Germany (DE)
Lead Signal
Germany's payments regulatory posture has shifted decisively toward enforcement across 2025-26, and this baseline cycle captures that turn across the full module spine. The single most consequential read of the operating environment is that BaFin has moved from rule-setting to active enforcement on multiple fronts simultaneously. DORA (Reg (EU) 2022/2554) has been directly applicable since 17 Jan 2025, supplemented domestically by the Finanzmarktdigitalisierungsgesetz (FinmadiG) amending KWG/KAGB/WpHG/ZAG; BaFin is Germany's national ICT incident reporting hub with a four-hour initial notification deadline via the BaFin-MVP portal, and over 600 serious ICT incidents have been registered since Jan 2025 (63% third-party-linked). The pivotal datapoint is that BaFin issued its first DORA enforcement notice in Q3 2025 — a EUR 450,000 fine for inadequate ICT third-party risk documentation. That first fine, taken together with the closed MiCAR grandfathering window and BaFin's record EUR 45m AML fine, signals a post-Wirecard tightening that raises compliance cost across both bank and non-bank PSPs.
The enforcement turn is reinforced on the AML axis. Germany now hosts the EU Anti-Money-Laundering Authority (AMLA) in Frankfurt, operational from 1 July 2025, which directly oversees high-risk institutions and coordinates national supervisors — a development carried here as a Sentinel.gi-fed position rather than original WPM illicit-finance analysis. The convergence of AMLA's Frankfurt go-live, the first DORA fine, and the MiCAR grandfathering close concentrates regulatory intensity into the 2025-26 window, with the jurisdiction risk direction assessed as tightening.
Outlook
The near-term trajectory is one of accreting supervisory intensity. The ECB Governing Council moved the digital euro to its next phase on 29 October 2025, targeting a potential first issuance during 2029 (assuming Regulation adoption in 2026), with pilots potentially from mid-2027; in parallel, the bank-led Wero wallet expanded to online-shop payments from November 2025, and EPI's leadership has publicly framed the digital euro as risking crowding-out of private solutions like Wero. This parallel CBDC and bank-led wallet pair creates strategic uncertainty that German operators must navigate in A2A and wallet roadmaps. National BAIT/VAIT/KAIT/ZAIT circulars are expected to transition into DORA unified standards, some to 1 Jan 2027, and the PSR/PSD3 package is expected to enter force in 2026-H2. The standing read is a tightening jurisdiction in which the bank-PSP versus non-bank PI/EMI access split remains the analytical spine across licensing, safeguarding, settlement access and correspondent banking.
Other Developments
On stablecoins, the standing position is that euro stablecoins are regulated as e-money tokens under MiCAR, with Germany having enacted the Kryptomaerkteaufsichtsgesetz (KMAG) to implement MiCAR domestically and arm BaFin with name-and-warn powers and authority to suspend or prohibit non-compliant offerings. Germany used a 12-month MiCAR grandfathering window that closed end-2025, against full 18-month windows in France, Malta and Luxembourg to July 2026; Ethena Labs ceased its German subsidiary and declined German MiCA authorisation after BaFin scrutiny. On 1 July 2025 BaFin granted AllUnity an EMI licence to issue EURAU, positioned as the first euro stablecoin in Germany fully MiCA-authorised. This W2 position is deliberately held at Assessed: an ownership-structure discrepancy was flagged in challenge and there is no Tier-1 BaFin register or press citation in the findings, so the joint-venture parties are not asserted here pending verification against the BaFin ZAG register.
On instant payments, the EU Instant Payments Regulation (adopted 13 March 2024) requires euro PSPs to receive instant credit transfers from 9 Jan 2025 and to send from 9 Oct 2025; SCT Inst settles up to EUR 100,000 in around ten seconds. The outgoing send mandate makes instant euro transfers universal across euro PSPs and reshapes retail rail economics. High-value and wholesale settlement runs through the Eurosystem TARGET family operated by the Bundesbank, with the unified ECMS added in June 2025, and Germany running a structurally large positive TARGET balance of around EUR 1.06 trillion as of 31 Aug 2025.
On consumer protection, German rules rest on PSD2 (via ZAG and BGB §§675c ff.): unauthorised payments are refundable within one bank working day and payer card liability is capped at EUR 50. Critically, APP/authorised-push-payment fraud has no general mandatory reimbursement regime; the PSR/PSD3 deal concluded 27 November 2025 introduces only a narrow reimbursement duty limited to PSP-impersonation (spoofing) fraud, leaving most investment and pig-butchering scams outside mandatory reimbursement. This leaves German PSPs with materially lighter APP-fraud liability than UK peers.
Commercially, the W13 ledger shows acquiring consolidation and A2A repositioning. On 12 March 2026 Unzer Group acquired AllCash's point-of-sale operations in Plauen, adding 500+ terminals and around 2.5m annual transactions to expand in eastern Germany, with the deal value undisclosed. Mollie agreed to acquire London-based A2A specialist GoCardless for EUR 1.1bn in stock, valuing the combined group at EUR 4.1bn. Berlin BaaS provider Solaris raised a Series G of EUR 140m in February 2025. The Mollie-GoCardless and several other commercial signals rest substantially on Tier-4 sourcing and require primary-source verification.
Cross-Monitor Connections
Two surfaces route to the Financial Intelligence Monitor. The W11 AML/CFT surface — AMLA's Frankfurt go-live, persistent cash-economy and real-estate laundering exposure, and the payment-gateway choke point post-Wirecard — is Sentinel-fed; any original illicit-finance or sanctions-evasion assessment beyond the carried Sentinel position belongs to FIM. Separately, the EURAU euro stablecoin and the explored TIPS interlinking with India's UPI carry potential illicit-finance and sanctions-evasion significance that should be assessed by FIM rather than treated as a WPM conclusion.
Domains
14 regulatory modules · click to expand the full sub-briefLicensing, Authorisation & Market Access
ConfirmedGermany authorises payment institutions (PIs) under ZAG §10 and e-money institutions (EMIs) under ZAG §11 within the Zahlungsdiensteaufsichtsgesetz, which transposes PSD2/EMD2; account information service providers (AISPs) register only under §34.
Stablecoins & Digital Money
AssessedMiCAR (Reg (EU) 2023/1114) is directly applicable, and Germany enacted the Kryptomaerkteaufsichtsgesetz (KMAG) to implement MiCAR domestically and arm BaFin with name-and-warn powers and authority to suspend or prohibit non-compliant offerings.
Operational Resilience & Critical Infrastructure
ConfirmedDORA (Reg (EU) 2022/2554) has been directly applicable since 17 Jan 2025, supplemented domestically by the Finanzmarktdigitalisierungsgesetz (FinmadiG) amending KWG/KAGB/WpHG/ZAG.
Commercial Intelligence (M&A, Investment & Product) — trailing 12 months
AssessedThis module renders discrete commercial events.
Conduct, Safeguarding & Promotions
ConfirmedZAG §§17-18 require PIs and EMIs to safeguard customer and e-money funds either by insolvency-proof segregation in a trust account or low-risk liquid assets, or by insurance or guarantee from an insurer or credit institution; §27 requires proper business organisation.
Scheme & Network Compliance
ConfirmedThe Bundesbank independently oversees the domestic girocard debit scheme — the umbrella brand of the German Banking Industry Committee (DK) — via an MoU with the DK, while international schemes (Visa Europe, Mastercard Europe) are overseen by Eurosystem expert teams.
Full per-domain detail — all 14 modules
W1aConfirmedLicensing, Authorisation & Market Access
see this theme across all jurisdictions →5 claimsBaFin authorises PIs (ZAG §10) and EMIs (ZAG §11); AISPs register under §34; bank-PSP vs non-bank PI/EMI core split; EWR passporting available.
Periodic update 2026-07-08T06:48:19Z
Licensing, Authorisation & Market Access
The German licensing and market-access environment is in a period of structured transition driven by the advancing PSD3 and Payment Services Regulation legislative package at the EU level and the continuing operation of the Zahlungsdiensteaufsichtsgesetz at the national level.
**PSD3/PSR Legislative Progression**
On 17 April 2026, the Council of the EU issued a formal 'I' Item Note circulating the final compromise texts of PSD3 and the PSR to COREPER for approval. This followed provisional political agreement between the Council and the European Parliament reached in November 2025. The issuance of the 'I' Item Note is a procedural signal of imminent formal adoption: 'I' Items are placed on the Council agenda for approval without debate, indicating that the text is considered settled at the political level. Formal adoption by both institutions is the next step before the package enters the Official Journal and the transposition clock begins for member states.
For Germany, the significance of this progression is immediate and operational. BaFin has flagged that PSD3 expectations will be reflected in new authorisation files from 2026 onward, meaning that firms currently in the authorisation pipeline — or planning to enter it — are already being assessed against a forward-looking standard that anticipates the PSD3 framework, even before formal transposition.
**EMI Reauthorisation: The End of the EMD2 Regime**
The most structurally significant licensing change embedded in PSD3 for the German non-bank payment sector is the elimination of the separate Electronic Money Directive 2 regime. Under PSD3, EMIs are reclassified as a sub-category of payment institutions, and existing EMIs are required to seek reauthorisation as PIs. This is not a grandfathering arrangement: it is a mandatory reauthorisation process that will require affected firms to demonstrate compliance with the PI authorisation standard, which carries different — and in several respects more demanding — requirements than the EMD2 track.
For Germany, where EMIs are currently authorised under the ZAG's EMI provisions, this creates a defined transition task. The ZAG transposes both PSD2 and EMD2 and governs BaFin's authorisation of both PIs and EMIs. The reauthorisation requirement means that the ZAG's EMI track will effectively be wound down as a standalone licensing category once PSD3 is transposed into German law. Firms that have built their operating models around the EMI licence — including those using the EMI framework for e-money issuance in conjunction with payment account services — will need to assess whether their current authorisation scope maps cleanly onto the PI sub-category structure or whether material changes to their regulatory perimeter are required.
The bank versus non-bank distinction is directly relevant here. Credit institutions authorised under the KWG are not affected by the EMI reauthorisation requirement; the structural change falls entirely on non-bank PIs and EMIs. This asymmetry reinforces the existing market-access differential between bank and non-bank payment service providers in Germany, at least during the transition period.
**BaFin Authorisation Practice**
BaFin's forward-signalling on PSD3 expectations in new authorisation files is assessed as a practical anticipatory measure rather than a formal regulatory instrument. The ZAG remains the operative licensing statute until PSD3 is transposed. However, the signal that BaFin is already calibrating its authorisation assessments to PSD3 expectations means that firms seeking new PI or EMI authorisations in Germany in 2026 are effectively operating in a dual-standard environment: formally assessed under ZAG, but with BaFin applying forward-looking PSD3 criteria in its substantive review. This creates planning complexity for applicants, particularly on substance requirements, governance standards, and the safeguarding architecture that PSD3 will mandate.
Outlook
The near-term outlook for W1a in Germany is one of accelerating transition. Formal PSD3/PSR adoption is expected to follow the COREPER approval process, after which the transposition period will begin. BaFin's anticipatory posture on authorisation files means the practical impact of PSD3 on German licensing is already being felt. The EMI reauthorisation requirement is the single most operationally significant change for the non-bank sector and will require affected firms to initiate transition planning well in advance of the transposition deadline. The coverage gap on DE-specific insolvency-law primary sources for PSD3 safeguarding ring-fencing provisions is noted; that gap is carried forward to the next cycle.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
Licensing, Authorisation & Market Access
Germany authorises payment institutions (PIs) under ZAG §10 and e-money institutions (EMIs) under ZAG §11 within the Zahlungsdiensteaufsichtsgesetz, which transposes PSD2/EMD2; account information service providers (AISPs) register only under §34. BaFin is the single authorising authority, cooperating with the Bundesbank. The core market-access split runs between the bank-PSP (a KWG credit institution) and the non-bank PI/EMI — this distinction drives whether safeguarding or deposit-protection obligations attach, and is the analytical spine of the module. Capital tiers run EUR 20k-125k by service type, and EWR passporting is available to authorised institutions seeking German and wider EEA access. This standing position defines the market-entry routes and capital floors for any payments operator, and the bank versus non-bank split flows directly into the safeguarding obligations addressed in W1b.
Outlook
The licensing architecture is established and stable as standing knowledge. The live pressure on the regime comes less from authorisation mechanics than from the tightening supervisory posture downstream — enforcement intensity in resilience, AML and stablecoin oversight is reshaping the effective cost of holding a German licence rather than the route to obtaining one.
Periodic update 2026-07-07T15:50:56Z
Licensing, Authorisation & Market Access
Germany authorises payment institutions (PIs) under ZAG §10 and e-money institutions (EMIs) under ZAG §11 within the Zahlungsdiensteaufsichtsgesetz, which transposes PSD2/EMD2; account information service providers (AISPs) register only under §34. BaFin is the single authorising authority, cooperating with the Bundesbank. The core market-access split runs between the bank-PSP (a KWG credit institution) and the non-bank PI/EMI — this distinction drives whether safeguarding or deposit-protection obligations attach, and is the analytical spine of the module. Capital tiers run EUR 20k-125k by service type, and EWR passporting is available to authorised institutions seeking German and wider EEA access. This standing position defines the market-entry routes and capital floors for any payments operator, and the bank versus non-bank split flows directly into the safeguarding obligations addressed in W1b.
Outlook
The licensing architecture is established and stable as standing knowledge. The live pressure on the regime comes less from authorisation mechanics than from the tightening supervisory posture downstream — enforcement intensity in resilience, AML and stablecoin oversight is reshaping the effective cost of holding a German licence rather than the route to obtaining one.
