On-shore VASP in Estonia
Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.
On-shore VASP is conditionally permitted in Estonia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Full AML/KYC/CDD policies mandatory under MLTFPA — customer identification, verification, transaction monitoring, source-of-funds checks.
- Suspicious activity reporting to the Financial Intelligence Unit (FIU).
- Appoint a dedicated AML officer with financial sector experience (employed under contract).
- Screen customers and transactions against UN and EU sanctions lists; tailor controls to risk profiles.
- Travel Rule applies to all transaction amounts with no de minimis threshold — collect and transmit originator/beneficiary data for all transfers (per AML Act Section 25(23)).
- Ongoing compliance audits and annual financial audits.
- MiCA reporting obligations to the Financial Supervision Authority (FSA/Finantsinspektsioon).
- Data retention and internal controls obligations under MLTFPA.
Key Restrictions
- Must incorporate as Estonian OÜ (LLC) or AS (public limited company) with a physical office in Estonia.
- At least one management board member must be an Estonian or EEA resident.
- Must maintain an Estonian bank account.
- Demonstrate 'genuine local substance' for regulatory inspections.
- Capital requirement: €250,000 for transfer/custody services (on-shore VASP offering custody/transfer); €100,000 minimum for exchange-only services.
- State fee of €10,000 for license application.
- Full CASP license (single license regime) mandatory — combines previously separate exchange/wallet licenses.
- Transition period: prior FIU VASP registrations valid only until July 1, 2026; full transition to FSA licensing required.
Key Risks
- Regulatory regime transition (FIU → FSA) creates timeline pressure and potential gaps during migration.
- Many VASP licenses were withdrawn in 2020 — enforcement precedent exists for aggressive cleanup.
- Travel Rule has no de minimis threshold, imposing heavy data collection burdens on all transactions.
- Estonian authorities (EFSRA) described as having a 'conservative stance' on VASPs, increasing application scrutiny.
- Notarized/apostilled documents required for foreign key persons — adds cost and delay.
- Post-MiCA licensing timeline from FSA not clearly specified — potential for extended review periods.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Authorized capital: €250,000 for transfer/custody services (vs. €100,000 for exchange).
Physical headquarters in Estonia, customer identification, annual audits, internal controls, data retention, and good business reputation.
Registration in the Estonian cryptocurrency license register, with ongoing supervision including financial reports and internal control submissions.
Money Laundering and Terrorist Financing Prevention Act (MLTFPA): https://www.riigiteataja.ee/en/eli/ee/Riigikogu/act/520062020002/consolide (via )
Crypto Asset Market Act (CMA): National implementation of MiCA (via )
EU MiCA Regulation (2023/1114): https://eur-lex.europa.eu/eli/reg/2023/1114/oj (via )
EFSRA/FIU licensing: https://www.fi.ee/en (via )
Firms must screen customers and transactions against UN and EU sanctions lists, tailoring controls to risk profiles.
Appoint an AML officer with financial sector experience and ensure at least one management board member is an Estonian resident.
VASPs provide services like virtual currency exchange or wallet services and must maintain internal controls, annual financial reports, and independent audits.
Financial Supervision Authority (FSA, or Finantsinspektsioon): Primary regulator for CASPs and issuers since January 1, 2025 (transferred from FIU); handles licensing, supervision, enforcement, and compliance with MiCA, DORA, financial requirements, consumer protection, and governance.
Financial Intelligence Unit (FIU): Supervised VASPs until end of 2024; prior issuer of licenses (many withdrawn in 2020, ~400 active as of then); legacy licenses valid until July 1, 2026, after which transition to FSA required.
Estonian Financial Supervision and Resolution Authority (EFSRA): Oversees broader financial services market, including FinTech innovation, with a conservative stance on VASPs.
Crypto Asset Market Act (July 1, 2024): Aligns Estonia with EU MiCA (Regulation 2023/1114) and DORA (Regulation (EU) 2022/2554); expands regulation to exchanges, wallets, trading platforms, custodians, and token issuers; mandates FSA licensing, local office, capital adequacy, client protection, and complaint handling.
Markets in Crypto-Assets (MiCA) Regulation (effective EU-wide, implemented in Estonia 2025): Unified EU framework; imposes stricter AML, local presence, share capital, and internal controls; all Estonian crypto operations now comply.
