EAA compliance for FinTech and financial services
Financial services organisations face a dual compliance problem: EAA obligations and sector-specific enforcement authorities that differ by market. Here is what that means in practice.
FinTech and financial services organisations often assume that existing regulatory compliance (PSD2, GDPR, DORA) provides a foundation for EAA readiness. In practice, accessibility is a distinct obligation with its own requirements, its own enforcement authorities, and its own evidence standards. The Barómetro de Accesibilidad Web 2025 found financial services the worst-performing sector for accessibility, with 18% of sites non-conformant, the highest rate of any sector surveyed.
Worst-performing is also the widest opening. The failures cluster at the journeys that decide revenue: opening an account, getting a quote, making a payment. Every one you fix is a customer who can now finish what they came to do, in a sector where acquisition cost is already high and switching friction is already low.
The enforcement authority differs by market
One of the most important things for FinTech organisations to understand is that the EAA enforcement authority for financial services is not the same as for general e-commerce in some markets. Getting this wrong means engaging the wrong regulator, or worse, assuming you have no current exposure when you do.
Netherlands
For financial services organisations operating in the Netherlands, the enforcement authority is the AFM (Authority for Financial Markets), not the ACM which covers e-commerce and telecoms. The AFM has the same reach as the ACM: penalties up to €900,000, or up to 10% of annual turnover where that is higher. The Netherlands also requires proactive mandatory reporting of your compliance position, with documentation and a compliance declaration ready for the AFM on request.
Ireland
The Central Bank of Ireland is the designated competent authority for consumer banking and financial services, not ComReg, which covers electronic communications. Ireland’s regime carries director-level accountability: company officers can be held personally liable for an offence committed with their consent or neglect, with penalties on indictment up to €60,000 and up to 18 months. The practical defence is documented due diligence, and it only works if it already exists when a question arrives.
Sweden
PTS oversees digital financial services under the EAA in Sweden, with active supervision underway across multiple sectors and an audit programme running through 2026. Digital banking apps, payment platforms, and investment portals are all in scope. The maximum fine is SEK 10,000,000 (approximately €900,000).
Germany
The BFSG covers digital financial services offered to German consumers. The private enforcement mechanism (Abmahnungen) applies: competitors and law firms can send legal demands without any regulator being involved. Market surveillance can separately impose fines on a two-tier scale: up to €10,000 for standard violations, and up to €100,000 for serious or repeated ones.
What financial services products are in scope
The EAA covers digital services and products offered to consumers. For FinTech and financial services, this includes:
- Mobile banking applications and web banking portals
- Payment services and digital wallets
- Investment platforms and trading apps
- Insurance product portals and quote engines
- Lending and credit application platforms
- Customer onboarding and identity verification flows
- Account management and billing systems
B2B-only financial products used exclusively by other businesses rather than consumers may fall outside scope. However, many FinTech platforms have both business and consumer users, and the consumer-facing elements bring the whole product into scope for accessibility assessment purposes.
The intersection with other financial regulation
PSD2, DORA, and MiCA all create overlapping obligations for digital financial services. The EAA adds accessibility as a distinct layer. Unlike those regulations, EAA compliance is not primarily about data, security, or operational resilience: it is about whether the product actually works for users with disabilities. The two types of compliance are complementary but separate, and an organisation that is fully compliant with PSD2 may still have significant EAA exposure.
The accessibility statement is the starting point for enforcement. In Ireland, it is among the first documents the Central Bank requests. In the Netherlands, it forms part of the mandatory reporting declaration to the AFM. An organisation without a published accessibility statement starts any enforcement interaction at a disadvantage, regardless of how much technical work has been done on the product itself.
What EAA compliance requires
One of the most common and least-recognised EAA barriers in financial services is authentication. OTP codes that expire in 30-60 seconds create impossible time pressures for users who rely on screen readers or keyboard navigation. CAPTCHA verification added alongside login processes is largely inaccessible to blind users. SMS-only OTP delivery excludes deaf-blind users who rely on Braille displays. Under EAA, authentication flows are in scope. They are core user journeys, not peripheral features.
For a FinTech or financial services organisation, full EAA compliance requires four things: technical conformance against EN 301 549 (WCAG 2.1 Level AA), a published accessibility statement, active governance with a named owner and regular testing rhythm, and documentary evidence of ongoing management. Most organisations we speak with have addressed at most one of the four.
Find out where your organisation stands
Our free initial assessment is your starting point: it helps you place your platform, get a read on your exposure, and see what a proportionate next step looks like.
Book your free assessment today