EST · MMXXVI
Home/Jurisdictions/Estonia/Travel rule compliance program in Estonia
Compliance, AML & Travel Rule

Travel rule compliance program in Estonia

Travel rule compliance program in Estonia. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

An Estonian virtual asset service provider (VASP) – a firm registered to exchange, transfer or custody digital assets – sits at the intersection of two demanding compliance regimes: the national anti-money-laundering rules enforced by the Financial Intelligence Unit (FIU, Estonian: Rahapesu Andmebüroo, or RAB) and the Travel Rule (the obligation to pass originator and beneficiary identifying data with every qualifying virtual-asset transfer). Together, these requirements define a compliance program that regulators can audit at any time. Getting the architecture right before the FIU visits is not a matter of housekeeping – it is a licensing condition with direct banking consequences.

Estonia was among the first EU member states to build a dedicated VASP registration regime, and it remains one of the more actively supervised environments in Europe. The FIU has suspended and revoked a substantial number of registrations in successive enforcement waves. For any operator still holding an Estonian VASP registration – or considering one as a base for EU market access ahead of full MiCA (Markets in Crypto-Assets Regulation) CASP authorisation – a documented, tested Travel Rule compliance program is not optional. This page explains what that program must contain, how it interacts with the broader AML/KYC framework, and where cross-border structures create compliance gaps that enforcement consistently exploits.

Estonian VASP Registration and the FIU's Supervisory Posture

The FIU is Estonia's primary AML supervisor for digital-asset businesses, and it treats Travel Rule compliance as a live audit criterion rather than a disclosure formality. Operators registered under the Estonian AML regime are obligated to implement FATF Recommendation 15 – the international standard that extends AML/CFT obligations to virtual assets and VASPs – and the Travel Rule flows directly from that obligation. FATF Recommendation 15 requires that both the sending and receiving VASP collect, verify and transmit originator and beneficiary information for transfers that meet or exceed the applicable threshold.

The FIU has demonstrated willingness to use suspension and revocation as enforcement tools rather than final-resort sanctions. Operators who lack demonstrable Travel Rule controls – not merely those who have suffered a detected violation – face heightened scrutiny. In our practice, we have seen FIU supervisory inquiries focus sharply on whether a VASP can produce its Travel Rule policy, its counterparty VASP due-diligence records and evidence of message transmission for sample transactions.

Estonia's regime is also transitioning toward full MiCA alignment. The CASP authorisation framework under MiCA/ESMA will supersede the current registration model for most activities. Firms that have allowed their Travel Rule infrastructure to lag will face a more demanding authorisation gate when the transition window closes.

What the Travel Rule Requires in Practice

The Travel Rule obliges a VASP to attach originator and beneficiary data to every qualifying virtual-asset transfer and to make that data available to the receiving institution and to supervisory authorities on request. In practice, a compliant program has four operational layers.

First, data collection: the originating VASP must collect the originator's full legal name, account number or wallet identifier, and a verified address, national identity number or date and place of birth – depending on the risk tier and the jurisdiction of the receiving VASP. The beneficiary's name and account identifier must also be collected.

Second, data transmission: the collected data must travel with the transaction or in a linked, secure message to the beneficiary VASP before or concurrent with the transfer. Estonia's AML rules align with FATF guidance on the permissible transmission channels, and they impose a strict timeline: transmission must not be deferred to post-settlement.

Third, counterparty VASP verification: before sending Travel Rule data to a receiving VASP, the originating VASP must verify that the counterparty is a regulated entity. This is where many smaller operators fail. A policy that covers domestic transfers but lacks a process for dealing with counterparties in non-FATF-member jurisdictions – or with unhosted wallets – is systematically incomplete.

Fourth, record-keeping: all Travel Rule data and transmission records must be retained for a period specified in the applicable AML rules. The FIU can request these records during a supervisory review, and gaps in the record are treated as gaps in compliance.

Building the AML/KYC Framework Around the Travel Rule

The Travel Rule does not stand alone. It is the data-transfer dimension of a broader KYC framework – the set of controls a VASP uses to identify its customers, assess risk and monitor activity over time. The FIU evaluates Travel Rule compliance in context: a firm with weak customer due diligence will find its Travel Rule controls discounted even if the transmission mechanics are correct.

A compliant Estonian VASP program typically links these components. The KYC onboarding layer produces the verified customer identifiers that the Travel Rule transmission will carry. The transaction monitoring layer flags transfers that may require enhanced scrutiny – including those to counterparties in high-risk jurisdictions or to unhosted wallets. The risk assessment layer determines whether a given counterparty VASP relationship requires enhanced due diligence before data is transmitted.

The MLRO (Money Laundering Reporting Officer) sits at the centre of this structure. Estonian law requires VASPs to appoint a natural person as MLRO. That person bears personal responsibility for the program's fitness, for suspicious-transaction reporting to the FIU and for the firm's AML/CFT training regime. The FIU pays particular attention to whether the MLRO has adequate seniority, relevant expertise and genuine operational authority – not merely a title.

