Why correspondent banking access defines your Estonia strategy
Correspondent banking access in Estonia determines whether a digital-asset or payments business can actually operate – not merely exist on paper. A company holding a valid licence but lacking USD or EUR correspondent rails cannot settle trades, receive merchant proceeds or pay counterparties. The two questions that matter are: which legal structures unlock access, and what do the banks and regulators now require before they say yes.
Estonia has been a primary EU entry point for virtual asset service providers (VASPs – businesses offering crypto exchange, custody or transfer services) and licensed payment institutions for well over a decade. Under the current regime, the Bank of Estonia supervises VASP registration and the Financial Intelligence Unit (FIU, Rahapesu Andmebüroo) retains authority over AML compliance and licence validity. Since a sweeping overhaul of the anti-money-laundering regime, both bodies apply materially higher scrutiny to inbound applicants – particularly those with cross-border operating models.
This page sets out the regulated basis for correspondent banking access, the practical onboarding process, the cross-border interactions that trip up most applicants, and the decision points a business must resolve before committing resources.
What the regulatory regime actually requires
The regulated basis for correspondent banking access in Estonia sits at the intersection of two distinct bodies of law: the national AML/CFT legislation (which implements the FATF Recommendations, including Recommendation 15 on virtual assets and the Travel Rule – the obligation to pass originator and beneficiary data with a crypto transfer) and EU-level requirements under the Payment Services Directive and the evolving MiCA (Markets in Crypto-Assets Regulation) regime overseen by the Bank of Estonia as the competent authority.
For a crypto company, the operative question is whether it holds – or must hold – a VASP registration, a payment institution (PI) licence, an e-money institution (EMI) licence, or a combination of all three. Each instrument carries different capital expectations, AML obligations and, critically, different weight with correspondent banks. Banks conducting their own due diligence on your entity look first at the licence category, then at the quality of the compliance programme behind it, and finally at the beneficial-ownership and source-of-funds picture.
An entity that holds only a VASP registration but routes fiat through a third-party EMI will be assessed differently from one that holds its own PI or EMI licence with direct access to SEPA. Neither approach is categorically better – each carries trade-offs in cost, timeline and regulatory exposure that depend on the business model.
Who needs which instrument?
Most digital-asset businesses accessing Estonia require at minimum a VASP registration, but the banking question forces a further analysis of the payment layer. The licence stack depends on where the fiat flows sit.
A crypto exchange that holds client fiat and converts it to digital assets is almost certainly providing a payment service. Without a PI or EMI licence – or a banking relationship with an institution that performs that function on its behalf – it is operating in a grey area that correspondent banks will not support. Correspondent banks in the major settlement currencies (EUR, USD, GBP) require their respondent institutions to be licensed for every regulated activity they conduct. An Estonian entity that is a registered VASP but unlicensed for the fiat leg creates a compliance exposure for the correspondent – and that exposure leads to a declined onboarding or a terminated account.
Businesses that rely entirely on a single offshore licence to serve EU customers face a further obstacle: under MiCA and the Bank of Estonia's updated guidance, an entity marketing crypto-asset services into Estonia – regardless of where it is incorporated – may trigger local registration or authorisation obligations. The assumption that one offshore registration covers all markets is one of the most expensive mistakes we see in our practice.
At a minimum, most inbound businesses accessing Estonian banking will need a VASP registration with the FIU and a payment services arrangement that is itself licensed under EU law. The exact instrument – whether a PI licence, an EMI licence, or an arrangement with a licensed EMI – turns on transaction volumes, the nature of the client base and the long-term jurisdictional plan.
For a scoped assessment of your licence and banking stack, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking counterparties – change the analysis significantly. Map your options.
How does the correspondent banking onboarding process work in Estonia?
Correspondent banking onboarding in Estonia follows a structured due-diligence sequence that is longer and more document-intensive than standard corporate account opening in most non-EU jurisdictions. The process typically proceeds in three phases: pre-qualification, enhanced due diligence (EDD), and credit and compliance committee review.
In the pre-qualification phase, the bank assesses whether the applicant falls within its appetite at all. For digital-asset businesses, the screening criteria include: the category of licence held, the jurisdictions from which customers are sourced, the nature of the counterparties to whom funds are sent, and the AML/KYC framework in place. Many rejections occur here – not because the business is non-compliant, but because the institution's internal policy excludes certain crypto sub-sectors entirely.