Periodic update 2026-07-07T14:06:03Z
Licensing, Authorisation & Market Access
Germany authorises payment institutions (PIs) under ZAG §10 and e-money institutions (EMIs) under ZAG §11 within the Zahlungsdiensteaufsichtsgesetz, which transposes PSD2/EMD2; account information service providers (AISPs) register only under §34. BaFin is the single authorising authority, cooperating with the Bundesbank. The core market-access split runs between the bank-PSP (a KWG credit institution) and the non-bank PI/EMI — this distinction drives whether safeguarding or deposit-protection obligations attach, and is the analytical spine of the module. Capital tiers run EUR 20k-125k by service type, and EWR passporting is available to authorised institutions seeking German and wider EEA access. This standing position defines the market-entry routes and capital floors for any payments operator, and the bank versus non-bank split flows directly into the safeguarding obligations addressed in W1b.
Outlook
The licensing architecture is established and stable as standing knowledge. The live pressure on the regime comes less from authorisation mechanics than from the tightening supervisory posture downstream — enforcement intensity in resilience, AML and stablecoin oversight is reshaping the effective cost of holding a German licence rather than the route to obtaining one.
Read the full sub-brief
Licensing, Authorisation & Market Access
Germany authorises payment institutions (PIs) under ZAG §10 and e-money institutions (EMIs) under ZAG §11 within the Zahlungsdiensteaufsichtsgesetz, which transposes PSD2/EMD2; account information service providers (AISPs) register only under §34. BaFin is the single authorising authority, cooperating with the Bundesbank. The core market-access split runs between the bank-PSP (a KWG credit institution) and the non-bank PI/EMI — this distinction drives whether safeguarding or deposit-protection obligations attach, and is the analytical spine of the module. Capital tiers run EUR 20k-125k by service type, and EWR passporting is available to authorised institutions seeking German and wider EEA access. This standing position defines the market-entry routes and capital floors for any payments operator, and the bank versus non-bank split flows directly into the safeguarding obligations addressed in W1b.
Outlook
The licensing architecture is established and stable as standing knowledge. The live pressure on the regime comes less from authorisation mechanics than from the tightening supervisory posture downstream — enforcement intensity in resilience, AML and stablecoin oversight is reshaping the effective cost of holding a German licence rather than the route to obtaining one.
BaFin authorises PIs (ZAG §10) and EMIs (ZAG §11); AISPs register under §34; bank-PSP vs non-bank PI/EMI core split; EWR passporting available.
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Euro stablecoins regulated as EMTs under MiCAR; KMAG implements MiCAR domestically arming BaFin name-and-warn powers; EURAU (AllUnity) first MiCA-authorised German euro stablecoin (1 July 2025); grandfathering closed end-2025.
Periodic update 2026-07-08T06:48:19Z
Prudential Standards & Capital Requirements
No material signal was identified for Germany under W2 (Prudential Standards and Capital Requirements) this cycle. The PSD3/PSR package carries prudential implications — including changes to own-funds requirements and safeguarding diversification obligations — but no Germany-specific prudential-standards development beyond what is captured under W1a and W12 was resolved this cycle.
Outlook
PSD3 transposition will carry prudential-standards implications for German PIs and EMIs. This module will be updated when DE-specific prudential-standards material is available.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
Stablecoins & Digital Money
MiCAR (Reg (EU) 2023/1114) is directly applicable, and Germany enacted the Kryptomaerkteaufsichtsgesetz (KMAG) to implement MiCAR domestically and arm BaFin with name-and-warn powers and authority to suspend or prohibit non-compliant offerings. Germany used a 12-month MiCAR grandfathering window that closed end-2025, against full 18-month windows in France, Malta and Luxembourg to July 2026; Ethena Labs ceased its German subsidiary and declined German MiCA authorisation after BaFin scrutiny. On 1 July 2025 BaFin granted AllUnity an EMI licence to issue EURAU (token launched 29 July 2025), positioned as the first euro stablecoin in Germany fully MiCA-authorised and 1:1 euro-collateralised with proof-of-reserves disclosures. E-money tokens are regulated as e-money under EMD2/ZAG and as crypto-assets under MiCAR simultaneously; per §11(1) ZAG only CRR credit institutions or licensed EMIs may issue, a position that bears on both bank and non-bank issuers. This first MiCA-authorised euro EMT under a German EMI licence sets a replicable authorisation template for the EEA.
Outlook
The module is held at Assessed. An ownership-structure discrepancy was flagged in challenge — DWS/Flow Traders/Galaxy per CoinDesk and AllUnity versus a Deutsche Boerse variant per Bullish — and there is no Tier-1 BaFin register or press citation in the findings, so the joint-venture parties are deliberately not asserted pending verification against the BaFin ZAG register. The closed grandfathering window and BaFin's enforcement posture create earlier compliance deadlines for crypto and stablecoin operators in Germany than in slower-transitioning member states.
Periodic update 2026-07-07T15:50:56Z
Stablecoins & Digital Money
MiCAR (Reg (EU) 2023/1114) is directly applicable, and Germany enacted the Kryptomaerkteaufsichtsgesetz (KMAG) to implement MiCAR domestically and arm BaFin with name-and-warn powers and authority to suspend or prohibit non-compliant offerings. Germany used a 12-month MiCAR grandfathering window that closed end-2025, against full 18-month windows in France, Malta and Luxembourg to July 2026; Ethena Labs ceased its German subsidiary and declined German MiCA authorisation after BaFin scrutiny. On 1 July 2025 BaFin granted AllUnity an EMI licence to issue EURAU (token launched 29 July 2025), positioned as the first euro stablecoin in Germany fully MiCA-authorised and 1:1 euro-collateralised with proof-of-reserves disclosures. E-money tokens are regulated as e-money under EMD2/ZAG and as crypto-assets under MiCAR simultaneously; per §11(1) ZAG only CRR credit institutions or licensed EMIs may issue, a position that bears on both bank and non-bank issuers. This first MiCA-authorised euro EMT under a German EMI licence sets a replicable authorisation template for the EEA.
Outlook
The module is held at Assessed. An ownership-structure discrepancy was flagged in challenge — DWS/Flow Traders/Galaxy per CoinDesk and AllUnity versus a Deutsche Boerse variant per Bullish — and there is no Tier-1 BaFin register or press citation in the findings, so the joint-venture parties are deliberately not asserted pending verification against the BaFin ZAG register. The closed grandfathering window and BaFin's enforcement posture create earlier compliance deadlines for crypto and stablecoin operators in Germany than in slower-transitioning member states.
Periodic update 2026-07-07T14:06:03Z
Stablecoins & Digital Money
MiCAR (Reg (EU) 2023/1114) is directly applicable, and Germany enacted the Kryptomaerkteaufsichtsgesetz (KMAG) to implement MiCAR domestically and arm BaFin with name-and-warn powers and authority to suspend or prohibit non-compliant offerings. Germany used a 12-month MiCAR grandfathering window that closed end-2025, against full 18-month windows in France, Malta and Luxembourg to July 2026; Ethena Labs ceased its German subsidiary and declined German MiCA authorisation after BaFin scrutiny. On 1 July 2025 BaFin granted AllUnity an EMI licence to issue EURAU (token launched 29 July 2025), positioned as the first euro stablecoin in Germany fully MiCA-authorised and 1:1 euro-collateralised with proof-of-reserves disclosures. E-money tokens are regulated as e-money under EMD2/ZAG and as crypto-assets under MiCAR simultaneously; per §11(1) ZAG only CRR credit institutions or licensed EMIs may issue, a position that bears on both bank and non-bank issuers. This first MiCA-authorised euro EMT under a German EMI licence sets a replicable authorisation template for the EEA.
Outlook
The module is held at Assessed. An ownership-structure discrepancy was flagged in challenge — DWS/Flow Traders/Galaxy per CoinDesk and AllUnity versus a Deutsche Boerse variant per Bullish — and there is no Tier-1 BaFin register or press citation in the findings, so the joint-venture parties are deliberately not asserted pending verification against the BaFin ZAG register. The closed grandfathering window and BaFin's enforcement posture create earlier compliance deadlines for crypto and stablecoin operators in Germany than in slower-transitioning member states.
Read the full sub-brief
Stablecoins & Digital Money
MiCAR (Reg (EU) 2023/1114) is directly applicable, and Germany enacted the Kryptomaerkteaufsichtsgesetz (KMAG) to implement MiCAR domestically and arm BaFin with name-and-warn powers and authority to suspend or prohibit non-compliant offerings. Germany used a 12-month MiCAR grandfathering window that closed end-2025, against full 18-month windows in France, Malta and Luxembourg to July 2026; Ethena Labs ceased its German subsidiary and declined German MiCA authorisation after BaFin scrutiny. On 1 July 2025 BaFin granted AllUnity an EMI licence to issue EURAU (token launched 29 July 2025), positioned as the first euro stablecoin in Germany fully MiCA-authorised and 1:1 euro-collateralised with proof-of-reserves disclosures. E-money tokens are regulated as e-money under EMD2/ZAG and as crypto-assets under MiCAR simultaneously; per §11(1) ZAG only CRR credit institutions or licensed EMIs may issue, a position that bears on both bank and non-bank issuers. This first MiCA-authorised euro EMT under a German EMI licence sets a replicable authorisation template for the EEA.
Outlook
The module is held at Assessed. An ownership-structure discrepancy was flagged in challenge — DWS/Flow Traders/Galaxy per CoinDesk and AllUnity versus a Deutsche Boerse variant per Bullish — and there is no Tier-1 BaFin register or press citation in the findings, so the joint-venture parties are deliberately not asserted pending verification against the BaFin ZAG register. The closed grandfathering window and BaFin's enforcement posture create earlier compliance deadlines for crypto and stablecoin operators in Germany than in slower-transitioning member states.
Euro stablecoins regulated as EMTs under MiCAR; KMAG implements MiCAR domestically arming BaFin name-and-warn powers; EURAU (AllUnity) first MiCA-authorised German euro stablecoin (1 July 2025); grandfathering closed end-2025.
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
W3ConfirmedOperational Resilience & Critical Infrastructure
see this theme across all jurisdictions →4 claimsDORA directly applicable since 17 Jan 2025 + FinmadiG; BaFin national ICT hub, 4-hour deadline; first DORA fine EUR 450k Q3 2025; 600+ incidents registered.
Periodic update 2026-07-08T06:48:19Z
Consumer Protection & Dispute Resolution
No material signal was identified for Germany under W3 (Consumer Protection and Dispute Resolution) this cycle beyond the APP-fraud reimbursement obligations captured under W1b, which carry direct consumer-protection implications. The BaFin consumer fraud warning (7 April 2026) is noted as a dashboard-tier enforcement signal.
Outlook
The PSR's APP-fraud reimbursement framework will be the primary consumer-protection development to track for Germany upon transposition. This module will be updated when DE-specific consumer-protection or dispute-resolution material is available.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
Operational Resilience & Critical Infrastructure
DORA (Reg (EU) 2022/2554) has been directly applicable since 17 Jan 2025, supplemented domestically by the Finanzmarktdigitalisierungsgesetz (FinmadiG) amending KWG/KAGB/WpHG/ZAG. BaFin is Germany's national ICT incident reporting hub with a four-hour initial notification deadline via the BaFin-MVP portal; over 600 serious ICT incidents have been registered since Jan 2025, 63% of them third-party-linked. BaFin issued its first DORA enforcement notice in Q3 2025 — a EUR 450,000 fine for inadequate ICT third-party risk documentation — and the 2026 information register window ran 9-30 March 2026. The four-hour reporting deadline and the now-landed first fine materially raise ICT-resilience compliance cost for German PSPs and their third-party providers, across both bank and non-bank institutions.
Outlook
Resilience is on an escalating trajectory. National BAIT/VAIT/KAIT/ZAIT circulars are expected to transition into DORA unified standards, some to 1 Jan 2027, consolidating the German ICT supervisory stack into the EU framework. With the first enforcement notice issued, the supervisory pattern is now established rather than prospective.
Periodic update 2026-07-07T15:50:56Z
Operational Resilience & Critical Infrastructure
DORA (Reg (EU) 2022/2554) has been directly applicable since 17 Jan 2025, supplemented domestically by the Finanzmarktdigitalisierungsgesetz (FinmadiG) amending KWG/KAGB/WpHG/ZAG. BaFin is Germany's national ICT incident reporting hub with a four-hour initial notification deadline via the BaFin-MVP portal; over 600 serious ICT incidents have been registered since Jan 2025, 63% of them third-party-linked. BaFin issued its first DORA enforcement notice in Q3 2025 — a EUR 450,000 fine for inadequate ICT third-party risk documentation — and the 2026 information register window ran 9-30 March 2026. The four-hour reporting deadline and the now-landed first fine materially raise ICT-resilience compliance cost for German PSPs and their third-party providers, across both bank and non-bank institutions.
Outlook
Resilience is on an escalating trajectory. National BAIT/VAIT/KAIT/ZAIT circulars are expected to transition into DORA unified standards, some to 1 Jan 2027, consolidating the German ICT supervisory stack into the EU framework. With the first enforcement notice issued, the supervisory pattern is now established rather than prospective.
Periodic update 2026-07-07T14:06:03Z
Operational Resilience & Critical Infrastructure
DORA (Reg (EU) 2022/2554) has been directly applicable since 17 Jan 2025, supplemented domestically by the Finanzmarktdigitalisierungsgesetz (FinmadiG) amending KWG/KAGB/WpHG/ZAG. BaFin is Germany's national ICT incident reporting hub with a four-hour initial notification deadline via the BaFin-MVP portal; over 600 serious ICT incidents have been registered since Jan 2025, 63% of them third-party-linked. BaFin issued its first DORA enforcement notice in Q3 2025 — a EUR 450,000 fine for inadequate ICT third-party risk documentation — and the 2026 information register window ran 9-30 March 2026. The four-hour reporting deadline and the now-landed first fine materially raise ICT-resilience compliance cost for German PSPs and their third-party providers, across both bank and non-bank institutions.
