
Relevant articles
- Article
- Jul 14, 2026
- 10 min read
Learn how to create an AML compliance policy covering CDD, MLRO duties, SAR filing, and audits, and get a free FINRA template to help you get started.

- Article
- Jun 24, 2026
- 11 min read
KYC helps gambling operators prevent fraud, comply with AML regulations, and avoid hefty fines. Explore casino KYC requirements, verification process…

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.


