Estonia has long been one of the most accessible EU entry points for digital-asset businesses, and its anti-money laundering and counter-terrorism financing (AML/CFT) regime is now among the most closely watched in the region. Following a sweeping reform of the Money Laundering and Terrorist Financing Prevention Act, the Financial Intelligence Unit (FIU) – Estonia's primary VASP supervisor – raised the bar materially for what an acceptable compliance program looks like. Operators who moved early under the prior light-touch regime are discovering that grandfathered registrations do not insulate them from current supervisory expectations. This page sets out what AML/CFT policy drafting in Estonia requires today, how the process works for an inbound business, and where cross-border complexity changes the calculus.
A virtual asset service provider (VASP) registered in Estonia must maintain a written AML/CFT policy that satisfies both the Estonian domestic framework and, as the MiCA (Markets in Crypto-Assets Regulation) transition progresses, the standards demanded by ESMA and the applicable national competent authority. The policy is not a template exercise. The FIU reviews it during authorisation, re-examines it on supervisory visits and treats material gaps as grounds for licence suspension or revocation.
The sections below walk through the regulatory basis, the core policy components, the cross-border reality for a business serving clients outside Estonia, and the practical steps to build a program that survives FIU scrutiny.
What Legal Regime Governs AML/CFT Policy in Estonia?
Estonia's AML/CFT obligations for VASPs flow from the Money Laundering and Terrorist Financing Prevention Act, which implements the EU's successive Anti-Money Laundering Directives, and from the broader EU AML package that is progressively reshaping national regimes. The Financial Intelligence Unit is the registration and supervision authority for VASPs under the Estonian framework, holding powers to grant, condition and revoke registrations, conduct on-site inspections and issue financial penalties. ESMA's developing technical standards under MiCA will progressively overlay these domestic requirements, tightening the floor for any CASP (Crypto-Asset Service Provider) operating across the EU.
The FATF Recommendation 15 standard – which requires jurisdictions to apply AML/CFT controls to virtual asset activities – is directly reflected in the Estonian regime. Operators we advise regularly underestimate how literally the FIU reads the FATF standard when assessing policy documentation. The agency expects to see the risk-based approach operationalized, not simply described. That means documented risk assessments, tiered customer due diligence, and controls that demonstrably map to identified risks.
The Travel Rule – the obligation under FATF Recommendation 16 to pass originator and beneficiary data with virtual asset transfers above the applicable threshold – applies to VASPs registered in Estonia. Policy documentation must address not only how the firm collects and transmits this data but also what it does when a counterpart VASP in a third country does not comply. Regulators in the leading hubs, including the FIU, increasingly expect a counterpart-VASP due-diligence procedure to be embedded in the written policy.
For a scoped assessment of your AML/CFT documentation requirements in Estonia, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base geography and the product categories – change the analysis materially. Map your options.
What Must an Estonian VASP's AML/CFT Policy Contain?
An AML/CFT policy for an Estonian VASP must cover, at minimum, seven substantive areas: the business risk assessment, customer due diligence (CDD) and enhanced due diligence (EDD) procedures, the Travel Rule compliance protocol, transaction monitoring, suspicious activity reporting, record-keeping, and the internal control and training framework. Each area requires written procedures, not high-level principles. The FIU expects to pick up a policy document and trace a specific customer scenario through each step.
The business-wide risk assessment is the foundation. It must document the firm's inherent risk exposure by product, customer type, geography and delivery channel, and then map the controls that bring residual risk to an acceptable level. In our cross-border practice, we see operators produce assessments that read like generic templates and fail to address their specific product – for example, a DeFi aggregator that also provides fiat off-ramps carries a materially different risk profile than a simple exchange, and the assessment must say so.
CDD procedures must specify the verification steps for individuals and legal entities, the triggers for EDD, and the circumstances in which a business relationship is to be declined or exited. Beneficial ownership documentation is a consistent FIU focus. Businesses with a complex holding structure – a common feature of multi-jurisdiction digital-asset groups – must show that the policy reaches through to the ultimate natural-person owners.
