- Australia
- Austria
- Bangladesh
- Belgium
- Brazil
- Bulgaria
- Canada
- China
- Croatia
- Cyprus
- Czech Republic
- Denmark
- Egypt
- Estonia
- Eswatini
- Ethiopia
- Finland
- France
- Germany
- Greece
- Haiti
- Hong Kong
- Hungary
- India
- Iraq
- Ireland
- Indonesia
- Italy
- Japan
- Jordan
- Kazakhstan
- Kenya
- Kosovo
- Kuwait
- Latvia
- Lithuania
- Luxembourg
- Malaysia
- Malta
- Mauritius
- Mexico
- Micronesia
- Moldova
- Mongolia
- Montenegro
- Morocco
- Mozambique
- Myanmar
- Namibia
- Nauru
- Nepal
- Nigeria
- Nicaragua
- Niue
- Norway
- Netherlands
- New Zealand
- Oman
- Pakistan
- Palau
- Palestine
- Panama
- Papua New Guinea
- Paraguay
- Peru
- Puerto Rico
- Philippines
- Portugal
- Poland
- Qatar
- Republic of Congo
- Romania
- Russia
- Rwanda
- Samoa
- San Marino
- Senegal
- Serbia
- Seychelles
- Sierra Leone
- Singapore
- Slovakia
- Slovenia
- Somalia
- South Africa
- South Korea
- South Sudan
- Spain
- Sri Lanka
- St Kitts and Nevis
- St Maarten
- St Lucia
- Sweden
- Switzerland `
- Syria
- Taiwan
- Tajikistan
- Tanzania
- Thailand
- Timor Leste
- Togo
- Tonga
- Trinidad and Tobago
- Turkey
- Turks and Caicos
- Turkmenistan
- Tunisia
- Tuvalu
- Uganda
- Ukraine
- UK
- USA
- Vietnam
AUSTRIA KYC, KYB AND AML
Scale Identity Verification and KYC Operations in Austria
Verify Austrian customers and businesses through ID Austria, NFC, QES, identity documents, biometrics and KYB. Reduce manual review, maintain consistent audit evidence and run one connected workflow designed to support the FM-GwG today and AMLR from 10 July 2027.
Operational Performance for Austria KYC
Our Numbers Speak Volumes
99.17%
First-Pass
Verification Rate
< 10 sec
Median
Verification Time
5+
Austrian ID Methods
Supported
Austria IDV/KYC Challenges
The eID Gap
ID Austria is notified at the highest eIDAS assurance level, yet many customers are still onboard with photographed documents rather than their eID. Manual capture is slower and easier to spoof.
Austrian Names Break Global Matching
Müller and Mueller, Weiß and Weiss, hyphenated and double surnames trigger false positives, and manual review spikes when diacritics are lost in international databases.
KYB Runs Across Four Registries
Firmenbuch, GISA, UID and WiEReG sit in separate systems, so analysts stitch legal existence, trade status, tax identity and ownership together by hand, and AMLR's UBO test, 25% or more ownership or other control, sets who must be traced.
Registry Data Is Not Verification
Firmenbuch and GISA confirm a company exists, not who controls it or whether they are sanctioned. WiEReG extracts still need sanctions and PEP screening layered on top of registry lookups.
Regulatory Update
What AMLR Changes for Identity Verification in Austria
The EU Anti-Money Laundering Regulation (EU) 2024/1624 applies directly in Austria from 10 July 2027, with no transposition period. The FM-GwG will be amended to sit alongside it. AMLA, the new EU supervisor in Frankfurt, directly supervises selected entities from 2028.
Timeline
- End of 2026 Member State EUDI Wallet issuance deadline
- 10 July 2027 AMLR applies, no transposition
- Late 2027 eIDAS 2.0 Art 5f wallet acceptance applies
- 2028 AMLA direct supervision begins
eIDAS Is Expressly Recognised
Article 22(6) sets two routes, an identity document plus reliable, independent sources or eIDAS eID at substantial or high plus qualified trust services. Both are valid. ID Austria and QES are eIDAS routes, Online-IDV continues under national rules, and firms should document which route and why.
