Hünermann Iken

00About HI

We advise at the intersection of prevention, crisis response and enforcement.

HÜNERMANN IKEN is a law boutique based in Frankfurt am Main, specialised in compliance, crisis management and regulatory special situations. We advise and represent national and international companies, financial institutions and their management and supervisory bodies.

Our work combines forensic experience from decades of international large-firm practice with operational knowledge of complex financial and group structures from an in-house leadership perspective. Every mandate is led by us personally. You therefore benefit directly from the partners' expertise.

View across the river Main towards the Frankfurt skyline at dusk.

01Why HI

What makes the difference for you

We know the systems from within

You do not receive an abstract risk assessment, but the judgement of someone who has been responsible for control and screening systems themselves — and who knows what can actually be implemented in your organisation.

Access that shortens the route

Reliable connections to regulators, investigating authorities and auditors help you precisely when speed matters and formal channels take too long.

Free of conflicts of interest

As a specialised boutique we are not bound by the conflict positions of large international organisations. We can act for you where others have to decline.

You speak to the decision-makers

No leverage model, no delegation to inexperienced associates. Whoever instructs us works with the partners — in strategy as well as in meetings with the authorities.

02Your team

Personal attention to every mandate is our priority. We stand behind it with our own names.

HÜNERMANN IKEN is a highly specialised boutique, led and operationally run by the name partners personally. We work without a leverage model: strategy, crisis team and meetings with authorities rest with the partners themselves. You therefore draw directly on their experience.

Portrait of Rolf Hünermann, attorney-at-law and partner

Rolf Hünermann

Attorney-at-law · Partner

Corporate governance · Internal investigations · Whistleblowing systems · ESG governance · M&A

Clients turn to Rolf Hünermann when decisions have to be taken under liability pressure at management or supervisory board level. For more than two decades he has advised companies and governing bodies on corporate governance, compliance and M&A transactions.

Before founding HÜNERMANN IKEN, he was for many years a partner and managing partner in the Frankfurt offices of leading international US and Magic Circle firms. He has outstanding experience in conducting internal investigations and in advising on ESG governance and whistleblowing systems. He has been listed continuously in renowned rankings for years, including Best Lawyers for corporate governance and compliance as well as for litigation.

rh@hi-comply.de +49 151 12542604

Portrait of Dr Jan-Gerrit Iken, attorney-at-law and partner

Dr Jan-Gerrit Iken

Attorney-at-law · Partner

Financial crime · Anti-money laundering · Sanctions · KYC and KYB · RegTech

When supervisors or investigating authorities raise questions on anti-money laundering, Dr Jan-Gerrit Iken knows the answer from both perspectives: that of the adviser and that of the officer in charge. He is among the most prominent experts in Europe for financial crime, anti-money laundering and sanctions.

He was Global Head of Monitoring & Screening and Deputy Group AML Officer at Deutsche Bank, and Deputy Chief Compliance Officer and Global Head of Financial Crime at Commerzbank. As Head of Group Compliance, Security & Forensics he led crisis and restructuring situations at international institutions, including Hypo Alpe Adria. Through innovation platforms he advances the use of legal and RegTech in order to meet KYC and KYB requirements in a scalable and legally sound manner. He is a co-founder of AFCA Germany, the public-private alliance against financial crime in Germany.

jgi@hi-comply.de +49 176 66809581

03Our expertise

How we support you

Open the area that comes closest to your situation.

Crisis Response

Managing compliance crises and critical incidents

The first hours after a dawn raid, a cyber incident or a money laundering suspicion determine how expensive the matter becomes. We take control so that your management remains able to act — and so that nothing is said or handed over that may later be used against you.

Ad-hoc crisis team
Immediate legal and strategic protection for the management body.
Managing authorities
Steering communications with public prosecutors, BaFin and international regulators.
Investigations

Internal investigations and enforcement

You need to know what actually happened: robustly, discreetly and documented in a way that holds up before authorities. We establish the facts — and then represent them vis-à-vis prosecutors and supervisors.

Investigations
Tailored internal investigations conducted with the utmost discretion and methodological precision.
Defence and enforcement
Representation in enforcement proceedings, defence against sanctions and administrative fines.
Counterparty Risk

Counterparty risk and advanced due diligence

Whether you should onboard, retain or exit a business partner depends on facts that are rarely in plain sight. We create the basis for that decision and structure contracts so that default, reputational and sanctions risks do not end up with you.

Counterparty risk
Analysis and legal structuring of contracts to minimise default, reputational and sanctions risks.
Deep-dive due diligence
Risk-based reviews in M&A transactions, joint ventures and strategic partnerships — financial crime, ESG, German Supply Chain Act (LkSG).
Monitorships

Monitorships and special representatives

A monitor or special representative on site changes day-to-day operations for months. We know these proceedings both from operational implementation and from legal support, and set them up so that the requirements are met without paralysing your business.

Supporting mandates
Preparing and supporting companies faced with a government-appointed monitor (e.g. by US authorities) or a special representative (e.g. appointed by BaFin).
Own appointment
Acting as independent experts to restore regulatory trust.
Compliance Architecture

Building and optimising compliance management systems

You need a system that holds up under examination — not a rulebook that merely looks good. We build it, or bring your existing system to a standard that supervisors and auditors accept.

Build-up
Threat and risk assessment, control and governance concept, roles and responsibilities, policy framework, training architecture and reporting lines — tailored to your business model and supervisory environment.
Enhancement and effectiveness
Maturity assessment, closing control gaps and preparing effectiveness audits, e.g. under IDW PS 980, including documentation for supervisors and auditors.
Policies & Operating Model

Policy framework and target operating model

Two things stand between a regulatory requirement and what your staff actually do: an intelligible instruction and an organisation able to deliver it. We design both together with your business functions, not from a desk far away.

Policy framework
A clear hierarchy of group policy, standard and procedural instruction — with unambiguous ownership, approval and review cycles, versioning, attestation and evidence of which rule covers which supervisory requirement.
Procedures
Translation into robust work instructions and control descriptions: who reviews what, in what order, with what discretion, with what documentation and with what escalation.
Target operating model
Structural and process organisation of the compliance function: delineation of first and second line, roles and interfaces, location and capacity model including near- and offshoring, committee structure, reporting lines and management KPIs.
Path to the target state
Baseline assessment, gap analysis and an implementation plan with defined milestones — so the target state does not stay on paper but is demonstrably reached in stages.
Technology

Use of technology and digitalisation of compliance

Requirements grow faster than your budget. That can only be resolved with technology that withstands scrutiny. We combine the legal requirement with knowledge of the systems meant to fulfil it — from our own operational responsibility in large groups.

Digitalising compliance processes
Mapping and redesigning manual workflows, eliminating media breaks, automating recurring review steps in onboarding, ongoing maintenance and reporting — with end-to-end, audit-proof documentation.
Selecting and validating solutions
Requirements definition, market screening and selection of RegTech applications for KYC, KYB, sanctions and PEP screening, transaction monitoring and adverse media research; followed by validation of rule sets, thresholds and hit rates — including tuning and evidence for supervisors.
Data as the foundation
Data quality, register connectivity and ownership data down to the ultimate beneficial owner are the prerequisite for any automation. We examine the origin, currency and verifiability of the data before decisions are based on it.
AI in control processes
Legal framework, governance and traceability when using artificial intelligence — purpose limitation and data protection, model and result documentation, final human decision, and the question of how an AI-supported result can be evidenced in proceedings.
Outsourcing and operations
Contractual and regulatory design of the use of external providers, instruction and audit rights, exit scenarios and the responsibility that remains in-house despite outsourcing.
Remediation

Remediation after incidents and regulatory findings

After a supervisory finding, what counts is not a statement of intent but proof that the deficiency has truly been remedied. We have run such programmes ourselves in large institutions and lead them from root cause analysis to closure evidence.

Root cause analysis and action plan
Root cause analysis across process, control, system and culture; from this, a prioritised action plan with deadlines and responsibilities that stands up before authorities.
Clean-up of legacy portfolios
Look-back analyses and large-scale portfolio remediation — KYC remediation of entire client portfolios, transaction look-backs, filing of omitted suspicious activity reports, clean-up of screening and data quality deficiencies.
Programme management
Governance of a multi-year remediation programme: resource and vendor management, quality assurance, progress reporting to the management board, supervisory board and regulator.
Closure and evidence
Evidence of sustained effectiveness towards BaFin, special representatives or a monitor — including when a programme can be closed and what remains in business-as-usual afterwards.
Regulatory Change

Advice on new legislation

You want to know what new requirements actually mean for your institution — not what the official journal says. We translate legislative projects into impact, effort and a roadmap you can defend at board level.

EU Anti-Money Laundering Regulation
Regulation (EU) 2024/1624 applies directly in all Member States from 10 July 2027 and replaces large parts of the German Money Laundering Act (GwG); it is flanked by the sixth Anti-Money Laundering Directive and the new EU authority AMLA, based in Frankfurt am Main, which will directly supervise selected high-risk institutions from 2028. We assess impact, regulatory gaps and the need to adapt due diligence, screening and documentation.
EU Anti-Corruption Directive
The directive that entered into force in May 2026 harmonises corruption offences and sanctions; Member States have two years to transpose it. For companies, the effective compliance management system therefore moves to the centre of the liability question. We review policies, third-party controls and training concepts against the new benchmark.
Further initiatives
Ongoing monitoring of adjacent regimes — sanctions law, supply chain, ESG reporting — and how they interact with existing control systems.
Ombuds Office & Training

External ombudsman, training and sounding board

Sometimes you need a body outside the organisation: for reports that do not get through internally, for a confidential second opinion and for training that goes beyond slogans.