Outlook
Resilience is on an escalating trajectory. National BAIT/VAIT/KAIT/ZAIT circulars are expected to transition into DORA unified standards, some to 1 Jan 2027, consolidating the German ICT supervisory stack into the EU framework. With the first enforcement notice issued, the supervisory pattern is now established rather than prospective.
Read the full sub-brief
Operational Resilience & Critical Infrastructure
DORA (Reg (EU) 2022/2554) has been directly applicable since 17 Jan 2025, supplemented domestically by the Finanzmarktdigitalisierungsgesetz (FinmadiG) amending KWG/KAGB/WpHG/ZAG. BaFin is Germany's national ICT incident reporting hub with a four-hour initial notification deadline via the BaFin-MVP portal; over 600 serious ICT incidents have been registered since Jan 2025, 63% of them third-party-linked. BaFin issued its first DORA enforcement notice in Q3 2025 — a EUR 450,000 fine for inadequate ICT third-party risk documentation — and the 2026 information register window ran 9-30 March 2026. The four-hour reporting deadline and the now-landed first fine materially raise ICT-resilience compliance cost for German PSPs and their third-party providers, across both bank and non-bank institutions.
Outlook
Resilience is on an escalating trajectory. National BAIT/VAIT/KAIT/ZAIT circulars are expected to transition into DORA unified standards, some to 1 Jan 2027, consolidating the German ICT supervisory stack into the EU framework. With the first enforcement notice issued, the supervisory pattern is now established rather than prospective.
DORA directly applicable since 17 Jan 2025 + FinmadiG; BaFin national ICT hub, 4-hour deadline; first DORA fine EUR 450k Q3 2025; 600+ incidents registered.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
W13AssessedCommercial Intelligence (M&A, Investment & Product) — trailing 12 months
see this theme across all jurisdictions →5 claimsDE commercial activity centres on acquiring consolidation and pan-European wallet build-out; key events Unzer-AllCash (Mar 2026), Mollie-GoCardless (EUR 1.1bn), Solaris Series G (EUR 140m), SumUp IPO prep.
Periodic update 2026-07-08T06:48:19Z
Commercial Intelligence (M&A, Investment & Product)
This cycle's W13 signal for Germany is substantive across all three commercial-event categories: M&A, investment, and leadership/strategic signalling. The events are rendered from the commercial_events array and are distinct from structural market-analysis (W6) and regulatory product-access themes (W9).
**SBI Holdings / Solaris: Majority Acquisition (M&A, Completed)**
Japan's SBI Holdings acquired a majority stake exceeding 70 percent in Berlin-based Banking-as-a-Service provider Solaris via a EUR 140 million investment round. The transaction ends Solaris's run as an independent unicorn; the firm was previously valued at USD 1.6 billion. The deal is assessed as completed. The amount is publicly disclosed.
Solaris is a non-bank payment institution operating in the BaaS infrastructure segment — it provides banking and payment infrastructure to third-party fintechs and brands under a regulated licence. The SBI acquisition represents a strategic-investor buyout of a German non-bank BaaS infrastructure provider by a major Japanese financial group. The deal rationale is characterised as a majority buyout ending Solaris's independent-unicorn status. The transaction is the most significant German BaaS-sector consolidation event identified this cycle and is consistent with the broader pattern — noted in the key judgments — of German fintech consolidation proceeding through strategic-investor buyouts rather than public listings.
The bank versus non-bank distinction is relevant here: Solaris operates as a non-bank PI/EMI-adjacent infrastructure provider, and its acquisition by a bank-affiliated strategic investor (SBI Holdings operates banking and financial-services businesses in Japan) raises questions about how the regulatory perimeter and BaFin supervisory relationship will evolve post-acquisition.
**Trade Republic: Secondary Transaction (Investment, Completed)**
Trade Republic closed 2025 with a EUR 1.2 billion secondary transaction that valued the firm at EUR 12.5 billion, roughly double its 2022 valuation. The amount is publicly disclosed. Trade Republic is a non-bank neo-broker and financial-ecosystem platform. The secondary transaction — in which existing shareholders sell stakes to new investors rather than the company raising primary capital — signals continued high private-market appetite for German retail-investment platform businesses at elevated valuations, even in the absence of a near-term IPO pathway.
**N26: Leadership Transition (Strategic Signal)**
N26 appointed Mike Dargan, a former UBS executive, as incoming CEO effective April 2026. Both co-founders stepped back from operational roles. N26 is classified as a bank (it holds a full banking licence in Germany). The leadership transition signal is that a public listing for N26 is likely years away. The appointment of an executive with a traditional banking background — rather than a fintech-native or capital-markets-oriented CEO — is consistent with a strategic posture focused on operational consolidation and regulatory relationship management rather than near-term IPO preparation.
**German Fintech/Insurtech Sector: Annual Investment Total**
German fintech and insurtech investment reached approximately EUR 14.2 billion in 2026, proving resilient despite record insolvencies of approximately 24,000 in the broader economy — a ten-year high. Notable raises within this total include Scalable Capital's EUR 155 million Series E and Munich-based AML-technology provider Hawk's USD 56 million raise. The sector-level investment figure is assessed rather than confirmed from a primary source, and the underlying data is sourced from a T4 (industry/commercial) source.
The resilience of fintech investment against a backdrop of broader economic stress is a structural signal: capital continues to flow into German fintech and insurtech businesses even as the wider economy contracts. The Hawk raise — an AML-technology provider — is noted as a commercial event with potential cross-monitor relevance to the W11 AML/CFT module, though W11 analysis is reserved for the Sentinel feed.
Outlook
The German commercial-intelligence picture is characterised by consolidation through strategic-investor buyouts (SBI-Solaris), secondary-market liquidity rather than IPOs (Trade Republic, N26 signal), and continued sector-level investment resilience. The near-term outlook is for further consolidation activity as the BaaS and non-bank PI/EMI sector navigates the PSD3 transition. The W13 commercial-event surface will be updated as new M&A, investment, and product-launch events are identified.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
Commercial Intelligence (M&A, Investment & Product)
This module renders discrete commercial events. On 12 March 2026 Unzer Group completed the acquisition of AllCash's point-of-sale operations in Plauen, Germany, adding 500+ terminals and around 2.5m annual transactions to expand in eastern Germany; the deal value was not publicly disclosed. Mollie agreed (announced late 2025) to acquire London-based A2A specialist GoCardless for EUR 1.1bn in stock (around 7x 2024 revenue), valuing the combined group at EUR 4.1bn — a transaction that reshapes account-to-account in the German-relevant market. Berlin BaaS provider Solaris completed a Series G investment of EUR 140m in February 2025, bringing total funding above EUR 530m and supporting embedded-finance and payments infrastructure. Together these reinforce SME acquiring consolidation and pan-European A2A repositioning.
Outlook
Commercial activity is escalating. The Mollie-GoCardless terms and several other commercial signals rest substantially on Tier-4 commercial-blog sourcing and require primary-source verification before being treated as confirmed; the Unzer-AllCash event is anchored on the company's own press release. Private-company commercial signals carry a deal-announcement over-index risk that is flagged in the gaps register.
Periodic update 2026-07-07T15:50:56Z
Commercial Intelligence (M&A, Investment & Product)
This module renders discrete commercial events. On 12 March 2026 Unzer Group completed the acquisition of AllCash's point-of-sale operations in Plauen, Germany, adding 500+ terminals and around 2.5m annual transactions to expand in eastern Germany; the deal value was not publicly disclosed. Mollie agreed (announced late 2025) to acquire London-based A2A specialist GoCardless for EUR 1.1bn in stock (around 7x 2024 revenue), valuing the combined group at EUR 4.1bn — a transaction that reshapes account-to-account in the German-relevant market. Berlin BaaS provider Solaris completed a Series G investment of EUR 140m in February 2025, bringing total funding above EUR 530m and supporting embedded-finance and payments infrastructure. Together these reinforce SME acquiring consolidation and pan-European A2A repositioning.
Outlook
Commercial activity is escalating. The Mollie-GoCardless terms and several other commercial signals rest substantially on Tier-4 commercial-blog sourcing and require primary-source verification before being treated as confirmed; the Unzer-AllCash event is anchored on the company's own press release. Private-company commercial signals carry a deal-announcement over-index risk that is flagged in the gaps register.
Periodic update 2026-07-07T14:06:03Z
Commercial Intelligence (M&A, Investment & Product)
This module renders discrete commercial events. On 12 March 2026 Unzer Group completed the acquisition of AllCash's point-of-sale operations in Plauen, Germany, adding 500+ terminals and around 2.5m annual transactions to expand in eastern Germany; the deal value was not publicly disclosed. Mollie agreed (announced late 2025) to acquire London-based A2A specialist GoCardless for EUR 1.1bn in stock (around 7x 2024 revenue), valuing the combined group at EUR 4.1bn — a transaction that reshapes account-to-account in the German-relevant market. Berlin BaaS provider Solaris completed a Series G investment of EUR 140m in February 2025, bringing total funding above EUR 530m and supporting embedded-finance and payments infrastructure. Together these reinforce SME acquiring consolidation and pan-European A2A repositioning.
Outlook
Commercial activity is escalating. The Mollie-GoCardless terms and several other commercial signals rest substantially on Tier-4 commercial-blog sourcing and require primary-source verification before being treated as confirmed; the Unzer-AllCash event is anchored on the company's own press release. Private-company commercial signals carry a deal-announcement over-index risk that is flagged in the gaps register.
Read the full sub-brief
Commercial Intelligence (M&A, Investment & Product)
This module renders discrete commercial events. On 12 March 2026 Unzer Group completed the acquisition of AllCash's point-of-sale operations in Plauen, Germany, adding 500+ terminals and around 2.5m annual transactions to expand in eastern Germany; the deal value was not publicly disclosed. Mollie agreed (announced late 2025) to acquire London-based A2A specialist GoCardless for EUR 1.1bn in stock (around 7x 2024 revenue), valuing the combined group at EUR 4.1bn — a transaction that reshapes account-to-account in the German-relevant market. Berlin BaaS provider Solaris completed a Series G investment of EUR 140m in February 2025, bringing total funding above EUR 530m and supporting embedded-finance and payments infrastructure. Together these reinforce SME acquiring consolidation and pan-European A2A repositioning.
Outlook
Commercial activity is escalating. The Mollie-GoCardless terms and several other commercial signals rest substantially on Tier-4 commercial-blog sourcing and require primary-source verification before being treated as confirmed; the Unzer-AllCash event is anchored on the company's own press release. Private-company commercial signals carry a deal-announcement over-index risk that is flagged in the gaps register.
DE commercial activity centres on acquiring consolidation and pan-European wallet build-out; key events Unzer-AllCash (Mar 2026), Mollie-GoCardless (EUR 1.1bn), Solaris Series G (EUR 140m), SumUp IPO prep.
Evidence — 5 structured claims
Key facts
- Content Tier
- D
- Sentinel Feed
- False
Event Findings
Safeguarding of customer/e-money funds is mandated by §§17–18 ZAG: funds must either be segregated in an insolvency-proof trust account or in liquid low-risk assets, or covered by insurance/guarantee from an insurer or credit institution. Conduct rules flow from PSD2 (transposed via ZAG and the German Civil Code, BGB §§675c ff.), including strong customer authentication for online payments, the surcharge ban, and lowered consumer liability (EUR 50) for lost/stolen cards. MaRisk for PSPs has been introduced via BaFin consultation. Supervising authority is BaFin jointly with the Bundesbank.
Periodic update 2026-07-08T06:48:19Z
Conduct, Safeguarding & Financial Promotions
The German conduct environment this cycle is shaped by two distinct but reinforcing developments: an imminent hard deadline on payment-for-order-flow and a substantive expansion of PSP obligations under the incoming PSR framework. A third, dashboard-tier item — BaFin's consumer fraud warning — illustrates the active enforcement-vector environment in which these structural changes are landing.
**PFOF Grandfathering Expiry: Germany's Compliance Cliff-Edge**
Germany is the only EU member state that has continued to exercise the domestic PFOF grandfathering exemption under Article 39a(2) of MiFIR. The EU-wide ban on payment for order flow took effect in March 2024; every other member state is already operating under the prohibition. Germany's exemption — the last one standing across the EU — expires on 30 June 2026. At the time of this cycle's synthesis date of 7 July 2026, that deadline has passed. German brokers and investment firms that were dependent on PFOF revenue are now operating under the EU-wide ban without any domestic carve-out.
The conduct implications are material. PFOF arrangements — under which brokers receive payments from trading venues or market makers in exchange for routing client orders — have been a significant revenue component for German retail-facing investment platforms. The removal of the exemption does not merely eliminate a revenue stream; it requires affected firms to restructure their order-routing arrangements, their best-execution frameworks, and their client-disclosure obligations. The compliance cliff-edge character of this transition — a hard expiry date rather than a phased wind-down — means that firms that delayed restructuring face immediate exposure.
This is a non-bank-sector-dominant issue. The PFOF arrangements at issue are primarily operated by non-bank investment firms and broker-dealers rather than credit institutions, though the distinction between bank and non-bank actors in the German retail-investment platform space is not always clean, particularly for neobanks that offer both payment accounts and investment products.