The Ownership Test Tightens
AMLR's test is 25% or more ownership, or control by other means, so WiEReG and KYB checks cover both. A lower bar, min 15%, may follow.
Existing Customers Get Re-Checked
AMLR expects existing customer records to be brought up to standard on a risk basis, not just new onboarding. Continuous monitoring keeps back-book files current between reviews.
Accountability Stays With You
Article 18 keeps customer due diligence accountable with the obliged entity even when verification is outsourced, so vendor evidence and clean audit trails matter more under AMLR.
FOR FMA-SUPERVISED BUSINESSES
Streamline FMA-Supervised Onboarding in Austria
Connect identity verification, QES, Penny Drop and compliance evidence in one configurable workflow for businesses operating within the FMA's supervisory remit. Reduce customer drop-off and manual handovers while giving compliance teams a consistent, review-ready record of every decision.
Verify the Customer
Verify identity using the configured route, such as ID Austria, NFC document reading or document and biometric checks.
Complete Qualified Signing
Apply and validate the QES within the same journey, keeping the signed document, verification result and supporting evidence together.
Confirm the Payment Account
Use Penny Drop Verification as a supporting fraud and account-ownership control, and keep the evidence alongside the QES and identity record.
Shufti's IDV/KYC Solutions for Austria
KYC Solutions
Onboarding built to support the FM-GwG for Austrian customers, with age and address checked in the same flow as identity, each check done in seconds.
Explore MoreFace Verification
Face verification binds the live person to the document with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness, stopping spoofs, masks and deepfakes.
.Age Verification
Selfie-based age estimation with document fallback for gaming and e-commerce, set to each Bundesland's youth protection age limit or, for gambling, the Glücksspielgesetz (BMF).
.Bank Account Verification
Confirms an Austrian bank account (AT IBAN) belongs to the customer, returning the registered account holder name for matching against the verified identity.
.Address Verification
Shufti verifies Austrian address-bearing documents, including the Meldebestätigung, utility invoices, telecom bills and bank statements from major Austrian issuers. Proof-of-address checks remain common in regulated onboarding.
.Document Verification
Verification of the Personalausweis, Aufenthaltstitel residence permit cards and Austrian ePassports, including NFC chip reading and German-language OCR extraction. Remains a permitted route for remote verification under AMLR.
.Identity Verification
Shufti confirms every customer is real and present, not a spoofed or synthetic identity. Biometric face matching and liveness detection run against 10,000+ active ID document types.
.KYB Solutions
Shufti checks firms as deeply as the people behind them to support your FM-GwG risk approach. Shufti checks registry records, beneficial ownership and VAT details in real time, then screens UBOs against 4,000+ global watchlists for sanctions and adverse media exposure.
Explore MoreBusiness Verification
Automated validation of Firmenbuch data, UID numbers in the ATU format, GISA trade licence records and managing directors. Reduces manual registry lookups and onboarding delays.
.Enhanced Due Diligence (EDD)
Structured risk profiling for complex ownership chains, cross-border entities and high-risk sectors, supporting Austria's risk-based AML obligations under the FM-GwG.
.AML Screening
Shufti screens customers and transactions in 240+ countries and territories, flagging sanctions, PEP and adverse media matches as they happen. Ongoing monitoring surfaces suspicious activity in time to meet local reporting obligations.
Explore More
AI Compliance Copilot
Helps compliance teams review verification and AML data, investigate alerts, and understand the reasoning behind risk signals. It brings relevant case information together to support faster, more consistent compliance decisions.
.
Transaction Monitoring
Ongoing transaction monitoring calibrated to Austrian financial flows flags anomalies against AML rules, supporting the risk-based controls expected by the FMA and the A-FIU.
.Supported Verification Methods for Austria
Every Verification Route Austria Uses, in One Platform
Shufti supports the full range of remote verification routes used in Austria, from the EUDI Wallet and ID Austria to document and biometric checks. Each method below shows what is live today and what is ready for the 2027 rollout.
