← Regulations / Estonia / Operating Models / Remote VASP

Remote VASP serving residents in Estonia

Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.

Conditional AI-Generated · Unreviewed

Remote VASP is conditionally permitted in Estonia with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Full AML/KYC/CFT obligations under the Money Laundering and Terrorist Financing Prevention Act (MLTFPA) and MiCA — mandatory customer identification, verification, transaction monitoring, source-of-funds checks
  • Suspicious Activity Reporting (SAR) to the FIU
  • Travel Rule applies to ALL transactions (no de minimis threshold) — must collect and transmit originator and beneficiary data per AML Act Section 25(23)
  • Screen customers and transactions against UN and EU sanctions lists, tailoring controls to risk profiles
  • Appoint a dedicated AML officer with financial sector experience; at least one management board member must be an Estonian resident
  • Annual financial audits and AML monitoring reports required
  • Ongoing supervisory submissions to the Financial Supervision Authority (FSA / Finantsinspektsioon)

Key Restrictions

  • Must incorporate as an Estonian legal entity (OÜ or AS) — no pure remote/cross-border service offering without local incorporation
  • Must maintain a physical office / place of business in Estonia ('genuine local substance' required for inspections)
  • At least one management board member must be an Estonian or EEA resident
  • Must hold an Estonian bank account for the entity
  • Must hold a CASP license from EFSA (Financial Supervision Authority) — not merely a registration — with authorized capital of €100,000 (exchange) or €250,000 (transfer/custody)
  • Transition from legacy FIU VASP registrations to full FSA licensing required by July 1, 2026
  • State fee of €10,000 for license application; comprehensive documentation package required including AML/KYC/KYT policies, business plan, governance structure, digital resilience plans

Key Risks

  • Unlicensed cross-border servicing of Estonian residents carries high enforcement risk — Estonia has a history of mass VASP license withdrawals (2020) and aggressively requires local substance
  • Operating without a local entity and CASP license exposed to FSA enforcement actions, fines under CMA Chapters 7-8, and potential criminal liability
  • Travel Rule compliance is strict (no threshold) and technically demanding for operators without local infrastructure
  • Post-MiCA transition period ends July 1, 2026 — legacy VASP registrations will expire, creating a cliff edge for non-compliant operators
  • Estonian FSA/EFSRA takes a conservative stance on VASPs/CASPs; genuine local substance requirement may be rigorously inspected

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Physical headquarters in Estonia, customer identification, annual audits, internal controls, data retention, and good business reputation.

licensing 50% confidence

CASP License: Mandatory for all providers of crypto-asset services, including exchanges, wallets, and transfers; covers virtual currency exchange and transfer services under the single license regime (previously separate).

licensing 50% confidence

Registration Regime: Providers must incorporate as an Estonian legal entity with a physical office, local board member/director (Estonian resident), and Estonian bank account; demonstrate "genuine local substance" for inspections. VAT registration with the Estonian Tax and Customs Board is also required post-incorporation.

licensing 50% confidence

Incorporate Local Entity: Submit memorandum/articles of association, share capital deposit certificate (€100,000+), and state fee to the Commercial Register.

licensing 60% confidence

Authorized capital: €250,000 for transfer/custody services (vs. €100,000 for exchange).

licensing 50% confidence

Submit Application: File electronically via FSA portal (for issuers from March 18, 2026) or by board member; state fee €10,000.

licensing 20% confidence

Appoint an AML officer with financial sector experience and ensure at least one management board member is an Estonian resident.

licensing 20% confidence

Firms must screen customers and transactions against UN and EU sanctions lists, tailoring controls to risk profiles.

licensing 60% confidence

Money Laundering and Terrorist Financing Prevention Act (MLTFPA): https://www.riigiteataja.ee/en/eli/ee/Riigikogu/act/520062020002/consolide (via )

licensing 60% confidence

Crypto Asset Market Act (CMA): National implementation of MiCA (via )

licensing 60% confidence

Financial Supervision Authority (FSA, or Finantsinspektsioon): Primary regulator for CASPs and issuers since January 1, 2025 (transferred from FIU); handles licensing, supervision, enforcement, and compliance with MiCA, DORA, financial requirements, consumer protection, and governance.

travel-rule 40% confidence

Threshold Amounts: No exceptions or de minimis threshold; applies to all transaction amounts per AML Act Section 25(23).

travel-rule 40% confidence

VASPs Covered: All Crypto Asset Service Providers (CASPs) or Virtual Asset Service Providers (VASPs) operating in Estonia, required to register with the Estonian FIU and submit details on operations, governance, and compliance. Includes crypto exchanges and custodians; transactions with self-hosted wallets require AML/CTF measures like enhanced due diligence, though full data transmission may not apply—VASPs must collect/retain originator/beneficiary info for authorities.

travel-rule 40% confidence

Technical Implementation Requirements: VASPs must collect and transmit originator and beneficiary data (e.g., name, essential for sanctions screening) for all transfers, even without thresholds. No transmission required for certain counterparties (details incomplete in sources), but risk monitoring and data retention are mandatory. Must align with EU frameworks like MiCA (transition to July 2026 for pre-2024 CASPs). Specific legislation: AML Act Sections 25(23), 25(24), 25(25), 25(27).

custody 20% confidence

Local Presence: At least one management board member (director) as permanent Estonian/EEA resident; local office/place of business in Estonia; Estonian bank account.

custody 20% confidence

Incorporate as Estonian OÜ (LLC) or AS (public limited company).

custody 20% confidence

Capital: Varies by service—€100,000 minimum for exchange services; €250,000 for transfer/custody services (own funds must cover risks). (Note: Older sources cite €12,000, outdated post-MiCA.)

custody 20% confidence

Post-2024 (CASP/MiCA era): Full authorization/licensing by EFSA, with rigorous supervision, audits, and MiCA compliance; prior VASP registrations are transitional until 2026.

custody 20% confidence

AML/KYC: Mandatory policies for customer identification/verification, transaction monitoring, source-of-funds checks, suspicious activity reporting to FIU; ongoing compliance audits.

custody 20% confidence

Other: Appoint dedicated AML officer (employed under contract, financial sector experience); good business reputation for owners/directors; auditor agreement; annual financial audits, MiCA reporting.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a remote VASP may not serve Estonian residents without first incorporating a local entity (OÜ or AS), securing a CASP license from the Financial Supervision Authority (FSA) with minimum capital of €100K–€250K, maintaining a physical office and a resident board member, and complying with full AML/CFT/Travel Rule obligations; pure cross-border unlicensed servicing is prohibited and carries significant enforcement risk.

Questions this verdict aims to answer

  • May a non-resident provider serve residents from abroad?
  • Does cross-border service trigger licensing, registration, or AML obligations?
  • What enforcement risk exists for unlicensed remote operators?