Bafin [DEU] ¦ Germany Tightens Oversight of Virtual IBANs Amid Fraud and Money Laundering Risks

Bafin [DEU] ¦ Germany Tightens Oversight of Virtual IBANs Amid Fraud and Money Laundering Risks

A broader compliance obligation for German credit institutions

German credit institutions issuing virtual IBANs with the country code DE to payment service providers (PSPs) must record those IBANs in the statutory account information file maintained under section 24c(1) of the German Banking Act (KWG).

Note

You can find an article on the risks of virtual IBANs in connection with underground banking here.

The obligation applies where a payment service provider receives virtual IBANs for distribution to its customers, who then use them for their own payment activities. It covers virtual IBANs issued directly or indirectly and applies regardless of whether the payment service provider is based in Germany, elsewhere in the European Economic Area or in a third country.

The requirement is not limited to regulated firms that are formally authorised to provide payment services. The relevant test is whether the business provides payment services or issues electronic money, or presents itself to the market as doing so. Even the appearance of such a business model may bring the activity within scope.

The arrangement also captures privileged payment service providers covered by section 1(1), sentence 1, numbers 2 to 5 of the German Payment Services Supervision Act (ZAG).

Why virtual IBANs create financial crime exposure

A virtual IBAN generally does not represent a separate bank account in the conventional sense. Instead, it identifies a customer or sub-account within an account structure operated by a payment service provider. Incoming funds may first be credited to the payment service provider’s account and then allocated to the relevant customer’s electronic money account or internal ledger.

From a financial crime perspective, however, the customer may use the virtual IBAN as though it were an individual payment account. It can be provided to business counterparties, used to receive transfers and presented in commercial relationships as a distinct account identifier. This creates a risk that the apparent account holder, the institution encoded in the IBAN and the person actually controlling or benefiting from the funds may not be the same party.

That separation can obstruct the work of banks, counterparties and public authorities. A payment may appear to be directed to an account held by a payment service provider, while the economic benefit is intended for an underlying customer. If the virtual IBAN is absent from the relevant account information file, an investigation based on that IBAN may fail to identify the underlying customer.

The measure therefore treats the virtual IBAN as creating a legally relevant appearance that a payment account exists at the institution whose bank code is encoded in the IBAN. The issuing credit institution is expected to address that appearance through complete and accurate recordkeeping.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"Germany is strengthening oversight of virtual IBANs to ensure that payment flows can be linked to the payment service provider, the end customer and the natural person ultimately controlling or benefiting from the funds. Credit institutions must record relevant virtual IBANs accurately and completely in the statutory account information file.

The measure addresses risks involving fraud, tax offenses, money laundering and terrorist financing, particularly where virtual IBANs obscure the identity of the true recipient. Banks and payment service providers should therefore review customer data, beneficial ownership information and legacy virtual IBAN portfolios without delay."

The required data relationship

For each relevant virtual IBAN, the payment service provider is to be recorded as the account holder. The end customer using the virtual IBAN for its own payment purposes must also be identified as the authorised disposer or beneficial owner, depending on the applicable relationship.

Where the end customer is a legal entity, the relevant natural person behind that entity must be identified. This places particular importance on the quality of customer and beneficial ownership information passed from the payment service provider to the issuing bank.

The obligation is imposed on the credit institution issuing the virtual IBAN. The institution may obtain the necessary information through the payment service provider, but outsourcing the collection process does not transfer or remove the statutory responsibility. The position remains the same where the payment service provider has its own obligation under section 24c(1) KWG.

This creates a chain of accountability. Payment service providers must be able to identify their customers and the persons who ultimately control or benefit from the relevant funds. Credit institutions must ensure that the information associated with the virtual IBAN is correctly and completely entered into the statutory file.

The connection to money laundering and predicate offenses

The measure is directly relevant to the detection of money laundering because virtual IBANs can obscure the movement of criminal proceeds. A customer may use a virtual IBAN to receive funds from multiple sources, transfer them through an electronic money account and move them onward without the underlying customer being visible from the IBAN alone.

That opacity is particularly problematic where the incoming funds are linked to predicate offenses. The concerns identified by German authorities include fraudulent claims for public support, the unlawful receipt of coronavirus aid and the reduction or evasion of value added tax (VAT). Other relevant predicate offenses may include investment fraud, payment fraud, cyber-enabled theft, sanctions evasion and the operation of unauthorised financial services.

Fraud proceeds are often dispersed across several accounts or payment platforms shortly after receipt. A virtual IBAN can facilitate this process by giving the payer a dedicated receiving identifier while allowing the provider to manage the underlying funds through a central account structure. If investigators cannot connect the identifier to the actual customer, tracing and recovery become significantly more difficult.

Tax offenses present a similar risk. A business involved in VAT fraud may use payment accounts and virtual IBANs to receive customer payments, route funds through several entities or conceal the relationship between trading activity and the persons controlling the proceeds. Accurate identification of the end customer improves the ability of authorities to connect payment flows with the relevant commercial and tax records.

The measure also addresses the risk of terrorist financing. Terrorist financing does not require proceeds from a criminal offense and may involve relatively small transactions. Nevertheless, the ability to identify the person using a virtual IBAN is important where funds are collected, pooled or distributed through payment accounts that appear to belong to an intermediary.

Immediate compliance for new virtual IBANs

The requirement for newly issued virtual IBANs applies from the day after publication of the general administrative order. The relevant entry must be made without delay and must be accurate and complete.

The immediate enforcement decision reflects the authorities’ assessment that virtual IBANs were being misused on a significant scale and that investigations were often complicated by cross-border structures. The stated concern is that waiting until the measure became legally final could prolong opportunities for fraud, money laundering and terrorist financing.

The immediate execution applies specifically to the obligation concerning newly issued virtual IBANs. Credit institutions remain entitled to challenge the measure through the administrative legal process, but an objection does not suspend that part of the order.

A six-month remediation period for existing portfolios

Credit institutions that had already issued relevant virtual IBANs when the measure entered into force receive six months to complete the required entries. The same standard applies to legacy portfolios: the information must be recorded correctly, completely and with the payment service provider and underlying customer properly identified.

If a credit institution cannot complete the remediation accurately, completely or within the required period, it must terminate the relevant payment service provider’s accounts or otherwise ensure that the virtual IBANs can no longer be used.

This creates a substantial operational requirement for institutions with large virtual IBAN programmes. They will need to identify the full population of affected IBANs, determine the associated payment service providers and end customers, verify beneficial ownership information and reconcile the records with the data submitted to the statutory account information file.

The remediation exercise should also be treated as a financial crime control review. Gaps in customer identification, inconsistent beneficial ownership data, unexplained account structures and unusually high transaction activity may indicate wider weaknesses in onboarding, monitoring or provider oversight.

Implications for banks and payment service providers

Credit institutions should assess whether their virtual IBAN products are being used solely for internal bookkeeping or whether end customers use the identifiers for their own payment activities. The latter situation is central to the order.

An exclusion applies where a non-payment-service business receives virtual IBANs merely to simplify its own accounting and the end customer does not use the IBAN for independent purposes beyond the payment itself. The distinction will depend on the actual business model and customer use, rather than on product labels alone.

Banks should therefore review contractual arrangements, product descriptions, customer terms, transaction flows and technical account structures. They should also establish clear information sharing requirements with payment service providers and define procedures for addressing incomplete or inconsistent data.

Payment service providers, although not the primary addressees of the order, are likely to face increased scrutiny from their banking partners. They may need to supply reliable data on end customers, authorised users and ultimate beneficial owners, including information relating to legal entities and the natural persons behind them.

Weaknesses in that data may lead to delayed onboarding, restrictions on new virtual IBAN issuance, termination of existing arrangements or enhanced supervisory attention.

Why the measure matters beyond account reporting

The order reinforces a wider regulatory principle: payment identifiers must not create a misleading impression about where an account is held or who controls the funds. A DE IBAN can suggest that the payment relationship is directly connected to a German credit institution. If the underlying customer is invisible in the relevant records, that apparent transparency is incomplete.

For investigators, accurate account information can provide an early link between a suspicious payment and the person who ultimately benefits from it. For banks, the requirement highlights the need to treat virtual IBAN programmes as part of the institution’s financial crime risk framework rather than as a purely technical payment product.

The practical effect is to reduce the distance between the visible payment identifier and the person behind the transaction. That is particularly important in cases involving fraud, tax offenses, money laundering and terrorist financing, where speed and accurate attribution can determine whether funds are frozen, recovered or moved beyond reach.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • BaFin ¦ Allgemeinverfügung zur Anordnung der Speicherung von Daten in einem Dateisystem nach § 24c Abs. 1 KWG ¦ Link
  • BaFin ¦ German Banking Act (Gesetz über das Kreditwesen, KWG) ¦ Link
  • BaFin ¦ German Payment Services Supervision Act (Gesetz über die Beaufsichtigung von Zahlungsdiensten, ZAG) ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.