EUDI Wallet
Wallet-ready · from 2027AMLR Article 22(6) expressly recognises eIDAS eIDs, including the EUDI Wallet. Austria is preparing its wallet under the eIDAS 2.0 rollout, building on its national digital identity system. Shufti is built to accept wallet-based verification as the Austrian wallet goes live.
Notified eID
LiveeIDAS HighID Austria, used through the ID Austria app, is Austria's notified eID at eIDAS level high (Official Journal, 27 April 2022). It replaced the Handy-Signatur and Bürgerkarte. Shufti supports ID Austria today.
Docless Database (eIDV)
LiveDatabase-driven verification confirms identity in seconds for low-risk onboarding with no document upload, using permitted reference data sources. Shufti escalates to stronger checks as risk rises.
NFC Chip Verification
LiveShufti reads the secure chip in the Austrian Personalausweis, the Aufenthaltstitel residence permit card and the Austrian ePassport. This is the high-assurance capture route where eID activation is still low.
Document and Face Biometric
LivePermitted under AMLR Art 22(6)(a). Document authentication of the Personalausweis, Aufenthaltstitel and Reisepass, paired with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness to confirm a real, present person.
Online-IDV Procedure
LiveThe FMA's Online-IDV (BGBl. II 5/2017 idF 470/2022, Aug 2026) allows staff-led video identification, with full audio and screenshots of customer and ID, and automated biometric identification on a chip-signed ID with video presence check and consent. Processors must match its safeguards and you stay responsible.
Qualified Electronic Signature
LiveThe FM-GwG recognises qualified electronic signatures and notified eIDs for remote identification. Shufti runs eIDAS-qualified signing powered by Evrotrust, an EU qualified trust service provider, producing PAdES-LTV signatures. For Austria the signing identity check runs through ID Austria, a notified eID supported for QES signing.
Independent Validation
Shufti's Recognition Across Independent Evaluations

Ranked Exceptional in the Liminal Index 2026 for age estimation
View Report
Differentiated by Gartner on document diversity and country coverage
Read more
Certified at iBeta Level 3 PAD with 0% APCER
Read Blog
Broadest global reach in the 2025 KuppingerCole Extended IDV report
Download Report
Ranked Top 5 in the DHS RIVR 2025 for identity validation
Read Blog
Top Vendor for Product Execution in the Liminal Index for KYC 2026
View Report
Ranked Exceptional for age verification by Liminal Index 2026
View Report
Recognised as a Leader in G2 Fall 2026 reports
Read MoreEvidence-Ready Checks Across People & Businesses
Verifications with robust evidentiary support
Individual Documents We Verify
Shufti verifies 15+ Austrian documents, including these.
View All Supported DocumentsPersonalausweis (Austrian Identity Card)
Primary photo ID for Austrian citizens. The card issued since August 2021 is biometric and EU-harmonised, with an NFC chip that supports high-assurance checks.
Reisepass (Austrian Passport)
Machine-readable Austrian passport issued under the Passgesetz. Biometric and ICAO-compliant, with an NFC chip that supports chip-based checks for cross-border onboarding.
EU Photocard Driving Licence
Austrian driving licence in the EU photocard format, often used as supporting ID in onboarding. Older paper licences can still surface until 19 January 2033.
Aufenthaltstitel (Austrian Residence Permit Card)
Electronic residence permit for third-country nationals, including Red-White-Red Card holders. A chip-based card with photograph and fingerprints for high-assurance verification.
Lichtbildausweis für EWR-Bürger (Photo ID Card for EEA Citizens)
Photo identity card for EEA and Swiss residents in Austria. It works as an identity document inside Austria for EEA citizens during onboarding and exception handling.
ID Austria and eAusweise
Austria's notified eID supports secure online identification at the highest eIDAS assurance level, and the eAusweise app can present digital IDs such as proof of age and driving licence.
