Remote VASP serving residents in Estonia
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Estonia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Full AML/KYC/CFT obligations under the Money Laundering and Terrorist Financing Prevention Act (MLTFPA) and MiCA — mandatory customer identification, verification, transaction monitoring, source-of-funds checks
- Suspicious Activity Reporting (SAR) to the FIU
- Travel Rule applies to ALL transactions (no de minimis threshold) — must collect and transmit originator and beneficiary data per AML Act Section 25(23)
- Screen customers and transactions against UN and EU sanctions lists, tailoring controls to risk profiles
- Appoint a dedicated AML officer with financial sector experience; at least one management board member must be an Estonian resident
- Annual financial audits and AML monitoring reports required
- Ongoing supervisory submissions to the Financial Supervision Authority (FSA / Finantsinspektsioon)
Key Restrictions
- Must incorporate as an Estonian legal entity (OÜ or AS) — no pure remote/cross-border service offering without local incorporation
- Must maintain a physical office / place of business in Estonia ('genuine local substance' required for inspections)
- At least one management board member must be an Estonian or EEA resident
- Must hold an Estonian bank account for the entity
- Must hold a CASP license from EFSA (Financial Supervision Authority) — not merely a registration — with authorized capital of €100,000 (exchange) or €250,000 (transfer/custody)
- Transition from legacy FIU VASP registrations to full FSA licensing required by July 1, 2026
- State fee of €10,000 for license application; comprehensive documentation package required including AML/KYC/KYT policies, business plan, governance structure, digital resilience plans
Key Risks
- Unlicensed cross-border servicing of Estonian residents carries high enforcement risk — Estonia has a history of mass VASP license withdrawals (2020) and aggressively requires local substance
- Operating without a local entity and CASP license exposed to FSA enforcement actions, fines under CMA Chapters 7-8, and potential criminal liability
- Travel Rule compliance is strict (no threshold) and technically demanding for operators without local infrastructure
- Post-MiCA transition period ends July 1, 2026 — legacy VASP registrations will expire, creating a cliff edge for non-compliant operators
- Estonian FSA/EFSRA takes a conservative stance on VASPs/CASPs; genuine local substance requirement may be rigorously inspected
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Physical headquarters in Estonia, customer identification, annual audits, internal controls, data retention, and good business reputation.
CASP License: Mandatory for all providers of crypto-asset services, including exchanges, wallets, and transfers; covers virtual currency exchange and transfer services under the single license regime (previously separate).
Registration Regime: Providers must incorporate as an Estonian legal entity with a physical office, local board member/director (Estonian resident), and Estonian bank account; demonstrate "genuine local substance" for inspections. VAT registration with the Estonian Tax and Customs Board is also required post-incorporation.
Incorporate Local Entity: Submit memorandum/articles of association, share capital deposit certificate (€100,000+), and state fee to the Commercial Register.
Authorized capital: €250,000 for transfer/custody services (vs. €100,000 for exchange).
Submit Application: File electronically via FSA portal (for issuers from March 18, 2026) or by board member; state fee €10,000.
Appoint an AML officer with financial sector experience and ensure at least one management board member is an Estonian resident.
Firms must screen customers and transactions against UN and EU sanctions lists, tailoring controls to risk profiles.
Money Laundering and Terrorist Financing Prevention Act (MLTFPA): https://www.riigiteataja.ee/en/eli/ee/Riigikogu/act/520062020002/consolide (via )
Crypto Asset Market Act (CMA): National implementation of MiCA (via )
Financial Supervision Authority (FSA, or Finantsinspektsioon): Primary regulator for CASPs and issuers since January 1, 2025 (transferred from FIU); handles licensing, supervision, enforcement, and compliance with MiCA, DORA, financial requirements, consumer protection, and governance.
Threshold Amounts: No exceptions or de minimis threshold; applies to all transaction amounts per AML Act Section 25(23).
VASPs Covered: All Crypto Asset Service Providers (CASPs) or Virtual Asset Service Providers (VASPs) operating in Estonia, required to register with the Estonian FIU and submit details on operations, governance, and compliance. Includes crypto exchanges and custodians; transactions with self-hosted wallets require AML/CTF measures like enhanced due diligence, though full data transmission may not apply—VASPs must collect/retain originator/beneficiary info for authorities.
Technical Implementation Requirements: VASPs must collect and transmit originator and beneficiary data (e.g., name, essential for sanctions screening) for all transfers, even without thresholds. No transmission required for certain counterparties (details incomplete in sources), but risk monitoring and data retention are mandatory. Must align with EU frameworks like MiCA (transition to July 2026 for pre-2024 CASPs). Specific legislation: AML Act Sections 25(23), 25(24), 25(25), 25(27).
Local Presence: At least one management board member (director) as permanent Estonian/EEA resident; local office/place of business in Estonia; Estonian bank account.
Incorporate as Estonian OÜ (LLC) or AS (public limited company).
Capital: Varies by service—€100,000 minimum for exchange services; €250,000 for transfer/custody services (own funds must cover risks). (Note: Older sources cite €12,000, outdated post-MiCA.)
Post-2024 (CASP/MiCA era): Full authorization/licensing by EFSA, with rigorous supervision, audits, and MiCA compliance; prior VASP registrations are transitional until 2026.
AML/KYC: Mandatory policies for customer identification/verification, transaction monitoring, source-of-funds checks, suspicious activity reporting to FIU; ongoing compliance audits.
Other: Appoint dedicated AML officer (employed under contract, financial sector experience); good business reputation for owners/directors; auditor agreement; annual financial audits, MiCA reporting.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP may not serve Estonian residents without first incorporating a local entity (OÜ or AS), securing a CASP license from the Financial Supervision Authority (FSA) with minimum capital of €100K–€250K, maintaining a physical office and a resident board member, and complying with full AML/CFT/Travel Rule obligations; pure cross-border unlicensed servicing is prohibited and carries significant enforcement risk.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?