The supervisory message, published on 10 July, follows a cross-sector review by the FMA’s Conduct Supervision function. The authority found areas requiring particular attention in how financial institutions define, process, document and analyse complaints. It warned that weak procedures can allow systemic problems to remain undetected, potentially exposing institutions to reputational damage and breaches of supervisory obligations.

The development is significant because it moves complaints management beyond the traditional boundaries of customer service and consumer protection. In the FMA’s interpretation, a complaint is also a source of risk intelligence. A repeated problem reported by customers may reveal weaknesses in a product, operational process, control environment or distribution model before those weaknesses become visible through conventional risk reporting.

The regulator’s approach reflects an increasingly important supervisory principle: information generated at the edge of an organisation can provide an earlier and more realistic warning than central reporting structures.

Formal risk indicators are often retrospective. They may depend on thresholds being exceeded, incidents being classified correctly or problems being escalated through several management layers. Customer complaints arrive through a different route. They capture the practical consequences of processes that are not functioning as intended.

A complaint about repeated account-access failures, unexplained transaction delays, incorrect customer data, unavailable digital services or unsuccessful authentication may initially appear to be a service issue. When similar cases occur repeatedly, however, they can indicate weaknesses in technology, change management, fraud controls, third-party services or operational resilience.

The FMA does not describe these examples as cyber incidents in its publication. Nevertheless, CyberKreuz analysis shows that the same complaints data can be particularly valuable for detecting technology and security-related problems. Customers often experience the effects of an operational or cyber weakness before the institution has formally identified its cause.

The regulator expects institutions to define clearly what constitutes a complaint and distinguish it from a general query or request for information. This apparently administrative distinction has substantial risk implications. An overly narrow definition can prevent relevant cases from entering the formal complaints process, reducing the amount of evidence available for trend analysis and management oversight.

The FMA also expects complaints procedures to be easily accessible. Customers should be able to find relevant information without specialist knowledge, including through websites and mobile applications. Complaints must be handled objectively and within the applicable deadlines, while conflicts of interest should be avoided.

The most consequential requirement concerns analysis and internal integration. The authority states that institutions must analyse, document and remediate systemic or recurring problems through appropriate measures. Internal procedures should be coherent, complete and adapted to the institution rather than relying on generic templates
.
This means that the effectiveness of complaints management cannot be measured solely by response times or the number of closed cases.

An institution may answer every customer within the required deadline and still operate an ineffective process if it fails to identify patterns across departments, products and communication channels. Closing a complaint resolves the individual case. It does not necessarily address the underlying cause.

The FMA’s position therefore places greater importance on aggregation. Institutions need to determine whether complaints that appear unrelated at first are connected to the same process, supplier, digital platform or control weakness.

This is especially relevant in complex financial organisations where responsibility is distributed across customer service, compliance, operations, information technology, fraud prevention, cybersecurity and outsourced service providers. Each function may see only part of the problem.

For example, a customer-service team may record several complaints about delayed payments. The IT department may separately investigate intermittent system performance. Fraud teams may see an increase in blocked transactions, while a third-party provider reports service instability. Without an integrated analysis, the institution may fail to recognise that all four signals originate from the same operational weakness.

The FMA’s message also has implications for management information.

Boards and senior executives commonly receive complaints statistics, but these reports often focus on volumes, categories, response deadlines and customer compensation. Such metrics are useful for conduct oversight, but they may not reveal whether complaints indicate a deterioration in operational resilience or internal controls.

More effective reporting would identify recurring causes, affected business services, responsible process owners, dependencies on technology providers and the status of corrective actions. It would also show whether similar complaints are appearing across several products or legal entities.

Institutions should consider linking complaints data to operational incidents, control failures, fraud events and technology problems. This does not mean that every customer complaint should be treated as a cyber or operational incident. It means that repeated patterns should be tested against information already held by risk, security and operations functions.

The timing is relevant. The FMA has increased its focus on digital operational resilience since the application of DORA in 2025. Its annual report describes greater supervisory transparency around cybersecurity and digital risk, while earlier supervisory publications have addressed ICT risk management and concentration risk arising from external technology providers.

The complaints publication is not formal DORA guidance and should not be presented as such. However, it complements the wider regulatory expectation that financial institutions understand how failures affect important business services and detect weaknesses before they develop into major incidents.

Under DORA, financial entities are expected to maintain an ICT risk-management framework, record and classify ICT-related incidents and learn from disruptions. Complaints analysis can support these processes by revealing customer-visible effects that may not yet have triggered internal incident thresholds.

The same principle applies beyond cybersecurity.

Repeated complaints may expose unsuitable product design, misleading information, weaknesses in sales processes, errors in fee calculations or inadequate claims handling. They may also indicate that corrective action taken after an earlier incident was incomplete.

The challenge for institutions is to avoid creating a process that collects large volumes of data without producing actionable insight.

Complaints systems frequently contain inconsistent categories, fragmented descriptions and limited information about root causes. Cases may be recorded differently across branches, subsidiaries or communication channels. This makes it difficult to identify patterns and compare risks.
Institutions should therefore review the quality and structure of complaints data as carefully as they review the formal procedure. Common definitions, consistent classification and links to relevant products, processes and systems are necessary if complaints are to function as a reliable risk indicator.

Automation and artificial intelligence may help institutions analyse large volumes of unstructured complaint text, identify recurring language and detect unusual changes in complaint patterns. These tools should support rather than replace human assessment. Poor data, weak categorisation or inappropriate models can produce misleading conclusions and create new conduct and governance risks.

The ownership of the process is equally important. Complaints management often sits within legal, compliance or customer-service functions. The FMA’s approach indicates that findings should also reach operational risk, information security, technology and senior management where relevant.

A clear escalation mechanism is needed when complaints suggest a systemic or recurring weakness. Institutions should define who decides whether a pattern requires a formal investigation, a control review, incident assessment or notification to the regulator.

Corrective actions should also be tracked to completion. A common weakness in risk management is that organisations identify a recurring issue and implement a local solution without confirming whether the same problem exists elsewhere.

The FMA’s publication does not introduce a new reporting obligation or impose a separate technology standard. Its significance lies in how it reframes an established regulatory requirement.

Complaints management is no longer merely the function that responds when a customer is dissatisfied. It is becoming part of the institution’s internal detection capability.

For cybersecurity and operational-resilience leaders, the practical lesson is to examine whether customer complaints are included in risk-monitoring and incident-detection processes. A mature organisation should be able to recognise when a series of apparently minor service problems forms evidence of a larger control or technology failure.

The Austrian regulator’s message is therefore broader than customer protection. It reflects an expectation that financial institutions learn systematically from the problems their customers encounter and use that information to identify weaknesses before they become regulatory breaches, major operational disruptions or lasting damage to trust.