On-shore VASP in Finland
Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.
On-shore VASP is conditionally permitted in Finland with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Registration with FIN-FSA as a 'virtual currency provider' under the Act on Virtual Currency Providers (572/2019)
- Full AML/CTF program including customer due diligence (CDD), risk assessment, and internal control mechanisms
- Suspicious Transaction Reporting (STR) to the Financial Intelligence Unit (FIU) within the National Bureau of Investigation
- Travel Rule compliance: real-time collection, verification, and transmission of sender/recipient names, addresses, and transaction descriptions for crypto-to-fiat, fiat-to-crypto, and peer-to-peer transactions
- Enhanced Due Diligence (EDD) for high-risk transactions
- Professional indemnity insurance required (no specific minimum share capital requirement under Finnish law)
- Management (CEO and at least one other board member) must be located in Finland
- Applicant must be a Finnish limited liability company (osakeyhtiö) or an EEA branch
- Progressive capital gains tax: 30% on capital income up to €30,000, 34% on portion exceeding €30,000; FIFO method for cost basis
- VAT exemption for exchange of crypto-to-fiat and crypto-to-crypto per ECJ Hedqvist ruling
Key Restrictions
- Must be incorporated as a Finnish limited liability company (osakeyhtiö) or an EEA branch
- CEO and at least one other board member must be located in Finland
- Full MiCA compliance timeline: initial measures 2023, gradual rollout 2024-2025, full enforcement 2026
- Mandatory transparency disclosures on the nature, risks, and costs of crypto assets
- Clear terms of use and accessible customer support mechanisms required
Key Risks
- Past FIN-FSA enforcement actions (Coinmotion public reprimand 2022, Tesseract Finance Oy public warning 2023) demonstrate active supervision and willingness to impose formal disciplinary measures for AML/CDD deficiencies
- Transition to full MiCA regime by 2026 will increase compliance burden; operators must invest in real-time transaction monitoring, KYC/AML systems now
- FIFO-only cost-basis method for crypto taxation may create complexity for portfolio management
- Crypto mining and staking rewards treated as taxable capital income at receipt — significant reporting burden
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Financial Supervisory Authority (FIN-FSA): The primary regulator responsible for authorizing and supervising all crypto-asset service providers, ensuring compliance with anti-money laundering (AML), consumer protection standards, and operational requirements.
Financial Intelligence Unit (FIU): Operates within the National Bureau of Investigation to receive and investigate suspicious transaction reports from crypto service providers, focusing on preventing money laundering and terrorist financing.
Issuance of licenses for providers offering stablecoins and other crypto assets.
Obligations for market makers, custodial services, and exchanges to comply with stringent operational standards.
2024-2025: Gradual rollout affecting broader categories of crypto service providers.
2026: Full enforcement across all covered activities.
Mandatory transparency disclosures regarding the nature, risks, and costs associated with crypto assets.
Requirements for clear terms of use and accessible customer support mechanisms.
Assessment Phase: Conduct a thorough audit of existing operations to identify gaps relative to MiCA’s requirements.
Regulatory Engagement: Engage with Finnish authorities (e.g., The Finnish Financial Supervisory Authority) early to ensure alignment and potentially expedite the licensing process.
Technology Upgrades: Invest in systems that support real-time transaction monitoring, KYC/AML checks, and data reporting capabilities as stipulated by MiCA.
Regulator Name: Financial Supervisory Authority (FIN-FSA)
The applicant must be a Finnish limited liability company (osakeyhtiö) or a branch of a limited liability company incorporated in an EEA country.
The management of the applicant must be located in Finland. This includes the CEO and at least one other member of the board of directors.
Capital Requirements (Professional Indemnity Insurance):
Unlike many traditional financial services, there is no specific minimum share capital requirement for virtual currency providers under Finnish law.
Providing services for exchanging virtual currency and fiat currency: This covers entities facilitating the purchase or sale of virtual currencies using traditional currencies (e.g., EUR, USD).
Providing custodial wallet services: This refers to services where an entity holds, stores, or transfers virtual currencies or private cryptographic keys on behalf of customers.
Objective: Prevent illicit activities by making it difficult for criminals to use money laundering techniques across borders.
Applicability: Applies to all financial services, including crypto-to-fiat and fiat-to-crypto exchanges, as well as peer-to-peer transactions involving cryptocurrencies.
Names and addresses of the sender and recipient
Description of the transaction (including amount and cryptocurrency type)
Compliance Infrastructure: Integrate robust systems for real-time collection, verification, and transmission of required data points.
Enhanced Due Diligence (EDD): Additional layers of verification for high-risk transactions may be necessary.
Capital Gains Tax Rates (Pääomatulon verokanta): Finland has a progressive capital income tax rate:
30% for the portion of capital income up to €30,000.
34% for the portion of capital income exceeding €30,000.
Acquisition Cost Method: Finland primarily applies the FIFO (First-In, First-Out) method by default. This means that the first crypto units acquired are considered the first ones sold. Taxpayers can sometimes use other methods if consistently applied and justifiable, but FIFO is the standard expectation.
Exemption for Exchange: The European Court of Justice (ECJ) ruling in the Hedqvist case (C-264/14) established that the exchange of traditional currencies for Bitcoin (and other virtual currencies) and vice versa, as well as exchanges between different virtual currencies, constitutes the supply of services exempt from VAT. Finland follows this interpretation.
Entity Targeted: Tesseract Finance Oy (now operating as Stableton). Violation Type: Providing virtual currency services without proper registration for a period, and deficiencies in internal control mechanisms, risk assessment, and customer due diligence processes for Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF). Penalty Amount: Public warning (julkinen varoitus). While not a monetary fine, it's a formal and significant disciplinary measure by the FIN-FSA, obliging the company to rectify its shortcomings. Outcome: The company was required to implement corrective measures to comply with the Virtual Currency Providers Act and AML/CTF obligations. The public warning serves as a significant mark on the company's regulatory record.
Entity Targeted: Coinmotion Oy (a registered virtual currency provider in Finland). Violation Type: Deficiencies in compliance with Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) obligations, specifically regarding customer due diligence, risk assessment, and internal control. The FIN-FSA found that Coinmotion's practices did not fully meet the requirements of the Act on Virtual Currency Providers and the Anti-Money Laundering Act. Penalty Amount: Public reprimand (julkinen huomautus). Similar to the public warning, this is a formal, non-monetary disciplinary action, indicating serious shortcomings that required immediate correction. Outcome: Coinmotion Oy was instructed to rectify the identified deficiencies in its AML/CTF processes to ensure full compliance with regulatory requirements.
Outcome: The company was required to implement corrective measures to comply with the Virtual Currency Providers Act and AML/CTF obligations. The public warning serves as a significant mark on the company's regulatory record.
Outcome: Coinmotion Oy was instructed to rectify the identified deficiencies in its AML/CTF processes to ensure full compliance with regulatory requirements.
Legal Basis: The primary legal framework is the Act on Virtual Currency Providers (572/2019), which came into force in Finland on May 1, 2019. This Act places virtual asset service providers (VASPs) under the supervision of the Finnish Financial Supervisory Authority (FIN-FSA) and subjects them to AML/CFT obligations akin to traditional financial institutions.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a locally-incorporated on-shore VASP in Finland must register with the FIN-FSA as a virtual currency provider under the Act on Virtual Currency Providers (572/2019), comply with full AML/CTF/CDD obligations (including Travel Rule), be a Finnish limited liability company with management located in Finland, and is subject to progressive MiCA implementation (2024-2026) and active FIN-FSA enforcement.
Questions this verdict aims to answer
- What license(s) are required to operate locally?
- What capital, governance, and reporting obligations apply?
- What is the application process and timeline?