EST · MMXXVI
Home/Jurisdictions/Estonia/Sanctions screening for crypto in Estonia
Compliance, AML & Travel Rule

Sanctions screening for crypto in Estonia

Sanctions screening for crypto in Estonia. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Estonia's crypto sector operates under one of the most actively enforced AML/CFT (anti-money laundering and counter-terrorist financing) regimes in the European Union. Every licensed VASP (virtual asset service provider) operating from or into Estonia must maintain a sanctions screening program that meets the standards of the Financial Intelligence Unit – FIU, Estonia's primary VASP supervisor. With MiCA now reshaping the EU regulatory environment, the obligations are tightening further: the question for any digital-asset business is not whether to screen, but whether its current program will survive an FIU examination. This page sets out what those obligations look like in practice, how they interact with cross-border operations, and where programs most frequently fail.

Sanctions screening for crypto in Estonia is a mandatory, continuous obligation – not a one-time onboarding check. Under the Estonian Money Laundering and Terrorist Financing Prevention Act (MLTFPA), every VASP authorised by the FIU must screen clients, beneficial owners, counterparties and transaction addresses against applicable sanctions lists before and during the business relationship. Failure to maintain an adequate program is a direct ground for licence suspension or revocation.

The sections below address the legal basis, the FIU's practical expectations, the cross-border interaction with the Travel Rule and banking rails, common program failures, and the decision point at which in-house resources are no longer sufficient.

What is the legal basis for sanctions screening in Estonia?

The obligation to screen sits in two overlapping regimes: Estonian domestic law and the directly applicable EU sanctions framework. The MLTFPA is the primary domestic instrument. It requires VASPs to implement customer due diligence (CDD), enhanced due diligence for higher-risk relationships, and ongoing transaction monitoring – including real-time screening against the UN, EU and national designated-persons lists. EU sanctions regulations, which apply directly in every member state, impose a separate and self-standing obligation to freeze assets and refrain from making funds available to designated persons or entities. A crypto firm operating in Estonia therefore carries both obligations simultaneously.

The FIU has authority under the MLTFPA to inspect, sanction and revoke the licences of VASPs that cannot demonstrate compliance. In the years preceding the 2022 licence reform – which reduced the licensed-VASP population in Estonia by roughly 80 percent, according to FIU reporting – the regulator repeatedly cited inadequate sanctions screening and incomplete beneficial-ownership records as the primary enforcement triggers. The FIU's enforcement posture has not softened post-reform: firms that survived the cull now operate under closer supervisory scrutiny, not less.

Under MiCA, the EU's Markets in Crypto-Assets Regulation, firms will transition from the current VASP registration model to a CASP (crypto-asset service provider) authorisation. The sanctions and AML layer is not replaced by MiCA; it runs alongside it. The practical effect is that the MLTFPA baseline remains in force through the transition period and beyond, with ESMA and the national competent authority – the FIU, in Estonia – jointly overseeing the expanded CASP population.

What does the FIU expect from a sanctions screening program?

The FIU applies a risk-based framework, but its minimum expectations are well-established from inspection practice and published guidance. A program that meets the bar will generally contain four interconnected elements: a current-list coverage policy, an address-screening layer, a transaction monitoring engine and an escalation-to-MLRO process.

List coverage must extend to the UN consolidated list, the EU financial sanctions register, OFAC's SDN list (relevant for dollar-denominated stablecoin flows), and any lists designated under Estonian national measures. Operators that restrict screening to a single list – typically because a vendor packages only one – expose themselves to a straightforward FIU finding. In our compliance practice, we see this mistake repeatedly in firms that grew quickly during the 2020–2021 cycle and installed a minimal onboarding tool without revisiting it as their volume and jurisdictional exposure expanded.

Address screening adds a dimension unique to crypto. The FIU expects VASPs to screen blockchain wallet addresses against sanctions-designated wallets – most recently those linked to North Korean state actors and Iran-related designations under EU and OFAC frameworks – using a forensic or transaction monitoring tool. This is not optional. A firm routing transactions through wallets that a forensic tool would flag cannot rely on a clean name-match result as a complete defence.

