ATLAS
← Back to News and Insights

BaFin tightens controls for virtual IBAN risks

2 min

BaFin’s supervisory notice requires German banks and payment service providers to strengthen risk-based virtual IBAN controls until 10 July 2027.

LinkedIn Post
BaFin tightens controls for virtual IBAN risks
A reviewed cross-border payment route represents virtual IBAN control risks. · Photo: Atlas Editorial

The BaFin supervisory notice dated 27 July 2026 requires banks and payment service providers to apply risk-based controls and monitoring to virtual IBAN arrangements until 10 July 2027.

The notice identifies virtual IBANs as a risk factor for money laundering and terrorist financing, including in connection with Underground Banking and other informal financial transfer systems. BaFin said institutions must use appropriate controls and monitoring measures to contain those risks.

A virtual IBAN resembles an IBAN and can route or redirect payments to a payment account where the funds are booked. The account holder is not necessarily the end customer using the virtual IBAN, which can complicate customer identification and the assessment of payment activity.

BaFin identifies indicators of heightened risk associated with virtual IBAN structures. The notice does not prescribe a uniform control package: customer-due-diligence, control and monitoring measures must reflect the assessed risk and the specific characteristics of the arrangement.

Affected institutions must document their review of vIBAN controls. They should assess customer identification, the relationship between account holders and end users, payment routing, beneficiary information and transaction monitoring against the risks and indicators described in the notice. Where risk is higher, institutions must adjust their anti-money-laundering measures accordingly.

BaFin’s notice is a German supervisory communication. It does not amend MiCA, the EU AML framework or another Level 1 instrument, and it does not create a Union-wide requirement. Level 1 binding force, Level 2 measures and national implementation questions remain separate from the notice.

The notice applies immediately and remains in force through 10 July 2027, when the EU AML Regulation is scheduled to enter into force. BaFin did not specify in the supplied notice a firm-level reporting form, a quantitative risk threshold or a separate filing timetable.

Banks and payment service providers in Germany using or providing virtual IBAN arrangements must maintain risk-based controls and monitoring through 10 July 2027, subject to subsequent BaFin communication or applicable legal change. The next dated milestone is the EU AML Regulation’s scheduled application on 10 July 2027.

Official source: Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
PaymentsAML ProgrammesTx MonitoringAML CFT

Permanent link to this Atlas analysis

Continue with coverage connected by market, topic and operating context.

Continue with Atlas

Move from this development into the relevant research, comparison and workflow.