Estonia AML Compliance — FIU Requirements, KYC & Transaction Monitoring
FIU AML requirements, KYC programs for CASP and payment firms, ongoing transaction monitoring under the Estonian Money Laundering and Terrorist Financing Prevention Act. We build the compliance and keep it sharp.
What Compliance & AML includes in Estonia
What you receive
How it works
Where to register and how we differ
Compliance & AML in Estonia — frequently asked questions
Every Estonian company falls under the Money Laundering and Terrorist Financing Prevention Act. The baseline set: a written AML risk assessment, a customer due diligence (CDD) policy, an appointed compliance officer (mandatory for obliged entities), and transaction records kept for at least 5 years. Financial services, virtual-currency operations, and company formation agents are obliged entities with enhanced requirements.
The FIU (Rahapesu Andmebüroo) requires obliged entities to file suspicious transaction reports (STRs), submit annual compliance reports, register in the FIU's information system, and undergo on-site inspections. Since 2022, enforcement has sharpened hard: licence revocations, fines up to €400,000 per violation. Crypto firms draw the closest AML scrutiny — and since 2025 they licence as CASPs with the FSA under MiCA (minimum capital €50,000–€150,000 by class), with legacy FIU VASP licences valid only to 1 July 2026.
Every OÜ must enter its ultimate beneficial owners — anyone owning or controlling more than 25% — in the e-Business Register, and that data is public. Keeping it current is mandatory; late updates draw fines. For complex structures with trusts or nominees, a declaration of indirect UBO is required. We check UBO compliance as part of the annual compliance review.
Enhanced due diligence (EDD) is mandatory for: politically exposed persons (PEPs) and their associates, high-risk countries on EU lists, non-face-to-face client relationships, complex or unusually large transactions, and correspondent banking links. For licensed crypto firms (CASPs), the FIU increasingly demands blockchain analytics — Chainalysis, Elliptic — as evidence of transaction monitoring.
Non-compliance turns into FIU precepts, administrative fines up to €400,000, suspension or revocation of regulated licences (CASP, EMI, PI), and in severe cases referral to the prosecutor for criminal liability. The FIU publishes its decisions openly. Between 2022 and 2024 the regulator revoked more than 1,000 VASP licences following its inspections. An annual AML audit from INNOVA clears these risks in advance.