**PSR: Payee-Name Verification and APP-Fraud Reimbursement**
The Payment Services Regulation introduces two conduct obligations of direct relevance to German PSPs. First, PSPs will be required to verify payee names against IBANs or unique identifiers for credit payments not already covered by the instant-payments rules. This extends verification-of-payee-style checks — already required for euro instant credit transfers under the Amended SEPA Regulation — to the broader credit-transfer universe. The practical effect is that the VoP infrastructure and operational processes that PSPs have built for instant payments will need to be extended to cover standard credit transfers as well.
Second, the PSR introduces expanded APP-fraud reimbursement obligations. PSPs will bear expanded liability for authorised push-payment fraud losses, building on the payee-name verification obligation as a fraud-prevention mechanism. The reimbursement framework under PSR is designed to create stronger incentives for PSPs to invest in fraud-detection and prevention, since the cost of reimbursement falls on the PSP where the verification obligation was not met or where the fraud was not flagged.
Both obligations apply to bank and non-bank PSPs. The bank versus non-bank distinction matters here primarily in terms of operational capacity: credit institutions typically have more developed fraud-detection infrastructure than smaller non-bank PIs and EMIs, meaning the compliance burden of the VoP extension and the reimbursement obligation may fall disproportionately on the non-bank sector in terms of implementation cost relative to scale.
**BaFin Consumer Fraud Warning (Dashboard)**
On 7 April 2026, BaFin issued a consumer warning against a fraudulent identity-fraud application circulating under the name 'FPM MIN' via WhatsApp groups. This is a dashboard-tier item — a discrete enforcement-vector signal rather than a rulemaking or supervisory-policy development. It is noted here because it illustrates the active fraud-vector environment in which PSD3's expanded APP-fraud reimbursement obligations will operate. The Telekommunikationsgesetz section 120 requires telecom providers to block or anonymise spoofed numbers used in such schemes, providing a parallel enforcement mechanism at the network layer.
Outlook
The PFOF deadline has passed; the immediate compliance question for affected German firms is now one of post-deadline posture rather than preparation. The PSR conduct obligations — VoP extension and APP-fraud reimbursement — will become operative upon PSD3/PSR transposition, with BaFin's anticipatory authorisation posture suggesting that the supervisory expectation is already moving ahead of the formal transposition date. The active fraud-vector environment reinforces the operational urgency of the APP-fraud reimbursement framework.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
Conduct, Safeguarding & Financial Promotions
ZAG §§17-18 require PIs and EMIs to safeguard customer and e-money funds either by insolvency-proof segregation in a trust account or low-risk liquid assets, or by insurance or guarantee from an insurer or credit institution; §27 requires proper business organisation. PSD2 conduct rules (via ZAG and BGB §§675c ff.) cap payer card liability at EUR 50, mandate one-working-day refund for unauthorised payments, and impose a surcharge ban. MaRisk for PSPs has been put to BaFin consultation. The safeguarding-mechanism choice and the EUR 50 liability cap directly shape e-money operating cost and consumer-redress exposure for non-bank PSPs — the bank versus non-bank distinction matters here because deposit-taking credit institutions sit outside the §§17-18 safeguarding regime.
Outlook
Safeguarding under the May 2026 rules is the live W1b item, and the MaRisk-for-PSPs consultation signals further conduct-side codification ahead. A noted gap is that financial-promotion enforcement specific to payments has no German analogue to a UK-style approver regime; conduct rests on UWG and BGB, leaving the promotion-enforcement angle comparatively under-developed.
Periodic update 2026-07-07T15:50:56Z
Conduct, Safeguarding & Financial Promotions
ZAG §§17-18 require PIs and EMIs to safeguard customer and e-money funds either by insolvency-proof segregation in a trust account or low-risk liquid assets, or by insurance or guarantee from an insurer or credit institution; §27 requires proper business organisation. PSD2 conduct rules (via ZAG and BGB §§675c ff.) cap payer card liability at EUR 50, mandate one-working-day refund for unauthorised payments, and impose a surcharge ban. MaRisk for PSPs has been put to BaFin consultation. The safeguarding-mechanism choice and the EUR 50 liability cap directly shape e-money operating cost and consumer-redress exposure for non-bank PSPs — the bank versus non-bank distinction matters here because deposit-taking credit institutions sit outside the §§17-18 safeguarding regime.
Outlook
Safeguarding under the May 2026 rules is the live W1b item, and the MaRisk-for-PSPs consultation signals further conduct-side codification ahead. A noted gap is that financial-promotion enforcement specific to payments has no German analogue to a UK-style approver regime; conduct rests on UWG and BGB, leaving the promotion-enforcement angle comparatively under-developed.
Periodic update 2026-07-07T14:06:03Z
Conduct, Safeguarding & Financial Promotions
ZAG §§17-18 require PIs and EMIs to safeguard customer and e-money funds either by insolvency-proof segregation in a trust account or low-risk liquid assets, or by insurance or guarantee from an insurer or credit institution; §27 requires proper business organisation. PSD2 conduct rules (via ZAG and BGB §§675c ff.) cap payer card liability at EUR 50, mandate one-working-day refund for unauthorised payments, and impose a surcharge ban. MaRisk for PSPs has been put to BaFin consultation. The safeguarding-mechanism choice and the EUR 50 liability cap directly shape e-money operating cost and consumer-redress exposure for non-bank PSPs — the bank versus non-bank distinction matters here because deposit-taking credit institutions sit outside the §§17-18 safeguarding regime.
Outlook
Safeguarding under the May 2026 rules is the live W1b item, and the MaRisk-for-PSPs consultation signals further conduct-side codification ahead. A noted gap is that financial-promotion enforcement specific to payments has no German analogue to a UK-style approver regime; conduct rests on UWG and BGB, leaving the promotion-enforcement angle comparatively under-developed.
Read the full sub-brief
Conduct, Safeguarding & Financial Promotions
ZAG §§17-18 require PIs and EMIs to safeguard customer and e-money funds either by insolvency-proof segregation in a trust account or low-risk liquid assets, or by insurance or guarantee from an insurer or credit institution; §27 requires proper business organisation. PSD2 conduct rules (via ZAG and BGB §§675c ff.) cap payer card liability at EUR 50, mandate one-working-day refund for unauthorised payments, and impose a surcharge ban. MaRisk for PSPs has been put to BaFin consultation. The safeguarding-mechanism choice and the EUR 50 liability cap directly shape e-money operating cost and consumer-redress exposure for non-bank PSPs — the bank versus non-bank distinction matters here because deposit-taking credit institutions sit outside the §§17-18 safeguarding regime.
Outlook
Safeguarding under the May 2026 rules is the live W1b item, and the MaRisk-for-PSPs consultation signals further conduct-side codification ahead. A noted gap is that financial-promotion enforcement specific to payments has no German analogue to a UK-style approver regime; conduct rests on UWG and BGB, leaving the promotion-enforcement angle comparatively under-developed.
Safeguarding of customer/e-money funds is mandated by §§17–18 ZAG: funds must either be segregated in an insolvency-proof trust account or in liquid low-risk assets, or covered by insurance/guarantee from an insurer or credit institution. Conduct rules flow from PSD2 (transposed via ZAG and the German Civil Code, BGB §§675c ff.), including strong customer authentication for online payments, the surcharge ban, and lowered consumer liability (EUR 50) for lost/stolen cards. MaRisk for PSPs has been introduced via BaFin consultation. Supervising authority is BaFin jointly with the Bundesbank.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Germany operates the domestic girocard debit scheme (umbrella brand of the German Banking Industry Committee / DK, formerly 'electronic cash'), independently overseen by the Bundesbank under an MoU with the DK; international schemes (Visa Europe, Mastercard Europe) are overseen by Eurosystem teams. The DK sets technical terminal standards via Technical Annex (TA 7.2) and the DC POS 3.0 approval procedure. EU Interchange Fee Regulation (Reg (EU) 2015/751, in force 9 Dec 2015) caps consumer interchange at 0.3% (credit) / 0.2% (debit); PSD2 bans surcharging on regulated cards. PCI DSS 4.0.1 is mandatory since 31 March 2025 for entities handling card data; girocard processors operate to PCI DSS Level 1.
Periodic update 2026-07-08T06:48:19Z
AML/CFT Licensing Conditions & Fit-and-Proper
No material signal was identified for Germany under W4 (AML/CFT Licensing Conditions and Fit-and-Proper) this cycle. BaFin's PSD3-anticipatory posture on new authorisation files is noted as carrying implicit fit-and-proper and AML/CFT-condition implications, but no DE-specific W4 development was resolved.
Outlook
PSD3 transposition will carry AML/CFT licensing-condition implications. This module will be updated when DE-specific material is available.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
Scheme & Network Compliance
The Bundesbank independently oversees the domestic girocard debit scheme — the umbrella brand of the German Banking Industry Committee (DK) — via an MoU with the DK, while international schemes (Visa Europe, Mastercard Europe) are overseen by Eurosystem expert teams. The DK sets terminal standards via Technical Annex TA 7.2 and the DC POS 3.0 approval procedure. The EU IFR caps interchange at 0.3% credit and 0.2% debit; girocard runs around 0.2-0.3%, well below the roughly 1% international level. PCI DSS 4.0.1 has been mandatory since 31 March 2025, and girocard processors operate at PCI DSS Level 1. girocard's sub-1% interchange and the DK terminal-approval regime shape merchant acceptance economics and POS hardware compliance for both bank and non-bank participants in Germany.
Outlook
Scheme and network compliance is stable. The standing pressures are incremental terminal-standard revisions through TA 7.2 and DC POS 3.0 and the ongoing PCI DSS 4.0.1 baseline, rather than structural change.
Periodic update 2026-07-07T15:50:56Z
Scheme & Network Compliance
The Bundesbank independently oversees the domestic girocard debit scheme — the umbrella brand of the German Banking Industry Committee (DK) — via an MoU with the DK, while international schemes (Visa Europe, Mastercard Europe) are overseen by Eurosystem expert teams. The DK sets terminal standards via Technical Annex TA 7.2 and the DC POS 3.0 approval procedure. The EU IFR caps interchange at 0.3% credit and 0.2% debit; girocard runs around 0.2-0.3%, well below the roughly 1% international level. PCI DSS 4.0.1 has been mandatory since 31 March 2025, and girocard processors operate at PCI DSS Level 1. girocard's sub-1% interchange and the DK terminal-approval regime shape merchant acceptance economics and POS hardware compliance for both bank and non-bank participants in Germany.
Outlook
Scheme and network compliance is stable. The standing pressures are incremental terminal-standard revisions through TA 7.2 and DC POS 3.0 and the ongoing PCI DSS 4.0.1 baseline, rather than structural change.
Periodic update 2026-07-07T14:06:03Z
Scheme & Network Compliance
The Bundesbank independently oversees the domestic girocard debit scheme — the umbrella brand of the German Banking Industry Committee (DK) — via an MoU with the DK, while international schemes (Visa Europe, Mastercard Europe) are overseen by Eurosystem expert teams. The DK sets terminal standards via Technical Annex TA 7.2 and the DC POS 3.0 approval procedure. The EU IFR caps interchange at 0.3% credit and 0.2% debit; girocard runs around 0.2-0.3%, well below the roughly 1% international level. PCI DSS 4.0.1 has been mandatory since 31 March 2025, and girocard processors operate at PCI DSS Level 1. girocard's sub-1% interchange and the DK terminal-approval regime shape merchant acceptance economics and POS hardware compliance for both bank and non-bank participants in Germany.
Outlook
Scheme and network compliance is stable. The standing pressures are incremental terminal-standard revisions through TA 7.2 and DC POS 3.0 and the ongoing PCI DSS 4.0.1 baseline, rather than structural change.
Read the full sub-brief
Scheme & Network Compliance
The Bundesbank independently oversees the domestic girocard debit scheme — the umbrella brand of the German Banking Industry Committee (DK) — via an MoU with the DK, while international schemes (Visa Europe, Mastercard Europe) are overseen by Eurosystem expert teams. The DK sets terminal standards via Technical Annex TA 7.2 and the DC POS 3.0 approval procedure. The EU IFR caps interchange at 0.3% credit and 0.2% debit; girocard runs around 0.2-0.3%, well below the roughly 1% international level. PCI DSS 4.0.1 has been mandatory since 31 March 2025, and girocard processors operate at PCI DSS Level 1. girocard's sub-1% interchange and the DK terminal-approval regime shape merchant acceptance economics and POS hardware compliance for both bank and non-bank participants in Germany.
Outlook
Scheme and network compliance is stable. The standing pressures are incremental terminal-standard revisions through TA 7.2 and DC POS 3.0 and the ongoing PCI DSS 4.0.1 baseline, rather than structural change.
Germany operates the domestic girocard debit scheme (umbrella brand of the German Banking Industry Committee / DK, formerly 'electronic cash'), independently overseen by the Bundesbank under an MoU with the DK; international schemes (Visa Europe, Mastercard Europe) are overseen by Eurosystem teams. The DK sets technical terminal standards via Technical Annex (TA 7.2) and the DC POS 3.0 approval procedure. EU Interchange Fee Regulation (Reg (EU) 2015/751, in force 9 Dec 2015) caps consumer interchange at 0.3% (credit) / 0.2% (debit); PSD2 bans surcharging on regulated cards. PCI DSS 4.0.1 is mandatory since 31 March 2025 for entities handling card data; girocard processors operate to PCI DSS Level 1.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Germany's euro corridors run on SEPA (SCT, SCT Inst / SDD) regulated by the Bundesbank and EU SEPA Regulation (260/2012); high-value/wholesale settlement runs through TARGET (T2/RTGS, T2S, TIPS). The EU Instant Payments Regulation (adopted 13 March 2024) mandates incoming instant transfers from Jan 2025 and outgoing from Oct 2025, with SCT Inst settling up to EUR 100,000 within ~10 seconds. Cross-border non-SEPA flows route via SWIFT correspondent banking on ISO 20022 (global standard since March 2023); German consumers face among the higher average eurozone remittance costs. Eurosystem is exploring TIPS interlinking with India's UPI and Switzerland's instant system.
Periodic update 2026-07-08T06:48:19Z
Payment Rails, Settlement Infrastructure & Access
No Germany-specific mobile-money-equivalent rail delta was identified this cycle. The SEPA Instant compliance-assessment transition captured under W9 is the primary rail-adjacent development; it is carried there rather than duplicated here.
Outlook
The SEPA Instant compliance-assessment phase and the PSR's VoP extension are the primary rail-infrastructure developments to track for Germany. This module will be updated when DE-specific rail or settlement-infrastructure material is available.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
Payment Corridor Dynamics
The EU Instant Payments Regulation (adopted 13 March 2024, amending the SEPA Regulation, the cross-border payments regulation, the Settlement Finality Directive and PSD2) requires euro PSPs to receive instant credit transfers from 9 Jan 2025 and to send from 9 Oct 2025; SCT Inst settles up to EUR 100,000 in around ten seconds. High-value and wholesale settlement runs through TARGET (T2 RTGS, T2S, TIPS, plus ECMS since June 2025). Non-SEPA flows route via SWIFT correspondent banking on ISO 20022, and German consumers face among the higher average eurozone remittance costs. The Eurosystem is exploring TIPS interlinking with India's UPI and the Swiss instant system. The outgoing instant-transfer mandate from October 2025 forces all euro PSPs to offer SCT Inst, reshaping retail rail economics and enabling A2A wallet build-out.
Outlook
The SEPA corridor is opening, with instant euro transfers now universal. The DE-Asia non-SEPA corridor remains thin in the evidence base — only directional SWIFT routing and cost statements are captured, with corridor-level pricing and volume granularity absent — though the explored TIPS-UPI interlinking could open that corridor over time.
Periodic update 2026-07-07T15:50:56Z
Payment Corridor Dynamics
The EU Instant Payments Regulation (adopted 13 March 2024, amending the SEPA Regulation, the cross-border payments regulation, the Settlement Finality Directive and PSD2) requires euro PSPs to receive instant credit transfers from 9 Jan 2025 and to send from 9 Oct 2025; SCT Inst settles up to EUR 100,000 in around ten seconds. High-value and wholesale settlement runs through TARGET (T2 RTGS, T2S, TIPS, plus ECMS since June 2025). Non-SEPA flows route via SWIFT correspondent banking on ISO 20022, and German consumers face among the higher average eurozone remittance costs. The Eurosystem is exploring TIPS interlinking with India's UPI and the Swiss instant system. The outgoing instant-transfer mandate from October 2025 forces all euro PSPs to offer SCT Inst, reshaping retail rail economics and enabling A2A wallet build-out.
Outlook
The SEPA corridor is opening, with instant euro transfers now universal. The DE-Asia non-SEPA corridor remains thin in the evidence base — only directional SWIFT routing and cost statements are captured, with corridor-level pricing and volume granularity absent — though the explored TIPS-UPI interlinking could open that corridor over time.
Periodic update 2026-07-07T14:06:03Z
Payment Corridor Dynamics
The EU Instant Payments Regulation (adopted 13 March 2024, amending the SEPA Regulation, the cross-border payments regulation, the Settlement Finality Directive and PSD2) requires euro PSPs to receive instant credit transfers from 9 Jan 2025 and to send from 9 Oct 2025; SCT Inst settles up to EUR 100,000 in around ten seconds. High-value and wholesale settlement runs through TARGET (T2 RTGS, T2S, TIPS, plus ECMS since June 2025). Non-SEPA flows route via SWIFT correspondent banking on ISO 20022, and German consumers face among the higher average eurozone remittance costs. The Eurosystem is exploring TIPS interlinking with India's UPI and the Swiss instant system. The outgoing instant-transfer mandate from October 2025 forces all euro PSPs to offer SCT Inst, reshaping retail rail economics and enabling A2A wallet build-out.
Outlook
The SEPA corridor is opening, with instant euro transfers now universal. The DE-Asia non-SEPA corridor remains thin in the evidence base — only directional SWIFT routing and cost statements are captured, with corridor-level pricing and volume granularity absent — though the explored TIPS-UPI interlinking could open that corridor over time.
Read the full sub-brief
Payment Corridor Dynamics
The EU Instant Payments Regulation (adopted 13 March 2024, amending the SEPA Regulation, the cross-border payments regulation, the Settlement Finality Directive and PSD2) requires euro PSPs to receive instant credit transfers from 9 Jan 2025 and to send from 9 Oct 2025; SCT Inst settles up to EUR 100,000 in around ten seconds. High-value and wholesale settlement runs through TARGET (T2 RTGS, T2S, TIPS, plus ECMS since June 2025). Non-SEPA flows route via SWIFT correspondent banking on ISO 20022, and German consumers face among the higher average eurozone remittance costs. The Eurosystem is exploring TIPS interlinking with India's UPI and the Swiss instant system. The outgoing instant-transfer mandate from October 2025 forces all euro PSPs to offer SCT Inst, reshaping retail rail economics and enabling A2A wallet build-out.
Outlook
The SEPA corridor is opening, with instant euro transfers now universal. The DE-Asia non-SEPA corridor remains thin in the evidence base — only directional SWIFT routing and cost statements are captured, with corridor-level pricing and volume granularity absent — though the explored TIPS-UPI interlinking could open that corridor over time.
Germany's euro corridors run on SEPA (SCT, SCT Inst / SDD) regulated by the Bundesbank and EU SEPA Regulation (260/2012); high-value/wholesale settlement runs through TARGET (T2/RTGS, T2S, TIPS). The EU Instant Payments Regulation (adopted 13 March 2024) mandates incoming instant transfers from Jan 2025 and outgoing from Oct 2025, with SCT Inst settling up to EUR 100,000 within ~10 seconds. Cross-border non-SEPA flows route via SWIFT correspondent banking on ISO 20022 (global standard since March 2023); German consumers face among the higher average eurozone remittance costs. Eurosystem is exploring TIPS interlinking with India's UPI and Switzerland's instant system.
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Germany is one of Europe's most fragmented retail banking markets, structured into commercial banks (Deutsche Bank/Postbank, Commerzbank, UniCredit HVB), savings banks (Sparkassen, DekaBank, Landesbanken) and cooperative banks. Payments are cash- and bank-transfer-heavy: cash still ~51% of POS purchases (2023), girocard the dominant domestic debit scheme (~100m cards), PayPal leading online wallets, and invoice/Rechnungskauf and BNPL (Klarna, Ratepay) culturally entrenched. The non-bank PSP layer includes 90+ PIs / 10+ EMIs plus BaaS players (Solaris), neobanks (N26) and acquirers (Unzer). Post-Wirecard, BaFin oversight tightened sharply.
Periodic update 2026-07-08T06:48:19Z
Market Structure & Competition
No material signal was identified for Germany under W6 (Market Structure and Competition) this cycle as a standalone structural-analysis item. The SBI-Solaris acquisition and the broader German fintech consolidation pattern are commercial-intelligence events carried under W13. Structural M&A trend analysis for the German BaaS and fintech sector will be developed as the consolidation pattern accretes across cycles.
Outlook
The German fintech consolidation pattern — strategic-investor buyouts rather than IPOs — is a structural market-structure development to track. This module will be updated when DE-specific competition or market-structure regulatory material is available.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
Industry Structure & Commercial Dynamics
Germany is one of Europe's most fragmented retail banking markets, spanning commercial banks, around 349 savings banks (Sparkassen) and Landesbanken, and cooperative banks. Payments are cash- and bank-transfer-heavy: cash accounted for around 51% of POS purchases in 2023, girocard is the dominant domestic debit scheme, PayPal leads online at around 46% preference, and invoice (Rechnungskauf) and BNPL (Klarna, Ratepay) methods are entrenched. The non-bank PSP layer includes 90+ PIs and 10+ EMIs plus BaaS (Solaris), neobanks (N26) and acquirers (Unzer). Post-Wirecard, BaFin oversight tightened sharply. This cash-heavy, fragmented structure plus entrenched invoice and BNPL methods shapes product-market fit for any payments entrant.
Outlook
The structural profile is stable as standing market analysis. Note that specific announced deals and funding rounds are carried as discrete events in W13; this module holds the structural read rather than individual transactions.
Periodic update 2026-07-07T15:50:56Z
Industry Structure & Commercial Dynamics
Germany is one of Europe's most fragmented retail banking markets, spanning commercial banks, around 349 savings banks (Sparkassen) and Landesbanken, and cooperative banks. Payments are cash- and bank-transfer-heavy: cash accounted for around 51% of POS purchases in 2023, girocard is the dominant domestic debit scheme, PayPal leads online at around 46% preference, and invoice (Rechnungskauf) and BNPL (Klarna, Ratepay) methods are entrenched. The non-bank PSP layer includes 90+ PIs and 10+ EMIs plus BaaS (Solaris), neobanks (N26) and acquirers (Unzer). Post-Wirecard, BaFin oversight tightened sharply. This cash-heavy, fragmented structure plus entrenched invoice and BNPL methods shapes product-market fit for any payments entrant.
Outlook
The structural profile is stable as standing market analysis. Note that specific announced deals and funding rounds are carried as discrete events in W13; this module holds the structural read rather than individual transactions.
Periodic update 2026-07-07T14:06:03Z
Industry Structure & Commercial Dynamics
Germany is one of Europe's most fragmented retail banking markets, spanning commercial banks, around 349 savings banks (Sparkassen) and Landesbanken, and cooperative banks. Payments are cash- and bank-transfer-heavy: cash accounted for around 51% of POS purchases in 2023, girocard is the dominant domestic debit scheme, PayPal leads online at around 46% preference, and invoice (Rechnungskauf) and BNPL (Klarna, Ratepay) methods are entrenched. The non-bank PSP layer includes 90+ PIs and 10+ EMIs plus BaaS (Solaris), neobanks (N26) and acquirers (Unzer). Post-Wirecard, BaFin oversight tightened sharply. This cash-heavy, fragmented structure plus entrenched invoice and BNPL methods shapes product-market fit for any payments entrant.
Outlook
The structural profile is stable as standing market analysis. Note that specific announced deals and funding rounds are carried as discrete events in W13; this module holds the structural read rather than individual transactions.
Read the full sub-brief
Industry Structure & Commercial Dynamics
Germany is one of Europe's most fragmented retail banking markets, spanning commercial banks, around 349 savings banks (Sparkassen) and Landesbanken, and cooperative banks. Payments are cash- and bank-transfer-heavy: cash accounted for around 51% of POS purchases in 2023, girocard is the dominant domestic debit scheme, PayPal leads online at around 46% preference, and invoice (Rechnungskauf) and BNPL (Klarna, Ratepay) methods are entrenched. The non-bank PSP layer includes 90+ PIs and 10+ EMIs plus BaaS (Solaris), neobanks (N26) and acquirers (Unzer). Post-Wirecard, BaFin oversight tightened sharply. This cash-heavy, fragmented structure plus entrenched invoice and BNPL methods shapes product-market fit for any payments entrant.
Outlook
The structural profile is stable as standing market analysis. Note that specific announced deals and funding rounds are carried as discrete events in W13; this module holds the structural read rather than individual transactions.
Germany is one of Europe's most fragmented retail banking markets, structured into commercial banks (Deutsche Bank/Postbank, Commerzbank, UniCredit HVB), savings banks (Sparkassen, DekaBank, Landesbanken) and cooperative banks. Payments are cash- and bank-transfer-heavy: cash still ~51% of POS purchases (2023), girocard the dominant domestic debit scheme (~100m cards), PayPal leading online wallets, and invoice/Rechnungskauf and BNPL (Klarna, Ratepay) culturally entrenched. The non-bank PSP layer includes 90+ PIs / 10+ EMIs plus BaaS players (Solaris), neobanks (N26) and acquirers (Unzer). Post-Wirecard, BaFin oversight tightened sharply.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
The defining payments-litigation complex remains Wirecard: the 2020 insolvency (EUR 1.9bn missing) drove the Financial Market Integrity Strengthening Act (FISG, 2021) expanding BaFin powers; the Munich Regional Court found former board members liable for EUR 140m in 2024/2025 and criminal proceedings continue. Phishing/unauthorised-payment case law under BGB §§675u–675w (PSD2) is active, with the BGH (5 Mar 2024, XI ZR 107/22) placing the burden of proving authorisation/SCA on the bank. Enforcement intensified in 2025: BaFin levied a record EUR 45m AML fine and a EUR 25m greenwashing fine; 'Operation Chargeback' (Nov 2025) dismantled a EUR 300m card-fraud network routed partly through German gateways.
Periodic update 2026-07-08T06:48:19Z
Cross-Border Payments & Remittances
No material signal was identified for Germany under W7 (Cross-Border Payments and Remittances) this cycle. No corridor-tracker entries were generated for DE this cycle.
