Germany

Germany - Market Insights

Law Over Borders Comparative Guide: White-collar Crime Law Guide

15 Sep 2026
White-collar Crime Law Guide White-collar Crime Law Guide
Q&A Market Insights

Regulation, enforcement and corporate liability in transition

In Germany, the importance of commercial criminal law has steadily increased in recent years. This trend is driven by multiple factors, including geopolitical developments — most notably the sanctions regimes enacted in response to the war in Ukraine — as well as the long-standing, and at times only partially effective, efforts by authorities to combat financial crime and local and international money laundering schemes. In this context, Germany continues to face criticism as a “money laundering hub”. These areas have not only attracted public attention, but revealed structural weaknesses in corporate governance, regulatory supervision and enforcement practice. Authorities have intensified their investigative focus, the regulatory framework is tightened and related criminal provisions are continuously expanded and sharpened. At the same time, modernisation of investigative powers is being considered, including the use of artificial intelligence (AI). Investigative authorities, however, are constrained by limited personnel and technical resources. The growing number of cases has created significant backlogs, with investigations and court proceedings often taking several years to conclude, resulting in uncertainty for the parties involved.

For companies, these developments have resulted in an increasing pressure to act. Legislators, investigative authorities and courts have signalled their intent to pursue white‑collar crime more vigorously and to address existing enforcement gaps. This has direct consequences for regulatory requirements, compliance obligations and the personal liability exposure of executives.

Selected German trends in white-collar crime

Sanctions and foreign trade law

Since the beginning of the war in Ukraine, sanctions law has developed into a core area of criminal prosecution. Regulatory density has increased significantly; the scope of criminalised conduct has been broadened and statutory thresholds for criminal liability have been lowered.

This development is illustrated by the recent amendment to the German Foreign Trade and Payments Act (AWG), which entered into force on 6 February 2026 and implemented EU Directive 2024/1226 on criminal sanctions law. The Directive seeks to ensure uniform and effective criminal enforcement of existing sanctions regimes across the European Union. Key changes include:

  • An expansion and differentiation of criminal offences, in particular in the financial sector (e.g. asset concealment for the purpose of circumventing sanctions).
  • The reclassification of previously administrative offences as criminal offences (e.g. prohibitions on transactions, financial services and investments), thereby eliminating the possibility of voluntary self‑disclosure.
  • The establishment of a criminally sanctioned general reporting obligation for frozen assets (“duty of all persons”).
  • Criminal liability for grossly negligent violations relating to dual‑use items (“recklessness”), punishable with imprisonment of up to three years.
  • The abolition of the two‑day grace period: sanctions now apply immediately upon publication in the Official Journal of the European Union.
  • An increase in the maximum level of corporate fines from EUR 10 million up to EUR 40 million where sanctions offences are committed by executives or as a result of breaches of supervisory duties.

At the same time, enforcement authorities have adopted a robust enforcement approach, as evidenced by a sharp rise in the number of investigations. Companies trading in dual‑use items, high‑tech components, and other industrial products are now subject to more audits, on‑site inspections and criminal investigations.

For companies and their management, these changes entail an increase in liability exposure. Even minor deficiencies in the implementation of sanctions requirements may now trigger criminal liability immediately due to the elimination of the grace period. The extension of criminal liability to reckless conduct and the imposition of reporting obligations further amplify this risk. In addition, corporate fines may reach levels that pose an existential threat. While the legislative objective is not to penalise compliant companies, the focus lies firmly on the effective enforcement of existing sanctions. As a result, companies are prioritising sanctions compliance and seeking to manage the growing regulatory density and associated risks through targeted measures, including robust screening procedures, internal compliance programmes and staff training.

Geopolitical crises drive activity in the defence sector and stimulate innovation in dual‑use technologies. Nevertheless, the criminal law framework governing foreign trade restrictions and licensing requirements remains insufficiently familiar to many companies, despite rigorous enforcement by the authorities. Accurate, yet often complex, classification of goods (e.g. war weapons, military equipment or dual‑use items) is therefore of central importance.

Against this backdrop, the planned reform of EU foreign direct investment (FDI) screening underlines the trend towards preventive regulation of sensitive technologies, strengthened by criminal enforcement mechanisms and aimed at the protection of critical know‑how. This is to be achieved through the establishment of minimum standards for investment screenings in areas such as dual‑use items, critical technologies and critical infrastructure.

Anti‑money laundering (AML)

A comparable increase in regulatory density and enforcement intensity can be observed in anti‑money laundering laws. At both EU and national level, requirements are expanded and refined as part of a comprehensive strategy to combat money laundering and terrorist financing.