Entity Identity
Firmenbuchauszug (Commercial Register Extract)
Commercial register extract from the Firmenbuch. Confirms legal name, FN number, legal form, registered address, directors and authorised signatories for KYB.
Gesellschaftsvertrag / Satzung (Articles of Association)
Founding documents that evidence a company's governance structure and shareholder framework during KYB onboarding.
GISA Extract (Trade Licence Register)
Extract from Austria's trade licence information system. Confirms trade permissions for businesses regulated under the Gewerbeordnung, including sole traders outside the Firmenbuch.
Tax Identity
Steuernummer (Austrian Tax Number)
Tax number issued by Finanzamt Österreich. Confirms a person or business is registered for tax and supports KYB and fiscal identity checks for onboarding.
UID-Nummer (VAT Identification Number)
VAT identification number in the ATU format, verifiable via EU VIES. Confirms a business is VAT-registered and trading legitimately.
Ownership & Control (UBO)
WiEReG Extract (Beneficial Owners Register)
Austria's central UBO register, run by the Federal Ministry of Finance. Shufti checks control data against it, with the AMLR ownership test applied at 25% or more for entities.
Gesellschafterliste (Shareholder List)
Shareholder evidence from Firmenbuch filings and corporate documents. Shufti uses it to map shareholdings and identify the people behind an Austrian company for UBO checks.
Languages We Cover
German-Language Document Parsing
Native German-language parsing keeps umlauts, ß and compound names intact across the Personalausweis, Aufenthaltstitel, Firmenbuch and WiEReG records, so checks stay accurate against official sources. Croatian, Slovenian and Hungarian carry official status in some regions, so records can hold local-language edge cases.
Name Matching Logic
Name and address matching handles Austrian formatting, umlauts and double surnames, resolving variants such as Müller and Mueller or Weiß and Weiss while keeping the original extracted value visible.
Cross-Document Consistency Checks
Cross-document consistency checks reconcile names and identifiers across the Personalausweis, Aufenthaltstitel, Firmenbuch and WiEReG records to catch mismatches before they reach manual review.
Governance & Controls
Audit-Ready Decisions, Lower Operational Drag
Fewer Avoidable Re-submissions
Optimised capture for Austrian ID formats and the NFC-enabled Personalausweis cuts avoidable re-submissions and manual review.
Cleaner Audit Trails
Structured logs aligned to FM-GwG retention (§ 21) and goAML reporting (§ 16) keep every onboarding decision audit-ready.
Better Name Matching Outcomes
Matching handles umlauts, ß conversion and double surnames common in Austria, reducing false positives and manual review.
One Workflow, One Back Office
KYC, KYB and AML screening are consolidated in one operational case view across Firmenbuch, GISA, WiEReG and screening outcomes.
National ID-First Flow Design
Personalausweis and ID Austria-first onboarding reflects Austria's national identity ecosystem and the way customers actually verify.
Continuous Compliance
Compliance that does not stop at onboarding
AMLR treats customer due diligence as a continuing obligation. Perpetual monitoring keeps the customer picture current between reviews, so risk is caught when it appears, not at the next annual check.
Surface Changes as it happens
DetectPerpetual monitoring flags risk when it appears, not at the next annual review. Behavioural biometrics, background fraud signals, and ongoing sanctions and PEP screening watch every active relationship.
Step up when the signal fires
VerifyWhen a signal fires, re-verification confirms the person or the ownership change using the same live methods above, so a flag turns into a resolved decision.
Keep the file audit-ready
ComplyEvery check and decision is logged to FM-GwG record-keeping standards, so the file is organised and retrievable for internal audit and supervisory review.
Perpetual KYC
pKYCKeeps individual customer risk current with behavioural biometrics, background fraud signals and ongoing AML screening, so back-book records stay standard-ready.
Perpetual KYB
pKYBMonitors WiEReG and Firmenbuch records, so a shift past the 25% or more UBO threshold, or a change of control, is caught between reviews.
Built To Fit Austria's Compliance Landscape
FMA (Financial Market Authority)
Supervises Austria's financial sector for AML/CFT under the FM-GwG, with financial sanctions supervision in its remit. Shufti supports CDD evidence, sanctions checks, EDD triggers and review-ready decision logs.
OeNB (Oesterreichische Nationalbank)
Austria's central bank supports payment systems oversight and financial stability. Shufti keeps onboarding, risk events and monitoring evidence aligned across customer and payment reviews.
A-FIU (Austrian Financial Intelligence Unit)
Austria's FIU, housed at the Bundeskriminalamt, analyses § 16 FM-GwG suspicious reports via goAML. Shufti organises identity evidence, screening hits, notes and timestamps for escalation.
Federal Ministry of Finance, WiEReG and FinanzOnline
Owns national AML policy and oversees WiEReG and the tax services used in UID workflows. Shufti helps capture UBO data, organise WiEReG evidence and link tax identifiers in KYB.
Austrian Data Protection Authority (DSB)
Austria's privacy authority enforces GDPR and the national DSG. Shufti supports controlled retention, traceable processing and clear deployment choices.
Federal Ministry of the Interior (BMI)
Oversees passports, identity cards, residence documents and ID Austria. Shufti supports evidence-ready capture and review across these identity journeys.
Firmenbuch, Justice Ministry
Maintains the commercial register and JustizOnline extracts. Shufti helps verify legal existence, status, directors and filings in one KYB flow.
GISA (Austrian Business Licence Information System)
Records Austrian trade-licence data, including sole traders outside the Firmenbuch. Shufti helps verify licensed activity, location and business status.
AMLA (EU Anti-Money Laundering Authority)
The new EU-level supervisor has been established in Frankfurt since July 2025. Begins direct supervision of selected high-risk cross-border entities from 2028 and shapes technical standards under AMLR.
Deployment Option
Cloud in EU and Austrian regions such as Azure Austria East and Exoscale Vienna, or on-premise, keeps Austrian customer data in-region and supports GDPR accountability.
Regulatory Alignment
Aligned with FM-GwG due diligence obligations, UBO verification and recordkeeping duties, as well as GDPR and DSG principles and AMLR requirements applying from July 2027.
Retention Controls
§ 21 FM-GwG sets ten-year retention once the relationship or transaction ends, then deletion (Abs. 2). From July 2027 AMLR Art 77 sets five years. Retention and purge settings follow your legal schedule.
Encryption & Security
Encryption in transit and at rest, with access controls and audit logs, supports Article 32 GDPR and DSG duties under ISO 27001 certification and SOC 2 Type II attestation.
Processor Role
Shufti is a data processor providing verification technology, not legal or regulatory advice. Due diligence and method choice remain the obliged entity's responsibility, documented in its risk assessment.
Biometric Processing
The lawful basis for processing is set by the controller. Biometric data used to uniquely identify a person engages Article 9 GDPR, and human review is available in the workflow.
Data and Privacy Controls in Austria
Austria AML Sources That Strengthen Decisions
We screen against 215+ sanction regimes, 4,000+ watchlists, 100,000+ adverse-media sources, and 6M+ PEPs across Austria and globally. A few of them are:
Financial Market Authority (FMA)
Austrian Financial Intelligence Unit (A-FIU)
Federal Ministry of Finance (BMF)
Federal Ministry of Justice (BMJ)
Austrian Bar Association (ÖRAK)
Chamber of Tax Advisers and Public Accountants (KSW)
Firmenbuch (Commercial Register)
EU Consolidated Financial Sanctions List
UN Security Council Consolidated List
FATF
Egmont Group of FIUs
European Banking Authority (EBA)
EU AMLA (Anti-Money Laundering Authority)
SEE SHUFTI IN YOUR AUSTRIA WORKFLOW
Turn Austrian Verification Requirements into a Smoother Customer Journey
Share your customer types, risk rules and current onboarding process. A Shufti specialist will show you how to connect identity verification, KYB, QES, Penny Drop and ongoing monitoring, reducing operational hand-offs while keeping decision evidence organised for compliance review.
