D1 Sanctions Architecture and Evasion
Sanctions Architecture and Evasion
Continue reading
Austria has closed a significant institutional seam in its sanctions-supervision architecture. As of 1 January 2026, the Finanzmarktaufsicht (FMA) became the sole supervisor for financial sanctions and AML/CFT across the country's financial market, under the newly adopted Sanctions Act 2024, which replaces the Sanctions Act 2010. Prior to this consolidation, sanctions and AML/CFT supervision sat across a more fragmented set of arrangements; the new architecture brings credit and financial institutions, payment institutions, investment firms, alternative investment fund managers, insurers, and crypto-asset service providers under a single supervisory roof for both functions simultaneously.
The architectural significance of this move should be read against Austria's 2026 FATF mutual evaluation, which found clear progress in strengthening the country's AML/CFT legal and regulatory framework but nonetheless placed Austria in enhanced follow-up. The follow-up placement did not turn on sanctions architecture as such, but on unresolved capacity in ML investigation and prosecution — a gap independently corroborated by an IMF publication of the same underlying assessment, and one that has persisted since at least 2016. The consolidation therefore represents genuine progress on the architecture side of the sanctions-and-AML equation, but it has not yet been shown to resolve the capacity-side gap that FATF specifically flagged.
A further extension of this architecture brings crypto-asset service providers explicitly within the unified sanctions-screening framework alongside banks and payment institutions, rather than leaving CASPs to a separate or delayed sanctions-compliance track. This positions Austria among jurisdictions treating crypto infrastructure as a first-class citizen within mainstream sanctions supervision from the outset of a consolidated framework, rather than retrofitting crypto-specific sanctions rules after the fact.
No AT-specific evidence of sanctions-evasion typologies, autonomous-listing divergence, or enforcement actions specifically tied to sanctions breaches (as distinct from AML/CFT due-diligence breaches) surfaced this cycle. The Sparkasse Oberösterreich fine, discussed under the AML/CFT domain, pertains to due-diligence obligations rather than sanctions screening specifically, and should not be read as a sanctions-architecture finding.
Outlook
The key question for the sanctions-architecture domain going forward is whether the FMA's consolidated supervisory mandate produces measurable improvement in the capacity gaps FATF identified, particularly around ML investigation and prosecution resourcing, over the multi-year follow-up period FATF has set. The integration of CASPs into the unified framework is also worth tracking as Austria's crypto-licensing activity under MiCA continues; how sanctions screening interacts with that separate regulatory track will be a useful signal of the consolidated architecture's practical reach.