In our cross-border practice, we regularly advise operators who have built sound KYC onboarding but have not connected it to their Travel Rule workflow. The result is a compliance program with a structural gap: data collected at onboarding never reaches the transfer message, and the transmission record is incomplete. The FIU treats that gap as a program failure, not a technical glitch.

For a scoped assessment of your current Travel Rule architecture, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity's registered activities, the user base's jurisdictions, the banking rails you rely on – change the analysis materially.

Unhosted Wallets and the High-Risk Counterparty Problem

Transfers to or from unhosted wallets – wallets not held at a regulated VASP – present the most acute Travel Rule compliance challenge for Estonian operators. The FIU's supervisory posture treats unhosted-wallet transfers as inherently higher risk. A compliant program must address them explicitly.

The minimum expected controls for unhosted-wallet transfers include: a risk-based threshold above which enhanced verification of the wallet's beneficial owner is required; a process for collecting self-attribution evidence where the unhosted wallet belongs to the VASP's own customer; and a documented policy on transfers where self-attribution cannot be obtained.

FATF guidance on unhosted wallets has evolved, and the EU's regulatory direction under MiCA-adjacent rules (specifically, the Transfer of Funds Regulation as applied to crypto-asset transfers) imposes requirements that go beyond the FATF baseline in some respects. An Estonian VASP that has not updated its unhosted-wallet policy since the earlier FATF guidance may be out of step with current supervisory expectations even if it was compliant when the policy was written.

Counterparty VASPs in non-FATF-member or high-risk jurisdictions create a parallel challenge. Transmitting Travel Rule data to a counterparty that has no regulatory obligation to protect or use that data correctly creates both a compliance gap and a data-protection exposure under Estonian and EU law. A robust program maps each counterparty jurisdiction against the FATF assessment list and applies tiered controls accordingly.

How Does the Cross-Border Structure Affect Travel Rule Obligations?

An Estonian VASP operating in a multi-entity group structure – for example, a holding company in one jurisdiction, an Estonian operating entity and a custody vehicle elsewhere – must assess Travel Rule obligations at each inter-entity transfer point. Intra-group transfers between VASP entities are not automatically exempt. Where both entities meet the definition of a VASP under the applicable regime, the Travel Rule applies to transfers between them just as it does to third-party transfers.

Banking is the pressure point where cross-border compliance failures surface fastest. Estonian and EU banks servicing VASPs have elevated their own AML due diligence standards significantly in recent years. A VASP that cannot demonstrate a functioning Travel Rule program – including its policy documents, MLRO appointment, transaction monitoring system and counterparty VASP due-diligence records – will find it increasingly difficult to open or maintain euro-area banking relationships.

Tax interaction is a secondary but real consideration. Where Travel Rule data is transmitted across borders, the originator's jurisdiction, the beneficial owner's residence and the location of the receiving VASP can all create tax reporting hooks. In our practice, we advise operators to map the data flows of their Travel Rule transmissions against their entity structure's tax footprint before finalising the program design. A Travel Rule solution that transmits data to a jurisdiction where the operator has an inadvertent permanent establishment or a tax-reporting obligation is not just a compliance issue – it is a structuring issue.

For operators sitting between Estonia and another hub – the UK, Singapore or a DIFC-regulated entity, for example – the Travel Rule requirements of both jurisdictions apply. The FCA (Financial Conduct Authority) has its own Travel Rule expectations under the UK's AML regime, and the MAS (Monetary Authority of Singapore) enforces Travel Rule obligations under the Payment Services Act. A dual-jurisdiction compliance program must satisfy the stricter of the two regimes at every relevant transfer point.

The Inbound Operator Process: Registering and Building Compliance in Estonia

For an inbound operator establishing an Estonian VASP registration as a MiCA pre-authorisation base, the compliance program must be in place before registration is granted – not built afterward. The FIU's application review includes an assessment of the proposed AML/CFT program, the MLRO's credentials and the firm's risk appetite statement.

The practical build sequence runs as follows. First, the operator conducts a business-model risk assessment: which activities will the Estonian entity perform, which customer segments will it serve, and which counterparty jurisdictions will its transfers reach? This assessment drives the calibration of every downstream control.

Second, the AML/CFT policy suite is drafted: the AML/KYC policy, the Travel Rule policy, the transaction monitoring policy, the suspicious-activity reporting procedures and the sanctions-screening policy. Each document must reflect the actual business model – generic templates that do not match the operator's transaction types are a common FIU criticism.

Third, the technology stack is selected and configured: a customer identity and verification platform, a Travel Rule messaging solution compatible with the primary protocols in use (TRISA, OpenVASP, or one of the major commercial Travel Rule solutions), and a transaction monitoring engine calibrated to the operator's asset and customer risk profile.

Fourth, the MLRO is appointed and the internal training program is built. The MLRO must be available to the FIU and must have genuine decision-making authority over compliance matters.

Fifth, the program is tested against sample transactions before go-live. This dry-run step – simulating Travel Rule data collection, transmission and receipt – catches integration failures before they produce a supervisory finding.