Businesses that pass pre-qualification move to EDD. At this stage, the bank requires the beneficial ownership register extract, the AML policy and procedures manual, the last two audited financial statements, transaction monitoring reports and – increasingly – a demonstration that the Travel Rule compliance system is operational, not merely documented. A Travel Rule system that exists on paper but has not been tested against real transfer flows will not satisfy a sophisticated correspondent's EDD team.
The compliance committee review is the final gate. Decisions at this stage turn on relationship factors as much as documentation: the quality of the introductory materials, the track record of the relationship managers and, in some cases, whether the bank has existing exposure to the applicant's sector. Timelines from first contact to account activation vary considerably – in our experience, businesses that arrive with complete, well-structured documentation packages move materially faster than those who respond reactively to information requests.
What cross-border factors complicate Estonian banking access?
The cross-border dimension of correspondent banking access in Estonia is where most applicants underestimate the complexity. Estonia is an EU member state. An Estonian entity's banking relationships are subject not only to the Bank of Estonia and FIU supervision but also to the sanctions and AML policies of the correspondent banks' home regulators – which may include the US Office of Foreign Assets Control (OFAC), the UK FCA and, in the case of USD correspondent chains, the Federal Reserve and FinCEN.
An Estonian payment institution that routes USD through a US correspondent bank is, at that moment, inside the US AML perimeter. The US correspondent will apply its own VASP-related screening. If the Estonian entity's customer base includes residents of jurisdictions that the US correspondent considers elevated risk, the chain is under pressure regardless of how clean the Estonian compliance posture is.
This multi-layer exposure means that a business cannot optimise for Estonian regulatory compliance alone. The architecture of the correspondent chain – which banks sit in which jurisdictions, which currencies are cleared where – must be designed with all intermediate compliance perimeters in mind. We map this for clients before the banking outreach begins, because the sequence matters: approaching correspondent B before structure A is resolved is the most common cause of avoidable rejections.
Tax interaction is a further cross-border variable. An Estonian holding company above an operating subsidiary in another EU jurisdiction creates a different banking risk profile than a single-entity structure. Banks assess group structures for evidence of regulatory arbitrage, and a structure that looks like it was designed to access a lenient regime while operating from a stricter one invites deeper scrutiny. The legal structure should reflect the genuine economic substance of the business – not merely the desired regulatory outcome.
A recent matter: fiat rails restored for a payments operator
In a recent engagement, a licensed payments operator had its EUR correspondent account suspended following a routine compliance review by the respondent bank. The immediate trigger was a cluster of flagged transactions involving a crypto exchange counterparty that the bank had subsequently blacklisted. The operator's own AML programme was sound, but it had not implemented a counterparty-level screening layer for crypto business partners – only for retail customers.
We conducted a rapid gap analysis, identified the missing counterparty-screening module, drafted the remediation documentation and supported the operator through the bank's formal reinstatement process. The account was reinstated within the bank's own internal review cycle, and the operator subsequently implemented a Travel Rule-compliant transfer architecture. The matter illustrated a pattern we see repeatedly: the proximate cause of a banking disruption is rarely a fundamental compliance failure – it is a documentation gap that an adversarial reviewer can characterise as systemic.
Which profile should choose which approach?
The right structure for correspondent banking access in Estonia depends on four variables: the business model, the target customer base, the transaction volumes and the long-term jurisdictional plan. No single arrangement works for every operator.
Profile A – Early-stage crypto exchange, EU customer base, sub-threshold volumes. The typical path is VASP registration with the FIU combined with an EMI onboarding arrangement through a regulated European e-money institution. This avoids the capital and timeline costs of a direct PI licence while maintaining compliant fiat rails. The key risk is dependency on a third-party EMI whose own banking relationships may not be stable – a risk that requires contractual protection and a contingency banking plan from day one.
Profile B – Established operator, multi-currency settlement, institutional counterparties. This profile typically requires a direct PI or EMI licence to access tier-one correspondent banking. The investment in a direct licence is justified by the reduced intermediary risk and the better credit terms available to directly licensed entities. The timeline to a direct licence is longer than for EMI onboarding, but the resulting banking stability is materially superior. VASP registration remains necessary in parallel if crypto services are offered.