Outlook
This module will be updated when DE-specific cross-border payments or remittances regulatory material is available.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
Legal & Litigation
The defining German payments-litigation complex is Wirecard: the 2020 insolvency (EUR 1.9bn missing) drove the FISG (2021) expanding BaFin powers. The Munich Regional Court (5 Sept 2024, 5 HK O 17452/21) found three former board members liable for EUR 140m for negligent fiduciary breach, with criminal proceedings continuing. The BGH (5 March 2024, XI ZR 107/22) placed the burden of proving authorisation and SCA on the bank under BGB §§675u-675w. At end-2025 BaFin levied a record EUR 45m AML fine and a EUR 25m greenwashing fine, and 'Operation Chargeback' (Nov 2025) dismantled a EUR 300m card-fraud network across 193 countries. The BGH SCA burden-of-proof ruling and the FISG-empowered BaFin shape PSP liability exposure and supervisory risk for both bank and non-bank operators.
Outlook
The litigation environment is stable but consequential, anchored by the durable BGH SCA burden allocation. Operation Chargeback rests on a single lower-tier source and is carried as illustrative rather than as a load-bearing finding.
Periodic update 2026-07-07T15:50:56Z
Legal & Litigation
The defining German payments-litigation complex is Wirecard: the 2020 insolvency (EUR 1.9bn missing) drove the FISG (2021) expanding BaFin powers. The Munich Regional Court (5 Sept 2024, 5 HK O 17452/21) found three former board members liable for EUR 140m for negligent fiduciary breach, with criminal proceedings continuing. The BGH (5 March 2024, XI ZR 107/22) placed the burden of proving authorisation and SCA on the bank under BGB §§675u-675w. At end-2025 BaFin levied a record EUR 45m AML fine and a EUR 25m greenwashing fine, and 'Operation Chargeback' (Nov 2025) dismantled a EUR 300m card-fraud network across 193 countries. The BGH SCA burden-of-proof ruling and the FISG-empowered BaFin shape PSP liability exposure and supervisory risk for both bank and non-bank operators.
Outlook
The litigation environment is stable but consequential, anchored by the durable BGH SCA burden allocation. Operation Chargeback rests on a single lower-tier source and is carried as illustrative rather than as a load-bearing finding.
Periodic update 2026-07-07T14:06:03Z
Legal & Litigation
The defining German payments-litigation complex is Wirecard: the 2020 insolvency (EUR 1.9bn missing) drove the FISG (2021) expanding BaFin powers. The Munich Regional Court (5 Sept 2024, 5 HK O 17452/21) found three former board members liable for EUR 140m for negligent fiduciary breach, with criminal proceedings continuing. The BGH (5 March 2024, XI ZR 107/22) placed the burden of proving authorisation and SCA on the bank under BGB §§675u-675w. At end-2025 BaFin levied a record EUR 45m AML fine and a EUR 25m greenwashing fine, and 'Operation Chargeback' (Nov 2025) dismantled a EUR 300m card-fraud network across 193 countries. The BGH SCA burden-of-proof ruling and the FISG-empowered BaFin shape PSP liability exposure and supervisory risk for both bank and non-bank operators.
Outlook
The litigation environment is stable but consequential, anchored by the durable BGH SCA burden allocation. Operation Chargeback rests on a single lower-tier source and is carried as illustrative rather than as a load-bearing finding.
Read the full sub-brief
Legal & Litigation
The defining German payments-litigation complex is Wirecard: the 2020 insolvency (EUR 1.9bn missing) drove the FISG (2021) expanding BaFin powers. The Munich Regional Court (5 Sept 2024, 5 HK O 17452/21) found three former board members liable for EUR 140m for negligent fiduciary breach, with criminal proceedings continuing. The BGH (5 March 2024, XI ZR 107/22) placed the burden of proving authorisation and SCA on the bank under BGB §§675u-675w. At end-2025 BaFin levied a record EUR 45m AML fine and a EUR 25m greenwashing fine, and 'Operation Chargeback' (Nov 2025) dismantled a EUR 300m card-fraud network across 193 countries. The BGH SCA burden-of-proof ruling and the FISG-empowered BaFin shape PSP liability exposure and supervisory risk for both bank and non-bank operators.
Outlook
The litigation environment is stable but consequential, anchored by the durable BGH SCA burden allocation. Operation Chargeback rests on a single lower-tier source and is carried as illustrative rather than as a load-bearing finding.
The defining payments-litigation complex remains Wirecard: the 2020 insolvency (EUR 1.9bn missing) drove the Financial Market Integrity Strengthening Act (FISG, 2021) expanding BaFin powers; the Munich Regional Court found former board members liable for EUR 140m in 2024/2025 and criminal proceedings continue. Phishing/unauthorised-payment case law under BGB §§675u–675w (PSD2) is active, with the BGH (5 Mar 2024, XI ZR 107/22) placing the burden of proving authorisation/SCA on the bank. Enforcement intensified in 2025: BaFin levied a record EUR 45m AML fine and a EUR 25m greenwashing fine; 'Operation Chargeback' (Nov 2025) dismantled a EUR 300m card-fraud network routed partly through German gateways.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Acquiring in Germany operates under the EU IFR (interchange caps) and PSD2/ZAG, with girocard acceptance handled via the DK/DC POS approval regime and international-scheme acquiring (Visa/Mastercard) processed by acquirers offering sub-1% effective rates post-IFR. Chargeback/dispute mechanics follow scheme rulebooks plus PSD2 refund rights. The market shows active consolidation among SME-focused 'tap-pack' acquirers (SumUp, myPOS, Teya, Unzer); high-risk-merchant practices were a central failure in the Wirecard third-party-acquirer model. PCI DSS 4.0.1 governs cardholder data handling for acquirers and processors.
Periodic update 2026-07-08T06:48:19Z
Merchant Acquiring, Onboarding & Chargebacks
The German merchant-acquiring, onboarding, and chargeback vector was not resolved this cycle. This is an explicitly noted coverage gap. The absence of signal on W8 means this cycle is under-specified on a payments-operating-model area that can carry material risk and compliance posture implications for acquiring banks and non-bank payment institutions operating in the German market.
Outlook
This module will be prioritised for resolution in the next cycle. The gap is carried forward.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
Merchant Acquiring & Risk
Acquiring in Germany operates under the EU IFR interchange caps and PSD2/ZAG, with girocard routed through the DK/DC POS regime and international-scheme acquiring at sub-1% effective rates post-IFR. SME 'tap-pack' acquirers (SumUp, Viva.com, myPOS, Square, Dojo, Flatpay) are taking share; myPOS bought Germany's Lavego (70,000 terminals, girocard acceptance) and Unzer is launching POS acceptance via Quickpay/Clearhaus. High-risk-merchant practices were central to the Wirecard third-party-acquirer failure, and PCI DSS 4.0.1 governs cardholder data handling. SME tap-pack consolidation is compressing acquiring margins and reshaping POS distribution, a dynamic concentrated in the non-bank PI/EMI layer.
Outlook
The acquiring market is escalating toward further consolidation. Specific deals — including Unzer's AllCash acquisition — are carried as discrete events in W13, while the structural margin-compression trend sits here.
Periodic update 2026-07-07T15:50:56Z
Merchant Acquiring & Risk
Acquiring in Germany operates under the EU IFR interchange caps and PSD2/ZAG, with girocard routed through the DK/DC POS regime and international-scheme acquiring at sub-1% effective rates post-IFR. SME 'tap-pack' acquirers (SumUp, Viva.com, myPOS, Square, Dojo, Flatpay) are taking share; myPOS bought Germany's Lavego (70,000 terminals, girocard acceptance) and Unzer is launching POS acceptance via Quickpay/Clearhaus. High-risk-merchant practices were central to the Wirecard third-party-acquirer failure, and PCI DSS 4.0.1 governs cardholder data handling. SME tap-pack consolidation is compressing acquiring margins and reshaping POS distribution, a dynamic concentrated in the non-bank PI/EMI layer.
Outlook
The acquiring market is escalating toward further consolidation. Specific deals — including Unzer's AllCash acquisition — are carried as discrete events in W13, while the structural margin-compression trend sits here.
Periodic update 2026-07-07T14:06:03Z
Merchant Acquiring & Risk
Acquiring in Germany operates under the EU IFR interchange caps and PSD2/ZAG, with girocard routed through the DK/DC POS regime and international-scheme acquiring at sub-1% effective rates post-IFR. SME 'tap-pack' acquirers (SumUp, Viva.com, myPOS, Square, Dojo, Flatpay) are taking share; myPOS bought Germany's Lavego (70,000 terminals, girocard acceptance) and Unzer is launching POS acceptance via Quickpay/Clearhaus. High-risk-merchant practices were central to the Wirecard third-party-acquirer failure, and PCI DSS 4.0.1 governs cardholder data handling. SME tap-pack consolidation is compressing acquiring margins and reshaping POS distribution, a dynamic concentrated in the non-bank PI/EMI layer.
Outlook
The acquiring market is escalating toward further consolidation. Specific deals — including Unzer's AllCash acquisition — are carried as discrete events in W13, while the structural margin-compression trend sits here.
Read the full sub-brief
Merchant Acquiring & Risk
Acquiring in Germany operates under the EU IFR interchange caps and PSD2/ZAG, with girocard routed through the DK/DC POS regime and international-scheme acquiring at sub-1% effective rates post-IFR. SME 'tap-pack' acquirers (SumUp, Viva.com, myPOS, Square, Dojo, Flatpay) are taking share; myPOS bought Germany's Lavego (70,000 terminals, girocard acceptance) and Unzer is launching POS acceptance via Quickpay/Clearhaus. High-risk-merchant practices were central to the Wirecard third-party-acquirer failure, and PCI DSS 4.0.1 governs cardholder data handling. SME tap-pack consolidation is compressing acquiring margins and reshaping POS distribution, a dynamic concentrated in the non-bank PI/EMI layer.
Outlook
The acquiring market is escalating toward further consolidation. Specific deals — including Unzer's AllCash acquisition — are carried as discrete events in W13, while the structural margin-compression trend sits here.
Acquiring in Germany operates under the EU IFR (interchange caps) and PSD2/ZAG, with girocard acceptance handled via the DK/DC POS approval regime and international-scheme acquiring (Visa/Mastercard) processed by acquirers offering sub-1% effective rates post-IFR. Chargeback/dispute mechanics follow scheme rulebooks plus PSD2 refund rights. The market shows active consolidation among SME-focused 'tap-pack' acquirers (SumUp, myPOS, Teya, Unzer); high-risk-merchant practices were a central failure in the Wirecard third-party-acquirer model. PCI DSS 4.0.1 governs cardholder data handling for acquirers and processors.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Two parallel innovation tracks dominate: (1) the bank-led Wero wallet (European Payments Initiative), live for P2P since 2024 and rolling into e-commerce from late 2025, with German issuers (Sparkassen, Postbank, Deutsche Bank, ING Germany, Commerzbank, Revolut) and acquirers joining; and (2) the ECB digital euro, which exited its preparation phase on 29 Oct 2025 and entered the next phase, targeting a possible first issuance in 2029 with pilots potentially from mid-2027. ECB selected five providers (incl. Giesecke+Devrient, equensWorldline) for core-component pilots in Oct 2025. Open banking is PSD2-mandated and moving toward PSD3/PSR. Tension exists between Wero/EPI and the digital euro over crowding-out.
Periodic update 2026-07-08T06:48:19Z
Product Innovation & Market Development
This cycle's W9 signal for Germany is anchored in two related but distinct developments: the transition of the EU Instant Payments Regulation into its compliance-assessment phase, and the PSR's extension of Verification of Payee to the full credit-transfer universe.
**IPR Compliance-Assessment Transition**
April 2026 marked a structural transition in the EU Instant Payments Regulation's lifecycle. The reporting cycle shifted from implementation tracking — in which PSPs were assessed on whether they had put in place the technical and operational infrastructure to send and receive instant credit transfers — to compliance assessment, in which PSPs are evaluated on whether they are meeting the IPR's substantive requirements in practice. This transition is significant for the German market because it signals that the SEPA Instant infrastructure is now treated as an operational baseline rather than a development project. The compliance-assessment phase enables the development of new real-time-settlement services and product propositions built on top of the SEPA Instant rail, since the rail's availability and reliability can now be assumed as a regulatory floor rather than a variable.
For German PSPs — both bank and non-bank — the compliance-assessment transition means that the focus of regulatory attention on instant payments shifts from 'have you built it' to 'are you using it correctly and consistently.' This creates both a compliance obligation and a product-development opportunity: PSPs that have invested in SEPA Instant infrastructure can now build differentiated services on top of a mandated, standardised rail.
**PSR: Verification of Payee Extension**
The Payment Services Regulation extends Verification of Payee to all credit transfers, building on the euro instant-credit-transfer VoP regime established under the Amended SEPA Regulation. The existing VoP obligation — which requires PSPs to check payee names against IBANs before executing instant credit transfers — was already a significant operational investment for German PSPs. The PSR's extension of that obligation to standard credit transfers broadens the scope of the VoP infrastructure requirement substantially.
The product-innovation dimension of this development is that VoP, once extended to all credit transfers, becomes a universal feature of the German payment account experience rather than a feature specific to instant-payment products. This creates a baseline expectation for payee-name verification across the full credit-transfer product range, which in turn shapes the product-design and user-experience requirements for German PSPs offering credit-transfer services.
The bank versus non-bank distinction is relevant here in terms of implementation capacity. Credit institutions with established SEPA Instant infrastructure are better positioned to extend VoP to standard credit transfers than smaller non-bank PIs and EMIs that may have built narrower instant-payment capabilities. The PSR's VoP extension therefore carries a disproportionate implementation burden for the non-bank sector.