The escalation process requires a documented path from a preliminary match through human review to a decision: clear, freeze or file a suspicious-activity report with the FIU. The timeline for that escalation is not prescribed to the hour in the MLTFPA, but the FIU expects it to be fast enough to prevent the disposition of funds while a potential match is under review. In practice, same-day escalation for high-risk matches is the operational floor most compliant firms operate at.

Crucially, the program must be tested. The FIU will ask, at inspection, for evidence that the screening engine has been validated against known-positive test cases. A program installed but never verified against a deliberate test scenario carries significant inspection risk.

For a scoped assessment of your sanctions screening program against the FIU's current expectations, contact OBOLUS at info@oboluslaw.com. The process above describes the standard requirements. Your entity structure, user base and banking relationships will change the analysis in ways a template checklist will not surface.

How does the Travel Rule interact with sanctions obligations in Estonia?

The Travel Rule – the obligation, drawn from FATF Recommendation 15 and implemented in EU law, to pass originator and beneficiary identifying data alongside a virtual-asset transfer – creates a direct feed into the sanctions screening workflow. A VASP in Estonia cannot fully discharge its Travel Rule obligation without confirming that neither the originator nor the beneficiary is a sanctioned person. The two programs must therefore be operationally integrated, not run as parallel silos.

In practice, this means the Travel Rule data collection layer (name, account number and address of originator; name and account number of beneficiary) feeds the same screening engine that handles onboarding CDD. Transfers where the originator VASP cannot or will not provide the required data must be assessed under an enhanced-due-diligence procedure – the FIU treats an absence of Travel Rule data as a risk indicator, not simply a technical gap.

The cross-border dimension is material here. An Estonian VASP receiving a transfer from a counterparty VASP in a jurisdiction that has not fully implemented the FATF Travel Rule – or that implements it at a different threshold – faces a data-quality problem. Sending to such a counterparty raises a similar issue. In our practice, we advise firms to maintain a counterparty-VASP risk register that documents each correspondent's Travel Rule posture, the evidence basis for that assessment, and the enhanced controls applied where the counterparty's program is unverified.

The FIU has specifically flagged unverified counterparty relationships as an inspection finding in published supervisory reports. An Estonian VASP that processes high volumes of transfers to or from VASPs in higher-risk jurisdictions without documented due diligence on those counterparties is unlikely to pass a supervisory review.

How does sanctions compliance interact with banking for Estonian crypto firms?

Banking access for Estonian VASPs has been structurally constrained since the high-profile de-risking events of 2019–2021, when several European banks exited the domestic crypto market following supervisory pressure and correspondent-bank concerns. The firms that retain banking relationships today hold them in part because their compliance programs – including sanctions screening – are demonstrably strong enough to satisfy a bank's own compliance function.

This creates a reciprocal dynamic. A VASP's AML/sanctions program is not only a regulatory requirement; it is the primary instrument through which the firm maintains and demonstrates bankability. A bank's compliance team conducting periodic enhanced due diligence on its crypto-sector clients will review the VASP's sanctions screening methodology, list coverage, address-screening capability and MLRO governance. A weak program here will lose banking, independent of whether the FIU has formally acted.

For firms banking outside Estonia – common where domestic options are limited – the jurisdictional interaction compounds. A payment institution or EMI in a second EU member state will apply its own regulator's expectations, which may be higher or lower than the FIU's baseline. In our cross-border practice, we regularly advise Estonian VASPs whose banking relationship sits in Lithuania, Malta or the Netherlands on the reconciliation between the FIU's expectations and those of the bank's home-state regulator. Gaps are addressable, but only if they are identified before the bank's next compliance cycle rather than in response to a de-banking notice.

If a prior banking relationship was closed, or a new application has stalled over compliance concerns, a structural review of the sanctions and AML program against the specific expectations of the target bank's regulator is often the fastest route to resolution. Write to OBOLUS at info@oboluslaw.com to map that gap analysis.

