BaFin Orders NORD/LB to Remedy Customer Data Deficiencies Under AML Rules
- 12 minutes ago
- 2 min read
Germany's financial regulator, the Federal Financial Supervisory Authority (BaFin), has ordered Norddeutsche Landesbank Girozentrale (NORD/LB) to address significant shortcomings in its customer data management after identifying breaches of the country's anti-money laundering (AML) legislation. The supervisory action reinforces regulators' growing focus on customer due diligence and data quality as essential components of effective financial crime prevention.

According to BaFin, the bank failed to maintain customer information in accordance with the requirements of Germany's Money Laundering Act, with supervisors identifying weaknesses in the processes used to update customer records and a substantial backlog of outdated customer data. Accurate and up-to-date customer information is a fundamental element of customer due diligence, enabling financial institutions to properly assess risk, monitor business relationships and detect potentially suspicious activity.
As part of the legally binding order, NORD/LB has been instructed to prepare and implement a comprehensive remediation plan aimed at eliminating the backlog and ensuring that all customer records are brought up to date. The bank must also provide regular progress reports to BaFin demonstrating that corrective measures are being implemented effectively and within the required timeframe. The supervisory order became legally binding on 14 June 2026.
Under Germany's AML framework, banks are required to conduct ongoing customer due diligence throughout the duration of a business relationship rather than relying solely on information obtained during onboarding. Institutions must periodically review and update customer identification data, beneficial ownership information and risk assessments to ensure they remain accurate and sufficient for detecting money laundering and terrorist financing risks. Outdated customer records can significantly reduce the effectiveness of transaction monitoring systems and hinder the identification of suspicious financial activity.
NORD/LB has acknowledged the regulator's findings and stated that it is working closely with BaFin to resolve the identified deficiencies. The bank indicated that it has already developed the required remediation programme and has begun implementing measures to improve customer data quality and strengthen its compliance framework. It also stated that significant progress has already been made in addressing the issues highlighted by the regulator.
The enforcement action forms part of a broader supervisory trend in Germany, where BaFin has increasingly scrutinised banks' AML controls and customer due diligence processes. Rather than focusing solely on suspicious transaction reporting, regulators are placing greater emphasis on the quality of underlying customer data, recognising that effective transaction monitoring and risk assessment depend on accurate, complete and regularly updated customer information.
The case serves as a reminder that AML compliance extends well beyond initial customer onboarding. Financial institutions are expected to maintain robust governance, effective data management processes and continuous monitoring throughout the customer lifecycle. As regulators continue to raise supervisory expectations, banks that fail to maintain accurate customer records may face increasingly stringent enforcement measures aimed at strengthening the integrity of the financial system and reducing opportunities for money laundering and terrorist financing.
By fLEXI tEAM





Comments