Outlook
The SEPA Instant compliance-assessment phase and the PSR's VoP extension together define the near-term product-innovation regulatory environment for German PSPs. The compliance-assessment transition creates a stable rail baseline on which new services can be built; the VoP extension creates a universal verification requirement that will shape product design across the credit-transfer product range. Both developments are on a trajectory toward full operationalisation upon PSD3/PSR transposition.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
Product Innovation & Market Development
On 29 October 2025 the ECB Governing Council moved the digital euro to its next phase, targeting a potential first issuance during 2029 (assuming Regulation adoption in 2026), with a pilot exercise and initial transactions potentially from mid-2027; five providers, including Giesecke+Devrient and equensWorldline, were selected in October 2025 to pilot core components (estimated EUR 1.3bn to issuance). In parallel, the bank-led Wero wallet (EPI, live for P2P since July 2024) expanded to online-shop payments from November 2025. EPI CEO Martina Weimert criticised the digital euro as risking crowding-out of private solutions like Wero. These parallel CBDC and bank-led wallet tracks create strategic crowding-out tension for German operators planning A2A and wallet roadmaps.
Outlook
Product development is escalating along two competing rails. The strategic uncertainty for operators turns on how the public digital euro and the private Wero proposition coexist as both mature toward broader retail use.
Periodic update 2026-07-07T15:50:56Z
Product Innovation & Market Development
On 29 October 2025 the ECB Governing Council moved the digital euro to its next phase, targeting a potential first issuance during 2029 (assuming Regulation adoption in 2026), with a pilot exercise and initial transactions potentially from mid-2027; five providers, including Giesecke+Devrient and equensWorldline, were selected in October 2025 to pilot core components (estimated EUR 1.3bn to issuance). In parallel, the bank-led Wero wallet (EPI, live for P2P since July 2024) expanded to online-shop payments from November 2025. EPI CEO Martina Weimert criticised the digital euro as risking crowding-out of private solutions like Wero. These parallel CBDC and bank-led wallet tracks create strategic crowding-out tension for German operators planning A2A and wallet roadmaps.
Outlook
Product development is escalating along two competing rails. The strategic uncertainty for operators turns on how the public digital euro and the private Wero proposition coexist as both mature toward broader retail use.
Periodic update 2026-07-07T14:06:03Z
Product Innovation & Market Development
On 29 October 2025 the ECB Governing Council moved the digital euro to its next phase, targeting a potential first issuance during 2029 (assuming Regulation adoption in 2026), with a pilot exercise and initial transactions potentially from mid-2027; five providers, including Giesecke+Devrient and equensWorldline, were selected in October 2025 to pilot core components (estimated EUR 1.3bn to issuance). In parallel, the bank-led Wero wallet (EPI, live for P2P since July 2024) expanded to online-shop payments from November 2025. EPI CEO Martina Weimert criticised the digital euro as risking crowding-out of private solutions like Wero. These parallel CBDC and bank-led wallet tracks create strategic crowding-out tension for German operators planning A2A and wallet roadmaps.
Outlook
Product development is escalating along two competing rails. The strategic uncertainty for operators turns on how the public digital euro and the private Wero proposition coexist as both mature toward broader retail use.
Read the full sub-brief
Product Innovation & Market Development
On 29 October 2025 the ECB Governing Council moved the digital euro to its next phase, targeting a potential first issuance during 2029 (assuming Regulation adoption in 2026), with a pilot exercise and initial transactions potentially from mid-2027; five providers, including Giesecke+Devrient and equensWorldline, were selected in October 2025 to pilot core components (estimated EUR 1.3bn to issuance). In parallel, the bank-led Wero wallet (EPI, live for P2P since July 2024) expanded to online-shop payments from November 2025. EPI CEO Martina Weimert criticised the digital euro as risking crowding-out of private solutions like Wero. These parallel CBDC and bank-led wallet tracks create strategic crowding-out tension for German operators planning A2A and wallet roadmaps.
Outlook
Product development is escalating along two competing rails. The strategic uncertainty for operators turns on how the public digital euro and the private Wero proposition coexist as both mature toward broader retail use.
Two parallel innovation tracks dominate: (1) the bank-led Wero wallet (European Payments Initiative), live for P2P since 2024 and rolling into e-commerce from late 2025, with German issuers (Sparkassen, Postbank, Deutsche Bank, ING Germany, Commerzbank, Revolut) and acquirers joining; and (2) the ECB digital euro, which exited its preparation phase on 29 Oct 2025 and entered the next phase, targeting a possible first issuance in 2029 with pilots potentially from mid-2027. ECB selected five providers (incl. Giesecke+Devrient, equensWorldline) for core-component pilots in Oct 2025. Open banking is PSD2-mandated and moving toward PSD3/PSR. Tension exists between Wero/EPI and the digital euro over crowding-out.
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Consumer protection in payments rests on PSD2 as transposed via ZAG and BGB §§675c ff., the BGB general civil-law regime, and the UWG. Unauthorised payments are refundable within one bank working day and payer card liability is capped at EUR 50. APP/authorised-push-payment fraud has NO general mandatory reimbursement regime (unlike the UK PSR model): under PSD2/BGB only unauthorised transactions are reimbursable, and the EU PSD3/PSR deal concluded 27 Nov 2025 introduces only a narrow reimbursement duty limited to PSP-impersonation ('spoofing') fraud. Phishing disputes are heavily litigated, with the burden of proving SCA on the bank. ADR/ombudsman routes (Schlichtungsstelle, ECC Germany) and the BGH frame redress.
Periodic update 2026-07-08T06:48:19Z
Digital Assets, Stablecoins & CBDC
No material signal was identified for Germany under W10 (Digital Assets, Stablecoins and CBDC) this cycle. The MiCA framework continues to govern stablecoin and crypto-asset service provider activity in Germany, but no DE-specific W10 development was resolved this cycle.
Outlook
This module will be updated when DE-specific digital-assets, stablecoin, or CBDC regulatory material is available.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
Consumer Protection & APP Fraud
German consumer protection rests on PSD2 (via ZAG and BGB §§675c ff.) and the UWG: unauthorised payments are refundable within one bank working day, and payer card liability is capped at EUR 50. APP/authorised-push-payment fraud has no general mandatory reimbursement regime, unlike the UK PSR model; the PSR/PSD3 deal concluded 27 November 2025 introduces only a narrow reimbursement duty limited to PSP-impersonation (spoofing) fraud, leaving most investment and pig-butchering scams outside mandatory reimbursement. The BGH 2024 ruling places the SCA burden of proof on the bank. The narrow spoofing-only scope leaves German PSPs with materially less APP-fraud liability than UK peers — a key cross-jurisdiction divergence for both bank and non-bank operators.
Outlook
Consumer protection is stable, with the PSR/PSD3 package expected to enter force in 2026-H2 carrying the spoofing-only reimbursement duty and broader PSD3 conduct changes. The absence of a general APP regime remains the defining feature relative to the UK.
Periodic update 2026-07-07T15:50:56Z
Consumer Protection & APP Fraud
German consumer protection rests on PSD2 (via ZAG and BGB §§675c ff.) and the UWG: unauthorised payments are refundable within one bank working day, and payer card liability is capped at EUR 50. APP/authorised-push-payment fraud has no general mandatory reimbursement regime, unlike the UK PSR model; the PSR/PSD3 deal concluded 27 November 2025 introduces only a narrow reimbursement duty limited to PSP-impersonation (spoofing) fraud, leaving most investment and pig-butchering scams outside mandatory reimbursement. The BGH 2024 ruling places the SCA burden of proof on the bank. The narrow spoofing-only scope leaves German PSPs with materially less APP-fraud liability than UK peers — a key cross-jurisdiction divergence for both bank and non-bank operators.
Outlook
Consumer protection is stable, with the PSR/PSD3 package expected to enter force in 2026-H2 carrying the spoofing-only reimbursement duty and broader PSD3 conduct changes. The absence of a general APP regime remains the defining feature relative to the UK.
Periodic update 2026-07-07T14:06:03Z
Consumer Protection & APP Fraud
German consumer protection rests on PSD2 (via ZAG and BGB §§675c ff.) and the UWG: unauthorised payments are refundable within one bank working day, and payer card liability is capped at EUR 50. APP/authorised-push-payment fraud has no general mandatory reimbursement regime, unlike the UK PSR model; the PSR/PSD3 deal concluded 27 November 2025 introduces only a narrow reimbursement duty limited to PSP-impersonation (spoofing) fraud, leaving most investment and pig-butchering scams outside mandatory reimbursement. The BGH 2024 ruling places the SCA burden of proof on the bank. The narrow spoofing-only scope leaves German PSPs with materially less APP-fraud liability than UK peers — a key cross-jurisdiction divergence for both bank and non-bank operators.
Outlook
Consumer protection is stable, with the PSR/PSD3 package expected to enter force in 2026-H2 carrying the spoofing-only reimbursement duty and broader PSD3 conduct changes. The absence of a general APP regime remains the defining feature relative to the UK.
Read the full sub-brief
Consumer Protection & APP Fraud
German consumer protection rests on PSD2 (via ZAG and BGB §§675c ff.) and the UWG: unauthorised payments are refundable within one bank working day, and payer card liability is capped at EUR 50. APP/authorised-push-payment fraud has no general mandatory reimbursement regime, unlike the UK PSR model; the PSR/PSD3 deal concluded 27 November 2025 introduces only a narrow reimbursement duty limited to PSP-impersonation (spoofing) fraud, leaving most investment and pig-butchering scams outside mandatory reimbursement. The BGH 2024 ruling places the SCA burden of proof on the bank. The narrow spoofing-only scope leaves German PSPs with materially less APP-fraud liability than UK peers — a key cross-jurisdiction divergence for both bank and non-bank operators.
Outlook
Consumer protection is stable, with the PSR/PSD3 package expected to enter force in 2026-H2 carrying the spoofing-only reimbursement duty and broader PSD3 conduct changes. The absence of a general APP regime remains the defining feature relative to the UK.
Consumer protection in payments rests on PSD2 as transposed via ZAG and BGB §§675c ff., the BGB general civil-law regime, and the UWG. Unauthorised payments are refundable within one bank working day and payer card liability is capped at EUR 50. APP/authorised-push-payment fraud has NO general mandatory reimbursement regime (unlike the UK PSR model): under PSD2/BGB only unauthorised transactions are reimbursable, and the EU PSD3/PSR deal concluded 27 Nov 2025 introduces only a narrow reimbursement duty limited to PSP-impersonation ('spoofing') fraud. Phishing disputes are heavily litigated, with the burden of proving SCA on the bank. ADR/ombudsman routes (Schlichtungsstelle, ECC Germany) and the BGH frame redress.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
W11AssessedAML/CFT & Financial Crime (Sentinel.gi-fed)
Sentinelsee this theme across all jurisdictions →8 claims[SENTINEL.GI POSITION — payments context only] Germany's AML/CFT regime for the payments sector rests on the Geldwäschegesetz (GwG), implementing the EU AMLDs, supervised by BaFin. The new EU Anti-Money-Laundering Authority (AMLA) commenced operations in Frankfurt on 1 July 2025, directly overseeing high-risk institutions and coordinating national supervisors. Enforcement against payments-adjacent firms is active (e.g. BaFin's EUR 6.5m Solaris SE fine in 2024 for delayed SARs; a record EUR 45m AML fine at end-2025). Payment gateways remain a noted fraud choke point post-Wirecard. WPM carries the Sentinel position only; no original illicit-finance analysis performed.
Periodic update 2026-07-08T06:48:19Z
AML/CFT & Financial Crime (Sentinel Feed)
W11 intelligence for the World Payments Monitor is sourced from the Sentinel.gi feed. No Sentinel-fed AML/CFT delta for Germany was available this cycle. This is an explicitly noted coverage gap. W11 content will be carried and attributed to the Sentinel feed when DE-specific material is returned by that feed. No original AML/CFT analysis is conducted within this module; all W11 intelligence is provenance-linked to the Sentinel source.
Outlook
This module will be updated when the Sentinel feed returns DE-specific AML/CFT material.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
AML/CFT & Financial Crime
This module carries a Sentinel.gi-fed position for payments context only; no original illicit-finance analysis is performed here. Per the Sentinel feed, Germany hosts the EU Anti-Money-Laundering Authority (AMLA) in Frankfurt, operational from 1 July 2025, raising its strategic AML profile; AMLA directly oversees high-risk institutions and coordinates national supervisors. Germany's payments-sector AML rests on the Geldwaeschegesetz (GwG) supervised by BaFin. The Sentinel position notes persistent cash-economy and real-estate laundering exposure, a consolidated federal AML authority being stood up, FATF-compliant status with stable risk direction and a mixed enablement-versus-enforcement posture, and payment gateways remaining a noted fraud choke point post-Wirecard. AMLA's Frankfurt seat and direct-supervision remit raise AML compliance scrutiny for high-risk German payments institutions across bank and non-bank lines. Source: Sentinel.gi feed (sentinel.DE-W11-amla).
Outlook
The AML surface is escalating per the Sentinel feed. Any original illicit-finance assessment, sanctions-evasion analysis, or enforcement deep-dive beyond this carried position is routed to the Financial Intelligence Monitor rather than concluded here.
Periodic update 2026-07-07T15:50:56Z
AML/CFT & Financial Crime
This module carries a Sentinel.gi-fed position for payments context only; no original illicit-finance analysis is performed here. Per the Sentinel feed, Germany hosts the EU Anti-Money-Laundering Authority (AMLA) in Frankfurt, operational from 1 July 2025, raising its strategic AML profile; AMLA directly oversees high-risk institutions and coordinates national supervisors. Germany's payments-sector AML rests on the Geldwaeschegesetz (GwG) supervised by BaFin. The Sentinel position notes persistent cash-economy and real-estate laundering exposure, a consolidated federal AML authority being stood up, FATF-compliant status with stable risk direction and a mixed enablement-versus-enforcement posture, and payment gateways remaining a noted fraud choke point post-Wirecard. AMLA's Frankfurt seat and direct-supervision remit raise AML compliance scrutiny for high-risk German payments institutions across bank and non-bank lines. Source: Sentinel.gi feed (sentinel.DE-W11-amla).