The timeline from program design to registration readiness varies by the complexity of the operator's business model. Simple exchange or transfer-service models with a focused customer base can move through the design, build and documentation phase in a matter of weeks. Complex multi-activity or multi-jurisdiction models take longer. We map the critical-path items at the outset so operators can set realistic board-level expectations.

Micro-Matter: Travel Rule Gap Identified Before Supervisory Review

In a recent compliance engagement, a payments-focused VASP with an existing Estonian registration asked us to review its Travel Rule program ahead of an anticipated FIU supervisory cycle. The firm had invested in a commercial KYC platform and believed its compliance architecture was complete. On review, we identified that its Travel Rule transmission process applied only to transfers above a single monetary threshold and did not distinguish between counterparty VASPs in FATF-member and non-member jurisdictions. Transfers to counterparties in several jurisdictions were being processed without any counterparty VASP due-diligence step. We rebuilt the counterparty risk-tiering framework, updated the Travel Rule policy to reflect the differentiated thresholds applicable under the transitional MiCA-adjacent rules, and implemented a pre-transmission verification workflow. The firm entered the supervisory review cycle with a defensible program and no material findings.

A Common Assumption: A Single Offshore Licence Removes the Travel Rule Obligation

A common assumption among operators entering the Estonian market is that holding a registration in a more leniently supervised jurisdiction satisfies the Travel Rule obligation globally. It does not. The Travel Rule obligation attaches to each VASP in the transfer chain in the jurisdiction where that VASP is registered and operates. An Estonian-registered VASP must comply with the FIU's Travel Rule expectations regardless of whether its group also holds a licence elsewhere.

A second variant of this assumption is that routing transfers through an entity that is not technically a VASP under Estonian law avoids the obligation. The FIU has been explicit in its supervisory communications that substance governs classification. An entity performing exchange, transfer or custody functions is a VASP for these purposes even if it has not self-classified as one.

We map the licence, banking and compliance stack across operating, custody and payment layers before operators commit to a structure. The cost of a structural review before launch is a fraction of the cost of remediation after a supervisory finding or a banking relationship is suspended.

If a prior compliance review stalled or a banking relationship was closed, write to OBOLUS at info@oboluslaw.com. A second read of the program can surface the structural reason and the route to resolution.

Self-Assessment Checklist for an Estonian VASP Travel Rule Program

Operators reviewing their own programs should work through these questions. Each gap is a potential FIU finding.

  • Is the Travel Rule policy a standalone document, or is it embedded in a general AML policy without transaction-specific procedures?
  • Does the policy define the applicable transfer threshold and distinguish between FATF-member and non-member counterparty jurisdictions?
  • Has the firm selected and implemented a Travel Rule messaging solution that covers all counterparty VASPs it transacts with?
  • Is there a documented counterparty VASP due-diligence process, including a record of each counterparty's regulatory status?
  • Does the unhosted-wallet policy specify the threshold for enhanced verification and the process for obtaining self-attribution evidence?
  • Are Travel Rule transmission records retained in a form that the FIU can access within the required timeframe?
  • Is the MLRO a named natural person with documented authority and access to the FIU reporting channel?
  • Has the program been tested against live or simulated transactions in the past twelve months?

A "no" or "unsure" against any of these items is a signal that the program requires attention before the next supervisory cycle.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a VASP to collect verified originator and beneficiary identifying data – name, account or wallet identifier, and address or identity reference – and transmit it to the receiving VASP concurrent with or before a qualifying virtual-asset transfer. The obligation applies at both ends of the transfer chain. Under FATF Recommendation 15, both the originating and receiving VASP bear compliance obligations, and record-keeping duties attach to both.

Who must act as MLRO for a crypto firm?

The MLRO must be a named natural person with genuine seniority, relevant expertise in AML/CFT and direct access to the firm's board and to the FIU reporting channel. The FIU assesses whether the MLRO has real operational authority, not merely a title. In practice, the MLRO oversees the compliance program, signs off on suspicious-activity reports, leads the internal training program and is the primary point of contact during supervisory reviews. Outsourced MLRO arrangements are possible but require careful structuring to satisfy the FIU's expectations.

How do regulators audit crypto AML programs?

The FIU typically combines document review with transaction-level testing. Supervisors request the firm's AML/CFT policies, the MLRO appointment record, training logs, suspicious-activity reports and a sample of Travel Rule transmission records for specific transactions. They then cross-reference the policy documents against actual transaction processing to test whether controls function as written. Gaps between documented policy and operational practice – for example, a Travel Rule policy that specifies counterparty due diligence but no evidence that it was performed – are treated as program failures rather than paperwork issues.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance programs that sit around them. Digital assets are the whole of our practice. We map the licence, banking and compliance stack across operating, custody and payment layers before clients commit to a structure. To discuss your Travel Rule program or Estonian VASP registration, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML program design, Travel Rule implementation and VASP supervision across EU and Baltic jurisdictions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours