Remote VASP serving residents in Austria
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Austria with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASP registration with FMA under § 32a FM-GwG (Finanzmarkt-Geldwäschegesetz) is mandatory for any entity providing services related to virtual currencies to Austrian residents
- Robust AML/KYC framework required: customer due diligence, transaction monitoring, risk management, and suspicious transaction reporting to the Financial Intelligence Unit (FIU)
- Appointment of a designated AML officer
- Fit and proper requirements for management and key persons
- Establishment of internal controls and risk management systems to prevent money laundering and terrorist financing
- From December 30, 2024 (MiCA full applicability): full CASP authorization from FMA required, with prudential safeguards, capital requirements, governance arrangements, and operational resilience obligations
- Complaint handling procedures for clients required under MiCA
- Travel Rule obligations apply under EU MiCA/AML framework, replacing fragmented national VASP regimes
Key Restrictions
- Foreign entities cannot serve Austrian residents from abroad without FMA registration (current) or MiCA CASP authorization (from 30 Dec 2024); no cross-border remote-only exemption exists
- Local establishment (registering with FMA) is effectively required — the FM-GwG imposes obligations on entities 'offering services in Austria', which implies a local nexus
- No dedicated 'license for remote VASPs' — a foreign VASP must go through the same FMA registration (current) or CASP authorization (post-MiCA) path as local firms
- Post-MiCA (from 30 Dec 2024): CASP authorization permits EU-wide passporting, but still requires authorization through a home member state regulator — cannot bypass by remaining purely remote
Key Risks
- Enforcement precedent: FMA has taken action against unregistered operators (e.g., KuCoin EU ordered to cease new business), demonstrating active enforcement against non-compliant VASPs serving Austrian residents remotely
- Operating without FMA registration (current) or CASP authorization (post-MiCA) exposes the operator to cease-and-desist orders, administrative fines, and potential criminal liability under Austrian AML laws
- Regulatory ambiguity pre-MiCA: the FM-GwG scope includes 'offering services in Austria' but lacks detailed guidance on what constitutes sufficient cross-border activity to trigger registration — creates uncertainty for remote operators
- Tax reporting risk: Austrian tax authorities (BMF) treat crypto gains as taxable income; remote operators may face difficulty complying with Austrian tax reporting obligations without a local presence
- Transition risk: the shift from FM-GwG registration to full MiCA CASP authorization by 30 Dec 2024 imposes material new prudential and organizational requirements that remote operators may not have prepared for
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Currently (Pre-MiCA Full Implementation): Partial, primarily AML/CFT-focused. Austria has a framework that primarily addresses anti-money laundering and counter-terrorist financing (AML/CFT) aspects, along with existing securities and tax laws that apply depending on the classification of the crypto asset. This means many crypto activities are not specifically regulated as financial services unless they fall under traditional definitions (e.g., a token classified as a security).
Geldwäsche- und Terrorismusfinanzierungsgesetz (GWG) – Anti-Money Laundering and Counter-Terrorist Financing Act (as amended):
Finanzmarktaufsicht (FMA) – Austrian Financial Market Authority:
VASP Registration: There is no dedicated "custody license" per se. Instead, entities providing custody of virtual assets are classified as Virtual Asset Service Providers (VASPs) and are required to register with the Austrian Financial Market Authority (FMA).
Scope: The FM-GwG defines "providers of services related to virtual currencies" to include "the safekeeping of virtual currencies for third parties" (i.e., custody).
Fit and Proper Management: Key persons involved in the management must demonstrate their suitability and reliability.
Robust AML/KYC Framework: Implementation of comprehensive policies and procedures for customer due diligence (KYC), transaction monitoring, risk management, and reporting of suspicious activities to the Financial Intelligence Unit (FIU).
Designated AML Officer: Appointment of a dedicated officer responsible for AML compliance.
Finanzmarkt-Geldwäschegesetz (FM-GwG): § 2 Z 22 FM-GwG defines virtual currency and § 32a FM-GwG outlines the registration requirements for providers of services related to virtual currencies.
Current: The FM-GwG, being an AML law, does not explicitly mandate prudential segregation of client crypto assets from the custodian's own assets.
EU-Wide Authorization: Custodians will need to obtain authorization as a CASP from the FMA. Once authorized, they can "passport" their services across the EU.
MiCA introduces robust requirements beyond AML, but Austrian regulator action (banning KuCoin EU from new business) shows that enforcement was still needed to address gaps, with KuCoin subsequently hiring a new AML chief and expanding compliance in Vienna
Prudential Safeguards: Capital requirements (see below).
Organizational Requirements: Clear governance arrangements, effective risk management, internal controls, and operational resilience.
Fit and Proper Requirements: For management and shareholders.
EU MiCA Regulation (EU 2023/1114) has replaced fragmented national VASP regimes with a harmonized CASP (Crypto-Asset Service Provider) authorization framework across all EU member states, including Austria. The 5th Anti-Money Laundering Directive (5AMLD/T5AMLD) VASP registration system is now superseded by MiCA's single EU-wide licensing regime, effective December 30, 2024.
Titles III (ARTs) and IV (EMTs) of MiCA, covering stablecoins, will apply from 30 June 2024.
The remaining provisions of MiCA for other crypto-assets and crypto-asset service providers will apply from 30 December 2024.
Complaint Handling: Procedures for client complaints.
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a foreign VASP serving Austrian residents remotely must register with the FMA under the FM-GwG (pre-MiCA) or obtain CASP authorization under MiCA (from 30 Dec 2024); there is no cross-border remote-only exemption, and the obligations are equivalent to those for local operators, including full AML/KYC frameworks, fit-and-proper management, and prudential safeguards under MiCA.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?