Remote VASP serving residents in Finland
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Finland with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Registration with FIN-FSA as a virtual currency provider (VCP) under the Act on Virtual Currency Providers (572/2019)
- Customer due diligence (CDD) obligations under AML/CTF requirements
- Risk assessment and internal control mechanisms for AML/CTF compliance
- Real-time transaction monitoring systems for KYC/AML checks
- Travel Rule compliance: collection, verification, and transmission of sender/recipient names, addresses, transaction description, and purpose of transfer
- Enhanced Due Diligence (EDD) for high-risk transactions
- Suspicious transaction reporting to the Financial Intelligence Unit (FIU) at the National Bureau of Investigation
- Mandatory transparency disclosures regarding nature, risks, and costs of crypto assets
- Clear terms of use and accessible customer support mechanisms
- Professional indemnity insurance (no specific minimum share capital required)
Key Restrictions
- Applicant must be a Finnish limited liability company (osakeyhtiö) or a branch of an EEA-incorporated company
- CEO and at least one board member must be located in Finland
- Cannot serve Finnish residents remotely from abroad without a Finnish-registered entity or EEA branch
- Full enforcement of MiCA across all covered activities expected by 2026
- Cross-border service without local registration constitutes unlicensed activity, subject to FIN-FSA enforcement (public warnings, public reprimands, corrective measures)
Key Risks
- Enforcement precedent: FIN-FSA issued a public warning to Tesseract Finance Oy (Oct 2023) for providing virtual currency services without proper registration and AML deficiencies
- Enforcement precedent: FIN-FSA issued a public reprimand to Coinmotion Oy (Feb 2022) for AML/CTF compliance deficiencies despite being a registered provider
- Operating without Finnish registration carries risk of formal disciplinary action, reputational damage, and mandated corrective measures
- Regulatory ambiguity during MiCA phase-in (2024-2026) — gradual rollout creates transitional compliance uncertainty
- Travel Rule compliance imposes significant operational overhead for cross-border transactions
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Financial Supervisory Authority (FIN-FSA): The primary regulator responsible for authorizing and supervising all crypto-asset service providers, ensuring compliance with anti-money laundering (AML), consumer protection standards, and operational requirements.
Financial Intelligence Unit (FIU): Operates within the National Bureau of Investigation to receive and investigate suspicious transaction reports from crypto service providers, focusing on preventing money laundering and terrorist financing.
Issuance of licenses for providers offering stablecoins and other crypto assets.
Obligations for market makers, custodial services, and exchanges to comply with stringent operational standards.
2024-2025: Gradual rollout affecting broader categories of crypto service providers.
2026: Full enforcement across all covered activities.
Mandatory transparency disclosures regarding the nature, risks, and costs associated with crypto assets.
Requirements for clear terms of use and accessible customer support mechanisms.
Assessment Phase: Conduct a thorough audit of existing operations to identify gaps relative to MiCA’s requirements.
Regulatory Engagement: Engage with Finnish authorities (e.g., The Finnish Financial Supervisory Authority) early to ensure alignment and potentially expedite the licensing process.
Technology Upgrades: Invest in systems that support real-time transaction monitoring, KYC/AML checks, and data reporting capabilities as stipulated by MiCA.
Regulator Name: Financial Supervisory Authority (FIN-FSA)
The applicant must be a Finnish limited liability company (osakeyhtiö) or a branch of a limited liability company incorporated in an EEA country.
The management of the applicant must be located in Finland. This includes the CEO and at least one other member of the board of directors.
Capital Requirements (Professional Indemnity Insurance):
Unlike many traditional financial services, there is no specific minimum share capital requirement for virtual currency providers under Finnish law.
Objective: Prevent illicit activities by making it difficult for criminals to use money laundering techniques across borders.
Applicability: Applies to all financial services, including crypto-to-fiat and fiat-to-crypto exchanges, as well as peer-to-peer transactions involving cryptocurrencies.
Names and addresses of the sender and recipient
Description of the transaction (including amount and cryptocurrency type)
Purpose of the transfer (if known)
Compliance Infrastructure: Integrate robust systems for real-time collection, verification, and transmission of required data points.
Enhanced Due Diligence (EDD): Additional layers of verification for high-risk transactions may be necessary.
Cross-Border Coordination: Effective communication with global counterparts is crucial for seamless adherence across jurisdictions.
Entity Targeted: Tesseract Finance Oy (now operating as Stableton). Violation Type: Providing virtual currency services without proper registration for a period, and deficiencies in internal control mechanisms, risk assessment, and customer due diligence processes for Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF). Penalty Amount: Public warning (julkinen varoitus). While not a monetary fine, it's a formal and significant disciplinary measure by the FIN-FSA, obliging the company to rectify its shortcomings. Outcome: The company was required to implement corrective measures to comply with the Virtual Currency Providers Act and AML/CTF obligations. The public warning serves as a significant mark on the company's regulatory record.
Entity Targeted: Coinmotion Oy (a registered virtual currency provider in Finland). Violation Type: Deficiencies in compliance with Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) obligations, specifically regarding customer due diligence, risk assessment, and internal control. The FIN-FSA found that Coinmotion's practices did not fully meet the requirements of the Act on Virtual Currency Providers and the Anti-Money Laundering Act. Penalty Amount: Public reprimand (julkinen huomautus). Similar to the public warning, this is a formal, non-monetary disciplinary action, indicating serious shortcomings that required immediate correction. Outcome: Coinmotion Oy was instructed to rectify the identified deficiencies in its AML/CTF processes to ensure full compliance with regulatory requirements.
Outcome: The company was required to implement corrective measures to comply with the Virtual Currency Providers Act and AML/CTF obligations. The public warning serves as a significant mark on the company's regulatory record.
Outcome: Coinmotion Oy was instructed to rectify the identified deficiencies in its AML/CTF processes to ensure full compliance with regulatory requirements.
Legal Basis: The primary legal framework is the Act on Virtual Currency Providers (572/2019), which came into force in Finland on May 1, 2019. This Act places virtual asset service providers (VASPs) under the supervision of the Finnish Financial Supervisory Authority (FIN-FSA) and subjects them to AML/CFT obligations akin to traditional financial institutions.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a non-resident remote VASP cannot serve Finnish residents from abroad without establishing a Finnish limited liability company (or EEA branch) and registering with FIN-FSA as a virtual currency provider under the Act on Virtual Currency Providers (572/2019), with full AML/CTF, Travel Rule, and MiCA obligations; remote unlicensed operation carries significant enforcement risk as demonstrated by prior FIN-FSA actions.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?