Frequently Asked Questions
Which identity documents can be used for onboarding in Austria?
Customers can use the Austrian Personalausweis, Reisepass, Aufenthaltstitel residence permit card, EU photocard driving licence and the Lichtbildausweis für EWR-Bürger, alongside ID Austria for eID-based verification. Shufti supports document, eID, NFC and biometric verification within one configurable workflow.
How does Shufti support FMA-supervised businesses in Austria?
Shufti connects identity verification, KYB, AML screening, QES, account verification and decision evidence in one configurable workflow. This helps businesses within the FMA's supervisory remit reduce manual hand-offs, standardise compliance records and prepare clearer evidence for internal audit and applicable supervisory review.
What documents are required for KYB in Austria?
Typically a Firmenbuch extract, UID number, GISA record where the business is trade-led, shareholder evidence and beneficial ownership details from WiEReG. Shufti verifies these in real time and screens the UBOs behind them against sanctions and PEP lists.
How are Austrian name variants handled in screening?
Matching accounts for umlauts, ß and ss equivalence, and hyphenated or double surnames, so variants such as Müller and Mueller or Weiß and Weiss resolve correctly and false positives on Austrian names stay low.
How long must AML records be retained in Austria?
Under § 21 Abs. 1 FM-GwG, ten years after the relationship or occasional transaction ends, then deletion (Abs. 2). From July 2027 AMLR Art 77 sets five years, extendable case by case by authorities. Shufti's controls follow your schedule.
Is EU-region data hosting available for Austrian data?
Yes. Shufti offers EU-based cloud regions, including Austrian options such as Azure Austria East and Exoscale Vienna, so Austrian customer data stays in-region in line with GDPR and the DSG. On-premise deployment is available where residency requirements are stricter.
What changes for Austria under AMLR from July 2027?
AMLR applies directly, so no Austrian transposition law is needed. It allows two routes, document-based and eIDAS-based, so notified eIDs like ID Austria, the EUDI Wallet and qualified trust services sit with document and biometric checks, and sets the beneficial ownership test at 25% or more, assessed with control.
How do QES and account verification work together under Austrian law?
§ 6 Abs. 4 FM-GwG recognises qualified electronic signatures and notified eIDs for remote identification. Where a workflow calls for account evidence, Shufti connects QES, Penny Drop Verification and supporting records, with Penny Drop as a supporting account-ownership control.
When will the EUDI Wallet be usable for onboarding in Austria?
Under eIDAS 2.0, Member States must issue wallets by end 2026, and from late 2027 Article 5f requires defined relying parties, not all regulated firms, to accept them. Austria is preparing its wallet on the foundation of its national digital identity system. Shufti is built to accept wallet-based verification as the Austrian wallet goes live, so onboarding flows will not need to be rebuilt.
Can we keep using video identification in Austria after July 2027?
That depends on national rules and on the Online-IDV staying in force. It has no expiry today, and AMLR Article 22(6) treats document-based and eIDAS-based checks as two permitted routes, so Online-IDV identification continues where national rules allow it, with a documented reason for the method. Shufti supports both, so firms can shift the mix over time.
Let’s Build Trust Into Your Business
1B+Verifications Processed
240+Regions Actively Processed
99.7%Accuracy Rate
Samer Al Tamimi
CEO of Safwa Bank
“We take our client’s privacy very seriously and always look for new innovative solutions to ensure a safe banking experience. Working with Shufti feels like a breath of fresh air, as their 100% in-house tech keeps our customer’s data free from vulnerabilities and fully safe and protected.”
Trusted. Compliant. Certified
Explore Shufti For Your Business
Get a personalised demo from our experts.
PROVEN PLAYBOOKS
Explore Practical KYC & AML Resources
10 July, 2026
Identity Verification in Europe: eIDAS 2.0 & EUDI Wallet
A practitioner's guide to verifying identity in Europe, covering eIDAS 2.0, the EUDI Wallet, docless eIDV and how to choose an eID provider for onboarding in the EU.
Product Guide





