VASP License Compliance Setup in Estonia

Obtaining a VASP license in Estonia requires detailed compliance system setup. After the reform, the regulator tightened requirements: a real office, a local MLRO, capital from €125,000. Many companies get rejected due to a formal AML policy or lack of actual presence. We specialize in documentation

Blockchain Development Services

Frequently Asked Questions

Latest works

  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1301
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1267
  • image_logo-advance_0.webp
    B2B Advance company logo design
    713
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    1003
  • image_logo-aider_0.webp
    AIDER company logo development
    943
  • image_crm_chasseurs_493_0.webp
    CRM development for Chasseurs
    1056

Obtaining a VASP license in Estonia requires detailed compliance system setup. After the reform, the regulator tightened requirements: a real office, a local MLRO, capital from €125,000. Many companies get rejected due to a formal AML policy or lack of actual presence. We specialize in documentation preparation and support with the FIU. Our experience: over 5 years and 20+ successful cases. Meanwhile, independent preparation often leads to additional regulator inquiries, doubling the average timeline — our compliance setup cuts this time in half compared to independent preparation.

A typical problem is a generic AML policy that does not account for the business model. We develop a policy from scratch, including transaction monitoring rules and EDD procedures, which reduces the number of follow-up inquiries from the regulator by three times. In this article, we break down the key FIU requirements and steps for successful license acquisition. Special attention is given to details that most often lead to rejection. Understanding these nuances will save you months of waiting.

How have requirements changed after the reform?

Real presence in Estonia: an office and at least one director or employee physically located in Estonia. Nominal director without actual presence is no longer accepted.

Local AML Compliance Officer: an appointed MLRO (Money Laundering Reporting Officer) with confirmed AML experience. The Estonian FIU checks CVs and may request an interview with the candidate.

Minimum capital: €125,000 for VCES, €250,000 for VCWS. Capital must be documented in the articles of association and confirmed by a bank statement. Important: these funds are not a license fee but serve as a guarantee of liability.

IT audit: an external IT audit by an Estonian auditor. Compliance with GDPR, security of client data storage, backup procedures, and transaction monitoring are checked. The auditor must be accredited by the FIU.

Parameter VCES VCWS
Minimum capital €125,000 €250,000
Main activity Exchange, trading Wallets, storage
AML requirements General + exchange monitoring General + storage security
IT audit Mandatory Mandatory, additionally cold wallet security

What requirements does the FIU have for the AML Policy?

The Estonian FIU expects specific elements in the AML Policy. We develop a document fully compliant with the Money Laundering and Terrorist Financing Prevention Act and considering the regulator's practice.

Mandatory sections according to MLTFPA: 1. Business model and risk description 2. Customer Due Diligence procedures (including enhanced for high-risk) 3. Transaction monitoring system with example rules 4. SAR reporting procedure (via FinanceIntelligence.ee portal) 5. Sanctions screening 6. Record keeping (5 years) 7. Staff training 8. Internal audit 9. Board-level oversight 

The FIU is known for requesting additional documents in 2–3 rounds. A generic policy from the internet leads to immediate rejection. We prepare the policy considering typical FIU remarks: a detailed business model description, realistic transaction rule examples, enhanced due diligence procedures for high-risk countries. For example, for an exchange service, we include structuring detection rules (more than 3 transactions just below the threshold within 24 hours) and mandatory sanctions screening via Chainalysis or similar.

How to set up transaction monitoring to meet FIU requirements?

Transaction monitoring is a key compliance element. The FIU expects the monitoring system to detect suspicious patterns in real time. In our practice, we define at least five rules: structuring, high-value transactions, rapid fund movement, interaction with high-risk countries, and abnormally frequent small deposits. Each rule must be documented with threshold values and actions triggered.

Example monitoring rules: 1. Structuring: >3 transactions below €1000 in 24h (alert + manual review) 2. High value: single transaction >€10,000 (automatic AML check) 3. Rapid movement: deposit + withdrawal within 24h (includes enhanced KYC) 4. High-risk country: any transaction involving FATF blacklist country (block) 5. Anomalous patterns: multiple small deposits from different addresses (manual review) 

Why does the FIU reject VASP license applications?

Most common reasons for rejection:

  • Incomplete AML policy – missing sections, no example monitoring rules.
  • Formal approach to MLRO – candidate lacks real AML compliance experience.
  • Lack of real presence – declared office turns out to be virtual.
  • Lack of transparency on source of funds – company cannot explain capital origin.

We help avoid these mistakes during the preparation phase.

Mistake How to avoid
Generic AML policy Develop tailored to business model, include detailed monitoring examples
No real office Rent physical office, hire local employee
Unsuitable MLRO Appoint candidate with confirmed AML experience

Technical requirements for IT infrastructure

// For the Estonian license, you need to document: const EstoniaVASPRequirements = { // Transaction monitoring rules (with examples of how they work) tmRules: [ "Structuring detection: >3 transactions just below €1000 within 24h", "High-value: single transaction >€10,000", "Rapid fund movement: deposit + withdrawal within 24h", "High-risk country: any transaction involving FATF blacklist country", ], // KYC levels linked to limits kycLevels: { BASIC: { limit: 1000, required: ["email", "phone", "wallet_screening"] }, STANDARD: { limit: 15000, required: ["government_id", "address", "liveness_check"] }, ENHANCED: { limit: Infinity, required: ["source_of_funds", "source_of_wealth", "video_call"] }, }, // SAR reporting sarReporting: { platform: "FinanceIntelligence.ee", deadlineDays: 10, // Estonia has stricter deadline than FATF standard reportingCriteria: ["suspicion of ML/TF", "unusual transaction patterns"], }, }; 

Application process

  1. Preparation of all documents (8–12 weeks)
  2. Submission via Estonian Business Register
  3. FIU review (60 working days by law, actually 3–5 months)
  4. Follow-up questions from FIU (usually 2–3 rounds)
  5. Receipt of license or reasoned refusal

State fees are paid separately.

What is included in our work

  • Development of AML Policy and CDD/EDD procedures
  • Setup of transaction monitoring rules tailored to business model
  • Preparation of document package for FIU
  • Support at all stages, including responses to FIU inquiries
  • Staff training on AML and KYC basics
  • Recommendations for MLRO selection and physical presence setup

Our compliance setup outperforms independent preparation: it cuts the license acquisition time in half.

Timeline

Compliance documentation preparation takes 4 to 8 weeks. The full license acquisition process (including FIU review) takes 3 to 6 months.

How to start

Contact us for an audit of your current documentation. We will assess readiness and propose an action plan. Request a consultation on compliance setup for the Estonian license — the first analysis is free.