AML & KYC in Austria is governed by a comprehensive legal framework that obliges banks, lawyers, accountants, real estate agents, and other designated entities to identify clients, monitor transactions, and report suspicious activity. Austria has significantly tightened its regime in recent years following pressure from the Financial Action Task Force (FATF) and the transposition of successive EU anti-money laundering directives. Non-compliance carries serious civil and criminal consequences. This guide explains who is covered, what the core obligations are, how supervision works, and what recent changes mean for businesses operating in Austria.
Who is covered by AML & KYC obligations in Austria
Austria';s primary AML legislation is the Finanzmarkt-Geldwäschegesetz (FM-GwG), which applies to the financial sector, and the Wirtschaftliche Eigentümer Registergesetz (WiEReG), which governs beneficial ownership disclosure. A parallel regime under the Gewerbeordnung and sector-specific laws extends obligations to non-financial businesses and professions.
Obliged entities under Austrian law include:
- Credit institutions and payment service providers
- Insurance undertakings and investment firms
- Auditors, tax advisers, and notaries
- Lawyers when involved in financial or real estate transactions
- Real estate agents and property developers
- Dealers in high-value goods where cash transactions exceed the relevant threshold
- Virtual asset service providers (VASPs) registered with the Financial Market Authority (FMA)
Each category faces obligations calibrated to its risk exposure. A bank faces daily transaction monitoring requirements; a notary faces them only when handling specific transaction types. The scope of "obliged entity" has expanded in recent legislative cycles, and businesses that were previously outside the regime should reassess their status.
A common mistake among foreign-owned businesses entering Austria is assuming that AML obligations apply only to banks. In practice, any entity that falls within the categories above must implement a full compliance programme, regardless of size or ownership structure.
Core KYC and customer due diligence requirements
Know Your Customer (KYC) is the process by which an obliged entity identifies and verifies the identity of its clients before establishing a business relationship or executing a transaction. Under the FM-GwG, Austrian obliged entities must apply customer due diligence (CDD) measures in three tiers: standard, simplified, and enhanced.
Standard CDD requires collecting and verifying the client';s identity using reliable, independent source documents. For legal entities, this means obtaining the company register extract, the articles of association, and identifying the beneficial owners registered in the WiEReG. Beneficial ownership is defined as natural persons who ultimately own or control more than 25% of a legal entity.
Simplified CDD may apply where the client or product presents a demonstrably low risk - for example, certain regulated financial instruments or publicly listed companies. Obliged entities must document the basis for applying simplified measures and cannot rely on simplified CDD as a default.
Enhanced due diligence (EDD) is mandatory in higher-risk situations, including:
- Business relationships with clients from high-risk third countries identified by the European Commission
- Transactions involving politically exposed persons (PEPs) and their close associates
- Correspondent banking relationships
- Complex or unusually large transactions with no apparent economic purpose
In practice, EDD means obtaining additional information about the source of funds and wealth, applying senior management approval before onboarding, and conducting more frequent ongoing monitoring. Many firms underestimate the documentation burden that EDD imposes and fail to maintain adequate records.
Ongoing monitoring is a continuous obligation, not a one-time check. Obliged entities must keep client data current, review transactions against the client';s expected profile, and update risk assessments when circumstances change. The FMA has cited inadequate ongoing monitoring as a recurring deficiency in supervisory inspections.
Beneficial ownership registration under WiEReG
The Wirtschaftliche Eigentümer Registergesetz (WiEReG) established Austria';s central beneficial ownership register, maintained by the Federal Ministry of Finance. All legal entities incorporated in Austria - including GmbH, AG, foundations, and associations - must disclose their ultimate beneficial owners and keep that information current.
The registration obligation falls on the legal entity itself, not on the beneficial owner. Entities must report within four weeks of any change in beneficial ownership. Failure to register or to update the register on time exposes the entity and its management to administrative fines, which can be substantial.
Obliged entities under the FM-GwG must cross-check client information against the WiEReG as part of their CDD process. Where discrepancies exist between the register entry and information obtained directly from the client, the obliged entity must report the discrepancy to the register authority. This reporting duty is a non-obvious requirement that many compliance teams overlook.