What are the most common sanctions screening failures the FIU identifies?

Supervisory practice across the FIU's published outputs points to a consistent set of failure modes. They are not exotic. They recur because they reflect the gap between a program designed at launch and the operational reality of a business that has grown or changed.

The first failure is stale list coverage. Sanctions lists are updated continuously – sometimes multiple times in a single week during geopolitical escalation. A firm that updates its screening lists quarterly, or that relies on a vendor without confirming the vendor's update frequency, may have been operating for weeks against an out-of-date list. The FIU treats this as a systemic failing, not a technical error.

The second is address-screening gaps. Some compliance tools screen names but do not screen wallet addresses. For a crypto-native firm, name-match alone is insufficient. The relevant question is whether a wallet the firm is transacting with has been linked to a designated entity. A forensic screening layer – integrated with, or alongside, the name-match engine – is necessary.

The third failure is inadequate beneficial-ownership look-through. A legal-entity client with a complex ownership chain may pass name-match screening at the entity level while a designated individual sits in the ownership structure two or three levels up. The MLTFPA requires look-through to the ultimate beneficial owner. The FIU has found repeatedly that look-through stops prematurely, particularly for clients structured through offshore holding vehicles.

The fourth is weak MLRO documentation. The MLRO (Money Laundering Reporting Officer) must be a named individual with appropriate authority, not a role shared informally or left unfilled during personnel transitions. When the FIU inspects, it will ask to speak with the MLRO and to review the MLRO's decision log. A log that is sparse, backdated or absent is an immediate finding.

In a recent compliance matter, an exchange operator with an Estonian VASP licence approached us ahead of a scheduled FIU inspection. Its address-screening tool had not been updated to cover a major new tranche of OFAC designations, and the beneficial-ownership register for a cluster of corporate clients was incomplete. We worked through a targeted remediation: updated the vendor integration, extended the look-through procedure to cover the affected client population, and prepared the MLRO's inspection file. The inspection proceeded without a formal finding. The remediation window was short – a matter of weeks from first instruction to examination-ready status.

Who must serve as MLRO and what does good governance look like?

Every VASP licensed under the MLTFPA must designate an MLRO who is responsible for internal AML/CFT oversight and for filing suspicious-activity reports with the FIU. The MLRO must have the seniority, independence and resource base to exercise that function without commercial interference – a position the FIU takes seriously and will probe at inspection.

For smaller Estonian VASPs, the MLRO is often a co-founder or a senior compliance hire. For firms operating across multiple jurisdictions, the question of whether a single MLRO can effectively cover all the relevant legal environments becomes a structural concern. Where a business has an Estonian VASP licence, an EU payment institution, and users in additional regulated jurisdictions, the MLRO's scope and the escalation architecture must reflect that complexity.

Good governance requires three documented outputs: a current risk assessment reviewed at least annually and after material business change; an internal audit or independent assessment of the AML/sanctions program; and a training record covering all relevant staff. These are not aspirational – the FIU expects to review them at inspection and may request them on short notice outside of a scheduled review cycle.

The cross-border dimension adds a further layer. An Estonian VASP with a group MLRO based outside Estonia must be able to demonstrate that the individual has adequate knowledge of the MLTFPA and the FIU's expectations, not merely of their home jurisdiction's regime. This is a recurring gap in firms that appoint a group compliance function and assume the Estonian position is covered by proximity.

How does a cross-border business structure its compliance across jurisdictions?

A digital-asset business that licenses through Estonia but serves users or maintains operations in other jurisdictions faces a compliance architecture challenge that a single-jurisdiction program cannot resolve. The Estonian FIU's expectations apply to the licensed entity. But the entity may also carry regulatory obligations in the jurisdictions where its users are located, where its banking sits, and where its technology infrastructure is deployed.

