Around 2017 an Estonian virtual currency service provider registration could be obtained by a company with a local address, a modest fee and a compliance file assembled by a service provider. Thousands were issued. Marketing decks across the industry described the holders as "EU regulated". Most of them had no meaningful presence in Estonia at all, and a share of them were later connected to conduct that Estonian authorities had no appetite to be associated with.
The state did something unusual: it revoked at scale. Amendments to the money laundering and terrorist financing prevention act sharply raised the requirements, and registrations that could not meet them were withdrawn. Anyone evaluating a jurisdiction today should read that as the base case, not the exception. A permission granted cheaply can be removed cheaply, and the removal takes your banking, your acquiring and your app store listing with it.
Who supervises what in Estonia now
Two bodies matter and they do different jobs. Finantsinspektsioon, the Estonian Financial Supervision and Resolution Authority, authorises and supervises credit institutions, investment firms, payment institutions, e-money institutions, insurers and fund managers, under the EU frameworks. It is a prudential and conduct supervisor. The Financial Intelligence Unit, Rahapesu Andmebüroo, is the anti money laundering authority and it was the body that held the old virtual currency registrations.
That split explains the confusion in a lot of old marketing material. A virtual currency service provider registration was an anti money laundering registration granted by the FIU. It was never a financial services licence granted by the financial supervisor, and describing it as one was always a stretch. Under the EU markets in crypto assets regulation, crypto asset service provider authorisation is a proper financial supervisory function and sits with Finantsinspektsioon. That is a different instrument with different standards, and we cover the shape of it in the MiCA licence explained and the process in the CASP licence process.
What tightened, concretely
The requirements that carried the most weight were substance requirements rather than money. Management resident in Estonia. A real registered office where the business is actually conducted. A local money laundering reporting officer with relevant experience who is not simultaneously the officer for dozens of unrelated companies. A business plan that describes an operating business. Audited accounts. Share capital raised in line with the activity rather than the statutory minimum for a shelf company.
Each of those is a filter on the same thing: whether anyone is in the country. Estonia is a small state whose e-residency programme made company formation genuinely easy, and the tightening was a correction to what that ease had produced in one sector. Company formation remained easy. Regulated activity stopped being easy. Those two facts are still confused in offshore formation marketing, and the confusion is the product being sold.
Descriptive only, not advice. Estonian requirements and the EU crypto framework are both moving, and any firm considering an application needs Estonian counsel on the current position before it structures anything.
Investment firms, which is a separate question
Estonia authorises MiFID II investment firms through Finantsinspektsioon, on the same EU basis as any other member state. Permissions are the standard set, capital scales with them, and the authorisation passports across the EEA subject to host state conduct rules. A retail CFD firm needs dealing on own account and inherits the full European product intervention regime, including leverage limits, negative balance protection and the marketing restrictions in the European CFD marketing restrictions.
Estonia has never been a volume jurisdiction for retail CFD authorisations the way Cyprus has, and a firm choosing it should be clear about why. The reasons that hold up are a genuine Baltic operating base, a preference for a small and reachable supervisor, and a digital administrative environment that reduces friction on everything except the licence itself. The reason that does not hold up is cost, because supervised operations in Estonia are not cheaper than supervised operations elsewhere in the EEA once the local hires are real.
Who accepts an Estonian permission
Correspondent banks read Estonia through two lenses. The country is an EU and euro area member with a strong administrative reputation, which is positive. The historic association between Baltic banking and non resident deposit flows, and the enforcement history that followed it, means some institutions apply extra scrutiny to Baltic-registered financial firms with non resident clients. Neither lens is about your firm specifically. Both affect whether an account opens.
Payment service providers and acquirers behave as they do everywhere. Trading and crypto sit in high risk merchant categories, priced with reserves and chargeback thresholds, regardless of the regulator named on the file. The licence determines whether the application is reviewed. The category determines the terms. Anyone surprised by that should read high-risk merchant accounts before signing a processing agreement.
Liquidity providers want audited financials, clear segregation of client assets and a credit case. Platform vendors and technology suppliers, our own category included, contract with the licensed entity and generally require evidence of the permission before go live. App stores and advertising platforms run financial services verification programmes that ask for a licence covering the target country, which an EEA authorisation with a passport notification supplies and a lapsed anti money laundering registration does not.
The general lesson
Estonia is the clearest worked example in Europe of a cheap permission being repriced by the state that issued it. The pattern repeats: a jurisdiction opens a route, volume arrives, the reputational cost lands, the rules change, and the firms that treated the permission as a document rather than an operation lose it. That is the lens to apply to every jurisdiction currently being marketed as fast and inexpensive, including the ones covered in offshore broker licences. Trading and crypto services carry a high risk of loss for clients, and a supervisor who has already had one bad cycle will act on that faster than one who has not.
"Estonia did not get stricter by accident. It got stricter because thousands of registrations had been issued to companies with no one actually in the country, and the state decided it owned that problem."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- The old Estonian virtual currency registration was an anti money laundering registration from the Financial Intelligence Unit, not a financial services licence from the financial supervisor.
- Estonia revoked registrations at scale after raising substance requirements, which is the standing risk in any jurisdiction that licenses cheaply and quickly.
- Crypto asset service provider authorisation under the EU framework sits with Finantsinspektsioon and is a genuine supervisory permission with different standards.
- Easy company formation and easy regulated activity are different things, and formation marketing routinely blurs them.
Frequently Asked Questions
Is an old Estonian crypto licence still valid?
Many virtual currency service provider registrations were withdrawn after the requirements were raised, and the EU crypto asset framework introduced a separate authorisation supervised by Finantsinspektsioon. Any firm relying on a historic registration should have its current status verified in the official registers and confirmed by Estonian counsel.
Who regulates investment firms in Estonia?
Finantsinspektsioon, the Estonian Financial Supervision and Resolution Authority, authorises and supervises credit institutions, investment firms, payment and e-money institutions, insurers and fund managers under the applicable EU frameworks.
Does an Estonian licence make banking and payments easier?
It is an EU authorisation, which is usually the entry condition for a bank or acquirer to review an application. Beyond that, decisions turn on client country risk, the merchant category applied to trading and crypto, chargeback exposure and sanctions screening, and Baltic financial firms with non resident client bases sometimes attract additional scrutiny.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.