← Regulations / Finland / Operating Models / Self-custodial wallet

Self-custodial wallet / non-custodial software in Finland

Publisher of software where users hold their own private keys. The publisher never holds, controls, or has access to user funds.

Conditional AI-Generated · Unreviewed

Self-custodial wallet is conditionally permitted in Finland without local incorporation, subject to AML obligations and low licensing burden.

Verdict Details

Permitted
conditional
Local entity required
No
Licensing burden
Low
Last updated
2026-07-13

AML Obligations

  • No AML obligations attach to the software publisher itself when it does not hold, control, or have access to user private keys or funds — the Finnish AML/VCP regime targets entities providing 'custodial wallet services' where the provider holds private keys on behalf of clients (see fi.aml.providing-custodial-wallet-services-this)
  • However, if the publisher provides any ancillary services such as swapping, fiat on/off ramps, or any form of transaction facilitation involving custody of keys or funds, AML obligations would attach under the Act on Virtual Currency Providers (572/2019) and require FIN-FSA registration

Key Restrictions

  • Cannot provide any custodial functionality — holding, storing, or transferring private keys on behalf of users — without triggering FIN-FSA registration as a virtual currency provider
  • Cannot offer integrated swapping, exchange, or fiat on/off-ramp services where the software publisher handles the keys or funds, as those would constitute virtual currency services requiring registration
  • Must ensure that the software is distributed as a non-custodial tool only, with clear disclaimers that the publisher does not act as an intermediary, custodian, or counterparty to transactions
  • If the software includes any revenue-generating features integrated with crypto transactions (e.g., fee-based swapping), the publisher may need to assess whether those features constitute regulated virtual currency services

Key Risks

  • Regulatory ambiguity: The line between pure software distribution (unregulated) and providing virtual currency services (regulated) is not explicitly defined in Finnish law for non-custodial wallet software; enforcement actions to date (Tesseract Finance, Coinmotion) have targeted custodial/registration failures, not software publishers
  • Risk that FIN-FSA or FIU could interpret certain software features (e.g., in-app swap integrations, transaction fee collection, sponsored transactions) as bringing the publisher within scope of the Virtual Currency Providers Act
  • Potential future MiCA implementation (2024-2026) may create new obligations for non-custodial wallet providers, including possible software-level KYC/AML requirements, though this is not yet settled
  • Consumer protection and transparency rules under MiCA (fi.licensing.mandatory-transparency-disclosures-regarding-the, fi.licensing.requirements-for-clear-terms-of) may apply to software publishers even without custody, requiring clear terms of use and risk disclosures

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

aml 60% confidence

Providing custodial wallet services: This refers to services where an entity holds, stores, or transfers virtual currencies or private cryptographic keys on behalf of customers.

aml 60% confidence

Custody Providers: Entities providing "custodial wallet services" are also explicitly defined as "virtual currency providers" and require registration with the FIN-FSA. This includes services where the private keys are held by the provider on behalf of the client.

aml 60% confidence

Providing services for exchanging virtual currency and fiat currency: This covers entities facilitating the purchase or sale of virtual currencies using traditional currencies (e.g., EUR, USD).

licensing 20% confidence

Financial Supervisory Authority (FIN-FSA): The primary regulator responsible for authorizing and supervising all crypto-asset service providers, ensuring compliance with anti-money laundering (AML), consumer protection standards, and operational requirements.

licensing 20% confidence

Mandatory transparency disclosures regarding the nature, risks, and costs associated with crypto assets.

licensing 20% confidence

Requirements for clear terms of use and accessible customer support mechanisms.

licensing 20% confidence

Assessment Phase: Conduct a thorough audit of existing operations to identify gaps relative to MiCA’s requirements.

licensing 20% confidence

2024-2025: Gradual rollout affecting broader categories of crypto service providers.

licensing 20% confidence

2026: Full enforcement across all covered activities.

Evidence fact fi.enforcement.the-primary-legal not found (may have been renamed).

enforcement 50% confidence

Entity Targeted: Tesseract Finance Oy (now operating as Stableton). Violation Type: Providing virtual currency services without proper registration for a period, and deficiencies in internal control mechanisms, risk assessment, and customer due diligence processes for Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF). Penalty Amount: Public warning (julkinen varoitus). While not a monetary fine, it's a formal and significant disciplinary measure by the FIN-FSA, obliging the company to rectify its shortcomings. Outcome: The company was required to implement corrective measures to comply with the Virtual Currency Providers Act and AML/CTF obligations. The public warning serves as a significant mark on the company's regulatory record.

enforcement 50% confidence

Entity Targeted: Coinmotion Oy (a registered virtual currency provider in Finland). Violation Type: Deficiencies in compliance with Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) obligations, specifically regarding customer due diligence, risk assessment, and internal control. The FIN-FSA found that Coinmotion's practices did not fully meet the requirements of the Act on Virtual Currency Providers and the Anti-Money Laundering Act. Penalty Amount: Public reprimand (julkinen huomautus). Similar to the public warning, this is a formal, non-monetary disciplinary action, indicating serious shortcomings that required immediate correction. Outcome: Coinmotion Oy was instructed to rectify the identified deficiencies in its AML/CTF processes to ensure full compliance with regulatory requirements.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — A publisher of non-custodial wallet software (where the publisher never holds user keys or funds) is not classified as a virtual currency provider under Finnish law and does not require FIN-FSA registration or face AML obligations, provided it refrains from any custodial, exchange, or transaction-facilitation activities; however, MiCA's gradual rollout (2024-2026) and consumer transparency rules may introduce new obligations for such software publishers.

Questions this verdict aims to answer

  • Does software publishing trigger VASP / MSB classification?
  • Do AML obligations attach when no custody exists?
  • What disclosure or consumer-protection rules apply?