External ombudsman
Assuming the ombuds function and operating the internal reporting channel as a third party within the meaning of the German Whistleblower Protection Act — confidential under attorney privilege, with a clear escalation and documentation line.
Training for executives
Tailored training for management boards, managing directors, supervisory boards and compliance functions — based on real case constellations instead of slogans, including crisis exercises and dawn raid simulations.
Sounding board
A confidential second opinion for compliance officers and anti-money laundering officers: an interlocutor who knows the role from experience, for matters of principle, escalations and resource decisions.
Interim Management

Filling key functions on a temporary basis

If a key function is vacant, we fill it ourselves on an interim basis — in the role, with authority to instruct and a duty to report, not advising from the outside.

Functions
Anti-money laundering officer and deputy, compliance officer, head of financial crime, head of compliance or security — including regulatory notification and suitability requirements.
Special situations
Leading a remediation programme, integration after an acquisition or carve-out, stabilisation after an incident, support during a restructuring.
Build-up and handover
The mandate ends as planned: we document processes and decisions, onboard the permanent hire and hand over transparently.
Clarity of role
Before taking on the role we clarify its boundaries, liability and possible conflicts of interest, so that the operational function remains compatible with professional rules for attorneys.

04Clients

Who we work for

Our clients are under supervision, under time pressure or under observation — often all three at once. We work for companies and institutions as well as directly for management board members, managing directors and supervisory board members who bear personal responsibility.

Financial sector

Major banks, private banks, asset managers, payment service providers and fintechs that have to answer to BaFin, the ECB and the Bundesbank. Here we know not only the requirement, but also the examiner who assesses it.

Non-financial sector

National and global industrial and trading companies, automotive suppliers and consumer goods manufacturers with multi-layered governance and supply chain requirements — down to the vetting of individual business partners.

Officers personally

Members of management boards, executive managements and supervisory boards who bear their own liability risks and need an adviser who clearly distinguishes between corporate and personal interests.

05Network

Connections that work in your favour

Regulatory special situations can rarely be resolved by legal means alone. So that you do not have to coordinate several service providers, we cooperate in a structured way with technology providers and auditors.

Legalian

Technology partner

A compliance platform with direct access to commercial and transparency registers worldwide. Legalian enables continuous monitoring of your client or customer portfolio across fragmented registers in all relevant jurisdictions, extensive sanctions lists and nested ownership chains, bundled in one portal with a transparent data basis — from the KYC engine through sanctions and PEP screening to enhanced due diligence and ongoing monitoring. legalian.io

Regbyrd

Technology partner

AI-supported compliance for banks, audit and advisory firms as well as companies in the non-financial sector: IDD and EDD reports, KYC and sanctions screening in hours instead of weeks. For companies this is above all relevant in third-party compliance — when vetting suppliers, sales intermediaries, consultants and joint venture partners under the German Supply Chain Act, sanctions law and anti-corruption requirements. Its Deep Research Investigation Tool produces a business intelligence profile of the counterparty: ownership and control structures, beneficial owners, sanctions and PEP links, adverse media and proceedings, condensed into a risk-rated basis for decisions. regbyrd.com

Authorities, auditors, law firms

Professional network

Reliable connections to national and international regulators and investigating authorities, to audit firms and forensic service providers, and to befriended law firms in the relevant jurisdictions.

06Insights

Publications, speaking engagements and awards

We are happy to comment on regulatory developments, supervisory practice and questions of combating financial crime. We do not provide information on ongoing or completed mandates — not even by way of confirmation.

Publication

New compliance boutique launched

JUVE reports on the founding of HÜNERMANN IKEN in Frankfurt by Rolf Hünermann, formerly McDermott Will & Schulte, and Dr. Jan-Gerrit Iken, formerly Deutsche Bank.

Award

Best of Technology Award 2026

WirtschaftsWoche awarded Legalian first place in the Legal category – for the platform that automates the KYC review end-to-end, from register query to reporting.

Award

JUVE

Rolf Hünermann has been named by JUVE as a leading name in internal investigations / compliance since 2012.

Award

Best Lawyers

Rolf Hünermann has been listed continuously since 2014 in corporate governance and compliance, litigation and mergers & acquisitions.

Publication

JUVE Rechtsmarkt

JUVE reports on Dr. Jan-Gerrit Iken's involvement with Legalian, a technology partner for compliance and AML solutions.

07Contact

Get to know us.

Every mandate begins with an initial, confidential and non-binding conversation — with the partners personally. In it we review the situation together with you, assess at short notice whether and how we can support you, and come back to you with an initial view on the way forward. An engagement is established only upon a separate written agreement.