Centralized exchange in Finland
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Finland with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Registration as a virtual currency provider (VCP) with the FIN-FSA under the Act on Virtual Currency Providers (572/2019)
- Full customer due diligence (CDD) under AML/CTF obligations — risk assessment, identity verification, beneficial ownership checks
- Enhanced Due Diligence (EDD) for high-risk transactions
- Real-time transaction monitoring systems for KYC/AML compliance and data reporting under MiCA
- Travel Rule obligations: collect, verify, and transmit sender/recipient names and addresses, transaction description (amount and crypto type), and purpose of transfer (if known) on all crypto transfers
- Suspicious transaction reporting (STR) to the Financial Intelligence Unit (FIU) at the National Bureau of Investigation
- Mandatory transparency disclosures on the nature, risks, and costs of crypto assets
- Professional indemnity insurance (no specific minimum share capital requirement under Finnish law for VCPs)
- Market makers, custodial services, and exchanges must comply with stringent operational standards under MiCA
Key Restrictions
- The applicant must be a Finnish limited liability company (osakeyhtiö) or a branch of an EEA-incorporated company
- Management (CEO and at least one other board member) must be located in Finland
- Custodial services require VASP registration — private keys held by the provider on behalf of clients triggers regulatory obligations
- MiCA full enforcement applies from 2026, with gradual rollout phases in 2024–2025 affecting broader categories of crypto service providers
- Mandatory transparency disclosures and clear terms of use with accessible customer support must be provided
Key Risks
- Enforcement precedent: FIN-FSA has issued public reprimands (Coinmotion Oy, 2022) and public warnings (Tesseract Finance Oy, 2023) for CDD and registration deficiencies — demonstrates active supervision
- Operating without proper registration or with AML deficiencies can result in formal disciplinary marks on the regulatory record (public warning / public reprimand)
- Travel Rule compliance requires robust cross-border coordination infrastructure — gaps in data transmission with counterparties are a common compliance gap
- Regulatory burden will increase under MiCA as full enforcement approaches in 2026 — early engagement with FIN-FSA is recommended
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Financial Supervisory Authority (FIN-FSA): The primary regulator responsible for authorizing and supervising all crypto-asset service providers, ensuring compliance with anti-money laundering (AML), consumer protection standards, and operational requirements.
Financial Intelligence Unit (FIU): Operates within the National Bureau of Investigation to receive and investigate suspicious transaction reports from crypto service providers, focusing on preventing money laundering and terrorist financing.
Issuance of licenses for providers offering stablecoins and other crypto assets.
Obligations for market makers, custodial services, and exchanges to comply with stringent operational standards.
2024-2025: Gradual rollout affecting broader categories of crypto service providers.
2026: Full enforcement across all covered activities.
Mandatory transparency disclosures regarding the nature, risks, and costs associated with crypto assets.
Requirements for clear terms of use and accessible customer support mechanisms.
Providing services for exchanging virtual currency and fiat currency: This covers entities facilitating the purchase or sale of virtual currencies using traditional currencies (e.g., EUR, USD).
Providing custodial wallet services: This refers to services where an entity holds, stores, or transfers virtual currencies or private cryptographic keys on behalf of customers.
Exchanges: Both exchanges offering fiat-to-crypto and crypto-to-crypto trading services are clearly defined as "virtual currency providers" and require registration with the FIN-FSA.
The applicant must be a Finnish limited liability company (osakeyhtiö) or a branch of a limited liability company incorporated in an EEA country.
The management of the applicant must be located in Finland. This includes the CEO and at least one other member of the board of directors.
Capital Requirements (Professional Indemnity Insurance):
Objective: Prevent illicit activities by making it difficult for criminals to use money laundering techniques across borders.
Names and addresses of the sender and recipient
Description of the transaction (including amount and cryptocurrency type)
Purpose of the transfer (if known)
Compliance Infrastructure: Integrate robust systems for real-time collection, verification, and transmission of required data points.
Enhanced Due Diligence (EDD): Additional layers of verification for high-risk transactions may be necessary.
Entity Targeted: Tesseract Finance Oy (now operating as Stableton). Violation Type: Providing virtual currency services without proper registration for a period, and deficiencies in internal control mechanisms, risk assessment, and customer due diligence processes for Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF). Penalty Amount: Public warning (julkinen varoitus). While not a monetary fine, it's a formal and significant disciplinary measure by the FIN-FSA, obliging the company to rectify its shortcomings. Outcome: The company was required to implement corrective measures to comply with the Virtual Currency Providers Act and AML/CTF obligations. The public warning serves as a significant mark on the company's regulatory record.
Entity Targeted: Coinmotion Oy (a registered virtual currency provider in Finland). Violation Type: Deficiencies in compliance with Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) obligations, specifically regarding customer due diligence, risk assessment, and internal control. The FIN-FSA found that Coinmotion's practices did not fully meet the requirements of the Act on Virtual Currency Providers and the Anti-Money Laundering Act. Penalty Amount: Public reprimand (julkinen huomautus). Similar to the public warning, this is a formal, non-monetary disciplinary action, indicating serious shortcomings that required immediate correction. Outcome: Coinmotion Oy was instructed to rectify the identified deficiencies in its AML/CTF processes to ensure full compliance with regulatory requirements.
Outcome: The company was required to implement corrective measures to comply with the Virtual Currency Providers Act and AML/CTF obligations. The public warning serves as a significant mark on the company's regulatory record.
Outcome: Coinmotion Oy was instructed to rectify the identified deficiencies in its AML/CTF processes to ensure full compliance with regulatory requirements.
Legal Basis: The primary legal framework is the Act on Virtual Currency Providers (572/2019), which came into force in Finland on May 1, 2019. This Act places virtual asset service providers (VASPs) under the supervision of the Finnish Financial Supervisory Authority (FIN-FSA) and subjects them to AML/CFT obligations akin to traditional financial institutions.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange operating in Finland must register as a virtual currency provider with the FIN-FSA, be a Finnish (or EEA-branch) limited liability company with management located in Finland, comply with full AML/CTF and Travel Rule obligations, and prepare for MiCA's full enforcement by 2026.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?