CASP License: Mandatory for all providers of crypto-asset services, including exchanges, wallets, and transfers; covers virtual currency exchange and transfer services under the single license regime (previously separate).
Registration Regime: Providers must incorporate as an Estonian legal entity with a physical office, local board member/director (Estonian resident), and Estonian bank account; demonstrate "genuine local substance" for inspections. VAT registration with the Estonian Tax and Customs Board is also required post-incorporation.
Incorporate Local Entity: Submit memorandum/articles of association, share capital deposit certificate (€100,000+), and state fee to the Commercial Register.
Prepare Documentation: Include AML/KYC/KYT policies, business model description, business plan, governance structure, internal controls, digital resilience plans, biographies/no-criminal-record certificates for key persons (notarized/apostilled for foreigners), and proof of office/local representative. All in Estonian (translations required).
Submit Application: File electronically via FSA portal (for issuers from March 18, 2026) or by board member; state fee €10,000.
Post-2024 (CASP/MiCA era): Full authorization/licensing by EFSA, with rigorous supervision, audits, and MiCA compliance; prior VASP registrations are transitional until 2026.
Capital: Varies by service—€100,000 minimum for exchange services; €250,000 for transfer/custody services (own funds must cover risks). (Note: Older sources cite €12,000, outdated post-MiCA.)
AML/KYC: Mandatory policies for customer identification/verification, transaction monitoring, source-of-funds checks, suspicious activity reporting to FIU; ongoing compliance audits.
Local Presence: At least one management board member (director) as permanent Estonian/EEA resident; local office/place of business in Estonia; Estonian bank account.
Other: Appoint dedicated AML officer (employed under contract, financial sector experience); good business reputation for owners/directors; auditor agreement; annual financial audits, MiCA reporting.
Incorporate as Estonian OÜ (LLC) or AS (public limited company).
Prepare documents: Ownership structure, CVs/proof of residency for directors/key personnel, business/AML/KYC policies, operational plan, capital proof, auditor agreement.
Submit to EFSA (Finantsinspektsioon); prior FIU role ended.
Post-approval: Annual audits, AML monitoring, change notifications.
Primary Estonian Laws: Crypto Asset Market Act (CMA); Money Laundering and Terrorist Financing Prevention Act (MLTFPA).
EU Framework: MiCA Regulation (EU) 2023/1114.
Authorities: EFSA (https://www.fi.ee/en/investeerimine/investeerimisvaldkonna-tegevuslubade-taotlemine/kruptovaraturu-tegevusluba); FIU (transitional).
Adopted and Effective Date: Implemented by Estonia’s Financial Intelligence Unit (FIU) under the Ministry of Finance via amendments to the AML Act. The rule took effect March 15, 2022, with a three-month compliance period ending June 15, 2022—the fastest Travel Rule enforcement globally. One source notes alignment with EU AMLD5 effective July 1, 2021, but primary enforcement dates are March/June 2022.
Threshold Amounts: No exceptions or de minimis threshold; applies to all transaction amounts per AML Act Section 25(23).
VASPs Covered: All Crypto Asset Service Providers (CASPs) or Virtual Asset Service Providers (VASPs) operating in Estonia, required to register with the Estonian FIU and submit details on operations, governance, and compliance. Includes crypto exchanges and custodians; transactions with self-hosted wallets require AML/CTF measures like enhanced due diligence, though full data transmission may not apply—VASPs must collect/retain originator/beneficiary info for authorities.
Technical Implementation Requirements: VASPs must collect and transmit originator and beneficiary data (e.g., name, essential for sanctions screening) for all transfers, even without thresholds. No transmission required for certain counterparties (details incomplete in sources), but risk monitoring and data retention are mandatory. Must align with EU frameworks like MiCA (transition to July 2026 for pre-2024 CASPs). Specific legislation: AML Act Sections 25(23), 25(24), 25(25), 25(27).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — an on-shore VASP is permitted in Estonia but requires a full CASP license from the Financial Supervision Authority (FSA) under the MiCA-aligned Crypto Asset Market Act, local incorporation with physical office and resident board member, €250,000 capital (for custody/transfer) or €100,000 (exchange), and comprehensive AML obligations including a zero-threshold Travel Rule.
Questions this verdict aims to answer
- What license(s) are required to operate locally?
- What capital, governance, and reporting obligations apply?
- What is the application process and timeline?