An application for an Estonian payment institution, e-money institution or gambling licence is judged largely on its documents. Two sets of documents are read most closely: the anti-money-laundering framework, which every such company must have as an obliged entity, and — for payment and e-money institutions — the arrangements that protect customers' money. Gambling operators must add player protection. This guide explains what these documents are and what our add-ons for AML/CFT internal rules, safeguarding and responsible gambling contain.
The guide is general information, not legal advice. The licence is granted or refused by the competent authority; no document guarantees the outcome.
AML/CFT: why the documents come first
Payment institutions, e-money institutions and gambling operators are obliged entities under the Estonian Money Laundering and Terrorist Financing Prevention Act (rahapesu ja terrorismi rahastamise tõkestamise seadus). Before they may start, they must have in place:
- a business-wide risk assessment that identifies the money-laundering and terrorist-financing risks of their customers, products, channels and countries, and the measures that address them;
- internal rules on customer due diligence — identification, verification, beneficial owners, politically exposed persons, ongoing monitoring and enhanced measures for higher-risk situations;
- procedures for sanctions screening and for reporting suspicious transactions to the Financial Intelligence Unit;
- a compliance officer and a training programme for the staff.
The authority reads these documents to judge whether the applicant understands its own business. Generic templates are easy to spot and are a common reason for long rounds of questions. The rules must match the actual product: a remittance business, a card issuer and a casino face very different risks.
Safeguarding customers' funds
A payment institution or e-money institution that receives funds from customers must protect them so that they are available to the customers if the institution fails. EU law allows two methods (Article 10 of Directive (EU) 2015/2366 for payment institutions; Article 7 of Directive 2009/110/EC for e-money institutions):
- segregation — the funds are kept separate from the institution's own funds and placed on a separate account with a credit institution or in secure, low-risk, liquid assets; or
- insurance or a comparable guarantee from an insurer or a credit institution outside the group, for the amount that would otherwise be segregated.
The application must describe the chosen method, the daily reconciliation that proves the funds are complete, and the records kept. In practice the hardest part is not the policy but the account: a safeguarding account is opened by a bank at its discretion, and banks ask for exactly these documents before they decide. Our guide to a bank account for a licensed company explains that step.
Responsible gambling and player protection
A gambling operator must show how it protects players: age verification, limits and self-exclusion, the handling of players who show signs of problem gambling, and how players can complain. These procedures are part of the licence application under the Estonian Gambling Act (hasartmänguseadus) and are also checked in supervision after the licence is granted.
What our add-ons include
AML/CFT internal rules, risk assessment and procedures — from
You receive: Business-wide risk assessment; internal rules and customer due diligence procedures; sanctions screening and reporting procedure; training plan.
Not included: Acting as your compliance officer; screening software; approval by any authority.
Safeguarding — policy and account documentation — from
You receive: Safeguarding policy (segregation or insurance/guarantee); daily reconciliation procedure; documentation pack for the safeguarding bank.
Not included: Opening the account (the bank decides); insurance or guarantee premiums.
Responsible gambling and player protection — from
You receive: Responsible gambling policy; self-exclusion and age verification procedures; player complaints procedure.
Not included: Gaming software certification; state fees.
Each add-on is quoted individually because the work depends on the business model. The AML/CFT package is available with a payment institution, e-money institution or gambling licence; safeguarding with a payment or e-money institution; responsible gambling with a gambling licence. State fees and the fees of the Financial Supervision Authority or the Tax and Customs Board are never included in our prices.
How to request a quote
Open the quote form on the licensed companies page, choose the licence and tick the documents you need; each shows its starting price. We reply with a written quote by email. No payment is taken on the page, and all communication takes place by email.
Frequently asked questions
Which AML documents does a payment, e-money or gambling licence application need?
The obliged entity must have a business-wide risk assessment, internal rules on customer due diligence, sanctions screening and reporting procedures, a compliance officer and a training plan under the Money Laundering and Terrorist Financing Prevention Act. The authority reads them to judge whether the applicant understands its own risks.
Will you act as our compliance officer or MLRO?
No. The compliance officer must be your own appointee, assessed by the authority. We write the AML/CFT framework and train your team on it; screening software and the officer's role are not part of the service.
What is safeguarding of customers' funds?
A payment or e-money institution must protect funds received from customers, either by segregating them on a separate account or in secure low-risk assets, or by insurance or a comparable guarantee (Article 10 of Directive (EU) 2015/2366; Article 7 of Directive 2009/110/EC). The application describes the method, the daily reconciliation and the records.
Do you open the safeguarding account?
No. The safeguarding account is opened by a bank at its own discretion. We prepare the policy and the documentation pack the bank asks for; insurance or guarantee premiums are third-party costs.
What player protection procedures does a gambling operator need?
Age verification, limits and self-exclusion, the handling of players showing signs of problem gambling, and a complaints procedure. They form part of the activity licence application under the Gambling Act and are checked again in supervision.
Does the responsible gambling package certify our gaming software?
No. Software certification is carried out by testing laboratories and is a third-party cost. The package covers the policies and procedures.