Transaction monitoring is increasingly technical. The policy must define monitoring parameters, alert-handling procedures, and the escalation path from an alert to a suspicious activity report to the FIU. Operators that run monitoring through a third-party system must document the governance of that system: who reviews alerts, what the escalation timeline is, and how false-positive rates are managed.
Record-keeping requirements under the Estonian framework align with the EU baseline: documents and data supporting CDD and transactions must be retained for a defined period following the end of a business relationship. The policy must specify the retention period, the storage format and the access controls.
Who Is Responsible for AML/CFT Compliance at a VASP?
Every Estonian VASP must appoint a money laundering reporting officer (MLRO) – a named senior individual with both the authority and the resources to execute the compliance program. The MLRO is the FIU's primary supervisory contact and personally responsible for the quality of suspicious activity reporting. The role cannot be split across jurisdictions in a way that the FIU cannot verify: the nominated individual must be identifiable, reachable and genuinely senior.
In our practice, governance structure is one of the most frequent failure points in FIU reviews. A MLRO who is also the CEO of a start-up exchange, with no dedicated compliance budget, is unlikely to satisfy supervisory expectations. The FIU looks for evidence that the MLRO has actual independence – the ability to escalate concerns to the board without obstruction – and that the compliance function has a documented reporting line.
For a cross-border group, the question of where the MLRO sits is non-trivial. If the Estonian entity is a subsidiary of a parent registered elsewhere, the FIU expects the Estonian entity to maintain its own compliance function. Relying entirely on a group compliance team based outside Estonia is a structural risk. We regularly advise multi-entity groups to document the division of compliance responsibilities across the group in a formal compliance governance map.
How Does the KYC Framework Operate in Practice?
The KYC (know-your-customer) framework in Estonia requires identity verification at onboarding and ongoing monitoring throughout the business relationship. The applicable standard draws on both the Estonian domestic AML legislation and the EU's technical standards under successive directives, with MiCA's CASP authorization requirements adding a further layer of consistency obligations as the framework matures.
Politically exposed persons (PEPs), customers from higher-risk jurisdictions and those with complex beneficial ownership structures all trigger enhanced due diligence. The policy must specify the EDD measures – typically deeper source-of-funds verification, senior management approval and shorter review cycles. Where a customer is connected to a jurisdiction on the FATF grey or black list, EDD is mandatory, and the policy should reflect the current state of the FATF list at the time of onboarding rather than at the date the policy was last revised.
Digital identity verification is widely used by Estonian VASPs, and the FIU accepts it where the method meets the reliability standard set out in the applicable guidance. The policy must document the verification method, the provider (as a category, not necessarily a named vendor) and the fallback procedure where digital verification fails. This is an area where operators frequently produce generic provisions that do not match their actual technical implementation – a discrepancy that FIU examiners quickly identify.
A micro-matter from our recent practice is instructive. A payments-focused digital-asset firm operating across three EU member states ran its KYC processes through a group-level system governed by another jurisdiction's compliance team. When the Estonian FIU reviewed the registration documentation, it found that the Estonian entity's KYC policy referred to procedures that did not exist as a standalone document within the Estonian legal entity. The policy had to be redrafted to reflect the Estonian entity's actual obligations, with explicit cross-references to the group framework and clear statements of where the Estonian entity's responsibilities began. The registration was subsequently confirmed without further escalation.
How Does the Travel Rule Apply to Estonian VASPs?
The Travel Rule requires Estonian VASPs to collect, verify and transmit originator and beneficiary information with every qualifying virtual asset transfer. The data set required – names, account identifiers and, in certain cases, physical addresses – mirrors the wire-transfer data obligations that apply to traditional payment firms. Transfers to or from a self-hosted wallet (an address not held by a regulated entity) require additional steps under the FIU's supervisory expectations: the VASP must document its process for assessing whether the self-hosted wallet is linked to its own customer and, if so, what verification it performs.
