DeFi Security AllianceRequest an audit
Menu

DeFi regulation & security

DeFi regulation in Finland

FIN-FSA’s application guidance connects the risk assessment to actual controls and responsible people. Adopted EU standards supply the current application requirements.

Sources checked
Published
Prepared by
DeFi Security Alliance

Scope: Finnish CASP AML application evidence. This is not a complete Finnish licensing, fee, token-issuance or taxation guide; the 2024 guidance is read alongside adopted EU rules.

Choose the application basis before preparing AML documents

ESMA's 7 July 2026 competent-authority compliance table identifies FIN-FSA for Finland. A new CASP application uses MiCA Article 62. Eligible existing financial institutions have the service-dependent Article 60 notification route.

FIN-FSA's AML documentation guidance of 23 August 2024 explains how to prepare the risk and control material. It predates the adopted technical standards. References in that paper to draft standards should now be read with Regulation 2025/305, rather than used as the current legal text.

Separate the risks and name the people responsible

The Finnish-language guidance separates money-laundering and terrorist-financing risks and calls for sanctions and national freezing-risk analysis. It asks who prepares and updates the assessments and how the selected controls follow from them.

Article 6 of Delegated Regulation 2025/305 specifies inherent and residual risk, proportionate controls, the AML officer, annual resources and effectiveness review information. Link customer due diligence, suspicious-transaction procedures and transfer-data controls to the services and risks actually described.

Turn a risk statement into testable evidence

This DeFiSec worksheet helps prepare the reasoning and operational records behind an application. It is not a FIN-FSA form.

Finland: AML risk-to-control worksheet
DecisionEvidence to prepareReview question
Risk distinctionSeparate ML, TF and sanctions assessmentsWhich exposure does each control address?
Distribution channelOnboarding and transfer-flow diagramsDoes the assessment describe the deployed product?
Accountable staffAML officer experience, authority and available resourcesCan this person investigate and escalate a failed control?
Control effectivenessReview schedule, results and remediation ownersWhat evidence shows the control works in practice?

Pharos Production's MiCA KYC implementation guide provides technical context for identity and compliance workflows. Reconcile that workflow with the Finnish assessment and the adopted application standard. Buying a KYC integration does not demonstrate that the provider's whole control system is effective.

Keep crypto-specific changes visible

For an eligible institution using the notification route, the Finnish guidance discusses the updated or crypto-relevant parts of existing documentation. Do not assume that an earlier policy already describes a new wallet, transfer feature or customer channel.

As a preparation control, retain a change log linking each product change to its risk, policy, implementation and reviewer. Revisit the scope analysis when control over assets or the interface changes. The Travel Rule guide expands the requirements for transfers involving self-hosted addresses.

Continue your research

Sources and further reading

Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.

  1. MiCA — Regulation (EU) 2023/1114European Union ·
  2. MiCA KYC requirements: onboarding and Travel Rule integrationPharos Production ·
  3. AML application documentation for crypto-asset service providersFIN-FSA ·
  4. Rahanpesun ja terrorismin rahoittamisen estämiseen liittyvät selvityksetFinanssivalvonta ·
  5. Delegated Regulation (EU) 2025/305European Union ·
  6. MiCA knowledge and competence guidelines: compliance tableESMA ·

Publication record

First publication of this guide and its source-backed evidence map.

Report an outdated source