Custodial wallet / SaaS in Finland
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Finland with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration as a 'virtual currency provider' with FIN-FSA is required (Act on Virtual Currency Providers 572/2019).
- Full AML/CTF compliance obligations apply: customer due diligence, risk assessment, internal control mechanisms (enforced via public warnings/reprimands e.g. Tesseract Finance Oy, Coinmotion Oy).
- Suspicious transaction reporting to the Financial Intelligence Unit (FIU) within the National Bureau of Investigation.
- Real-time transaction monitoring and KYC/AML screening systems required (per MiCA implementation).
- No specific minimum capital requirement, but professional indemnity insurance may be required.
- Mandatory transparency disclosures regarding the nature, risks, and costs associated with crypto assets.
- Requirements for clear terms of use and accessible customer support mechanisms.
Key Restrictions
- Operator must be a Finnish limited liability company (osakeyhtiö) or a branch of an EEA-incorporated company.
- CEO and at least one other board member must be located in Finland.
- Custodial wallet services are explicitly defined as 'virtual currency provider' activities requiring FIN-FSA registration.
- MiCA licensing timeline applies: initial compliance measures (2023), gradual rollout (2024-2025), full enforcement by 2026.
- White-label arrangement: both the SaaS provider (custodian) and the white-label client may have separate VASP obligations depending on who touches the virtual currency.
Key Risks
- Enforcement precedent: FIN-FSA has issued public warnings/reprimands (Tesseract Finance Oy, Coinmotion Oy) for AML deficiencies and unregistered operation, indicating active enforcement.
- Regulatory ambiguity around white-label/SaaS bifurcation of AML duties between custodian and client — unclear where obligations split.
- MiCA transition creates timeline pressure: operators must gap-assess existing operations against MiCA requirements and engage FIN-FSA early.
- No minimum capital requirement reduces barriers but increases scrutiny on operational and AML controls.
- Public enforcement actions (even non-monetary) are formal marks on regulatory record and can harm reputation with partners and regulators.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Financial Supervisory Authority (FIN-FSA): The primary regulator responsible for authorizing and supervising all crypto-asset service providers, ensuring compliance with anti-money laundering (AML), consumer protection standards, and operational requirements.
Financial Intelligence Unit (FIU): Operates within the National Bureau of Investigation to receive and investigate suspicious transaction reports from crypto service providers, focusing on preventing money laundering and terrorist financing.
Issuance of licenses for providers offering stablecoins and other crypto assets.
Obligations for market makers, custodial services, and exchanges to comply with stringent operational standards.
2024-2025: Gradual rollout affecting broader categories of crypto service providers.
2026: Full enforcement across all covered activities.
Mandatory transparency disclosures regarding the nature, risks, and costs associated with crypto assets.
Requirements for clear terms of use and accessible customer support mechanisms.
Assessment Phase: Conduct a thorough audit of existing operations to identify gaps relative to MiCA’s requirements.
Regulatory Engagement: Engage with Finnish authorities (e.g., The Finnish Financial Supervisory Authority) early to ensure alignment and potentially expedite the licensing process.
Technology Upgrades: Invest in systems that support real-time transaction monitoring, KYC/AML checks, and data reporting capabilities as stipulated by MiCA.
Providing custodial wallet services: This refers to services where an entity holds, stores, or transfers virtual currencies or private cryptographic keys on behalf of customers.
Custody Providers: Entities providing "custodial wallet services" are also explicitly defined as "virtual currency providers" and require registration with the FIN-FSA. This includes services where the private keys are held by the provider on behalf of the client.
The applicant must be a Finnish limited liability company (osakeyhtiö) or a branch of a limited liability company incorporated in an EEA country.
The management of the applicant must be located in Finland. This includes the CEO and at least one other member of the board of directors.
Capital Requirements (Professional Indemnity Insurance):
Unlike many traditional financial services, there is no specific minimum share capital requirement for virtual currency providers under Finnish law.
Entity Targeted: Tesseract Finance Oy (now operating as Stableton). Violation Type: Providing virtual currency services without proper registration for a period, and deficiencies in internal control mechanisms, risk assessment, and customer due diligence processes for Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF). Penalty Amount: Public warning (julkinen varoitus). While not a monetary fine, it's a formal and significant disciplinary measure by the FIN-FSA, obliging the company to rectify its shortcomings. Outcome: The company was required to implement corrective measures to comply with the Virtual Currency Providers Act and AML/CTF obligations. The public warning serves as a significant mark on the company's regulatory record.
Entity Targeted: Coinmotion Oy (a registered virtual currency provider in Finland). Violation Type: Deficiencies in compliance with Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) obligations, specifically regarding customer due diligence, risk assessment, and internal control. The FIN-FSA found that Coinmotion's practices did not fully meet the requirements of the Act on Virtual Currency Providers and the Anti-Money Laundering Act. Penalty Amount: Public reprimand (julkinen huomautus). Similar to the public warning, this is a formal, non-monetary disciplinary action, indicating serious shortcomings that required immediate correction. Outcome: Coinmotion Oy was instructed to rectify the identified deficiencies in its AML/CTF processes to ensure full compliance with regulatory requirements.
Outcome: The company was required to implement corrective measures to comply with the Virtual Currency Providers Act and AML/CTF obligations. The public warning serves as a significant mark on the company's regulatory record.
Outcome: Coinmotion Oy was instructed to rectify the identified deficiencies in its AML/CTF processes to ensure full compliance with regulatory requirements.
Legal Basis: The primary legal framework is the Act on Virtual Currency Providers (572/2019), which came into force in Finland on May 1, 2019. This Act places virtual asset service providers (VASPs) under the supervision of the Finnish Financial Supervisory Authority (FIN-FSA) and subjects them to AML/CFT obligations akin to traditional financial institutions.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS providers can operate in Finland as registered virtual currency providers under FIN-FSA supervision, but must be a Finnish or EEA-incorporated entity with local management, comply with full AML/CTF obligations, and transition to MiCA licensing by 2026; the white-label/SaaS split of AML duties creates some regulatory ambiguity.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?