The common structure – an Estonian operating entity, a payment layer in a second EU member state, and a custody or treasury function offshore – creates at least three distinct compliance perimeters. Each perimeter has its own regulator, its own sanctions-list obligations, and its own MLRO governance requirements. Where the perimeters do not align, a transaction that clears one entity's screening may not clear another's. The result is exposure at the weakest point in the chain.

A myth that we encounter regularly in this context: that a single VASP licence from a well-regarded jurisdiction is sufficient to cover global operations. It is not. The Estonian FIU licence covers Estonian-regulated activities. Users in jurisdictions with their own VASP or CASP obligations will require either a local licence or a careful analysis of whether an exemption, passport or permitted-business carve-out applies. Operating without that analysis is the path to the enforcement and de-banking risk that the AUDIENCE_PAIN framing describes – frozen rails, lost banking, FIU inquiry.

In our cross-border practice, we map the compliance architecture across the operating, custody and payment layers before a client commits capital to the structure. We identify where each entity's obligations sit, where the MLRO governance must be replicated or adapted, and where allied counsel in the relevant jurisdiction should be engaged to cover local requirements. That mapping exercise typically surfaces mismatches that the client had not identified – and that are far cheaper to fix at the design stage than after a regulatory examination.

To map your licence, banking and compliance stack before you commit to a structure, write to OBOLUS at info@oboluslaw.com.

Self-assessment: is your sanctions program examination-ready?

A well-built program answers "yes" to each of the following questions. Where the answer is "no" or "we are not sure," that gap requires attention before the FIU's next contact.

  • Does your sanctions screening cover the UN consolidated list, the EU financial sanctions register, OFAC SDN, and applicable national lists – and are those lists updated at least weekly?
  • Does your screening tool cover blockchain wallet addresses, not only entity and individual names?
  • Does your CDD process include beneficial-ownership look-through to the ultimate natural-person owner, including for complex offshore structures?
  • Is your MLRO a named individual with a documented decision log and current training record?
  • Does your Travel Rule data collection feed the same screening engine as onboarding CDD?
  • Do you maintain a counterparty-VASP risk register for all VASPs from whom you receive or to whom you send transfers?
  • Has your screening engine been tested against known-positive cases in the past twelve months?
  • Is your AML risk assessment current – reviewed since your last material business change?

If two or more of these questions expose a gap, the risk is not theoretical. The FIU has demonstrated, through the 2022 licence reform and subsequent enforcement actions, that it will act on program failures. The question is whether the gap is addressed proactively or in response to a supervisory inquiry.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 15 and implemented under EU law, requires a VASP to collect and transmit identifying information about the originator and beneficiary alongside every qualifying virtual-asset transfer. This includes name, account number and address for the originator, and name and account number for the beneficiary. The obligation applies to both the sending and receiving VASP. Where counterparty data is unavailable or incomplete, the receiving VASP must apply enhanced due diligence and assess whether the transfer should proceed.

Who must act as MLRO for a crypto firm?

Under the Estonian MLTFPA, every licensed VASP must designate a named MLRO with adequate seniority, independence and knowledge of the relevant legal obligations. The MLRO is responsible for internal AML/CFT oversight, maintaining the risk assessment and policy framework, and filing suspicious-activity reports with the FIU. For multi-jurisdiction groups, the MLRO covering the Estonian entity must demonstrate specific knowledge of the MLTFPA and FIU expectations – a group compliance officer based in another member state does not automatically satisfy this requirement.

How do regulators audit crypto AML programs?

The FIU conducts both scheduled and unannounced inspections. An inspection typically involves a review of the firm's AML risk assessment, policies and procedures, the MLRO's decision log, training records, a sample of CDD files including beneficial-ownership documentation, and evidence that the sanctions screening tool has been validated. Regulators increasingly ask for evidence of address screening alongside name-match outputs. A program that exists on paper but lacks documented operational execution – tested screening engines, current lists, complete MLRO logs – will not pass a substantive inspection.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance programs that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit. We work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications. To discuss your compliance position, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT program design, sanctions screening and supervisory engagement for VASPs operating in the EU.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours