← Regulations / Finland / Operating Models / DeFi frontend

DeFi protocol frontend in Finland

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Finland with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Registration as a virtual currency provider (VCP) with FIN-FSA is required if the frontend takes custody of or facilitates exchange/transfer of virtual currencies — this includes fee-taking via smart contract interaction where the operator controls or handles private keys.
  • Customer due diligence (CDD) is required under the Act on Virtual Currency Providers (572/2019), including identity verification, risk assessment, and ongoing monitoring.
  • Internal control mechanisms and AML/CTF risk assessments must be documented and maintained — deficiencies in these areas have led to enforcement actions (Tesseract Finance Oy public warning, Coinmotion Oy public reprimand).
  • Suspicious Transaction Reports (STRs) must be filed with the Financial Intelligence Unit (FIU) at the National Bureau of Investigation.
  • The management (CEO and at least one board member) must be located in Finland.
  • Professional indemnity insurance is required — no specific minimum share capital requirement under Finnish law.

Key Restrictions

  • The operator must be a Finnish limited liability company (osakeyhtiö) or a branch of an EEA-incorporated company.
  • If the frontend merely provides a non-custodial interface to permissionless smart contracts without taking custody of user funds or facilitating exchange/transfer (e.g., pure UI/aggregator with no fee on transfer), it may fall outside the VCP definition — but this is legally unsettled and high-risk.
  • Taking any fee tied to the exchange, transfer, or custody of virtual currencies likely triggers VCP registration requirements.
  • Geofencing/region-blocking is not explicitly mandated by Finnish law but is effectively required if the operator cannot comply with EU-wide MiCA obligations across the European Economic Area.
  • Under MiCA rollout: 2024-2025 gradual rollout affecting broader categories; full enforcement from 2026.

Key Risks

  • Regulatory ambiguity: It is unclear whether a purely non-custodial frontend that does not take fees from the transaction itself qualifies as a 'virtual currency provider' under the Act on Virtual Currency Providers (572/2019). Finnish enforcement actions (Tesseract, Coinmotion) have focused on custodial and exchange services, not pure frontends.
  • Enforcement precedent: FIN-FSA issued a public warning to Tesseract Finance Oy for operating without proper registration and for AML deficiencies, showing active enforcement even for non-traditional structures.
  • MiCA transition risk: The regime is in progressive rollout (2023-2026) — obligations may expand to cover frontends even more clearly by 2026.
  • If the frontend is deemed a VCP and fails to register, penalties include public warnings/reprimands and mandatory corrective measures; monetary fines may apply in serious cases.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 20% confidence

Financial Supervisory Authority (FIN-FSA): The primary regulator responsible for authorizing and supervising all crypto-asset service providers, ensuring compliance with anti-money laundering (AML), consumer protection standards, and operational requirements.

licensing 20% confidence

Financial Intelligence Unit (FIU): Operates within the National Bureau of Investigation to receive and investigate suspicious transaction reports from crypto service providers, focusing on preventing money laundering and terrorist financing.

licensing 20% confidence

Issuance of licenses for providers offering stablecoins and other crypto assets.

licensing 20% confidence

2024-2025: Gradual rollout affecting broader categories of crypto service providers.

licensing 20% confidence

2026: Full enforcement across all covered activities.

licensing 20% confidence

Mandatory transparency disclosures regarding the nature, risks, and costs associated with crypto assets.

licensing 20% confidence

Requirements for clear terms of use and accessible customer support mechanisms.

licensing 20% confidence

Technology Upgrades: Invest in systems that support real-time transaction monitoring, KYC/AML checks, and data reporting capabilities as stipulated by MiCA.

aml 60% confidence

Providing services for exchanging virtual currency and fiat currency: This covers entities facilitating the purchase or sale of virtual currencies using traditional currencies (e.g., EUR, USD).

aml 60% confidence

Providing custodial wallet services: This refers to services where an entity holds, stores, or transfers virtual currencies or private cryptographic keys on behalf of customers.

aml 60% confidence

Exchanges: Both exchanges offering fiat-to-crypto and crypto-to-crypto trading services are clearly defined as "virtual currency providers" and require registration with the FIN-FSA.

aml 60% confidence

Custody Providers: Entities providing "custodial wallet services" are also explicitly defined as "virtual currency providers" and require registration with the FIN-FSA. This includes services where the private keys are held by the provider on behalf of the client.

aml 60% confidence

Payment Processors: This depends on the nature of the service:

aml 60% confidence

The applicant must be a Finnish limited liability company (osakeyhtiö) or a branch of a limited liability company incorporated in an EEA country.

aml 60% confidence

The management of the applicant must be located in Finland. This includes the CEO and at least one other member of the board of directors.

aml 60% confidence

Capital Requirements (Professional Indemnity Insurance):

enforcement 50% confidence

Entity Targeted: Tesseract Finance Oy (now operating as Stableton). Violation Type: Providing virtual currency services without proper registration for a period, and deficiencies in internal control mechanisms, risk assessment, and customer due diligence processes for Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF). Penalty Amount: Public warning (julkinen varoitus). While not a monetary fine, it's a formal and significant disciplinary measure by the FIN-FSA, obliging the company to rectify its shortcomings. Outcome: The company was required to implement corrective measures to comply with the Virtual Currency Providers Act and AML/CTF obligations. The public warning serves as a significant mark on the company's regulatory record.

enforcement 50% confidence

Entity Targeted: Coinmotion Oy (a registered virtual currency provider in Finland). Violation Type: Deficiencies in compliance with Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) obligations, specifically regarding customer due diligence, risk assessment, and internal control. The FIN-FSA found that Coinmotion's practices did not fully meet the requirements of the Act on Virtual Currency Providers and the Anti-Money Laundering Act. Penalty Amount: Public reprimand (julkinen huomautus). Similar to the public warning, this is a formal, non-monetary disciplinary action, indicating serious shortcomings that required immediate correction. Outcome: Coinmotion Oy was instructed to rectify the identified deficiencies in its AML/CTF processes to ensure full compliance with regulatory requirements.

enforcement 50% confidence

Legal Basis: The primary legal framework is the Act on Virtual Currency Providers (572/2019), which came into force in Finland on May 1, 2019. This Act places virtual asset service providers (VASPs) under the supervision of the Finnish Financial Supervisory Authority (FIN-FSA) and subjects them to AML/CFT obligations akin to traditional financial institutions.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
low

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a DeFi protocol frontend that takes custody, facilitates exchange/transfer of virtual currencies, or takes fees from such activities likely requires registration as a virtual currency provider with FIN-FSA under the Act on Virtual Currency Providers (572/2019); however, purely non-custodial frontends with no fee-taking occupy a legally ambiguous space with limited enforcement precedent, creating material regulatory risk.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?