The emphasis on effective enforcement is reflected in the establishment of the new EU Anti‑Money Laundering Authority (AMLA), which has been headquartered in Frankfurt since 1 July 2025. In cooperation with national authorities, AMLA ensures consistent application of AML rules and strengthens coordination among national Financial Intelligence Units (FIUs). In addition, the EU AML Package finalised in 2024 establishes a new regulatory framework for anti‑money laundering at European level. At its core is the AML Regulation (Regulation (EU) 2024/1624), which will apply from 10 July 2027 and will largely replace national AML statutes, harmonising AML and counter‑terrorist financing obligations across all Member States. This framework is complemented by the AMLA Regulation (Regulation (EU) 2024/1620), AMLD6 (Directive (EU) 2024/1640), which requires transposition into national law, and the recast Transfer of Funds Regulation (TFR) (Regulation (EU) 2023/1113), which has covered crypto‑assets since 30 December 2024.

At national level, reform efforts continue. By way of example, the new German Money Laundering Reporting Regulation (GwGMeldV), effective as of 1 March 2026, clarifies and tightens the requirements for submitting suspicious transaction reports pursuant to section 43 of the German Anti‑Money Laundering Act (GwG). These developments entail considerable criminal and administrative liability risks. Obliged entities are required to report suspicious transactions without delay, including those involving crypto‑assets. Failures, delays or errors in reporting may result in administrative fines, while the execution of a transaction despite existing reporting obligations may give rise to criminal liability for (reckless) money laundering under section 261 of the German Criminal Code (StGB).

Of relevance is the judgment of the Court of Justice of the European Union (CJEU) of 29 January 2026 (C‑291/24). The Court confirmed direct corporate liability for infringements of EU AML rules resulting from organisational, supervisory or control failures, without the need to identify a responsible individual. This challenges the traditional national attribution model under section 30 of the German Administrative Offences Act (OWiG) and reinforces a liability concept that focuses less on individual fault and more on structural deficiencies.

From a practical perspective, these developments constitute a tightening of requirements. Despite the objective of harmonisation, companies face implementation challenges arising from pending EU implementing measures, parallel national reforms and intensified supervisory enforcement. Effective compliance structures are becoming the decisive line of defence against corporate‑level allegations, as demonstrated by the CJEU’s approach, under which deficiencies in organisation, supervision or control may alone suffice to establish liability.

Shifting liability concepts and increasing corporate fines

These developments reflect a trend toward stricter corporate sanctioning. Section 30 of OWiG is losing its relevance where EU law is applied. As illustrated by the CJEU judgment of 29 January 2026 (C‑291/24), recent case law paves the way for corporate liability independent of individual fault, calling into question the national attribution model. In areas such as data protection — where supervisory authorities have imposed substantial fines based on organisational deficiencies under the GDPR — and anti‑money laundering, this shift is already evident in enforcement practice and judicial decisions (CJEU judgment of 5 December 2023 (C‑807/21)).

Legislative initiatives also envisage higher corporate fines. While sanctions law has already introduced increased penalty ceilings, the implementation of EU directives — notably in the field of environmental criminal law (Directive (EU) 2024/1203) — may extend this approach to general administrative offences. Current reform proposals to implement the EU environmental crime directive provide for a fourfold increase in maximum fines — up to EUR 40 million for intentional and EUR 20 million for negligent violations. These changes would affect not only environmental law, but all offences falling within the scope of corporate liability under section 30 of OWiG. The declared aim is to ensure “effective, proportionate and dissuasive” sanctions and to align corporate fines with those applicable under related criminal and regulatory regimes.

Conclusion

These developments do not merely represent an expansion of individual criminal or administrative offences; rather, they indicate a fundamental shift in the regulatory handling of corporate risk. Notably, the substantive objectives of the failed German Corporate Sanctions Act (Verbandssanktionengesetz) — which remained unadopted during the previous legislative period — are now being realised through EU‑driven regulatory requirements, effectively achieving through the back door what could not be accomplished through domestic legislation. Commercial criminal law is evolving into an instrument of preventive behavioural regulation. The focus is no longer solely on individual misconduct, but on the organisational resilience and governance structures of companies. Compliance thus moves from a supportive function to a central determinant of liability exposure. For businesses, this marks a gradual paradigm shift: rising regulatory density, intensified enforcement and evolving liability standards mean that compliance is assessed not only on the basis of specific infringements, but also on the adequacy and effectiveness of the internal structures, processes and controls in place.