Profile C – Inbound non-EU operator seeking EU market access via Estonia. This profile faces the highest scrutiny. The combination of a non-EU parent structure, a newly established Estonian subsidiary and a crypto-linked business model is the precise risk profile that correspondent banks and the FIU have tightened their policies around. Demonstrating genuine substance – local management, a functioning compliance operation, real economic activity in Estonia – is not optional. It is the threshold requirement for any banking conversation to succeed.
If your banking relationship has been suspended or your application has stalled, write to OBOLUS at info@oboluslaw.com. A second read of the structure and the correspondence can surface the specific point of failure and the route to resolution. Map your options.
What mistakes are most likely to cost you the banking relationship?
Businesses seeking correspondent banking access in Estonia make a predictable set of errors. Awareness of these patterns is the first step toward avoiding them.
The most damaging mistake is applying for banking before the licence structure is complete. A bank that receives an onboarding application from an entity that describes itself as a crypto company but has not yet received its VASP registration will decline – and that decline will be recorded. Reapplying to the same institution after the registration is granted requires the business to explain the prior application, which triggers a higher scrutiny level than a clean first approach.
The second mistake is submitting an AML policy that was not written for the actual business. Template AML policies – and the industry is flooded with them – are immediately recognisable to experienced bank compliance reviewers. A policy that does not specifically address the customer segments, transaction types and counterparty profile of the business signals that the compliance programme is decorative rather than functional.
The third mistake is ignoring the Travel Rule at the onboarding stage. Even if a business's transaction volumes fall below the de-minimis threshold in its operating jurisdiction, demonstrating that a Travel Rule compliance architecture is in place signals operational seriousness to correspondent banks. Banks are increasingly treating Travel Rule readiness as an indicator of overall compliance maturity, not merely a box-ticking exercise.
A common assumption we encounter is that a single offshore licence – particularly one obtained in a jurisdiction with lighter-touch regulation – is sufficient to access Estonian or broader EU banking. It is not. The Bank of Estonia, the FIU and correspondent banks all assess the entity that holds the account and the activities it conducts, not merely the jurisdiction where a parent company registered. Operating under a regulatory umbrella that does not match the activities being conducted is a structural compliance failure that no amount of documentation can remedy after the fact.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital-Asset Businesses – full-service counsel on payment licence structuring and correspondent bank access across the EU and beyond
- Corporate bank account opening in Poland – a practical jurisdiction comparison for EU banking access from a CEE perspective
- Fund manager licensing under heightened scrutiny – regulatory counsel for investment vehicles with digital-asset exposure facing elevated compliance review
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily for three reasons: the company's AML/KYC programme does not meet the bank's own risk appetite; the company's counterparties – exchanges, custodians, or retail customers – include entities the bank considers elevated risk; or the company's licence does not cover all regulated activities it is conducting. In many cases the immediate trigger is a transaction-monitoring flag, but the underlying cause is a structural compliance gap that the flag simply surfaces. Remediation requires identifying the gap, not merely disputing the flag.
How can a VASP onboard with an EMI?
A VASP seeking to onboard with a regulated e-money institution (EMI) must satisfy the EMI's own enhanced due diligence requirements, which typically exceed standard corporate onboarding. The VASP will need to provide its registration certificate, a current AML policy, beneficial ownership documentation, projected transaction volumes and a description of its Travel Rule compliance architecture. EMIs that serve the crypto sector have become increasingly selective; a VASP that arrives with well-organised documentation and a clear business model will move through onboarding materially faster than one responding reactively to information requests.
What does client-money safeguarding require?
Client-money safeguarding under EU payment services law requires a licensed payment institution or EMI to hold customer funds separately from the firm's own funds, either in a designated safeguarding account at a credit institution or covered by an insurance policy or bank guarantee. The safeguarding obligation is not optional and applies from the first client transaction. Businesses that commingle client and operational funds – a common early-stage error – expose themselves to enforcement by the Bank of Estonia and to immediate account closure by their banking counterparties once the commingling is identified in a compliance review.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so the structure reflects both the regulatory requirement and the banking reality. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP registration, EMI onboarding and correspondent banking access across EU and EEA jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.