Access to the WiEReG is tiered. Authorities and obliged entities have full access. Members of the public have access to basic information, subject to restrictions that apply where disclosure would expose a beneficial owner to a disproportionate risk. Recent EU-level case law has influenced how member states, including Austria, balance transparency with privacy rights, and the Austrian rules have been adjusted accordingly.
In practice, founders of Austrian companies should treat WiEReG registration as a day-one obligation, not an afterthought. Delays in registration frequently surface during bank account opening, when credit institutions run their own CDD checks and discover that the register entry is missing or incomplete.
Suspicious activity reporting and the Financial Intelligence Unit
Austria';s Financial Intelligence Unit (A-FIU), operating within the Federal Criminal Police Office (Bundeskriminalamt), is the central body for receiving and analysing suspicious activity reports (SARs). Obliged entities must file a SAR immediately upon forming a suspicion that a transaction or business relationship involves proceeds of crime or is connected to terrorist financing.
The reporting obligation is unconditional. An obliged entity cannot delay a SAR to gather more information or to wait for internal approval processes. Filing a SAR does not require certainty - reasonable suspicion is sufficient. Tipping off the client that a SAR has been filed is a criminal offence under Austrian law.
After filing a SAR, the obliged entity must await clearance from the A-FIU before executing the transaction, unless the A-FIU grants permission or the waiting period expires. The standard waiting period is three working days, extendable in complex cases. If no instruction is received, the entity may proceed but must continue monitoring.
A practical scenario: a real estate agent in Vienna receives a cash offer from a foreign buyer for a residential property. The buyer cannot explain the source of funds coherently. The agent must file a SAR before proceeding, regardless of whether the transaction ultimately completes. Proceeding without filing exposes the agent to criminal liability for money laundering facilitation.
A second scenario: a law firm advises an Austrian GmbH on a corporate restructuring. During the engagement, the firm identifies that the company';s beneficial ownership structure does not match the WiEReG entry and that large sums have moved through the company';s accounts without clear commercial purpose. The firm must file a SAR and, separately, report the WiEReG discrepancy.
If your firm is uncertain whether a specific situation triggers reporting obligations, contact info@vlolawfirm.com. We can help structure the compliance response correctly the first time.
Supervision, enforcement, and recent regulatory changes
Supervision of AML & KYC compliance in Austria is split across several authorities. The Financial Market Authority (FMA) supervises banks, insurance companies, investment firms, and VASPs. The Austrian Chamber of Public Accountants and the Bar Association supervise their respective members. The district administrative authorities (Bezirksverwaltungsbehörden) supervise non-financial businesses such as real estate agents and dealers in high-value goods.
The FMA has increased the frequency and depth of AML inspections in recent years. Enforcement actions have resulted in public reprimands, administrative fines, and, in serious cases, licence revocations. The FMA publishes enforcement decisions, which creates reputational risk for non-compliant firms beyond the financial penalty itself.
Recent legislative changes in Austria reflect the ongoing transposition of the EU';s AML package, which includes a new AML Regulation (directly applicable across all member states), a revised AML Directive, and the establishment of the EU Anti-Money Laundering Authority (AMLA). AMLA will directly supervise the highest-risk obliged entities across the EU, including certain Austrian financial institutions. Austrian firms should anticipate that AMLA oversight will introduce additional reporting and governance requirements on top of existing national obligations.
Austria has also strengthened its rules on virtual assets. VASPs must register with the FMA, apply full CDD to all clients, and comply with the EU';s Transfer of Funds Regulation, which requires that transfers of crypto-assets above a certain threshold carry originator and beneficiary information. This is a relatively new area where enforcement is increasing and where many operators have historically underinvested in compliance infrastructure.
The FATF';s most recent mutual evaluation of Austria identified areas for improvement in the effectiveness of the AML regime, particularly regarding the supervision of non-financial businesses and professions. Austrian authorities have responded with enhanced supervisory activity in those sectors, and businesses that previously operated with minimal AML scrutiny should expect more frequent contact from supervisors.
