KYC & AML Compliance in Austria (2026): A Guide for Fintechs and Payment Firms

Austrian fintechs face a risk-based FM-GwG regime, not a document checklist — here's what customer due diligence, beneficial ownership, and sanctions escalation actually require in 2026.

Share
KYC & AML Compliance in Austria (2026): A Guide for Fintechs and Payment Firms

Austria's KYC and AML obligations are not a document check. They are a risk-based operating system that has to connect onboarding, beneficial ownership, sanctions, review, reporting, and records.

Direct answer: Austrian payment firms and fintechs subject to the Financial Markets Anti-Money Laundering Act (FM-GwG) need a risk-based workflow that identifies and verifies customers and beneficial owners, applies enhanced measures where risk requires it, investigates unusual activity, escalates suspicions, and preserves evidence. A remote flow is viable only when the evidence and controls support the decision.

As of 20 July 2026. This guide is an operational overview, not legal advice.

VOVE ID helps Austrian fintech and payment teams collect identity evidence, route exceptions, and keep a reviewable record when the compliance stack has to work across onboarding and risk operations. The failure is rarely a missing ID check. It is the break between a customer record, an ownership record, an escalation, and the evidence needed to defend the outcome.

This guide covers what Austria's FM-GwG actually requires in practice — customer identification, beneficial ownership, sanctions escalation, and retention. For the underlying framework, see our KYC Requirements Explained 2026.

This is exactly where Austria compliance operations stall.

Regulatory map: the workflow starts with the FM-GwG

For financial-market firms, the core AML/CFT statute is the FM-GwG. The Austrian Financial Market Authority (FMA) identifies credit institutions, financial institutions, payment institutions, electronic-money institutions, investment firms, and other financial-sector entities among the populations it supervises for these obligations. FMA's role overview is the practical starting point for deciding which supervisory perimeter applies.

The FM-GwG requires customer identification and verification using documents, data, or information from a credible and independent source. It expressly contemplates electronic identification means, relevant trust services, and other secure remote or electronic identification procedures. FM-GwG section 6 is why a digital flow must be designed as evidence collection, not merely conversion optimisation.

Customer due diligence: make the decision reproducible

An Austrian onboarding workflow needs more than an image of a document. Teams need a decision record that links the customer data, the verification result, the risk assessment, and any reviewer action.

For individuals, that usually means collecting the identity attributes required by the product and verifying them against reliable evidence. For businesses, it also means establishing the entity, understanding the intended relationship, and mapping the natural persons who ultimately own or control it.

Do not treat a successful upload as a completed compliance case. A case closes only when the team can show what was checked, what conflicts were resolved, and why the residual risk is acceptable.

Beneficial ownership: the register is an input, not the whole answer

Austria's Beneficial Owners Register Act (WiEReG) defines beneficial owners as the natural persons who ultimately own or control a legal entity. For companies, direct ownership or voting rights of more than 25% is a central threshold in the statutory definition. The current WiEReG text also makes clear why a control analysis cannot stop at a single shareholder list.

For a full breakdown of entity verification and beneficial ownership mapping, see our KYB Requirements Explained 2026.

Risk, sanctions, and escalation: where routine onboarding becomes AML work

Risk-based due diligence does not end once an account opens. A team needs clear triggers for additional information, enhanced review, restriction, or escalation. The FMA notes that firms subject to the FM-GwG must apply enhanced customer due diligence for connections to high-risk third countries designated for the EEA. Its current high-risk-country guidance also points teams back to the current EU and FATF sources.

Since 1 January 2026, the FMA states that it supervises financial-market participants' observance of financial sanctions under Austria's Sanctions Act 2024. Teams need a documented route from a potential match to a reviewed decision; a screening alert is not itself a final disposition. FMA sanctions information sets out the affected financial-market population.

When facts or transactions require suspicion analysis, escalation has to reach the right owner quickly. Austria's Federal Criminal Police Office identifies the Geldwäschemeldestelle, the Austrian FIU, as the reporting point for justified money-laundering or terrorist-financing suspicions from obliged professions. The FIU reporting-office guidance describes the role and the need to pay special attention to unusual transactions and patterns with no apparent economic or lawful purpose.

For a full breakdown of sanctions screening and reporting obligations, see our AML Requirements Explained 2026.

Records and privacy: retention must be engineered into the flow

Retention is not a back-office afterthought. FM-GwG section 21 requires obliged entities to retain customer-due-diligence documents and relevant transaction records for ten years after the relationship ends or an occasional transaction occurs, with rules on deletion after the statutory period and exceptions for certain proceedings. FM-GwG section 21 is a useful design constraint for data architecture and vendor due diligence.

How VOVE ID fits: evidence, review, and an audit-ready case

VOVE ID supports identity verification, biometric liveness, face matching, AML screening, KYB, and transaction monitoring. It supports 2,000+ document types across 200+ countries and helps detect document-template inconsistencies, invalid MRZ checksums, barcode or QR inconsistencies, and image manipulation. AML screening is customer-configurable and its data is refreshed daily; manual review can be used where the compliance team has sufficient evidence to approve a verification.

This is not a substitute for a firm's legal analysis or risk appetite. It gives operations a consistent way to execute that analysis.

Practical Austria KYC and AML checklist

Governance

  • Confirm the Austrian regulatory perimeter and accountable compliance owner.
  • Document the customer, product, geography, and channel risk methodology.
  • Define escalation ownership for higher-risk and sanctions-related cases.

Onboarding and KYB

  • Verify identity from reliable and independent evidence.
  • Capture a reproducible remote-onboarding evidence trail.
  • Map beneficial owners and record the control basis, not only the share percentage.

Monitoring and reporting

  • Set documented triggers for enhanced review and unusual-activity analysis.
  • Maintain a clear route from investigation to the Austrian FIU reporting process.
  • Preserve the evidence, decision, and reviewer action with the case.

Records and privacy

  • Build the FM-GwG retention period into record-management controls.
  • Limit access to case evidence and log reviewer activity.
  • Define deletion and legal-hold handling before data accumulates.

FAQ

Can Austrian fintechs onboard customers remotely? The FM-GwG recognizes secure remote or electronic identification procedures. The product team still needs to show that the evidence, risk controls, and exception handling are adequate for the relationship.

What does the 25% ownership threshold mean in Austria? WiEReG treats more than 25% of shares, voting rights, or participation as a central indicator of direct beneficial ownership. Ownership and control still need to be assessed through the actual structure.

Who handles suspicious-activity reporting in Austria? The Geldwäschemeldestelle at the Federal Criminal Police Office is Austria's FIU reporting point. Firms should build an internal escalation and decision record before a report is made.

How long must AML evidence be retained? FM-GwG section 21 generally specifies ten years after the end of a relationship or an occasional transaction for CDD and relevant transaction records. Teams should validate their own retention schedule with qualified counsel.

Conclusion

KYC and AML compliance in Austria is not a document-collection task. It is a controlled record of identity, ownership, risk, escalation, and retention.

Payment and fintech teams need to make every hand-off auditable, especially when onboarding happens remotely or a business has a layered ownership chain. Collection, verification, investigation, and case management are one workflow.

Want to see how VOVE ID supports a country-aware identity and compliance workflow?

Talk to the team.

This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. KYC/KYB/AML requirements may vary depending on jurisdiction, industry, and specific business circumstances. For up-to-date and binding compliance obligations, readers should refer to the relevant regulatory authorities or consult qualified professionals.