Germany’s Federal Financial Supervisory Authority (BaFin) issued a binding administrative order on 20 July 2026 directing Landesbank Hessen-Thueringen Girozentrale (Helaba) to rectify material deficiencies in its anti-money laundering and customer due diligence (CDD) controls.
What BaFin Found
The order addresses four specific failure categories:
- Customer identification and verification — Helaba’s onboarding processes contained gaps in both initial identity verification and ongoing customer data updates.
- Risk analysis — The bank’s internal risk-assessment model did not adequately capture the full spectrum of money laundering and terrorist financing risks associated with its client base.
- Transaction monitoring parameters — Automated transaction monitoring contained technical tracking errors and inadequately calibrated suspicious-activity thresholds.
- Suspicious-activity workflow optimisation — Alert-to-SAR escalation workflows required structural changes to meet BaFin’s expectations for a bank of Helaba’s systemically important profile.
BaFin ordered Helaba to overhaul its automated monitoring infrastructure and correct the technical deficiencies across all four areas.
Why This Matters for Regtech Vendors
The Helaba order is the latest in a pattern of BaFin enforcement against German financial institutions. FCA fines in the UK (Nationwide £44m, Starling £29m, Monzo £21m) set the enforcement tone in 2025-2026; BaFin’s action against a Landesbank signals that German regulators are now following with binding operational requirements, not just supervisory guidance.
For vendors in this chapter — particularly NICE Actimize, SAS Anti-Money Laundering, and Quantexa — the Helaba order represents a procurement trigger at German Landesbanks and savings banks that may have similarly dated AML infrastructure. Binding administrative orders of this type create an immediate, board-level mandate to upgrade automated monitoring systems rather than manage them incrementally.
SAS AML positions its AI-driven transaction monitoring and alert-management suite directly at the problem areas BaFin identified. NICE Actimize holds the SURVEIL-X conduct surveillance platform plus an integrated AML workflow suite that addresses the alert-to-SAR escalation gap in the order. Quantexa offers graph-analytics-based transaction monitoring that directly addresses the “inadequate monitoring parameters” finding through entity resolution across counterparties.
AMLA Context
The BaFin order comes in the same week as AMLA published its Taxonomy v4.3 for 2027 risk-assessment data collection (also 20 July 2026). The convergence of national-level enforcement and supranational-level data standardisation signals that the EU AML regime is entering a phase where both operational compliance and reporting-framework alignment are simultaneously required from all obliged entities.
Source: https://www.amlintelligence.com/2026/07/news-bafin-orders-helaba-to-fix-cdd-deficiencies/