German Banking Supervision

The Kreditwesengesetz (KWG)

German banking supervision is primarily governed by the Banking Act (Kreditwesengesetz, KWG), originally enacted in 1961 and substantially amended over successive reforms. The KWG establishes the regulatory framework for credit institutions (Kreditinstitute) and financial services institutions (Finanzdienstleistungsinstitute), implementing European banking directives including the Capital Requirements Regulation (CRR) and Capital Requirements Directive (CRD IV). The KWG operates within the Single Supervisory Mechanism (SSM), with the European Central Bank (ECB) exercising direct supervision over significant institutions while national authorities supervise less significant institutions.

BaFin: The Federal Financial Supervisory Authority

The Federal Financial Supervisory Authority (Bundesanstalt fur Finanzdienstleistungsaufsicht, BaFin) is the principal German financial regulator, established in 2002 through the merger of the former banking, insurance, and securities regulators. BaFin is an independent federal authority operating within the portfolio of the Federal Ministry of Finance, headquartered in Bonn and Frankfurt. Its mandate encompasses banking supervision (Bankenaufsicht), insurance supervision (Versicherungsaufsicht), and securities supervision (Wertpapieraufsicht).

BaFin’s banking supervisory functions include: licensing of credit institutions, ongoing prudential supervision, enforcement of capital and liquidity requirements, consumer protection in financial services, anti-money laundering oversight, and crisis management. BaFin exercises its powers through on-site inspections, off-site monitoring, reporting requirements, and enforcement measures including fines, removal of managers, and revocation of licences. The KWG grants BaFin extensive investigative powers, including the right to request information, access business premises, and conduct investigations.

Licensing Requirements

Section 32 KWG requires any undertaking seeking to conduct banking business (Bankgeschaft) or financial services (Finanzdienstleistungen) in Germany to obtain a written licence (Erlaubnis) from BaFin. Banking business is defined exhaustively in Section 1(1) KWG and includes: deposit business (Einlagengeschaft), lending business (Kreditgeschaft), discount business, securities business, custody business, investment fund business, guarantee business, and payment services. Financial services under Section 1(1a) KWG include investment brokerage, contract brokerage, financial portfolio management, and investment advisory services.

The licensing process requires the applicant to demonstrate: adequate capital (initial capital depending on the type of business, ranging from EUR 50,000 to EUR 5 million), reliable and professionally qualified management (Zuverlassigkeit and fachliche Eignung of Geschaftsleiter under Section 33 KWG), a viable business plan, appropriate organisational structure, and adequate risk management systems. BaFin must decide on the application within six months. Licences are subject to ongoing compliance and may be withdrawn if the conditions for licensing cease to be met.

Interaction with the Single Supervisory Mechanism

Since November 2014, the Single Supervisory Mechanism (SSM) established by Regulation 1024/2013 has fundamentally restructured banking supervision in the euro area. The ECB directly supervises significant institutions (bedeutende Institute), while BaFin and the Deutsche Bundesbank supervise less significant institutions (weniger bedeutende Institute) under the oversight of the ECB. An institution is classified as significant if: its total assets exceed EUR 30 billion; it represents a significant proportion of the domestic economy (assets exceeding 20 per cent of GDP); it has received direct public financial assistance; or it is among the three most significant institutions in the Member State.

For significant institutions, the ECB assumes direct supervisory responsibilities including licensing, ongoing supervision, stress testing, and enforcement. BaFin continues to play a supporting role, conducting on-site inspections on behalf of the ECB and exercising powers delegated by the ECB. For less significant institutions, BaFin remains the primary supervisor, applying the CRR and KWG under the monitoring framework established by the SSM Regulation. The Deutsche Bundesbank supports supervision through ongoing monitoring of institutions’ financial condition and compliance with prudential requirements.

Prudential Requirements

German credit institutions must comply with prudential requirements derived from the CRR and CRD IV. Capital requirements under CRR Pillar 1 include: Common Equity Tier 1 (CET1) capital of at least 4.5 per cent of risk-weighted assets (RWA), Tier 1 capital of 6 per cent, and total capital of 8 per cent. The KWG and national law impose additional buffers: the capital conservation buffer (2.5 per cent), the countercyclical capital buffer (0-2.5 per cent), systemic risk buffers, and institution-specific Pillar 2 requirements (SREP) determined by BaFin or the ECB. Section 10 KWG requires institutions to maintain adequate own funds in accordance with CRR rules.

Liquidity requirements under the CRR include the Liquidity Coverage Ratio (LCR), requiring institutions to hold sufficient high-quality liquid assets to cover net cash outflows over a 30-day stress period, and the Net Stable Funding Ratio (NSFR), requiring stable funding sources for long-term assets. Large exposure limits under Part Four CRR restrict exposure to a single client or group of connected clients to 25 per cent of eligible capital. Section 13 KWG imposes additional reporting obligations for large exposures.

Risk management requirements under Sections 25a-25c KWG require institutions to maintain sound and prudent management arrangements, including: a clear organisational structure with defined responsibilities, adequate risk management systems covering credit, market, operational, liquidity, and reputational risks, internal control mechanisms, and remuneration policies aligned with prudent risk-taking. Section 25a(1) KWG specifically requires institutions to have a business organisation that ensures compliance with all legal requirements and administrative provisions.

Deposit Protection

Germany operates a three-tier deposit protection system. The statutory deposit guarantee scheme (Einlagensicherung), established under the Deposit Guarantee Act (Einlagensicherungsgesetz, EinSiG) implementing the EU Deposit Guarantee Schemes Directive (2014/49/EU), protects deposits up to EUR 100,000 per depositor per institution. The scheme covers all credit institutions licensed in Germany and is administered by the Deposit Protection Fund (Einlagensicherungsfonds) of the Association of German Banks (Bundesverband deutscher Banken, BdB).

In addition to the statutory scheme, the German banking industry maintains institutional deposit protection (institutionelle Sicherungssysteme): the protection schemes of the savings banks (Sparkassen) and cooperative banks (Genossenschaftsbanken) provide coverage beyond the statutory EUR 100,000 limit, effectively guaranteeing all deposits at member institutions. These institutional protection schemes are recognised under Article 113 CRR as mutual guarantee schemes qualifying for preferential capital treatment.

Outsourcing and Operational Resilience

Section 25b KWG and BaFin’s Minimum Requirements for Risk Management (Mindestanforderungen an das Risikomanagement, MaRisk) govern outsourcing (Auslagerung) by credit institutions. Activities material to banking operations — including IT systems, compliance functions, internal audit, and risk management — may be outsourced only subject to strict requirements: the outsourcing must not impair the quality of internal control or BaFin’s ability to monitor regulatory compliance; a written outsourcing agreement must specify the rights and obligations of the parties; the institution must retain the ability to give instructions to the service provider; and BaFin must be notified of material outsourcing arrangements. Outsourcing to third countries is subject to additional scrutiny regarding data protection, access rights, and legal enforceability.