Learn more about the latest security and privacy threats
Editorial illustration for the article "BaFin orders Helaba to fix customer due diligence failures".

BaFin has ordered Helaba to remedy customer due diligence failures in identification, data updates and monitoring. What the July 2026 order means for KYC teams.

Table of contents

Germany's regulator BaFin published an order on 20 July 2026 requiring Landesbank Hessen-Thüringen (Helaba) to remedy customer due diligence failures across customer identification, verification and updating of customer data, risk analysis and transaction monitoring. It is the second BaFin money laundering measure against the bank in seven months.

  • BaFin ordered Helaba to take "geeignete und angemessene Maßnahmen", appropriate and suitable measures, to close gaps in money laundering and terrorist financing prevention.
  • The named failures cover the core of customer due diligence: identifying customers, verifying and keeping customer data current, risk analysis and automated transaction monitoring.
  • It is the second published BaFin measure in seven months, after a 20,000 euro fine published in December 2025 (final since November 2025) over shortcomings in its data processing systems.
  • The order became final on 20 June 2026 and was published under the naming provision of the German Money Laundering Act on 20 July 2026.
  • Helaba must review and update customer data and report progress to BaFin on an ongoing basis, a heavy remediation burden for a legacy balance sheet.

What did BaFin order Helaba to do?

BaFin ordered Helaba, one of Germany's largest public-sector Landesbanken, to take "geeignete und angemessene Maßnahmen" to remedy deficiencies in money laundering prevention. The named gaps sit at the heart of customer due diligence: customer identification, verification and updating of customer data, risk analysis and transaction monitoring. The bank must report progress continuously.

The order rests on the German Money Laundering Act (Geldwäschegesetz, GwG) and the Banking Act (Kreditwesengesetz, KWG), and appears on BaFin's public register of measures, where the regulator names firms once an order is final. Helaba told reporters it is "in close exchange with BaFin" and is implementing the required steps as quickly as possible. The bank was not fined this time; the measure is a remediation order, not a penalty.

FactDetail
InstitutionLandesbank Hessen-Thüringen Girozentrale (Helaba), Frankfurt
RegulatorBaFin (Federal Financial Supervisory Authority)
MeasureOrder to remedy money laundering prevention deficiencies
Named gapsCustomer identification, customer data verification and updating, risk analysis, transaction monitoring
Legal basisGeldwäschegesetz (GwG) and Kreditwesengesetz (KWG)
Order final20 June 2026
Published20 July 2026
Prior measure20,000 euro fine, final November 2025, over data processing systems

How did Helaba reach a second BaFin measure in seven months?

This is not a first warning. In December 2025 BaFin published a 20,000 euro fine against Helaba over shortcomings in the data processing systems the bank uses for money laundering prevention. That penalty pointed at the same machinery, the automated systems meant to flag suspicious flows, that resurfaces in the July 2026 order.

The escalation matters because German supervisory practice treats repeat findings as evidence that a control weakness is structural, not a one-off slip. A single late report can be a process error. A fine over monitoring systems, followed months later by an order covering identification, data quality, risk analysis and monitoring together, reads as a pattern. The table below sets out the sequence.

DateEvent
December 2025BaFin publishes a 20,000 euro fine over data processing systems (final since November 2025)
20 June 2026The remediation order becomes final and binding
20 July 2026The order is published on BaFin's measures register

What does this mean for your customer due diligence obligations?

The order is a map of where customer due diligence most often breaks, and every duty it touches is codified. Under the GwG, obliged entities must identify and verify customers (Sections 10 to 12), run a documented risk analysis (Section 5), keep customer information current through ongoing monitoring, retain records (Section 8) and file suspicious activity reports to the Financial Intelligence Unit (Section 43).

BaFin has singled out four of these. Identification and verification: the initial checks that anchor a file must be complete and evidenced, not assumed from legacy onboarding. Updating customer data: ongoing due diligence is a live duty, and stale addresses, beneficial owners or risk ratings are themselves a finding. Risk analysis: the institution-wide assessment under Section 5 must be current and drive controls, not sit on a shelf. Transaction monitoring: automated systems under Section 25h of the Banking Act must be calibrated to the firm's actual risk profile.

For teams outside Germany the read-across is direct. The EU single rulebook, the Anti-Money Laundering Regulation, hard-codes these same customer due diligence duties across all member states, and the new Anti-Money Laundering Authority (AMLA) will supervise the largest cross-border firms directly from 2028. A finding that your customer data is out of date will travel under a harmonised standard, not a national one.

What is still uncertain, and where are the risks?

The order sets an obligation to remediate, not a timeline the public can see, and that is the first open question. BaFin has not disclosed a deadline or the size of the affected book. What is visible is the escalation path. Where a bank fails to close gaps, BaFin can appoint a special commissioner, threaten penalty payments (Zwangsgeld) or impose a fresh fine.