The practical challenge is counterpart VASP compliance. When an Estonian VASP sends a transfer to a VASP in a jurisdiction that has not yet implemented the Travel Rule, data transmission may not be technically or procedurally possible. The policy must address this gap explicitly: what checks the firm runs on the counterpart VASP before sending, what the firm does when it cannot confirm counterpart compliance, and at what point a transfer is declined or suspended pending further verification.
Travel Rule implementation requires technical infrastructure. The policy must reference the solution the firm uses to transmit data, the format of the data transmitted and the records retained. In our cross-border practice, we see operators adopt a Travel Rule solution appropriate for one jurisdiction and then discover it does not cover the message format required by their Estonian counterparts. Aligning the technical and legal layers of Travel Rule compliance is a specific workstream that sits alongside – and must be integrated with – the broader AML/CFT policy.
If your Travel Rule documentation has gaps or your counterpart-VASP due-diligence procedure has not been tested against FIU expectations, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Map your options.
What Cross-Border Factors Affect AML/CFT Policy for an Estonian Entity?
An Estonian VASP registration does not, by itself, authorize the firm to conduct regulated business in every EU member state. Cross-border provision of services – including to customers resident in jurisdictions where the firm is not locally licensed – raises AML/CFT obligations that may exceed what the Estonian domestic framework requires. As MiCA's CASP passporting regime matures, the framework for cross-border service provision within the EU will become more coherent, but in the interim, operators must assess their obligations in each market they serve.
Banking is the most immediate cross-border pressure point. Estonian VASPs frequently bank outside Estonia – in Lithuania, Germany or further afield. A correspondent bank applying its own home-country AML standards may require documentation that goes beyond what the FIU mandated. We regularly see banks demand an AML/CFT policy that references specific technical standards, certification from an independent auditor or evidence of a live transaction monitoring system with named parameters. The Estonian policy must be drafted with the banking relationship in mind, not just with FIU compliance as the sole audience.
Tax interaction is a second layer. Where an Estonian VASP is part of a group structure – for example, with a holding entity in a different jurisdiction and customers in a third – the documentation of beneficial ownership, source of funds and transaction records serves both AML/CFT and tax reporting purposes. The policy framework should be designed from the outset to generate records that satisfy both regulatory regimes, avoiding the situation where AML records are held in a format or location that creates tax-reporting friction.
Operators expanding into the Asia-Pacific region via an Estonian base face a further layer of complexity: MAS in Singapore, the SFC in Hong Kong and other leading regulators may review the AML/CFT standards of a counterpart's home jurisdiction before accepting a correspondent relationship. An Estonian firm whose policy documentation is below regional best-practice may find that its cross-border banking and liquidity options narrow. The policy must be designed to satisfy an international peer review, not just a domestic supervisory visit.
What Mistakes Most Often Delay FIU Approval?
The most common reason the FIU returns or delays an AML/CFT policy submission is a mismatch between the written policy and the firm's actual business model. Generic policies drafted from EU templates without adaptation to the firm's specific product, customer base and technology stack consistently fail. The FIU is experienced at identifying boilerplate, and a submission that reads like a template creates an immediate credibility problem that takes significant time to correct.
A second recurring issue is the governance section. Firms that describe an MLRO role without specifying the individual's actual authority, budget and reporting line leave the FIU without confidence that the compliance function is real. Naming an MLRO without evidence that the individual has appropriate experience and actual independence within the organization is a closely related problem.
The Travel Rule procedure is a third frequent gap. Many operators produce a general statement of intention to comply with the Travel Rule but do not document the actual technical solution, the data fields collected, the counterpart-VASP assessment process or the handling of non-compliant counterparts. The FIU expects a procedure that can be audited: step-by-step, with decision points and escalation paths.
A common assumption among operators entering Estonia is that a well-crafted policy from another EU jurisdiction can be filed with minimal adaptation. In practice, the FIU reads submissions against its own supervisory guidance, which reflects the specific risk profile of the Estonian market and its prior enforcement experience. Transplanting a policy without re-grounding it in the Estonian legal basis, the FIU's specific expectations and the firm's own Estonian legal entity creates a document that satisfies nobody. We map the licence stack and the policy requirements across all operating, custody and payment layers before a client commits to a jurisdiction – that front-end analysis prevents the delays that follow a poorly adapted submission.
Self-Assessment: Is Your AML/CFT Policy FIU-Ready?
Before submitting an AML/CFT policy to the FIU, a VASP should be able to answer yes to each of the following questions. This is not a substitute for professional review, but it identifies the areas most likely to attract FIU scrutiny.
- Does the business-wide risk assessment specifically describe your product, customer types, geographies and delivery channels – not a generic digital-asset business?
- Is your MLRO a named individual with documented authority, a defined reporting line to the board and a compliance budget?
- Do your CDD and EDD procedures specify exactly what documents are collected, verified and retained for each customer category?
- Does your transaction monitoring section identify the specific parameters, alert-handling steps and escalation timeline your firm uses?
- Is your Travel Rule procedure complete – covering data collection, transmission format, counterpart-VASP assessment and self-hosted-wallet handling?
- Does your record-keeping section specify retention periods, storage formats and access controls aligned to the Estonian legal requirement?
- Has the policy been reviewed against your current banking relationship's AML requirements, not just the FIU's minimum standard?
- Is the policy a single, internally consistent document – not a set of cross-referenced external documents that cannot be reviewed in isolation?
A no answer to any of these questions indicates a gap that the FIU is likely to raise. In our practice, operators who complete this checklist honestly before submission consistently have shorter review cycles.
Related at OBOLUS
- AML/CFT and Travel Rule compliance for digital-asset businesses – the full practice overview covering KYC frameworks, Travel Rule implementation and policy drafting across leading hubs
- Travel Rule compliance program in Mauritius – how the Travel Rule obligation operates under the Mauritius VAITOS regime and what a compliant program requires
- Correspondent banking access in the United Kingdom – the banking relationship challenge for digital-asset firms and how FCA-standard AML documentation affects access
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule – derived from FATF Recommendation 16 and implemented in Estonia's AML legislation – requires a VASP to collect, verify and transmit originator and beneficiary information alongside every qualifying virtual asset transfer. The data set typically includes names, account or wallet identifiers and, in some cases, physical addresses. The obligation applies to both outgoing and incoming transfers, and the VASP must have a documented procedure for handling transfers where a counterpart does not comply. Self-hosted wallets require a separate assessment procedure under current supervisory expectations.
Who must act as MLRO for a crypto firm?
The MLRO must be a named, senior individual within the Estonian legal entity – not a shared group resource based in another jurisdiction. The FIU expects the MLRO to have genuine independence, direct board access and a documented compliance budget. For a VASP that is part of a multi-entity group, the Estonian MLRO must be identifiable, reachable and able to demonstrate that the Estonian entity's compliance function operates as a real, local function rather than a delegation to a parent-company team. Practical experience in AML compliance and, increasingly, digital-asset-specific knowledge are supervisory expectations.
How do regulators audit crypto AML programs?
The Finnish FIU and peer EU supervisors audit AML programs through a combination of desk-based documentation review and, for larger or higher-risk firms, on-site inspection. Examiners trace specific customer scenarios through the written policy – from onboarding and risk scoring through transaction monitoring and suspicious activity reporting – to confirm that the written procedure matches the firm's actual practice. Gaps between the documented policy and the live operational process are the most common audit finding. Firms are expected to maintain records that allow any transaction or customer relationship to be reconstructed and reviewed at short notice.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence, compliance and banking stack across all operating layers before you commit to a structure – preventing the delays and enforcement exposure that follow a poorly prepared submission. To discuss your AML/CFT policy needs in Estonia or another jurisdiction, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT policy documentation, VASP registration requirements and cross-border compliance program design for digital-asset businesses in the EU and beyond.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.