Outlook
The AML surface is escalating per the Sentinel feed. Any original illicit-finance assessment, sanctions-evasion analysis, or enforcement deep-dive beyond this carried position is routed to the Financial Intelligence Monitor rather than concluded here.
Periodic update 2026-07-07T14:06:03Z
AML/CFT & Financial Crime
This module carries a Sentinel.gi-fed position for payments context only; no original illicit-finance analysis is performed here. Per the Sentinel feed, Germany hosts the EU Anti-Money-Laundering Authority (AMLA) in Frankfurt, operational from 1 July 2025, raising its strategic AML profile; AMLA directly oversees high-risk institutions and coordinates national supervisors. Germany's payments-sector AML rests on the Geldwaeschegesetz (GwG) supervised by BaFin. The Sentinel position notes persistent cash-economy and real-estate laundering exposure, a consolidated federal AML authority being stood up, FATF-compliant status with stable risk direction and a mixed enablement-versus-enforcement posture, and payment gateways remaining a noted fraud choke point post-Wirecard. AMLA's Frankfurt seat and direct-supervision remit raise AML compliance scrutiny for high-risk German payments institutions across bank and non-bank lines. Source: Sentinel.gi feed (sentinel.DE-W11-amla).
Outlook
The AML surface is escalating per the Sentinel feed. Any original illicit-finance assessment, sanctions-evasion analysis, or enforcement deep-dive beyond this carried position is routed to the Financial Intelligence Monitor rather than concluded here.
Read the full sub-brief
AML/CFT & Financial Crime
This module carries a Sentinel.gi-fed position for payments context only; no original illicit-finance analysis is performed here. Per the Sentinel feed, Germany hosts the EU Anti-Money-Laundering Authority (AMLA) in Frankfurt, operational from 1 July 2025, raising its strategic AML profile; AMLA directly oversees high-risk institutions and coordinates national supervisors. Germany's payments-sector AML rests on the Geldwaeschegesetz (GwG) supervised by BaFin. The Sentinel position notes persistent cash-economy and real-estate laundering exposure, a consolidated federal AML authority being stood up, FATF-compliant status with stable risk direction and a mixed enablement-versus-enforcement posture, and payment gateways remaining a noted fraud choke point post-Wirecard. AMLA's Frankfurt seat and direct-supervision remit raise AML compliance scrutiny for high-risk German payments institutions across bank and non-bank lines. Source: Sentinel.gi feed (sentinel.DE-W11-amla).
Outlook
The AML surface is escalating per the Sentinel feed. Any original illicit-finance assessment, sanctions-evasion analysis, or enforcement deep-dive beyond this carried position is routed to the Financial Intelligence Monitor rather than concluded here.
[SENTINEL.GI POSITION — payments context only] Germany's AML/CFT regime for the payments sector rests on the Geldwäschegesetz (GwG), implementing the EU AMLDs, supervised by BaFin. The new EU Anti-Money-Laundering Authority (AMLA) commenced operations in Frankfurt on 1 July 2025, directly overseeing high-risk institutions and coordinating national supervisors. Enforcement against payments-adjacent firms is active (e.g. BaFin's EUR 6.5m Solaris SE fine in 2024 for delayed SARs; a record EUR 45m AML fine at end-2025). Payment gateways remain a noted fraud choke point post-Wirecard. WPM carries the Sentinel position only; no original illicit-finance analysis performed.
Evidence — 8 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- True
Event Findings
W12ConfirmedCorrespondent Banking, Settlement & Access
see this theme across all jurisdictions →4 claimsSettlement access for German institutions runs through the Eurosystem TARGET family operated by the Deutsche Bundesbank: T2 (CLM main cash accounts + RTGS) replaced TARGET2 in March 2023, with T2S dedicated cash accounts for securities and TIPS DCAs for instant payments; settlement is in central bank money. The Bundesbank operates the German component (TARGET2-BBk) and sets collateral requirements. Germany runs a structurally large positive TARGET balance (>EUR 1.06 trillion as of Aug 2025). Correspondent banking uses SWIFT on the ISO 20022 standard (global since March 2023); access criteria flow from Eurosystem participation rules and KWG/ZAG licensing.
Periodic update 2026-07-08T06:48:19Z
Correspondent Banking, Settlement & Access
The analytical spine of W12 is the access asymmetry between bank and non-bank payment service providers in the correspondent-banking and settlement-account context. This cycle's signal for Germany is concentrated in the tension between PSD3's optional central-bank safeguarding account mechanism and the ECB's institutional scepticism about that mechanism — a tension that has direct implications for how the bank versus non-bank access asymmetry evolves under the new regulatory framework.
**The Bank vs Non-Bank Access Asymmetry**
Credit institutions in Germany have direct access to Bundesbank settlement accounts and the TARGET2/T2 infrastructure. Non-bank payment institutions — PIs and EMIs authorised under the ZAG — do not have equivalent direct access. They depend on credit institutions for correspondent-banking services, including the maintenance of safeguarding accounts in which client funds must be held. This structural dependency creates a persistent access asymmetry: non-bank PIs and EMIs are operationally dependent on the willingness of credit institutions to provide and maintain correspondent-banking relationships, and that willingness has been inconsistent across the German market.
PSD3 was designed in part to address this asymmetry. One of its headline access-improvement tools is the optional mechanism allowing payment institutions to safeguard client funds in a central-bank account, rather than relying exclusively on credit-institution accounts or qualifying liquid assets. If operationalised, this mechanism would reduce non-bank PIs' dependency on credit institutions for safeguarding purposes, partially addressing the access asymmetry.
**ECB Scepticism: Decision ECB/2025/2**
ECB Decision ECB/2025/2, issued on 27 January 2025, expressed institutional scepticism about whether central-bank safeguarding accounts could impact overall systemic safety. The ECB's concern appears to centre on the systemic implications of large-scale non-bank PI fund flows being held directly at central banks, which could affect the structure of central-bank balance sheets and the transmission of monetary policy. This is a substantive institutional position, not a procedural objection, and it creates a significant uncertainty about whether the Bundesbank — as the relevant national central bank for German PIs — will in practice offer safeguarding accounts to non-bank PIs under the PSD3 optional mechanism.
The PSD3 text does not require central banks to offer such accounts; the mechanism is optional for central banks as well as for PIs. The ECB's scepticism therefore operates as a practical constraint on the availability of the mechanism, even if PSD3 formally provides for it. For German non-bank PIs and EMIs, this means that the central-bank safeguarding account option — which appeared in the PSD3 text as a potential solution to the correspondent-banking access problem — may not be available in practice, at least not without further clarification of the ECB's and Bundesbank's operational posture.
The Bundesbank's existing arrangements carry conceptual precedent for safeguarding-adjacent structures, but that precedent does not resolve the ECB's systemic-safety concern. The tension between PSD3's access-improvement intent and the ECB's institutional position is unresolved as of this cycle and will need to be watched through the transposition process.
**Implications for German PI/EMI Operating Models**
For German non-bank PIs and EMIs, the practical implication of this tension is that the correspondent-banking access asymmetry is unlikely to be resolved by the central-bank safeguarding account mechanism in the near term. Firms should not plan their safeguarding architecture on the assumption that Bundesbank accounts will be available. The alternative safeguarding routes — credit-institution accounts and qualifying liquid assets — remain the operative options, with all the access-dependency risks that entails.
The coverage gap on DE-specific insolvency-law primary sources for PSD3 safeguarding ring-fencing provisions is noted. The analysis of safeguarding insolvency protection in this module relies on general PSD3/PSR secondary sources; no DE-specific insolvency-law primary source was located this cycle.
Outlook
The ECB-PSD3 safeguarding tension is the primary W12 development to track for Germany. Resolution will depend on the ECB and Bundesbank clarifying their operational posture on central-bank safeguarding accounts during the PSD3 transposition process. Until that clarification is available, the bank versus non-bank access asymmetry in the German correspondent-banking context remains structurally unresolved. The insolvency-law coverage gap is carried forward.
3 earlier updates
Periodic update 2026-07-07T16:39:26Z
Correspondent Banking, Settlement & Access
The analytical spine of this module is the bank versus non-bank settlement-access asymmetry: direct settlement access is structured around Eurosystem participation, with non-bank PSPs reaching central bank money largely via sponsorship. Settlement access for German institutions runs through the Eurosystem TARGET family operated by the Bundesbank: T2 (CLM main cash accounts plus RTGS) replaced TARGET2 in March 2023, with T2S dedicated cash accounts and TIPS DCAs for instant payments, settling in central bank money under ISO 20022/HVPS+; the unified ECMS was added in June 2025. Germany runs a structurally large positive TARGET balance of around EUR 1.06 trillion as of 31 Aug 2025. Correspondent banking uses SWIFT on ISO 20022 (global since March 2023), and access criteria flow from Eurosystem participation rules and KWG/ZAG licensing. TARGET/T2 access and the ISO 20022 migration govern settlement reach and messaging compliance for German banks and, via sponsorship, non-bank PSPs.
Outlook
Settlement infrastructure is stable, with the ECMS addition completing the recent consolidation of the TARGET family. The standing question for operators remains the bank versus non-bank access divide that determines whether an institution settles directly or through a sponsor.
Periodic update 2026-07-07T15:50:56Z
Correspondent Banking, Settlement & Access
The analytical spine of this module is the bank versus non-bank settlement-access asymmetry: direct settlement access is structured around Eurosystem participation, with non-bank PSPs reaching central bank money largely via sponsorship. Settlement access for German institutions runs through the Eurosystem TARGET family operated by the Bundesbank: T2 (CLM main cash accounts plus RTGS) replaced TARGET2 in March 2023, with T2S dedicated cash accounts and TIPS DCAs for instant payments, settling in central bank money under ISO 20022/HVPS+; the unified ECMS was added in June 2025. Germany runs a structurally large positive TARGET balance of around EUR 1.06 trillion as of 31 Aug 2025. Correspondent banking uses SWIFT on ISO 20022 (global since March 2023), and access criteria flow from Eurosystem participation rules and KWG/ZAG licensing. TARGET/T2 access and the ISO 20022 migration govern settlement reach and messaging compliance for German banks and, via sponsorship, non-bank PSPs.
Outlook
Settlement infrastructure is stable, with the ECMS addition completing the recent consolidation of the TARGET family. The standing question for operators remains the bank versus non-bank access divide that determines whether an institution settles directly or through a sponsor.
Periodic update 2026-07-07T14:06:03Z
Correspondent Banking, Settlement & Access
The analytical spine of this module is the bank versus non-bank settlement-access asymmetry: direct settlement access is structured around Eurosystem participation, with non-bank PSPs reaching central bank money largely via sponsorship. Settlement access for German institutions runs through the Eurosystem TARGET family operated by the Bundesbank: T2 (CLM main cash accounts plus RTGS) replaced TARGET2 in March 2023, with T2S dedicated cash accounts and TIPS DCAs for instant payments, settling in central bank money under ISO 20022/HVPS+; the unified ECMS was added in June 2025. Germany runs a structurally large positive TARGET balance of around EUR 1.06 trillion as of 31 Aug 2025. Correspondent banking uses SWIFT on ISO 20022 (global since March 2023), and access criteria flow from Eurosystem participation rules and KWG/ZAG licensing. TARGET/T2 access and the ISO 20022 migration govern settlement reach and messaging compliance for German banks and, via sponsorship, non-bank PSPs.
Outlook
Settlement infrastructure is stable, with the ECMS addition completing the recent consolidation of the TARGET family. The standing question for operators remains the bank versus non-bank access divide that determines whether an institution settles directly or through a sponsor.
Read the full sub-brief
Correspondent Banking, Settlement & Access
The analytical spine of this module is the bank versus non-bank settlement-access asymmetry: direct settlement access is structured around Eurosystem participation, with non-bank PSPs reaching central bank money largely via sponsorship. Settlement access for German institutions runs through the Eurosystem TARGET family operated by the Bundesbank: T2 (CLM main cash accounts plus RTGS) replaced TARGET2 in March 2023, with T2S dedicated cash accounts and TIPS DCAs for instant payments, settling in central bank money under ISO 20022/HVPS+; the unified ECMS was added in June 2025. Germany runs a structurally large positive TARGET balance of around EUR 1.06 trillion as of 31 Aug 2025. Correspondent banking uses SWIFT on ISO 20022 (global since March 2023), and access criteria flow from Eurosystem participation rules and KWG/ZAG licensing. TARGET/T2 access and the ISO 20022 migration govern settlement reach and messaging compliance for German banks and, via sponsorship, non-bank PSPs.
Outlook
Settlement infrastructure is stable, with the ECMS addition completing the recent consolidation of the TARGET family. The standing question for operators remains the bank versus non-bank access divide that determines whether an institution settles directly or through a sponsor.
Settlement access for German institutions runs through the Eurosystem TARGET family operated by the Deutsche Bundesbank: T2 (CLM main cash accounts + RTGS) replaced TARGET2 in March 2023, with T2S dedicated cash accounts for securities and TIPS DCAs for instant payments; settlement is in central bank money. The Bundesbank operates the German component (TARGET2-BBk) and sets collateral requirements. Germany runs a structurally large positive TARGET balance (>EUR 1.06 trillion as of Aug 2025). Correspondent banking uses SWIFT on the ISO 20022 standard (global since March 2023); access criteria flow from Eurosystem participation rules and KWG/ZAG licensing.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False