The engineering burden is the deeper risk. "Review and update customer data" across a decades-old Landesbank book means re-contacting customers, re-collecting documents and reconciling records that were captured under older rules. That is expensive, slow and error-prone, and it competes with the same limited compliance headcount that is meant to clear monitoring alerts. Under-resourcing the remediation is how a first order becomes a second.

Timing sharpens the exposure. AMLA's data collection to identify entities for direct supervision runs to 15 August 2026, with a provisional list expected by end September 2026. A bank carrying an open, published customer due diligence order is not the profile that wants to stand out as the harmonised EU selection process begins.

How does this compare with other BaFin AML measures?

Helaba sits on a well-worn German escalation ladder, and the precedents show where an unremedied order can lead. BaFin appointed a special commissioner at N26 in 2021, fined the bank 4.25 million euros that year and a further 9.2 million euros, final in 2024, for late suspicious activity reporting. It kept a special monitor at Deutsche Bank from 2018 and, in 2023, ordered better transaction-monitoring systems under threat of penalty payments.

InstitutionBaFin actionEscalation
HelabaOrder to remedy identification, data updates, risk analysis, monitoring (2026)Prior 20,000 euro fine (2025); remediation ongoing
N26Order to fix AML controls plus growth cap and special commissioner (2021)Fines of 4.25m euros (2021) and 9.2m euros (final 2024)
Deutsche BankOrder to improve transaction-monitoring data processing (2023)Special monitor since 2018; penalty payments threatened

The pattern outside Germany is the same. Dutch regulator DNB fined ABN AMRO 8.5 million euros over customer due diligence failures on high-risk customers, and penalised a payments firm for a transaction monitoring gap. Customer data quality and monitoring calibration are the two failures European supervisors return to most.

How should compliance teams respond?

Start with the four gaps BaFin named, because they are the ones examiners test first. Reconcile your customer files against current identification and verification standards, not the rules in force when the account opened. Prove that ongoing monitoring actually refreshes customer data on a risk-based cycle, and evidence it. Re-run the institution-wide risk analysis under Section 5 and show it drives your control settings. Tune transaction monitoring to your real risk profile and document the calibration, including the alerts you suppress and why. Keep a clean audit trail that a supervisor can follow without a workshop.

The structural fix is to collect less and to keep what you hold verifiable. Zyphe verifies identity from the passport's NFC chip to ICAO 9303 and eIDAS standards, with two-step liveness and no image upload, then shards the data across a decentralised network so no single node holds a complete record and there is no central honeypot to breach or let drift. A reusable, customer-held credential means a verified identity can be re-presented and re-confirmed rather than re-collected, which is exactly the "update customer data" burden that put Helaba in front of BaFin twice. See how it works or book a demo.

The bottom line

Helaba's second BaFin measure in seven months is a reminder that customer due diligence is judged on live data, not onboarding-day paperwork. Identification, data freshness, risk analysis and monitoring are examined together, and a gap in any one is a finding. As the EU single rulebook and AMLA harmonise supervision, the institutions that fare best will be those that hold less personal data and can prove what they hold is current.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

BaFin ordered Helaba to take appropriate and suitable measures to remedy deficiencies in money laundering and terrorist financing prevention. The named gaps cover customer identification, the verification and updating of customer data, risk analysis and transaction monitoring. Helaba must review and update customer data and report progress to BaFin on an ongoing basis. It was not fined in this measure.

Not in the July 2026 order, which is a remediation instruction rather than a penalty. Helaba was fined separately in December 2025, when BaFin imposed 20,000 euros over shortcomings in its data processing systems. Because this is the second measure in seven months, further escalation, such as penalty payments or a special commissioner, is possible if the bank does not close the gaps.

Customer due diligence is not a one-time check at onboarding. The GwG requires ongoing monitoring, which means keeping identification, beneficial ownership and risk ratings current throughout the relationship. Stale data breaks screening and monitoring, because sanctions checks and transaction rules only work against accurate customer information. Regulators increasingly treat out-of-date customer data as a standalone failing.

The EU Anti-Money Laundering Regulation hard-codes the same customer due diligence duties across member states, replacing national divergence with a single rulebook. AMLA, the new EU authority, will directly supervise the largest cross-border firms from 2028 and is collecting data now to build its selection list. A national customer due diligence finding will increasingly be judged against a harmonised EU standard.

Audit the four areas BaFin named. Confirm identification and verification files meet current standards, prove ongoing monitoring refreshes customer data, refresh the Section 5 risk analysis, and document transaction-monitoring calibration. Reducing how much personal data you hold, and keeping it verifiable through reusable credentials, lowers both the remediation burden and the breach surface.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo