← Regulations / Finland / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Finland

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Finland with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Registration as a 'virtual currency provider' with FIN-FSA is required (Act on Virtual Currency Providers 572/2019).
  • Full AML/CTF compliance obligations apply: customer due diligence, risk assessment, internal control mechanisms (enforced via public warnings/reprimands e.g. Tesseract Finance Oy, Coinmotion Oy).
  • Suspicious transaction reporting to the Financial Intelligence Unit (FIU) within the National Bureau of Investigation.
  • Real-time transaction monitoring and KYC/AML screening systems required (per MiCA implementation).
  • No specific minimum capital requirement, but professional indemnity insurance may be required.
  • Mandatory transparency disclosures regarding the nature, risks, and costs associated with crypto assets.
  • Requirements for clear terms of use and accessible customer support mechanisms.

Key Restrictions

  • Operator must be a Finnish limited liability company (osakeyhtiö) or a branch of an EEA-incorporated company.
  • CEO and at least one other board member must be located in Finland.
  • Custodial wallet services are explicitly defined as 'virtual currency provider' activities requiring FIN-FSA registration.
  • MiCA licensing timeline applies: initial compliance measures (2023), gradual rollout (2024-2025), full enforcement by 2026.
  • White-label arrangement: both the SaaS provider (custodian) and the white-label client may have separate VASP obligations depending on who touches the virtual currency.

Key Risks

  • Enforcement precedent: FIN-FSA has issued public warnings/reprimands (Tesseract Finance Oy, Coinmotion Oy) for AML deficiencies and unregistered operation, indicating active enforcement.
  • Regulatory ambiguity around white-label/SaaS bifurcation of AML duties between custodian and client — unclear where obligations split.
  • MiCA transition creates timeline pressure: operators must gap-assess existing operations against MiCA requirements and engage FIN-FSA early.
  • No minimum capital requirement reduces barriers but increases scrutiny on operational and AML controls.
  • Public enforcement actions (even non-monetary) are formal marks on regulatory record and can harm reputation with partners and regulators.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 20% confidence

Financial Supervisory Authority (FIN-FSA): The primary regulator responsible for authorizing and supervising all crypto-asset service providers, ensuring compliance with anti-money laundering (AML), consumer protection standards, and operational requirements.

licensing 20% confidence

Financial Intelligence Unit (FIU): Operates within the National Bureau of Investigation to receive and investigate suspicious transaction reports from crypto service providers, focusing on preventing money laundering and terrorist financing.

licensing 20% confidence

Issuance of licenses for providers offering stablecoins and other crypto assets.

licensing 20% confidence

Obligations for market makers, custodial services, and exchanges to comply with stringent operational standards.

licensing 20% confidence

2024-2025: Gradual rollout affecting broader categories of crypto service providers.

licensing 20% confidence

2026: Full enforcement across all covered activities.

licensing 20% confidence

Mandatory transparency disclosures regarding the nature, risks, and costs associated with crypto assets.

licensing 20% confidence

Requirements for clear terms of use and accessible customer support mechanisms.

licensing 20% confidence

Assessment Phase: Conduct a thorough audit of existing operations to identify gaps relative to MiCA’s requirements.

licensing 20% confidence

Regulatory Engagement: Engage with Finnish authorities (e.g., The Finnish Financial Supervisory Authority) early to ensure alignment and potentially expedite the licensing process.

licensing 20% confidence

Technology Upgrades: Invest in systems that support real-time transaction monitoring, KYC/AML checks, and data reporting capabilities as stipulated by MiCA.

aml 60% confidence

Providing custodial wallet services: This refers to services where an entity holds, stores, or transfers virtual currencies or private cryptographic keys on behalf of customers.

aml 60% confidence

Custody Providers: Entities providing "custodial wallet services" are also explicitly defined as "virtual currency providers" and require registration with the FIN-FSA. This includes services where the private keys are held by the provider on behalf of the client.

aml 60% confidence

The applicant must be a Finnish limited liability company (osakeyhtiö) or a branch of a limited liability company incorporated in an EEA country.

aml 60% confidence

The management of the applicant must be located in Finland. This includes the CEO and at least one other member of the board of directors.

aml 60% confidence

Capital Requirements (Professional Indemnity Insurance):

aml 60% confidence

Unlike many traditional financial services, there is no specific minimum share capital requirement for virtual currency providers under Finnish law.

enforcement 50% confidence

Entity Targeted: Tesseract Finance Oy (now operating as Stableton). Violation Type: Providing virtual currency services without proper registration for a period, and deficiencies in internal control mechanisms, risk assessment, and customer due diligence processes for Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF). Penalty Amount: Public warning (julkinen varoitus). While not a monetary fine, it's a formal and significant disciplinary measure by the FIN-FSA, obliging the company to rectify its shortcomings. Outcome: The company was required to implement corrective measures to comply with the Virtual Currency Providers Act and AML/CTF obligations. The public warning serves as a significant mark on the company's regulatory record.

enforcement 50% confidence

Entity Targeted: Coinmotion Oy (a registered virtual currency provider in Finland). Violation Type: Deficiencies in compliance with Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) obligations, specifically regarding customer due diligence, risk assessment, and internal control. The FIN-FSA found that Coinmotion's practices did not fully meet the requirements of the Act on Virtual Currency Providers and the Anti-Money Laundering Act. Penalty Amount: Public reprimand (julkinen huomautus). Similar to the public warning, this is a formal, non-monetary disciplinary action, indicating serious shortcomings that required immediate correction. Outcome: Coinmotion Oy was instructed to rectify the identified deficiencies in its AML/CTF processes to ensure full compliance with regulatory requirements.

enforcement 50% confidence

Outcome: The company was required to implement corrective measures to comply with the Virtual Currency Providers Act and AML/CTF obligations. The public warning serves as a significant mark on the company's regulatory record.

enforcement 50% confidence

Outcome: Coinmotion Oy was instructed to rectify the identified deficiencies in its AML/CTF processes to ensure full compliance with regulatory requirements.

enforcement 50% confidence

Legal Basis: The primary legal framework is the Act on Virtual Currency Providers (572/2019), which came into force in Finland on May 1, 2019. This Act places virtual asset service providers (VASPs) under the supervision of the Finnish Financial Supervisory Authority (FIN-FSA) and subjects them to AML/CFT obligations akin to traditional financial institutions.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS providers can operate in Finland as registered virtual currency providers under FIN-FSA supervision, but must be a Finnish or EEA-incorporated entity with local management, comply with full AML/CTF obligations, and transition to MiCA licensing by 2026; the white-label/SaaS split of AML duties creates some regulatory ambiguity.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?