Building an effective AML compliance programme in Austria
An effective AML compliance programme in Austria must be risk-based, documented, and subject to regular review. The FM-GwG requires obliged entities to conduct a written business risk assessment that identifies the money laundering and terrorist financing risks specific to their client base, products, geographic exposure, and delivery channels.
The core components of a compliant programme include:
- A written risk assessment reviewed at least annually
- Written internal policies and procedures covering CDD, EDD, SAR filing, and record retention
- Appointment of a designated AML compliance officer with sufficient seniority and resources
- Regular staff training tailored to the entity';s specific risk profile
- Independent audit or review of the compliance function
Record retention is a frequently underestimated obligation. Austrian law requires obliged entities to retain CDD documents and transaction records for at least five years from the end of the business relationship or the date of the transaction. Records must be retrievable promptly in response to supervisory requests.
Many underestimate the governance dimension of AML compliance. Senior management bears personal responsibility for ensuring that the compliance programme is adequate. In enforcement proceedings, the FMA and other supervisors look at whether management was aware of deficiencies and whether they took timely corrective action. A compliance officer who flags problems but receives no management support is not sufficient protection for the firm.
For foreign-owned entities operating in Austria, a common mistake is importing a group-level compliance framework without adapting it to Austrian legal requirements. Group policies may not cover WiEReG reporting duties, Austrian-specific SAR procedures, or the particular supervisory expectations of the FMA. Local adaptation is not optional.
To discuss how your compliance programme measures up against current Austrian requirements, contact info@vlolawfirm.com. We can assist with gap analysis, policy drafting, and regulatory filings.
Frequently asked questions
What triggers enhanced due diligence for an Austrian obliged entity?
Enhanced due diligence is required whenever a business relationship or transaction presents a higher risk of money laundering or terrorist financing. Mandatory triggers under Austrian law include clients who are politically exposed persons, transactions involving counterparties from countries on the European Commission';s high-risk third-country list, and correspondent banking relationships. Obliged entities may also apply EDD on a discretionary basis where their own risk assessment identifies elevated risk, even if no mandatory trigger applies. EDD involves collecting more information about the client';s background, source of funds, and the purpose of the relationship, and requires senior management sign-off before onboarding proceeds. Records of the EDD process must be retained for at least five years.
How long does it take to set up an AML-compliant onboarding process in Austria, and what does it cost?
The timeline depends heavily on the complexity of the entity and the maturity of its existing compliance infrastructure. A financial institution building a programme from scratch should allow several months for policy drafting, technology integration, staff training, and internal testing. A smaller non-financial business may complete the process in a matter of weeks. Professional fees for legal and compliance advisory support vary significantly by scope, but firms should budget at least several thousand euros for a properly documented risk assessment and policy suite. Ongoing costs include staff time, training, and periodic external review. Cutting corners at the setup stage typically results in higher remediation costs later when supervisory deficiencies are identified.
Can a foreign company rely on CDD conducted by its parent or a third party in Austria?
Austrian law permits reliance on third-party CDD under specific conditions set out in the FM-GwG. The relying entity must obtain the necessary information immediately from the third party, ensure that CDD documents can be provided on request without delay, and satisfy itself that the third party is itself subject to equivalent AML obligations and supervision. Responsibility for compliance remains with the relying entity - it cannot outsource liability. Reliance on a parent company';s CDD is permissible within a group, provided the group applies equivalent standards and the local entity has verified this. In practice, supervisors scrutinise reliance arrangements closely, and the relying entity must be able to demonstrate that it has genuinely assessed the third party';s compliance standards rather than simply assumed them.
Conclusion
Austria operates one of the more demanding AML & KYC regimes in the EU, covering a wide range of financial and non-financial businesses. Recent legislative changes, increased supervisory activity, and the forthcoming AMLA framework are raising the compliance bar further. Businesses operating in Austria - whether domestic or foreign-owned - must treat AML compliance as an ongoing operational priority, not a one-time exercise.
VLO Law Firms advises international clients on AML & KYC matters in Austria. We can assist with compliance programme design, beneficial ownership registration, suspicious activity reporting procedures, and regulatory engagement with the FMA and other supervisors. To request a consultation, contact: info@vlolawfirm.com