- Australia
- Austria
- Bangladesh
- Belgium
- Brazil
- Bulgaria
- Canada
- China
- Croatia
- Cyprus
- Czech Republic
- Egypt
- Estonia
- Eswatini
- Ethiopia
- France
- Germany
- Greece
- Haiti
- Hong Kong
- Hungary
- India
- Iraq
- Ireland
- Indonesia
- Italy
- Japan
- Jordan
- Kazakhstan
- Kenya
- Kosovo
- Kuwait
- Latvia
- Luxembourg
- Malaysia
- Malta
- Mauritius
- Mexico
- Micronesia
- Moldova
- Montenegro
- Morocco
- Mozambique
- Myanmar
- Namibia
- Nauru
- Nepal
- Nigeria
- Nicaragua
- Niue
- Norway
- Netherlands
- New Zealand
- Oman
- Pakistan
- Palau
- Palestine
- Panama
- Papua New Guinea
- Paraguay
- Peru
- Puerto Rico
- Philippines
- Portugal
- Poland
- Qatar
- Republic of Congo
- Romania
- Russia
- Rwanda
- Samoa
- San Marino
- Senegal
- Serbia
- Seychelles
- Sierra Leone
- Singapore
- Slovakia
- Slovenia
- Somalia
- South Africa
- South Korea
- South Sudan
- Spain
- Sri Lanka
- St Kitts and Nevis
- St Maarten
- St Lucia
- Sweden
- Switzerland `
- Syria
- Taiwan
- Tajikistan
- Tanzania
- Thailand
- Timor Leste
- Togo
- Tonga
- Trinidad and Tobago
- Turkey
- Turks and Caicos
- Turkmenistan
- Tunisia
- Tuvalu
- Uganda
- Ukraine
- UK
- Uruguay
- USA
- Uzbekistan
- Vatican City
- Vietnam
- Venezuela
- Vanuatu
ESTONIA KYC, KYB AND AML
Scale Identity Verification and KYC Operations in Estonia
Verify Estonian customers and businesses through Estonia's notified eID scheme, Smart-ID, NFC, QES, identity documents, biometrics and KYB. Reduce manual review, maintain consistent audit evidence and run one connected workflow designed to support the Money Laundering and Terrorist Financing Prevention Act, known in Estonia as RahaPTS, today and AMLR from 10 July 2027.
Operational Performance for Estonia KYC
Our Numbers Speak Volumes
98.94%
First-pass
verification rate
< 10 sec
Median
verification time
6
Estonian ID methods
supported
Estonia IDV/KYC Challenges
The Everyday eID and the Notified eID Are Not the Same Thing
Smart-ID is the credential many Estonian customers reach for first. It is a private-sector scheme, not an eIDAS-notified scheme under Section 31(3), so using it for remote identification depends on meeting Section 31(3¹)'s conditions where a Section 31(3) route cannot be used.
E-Residency Onboarding Needs a Second Document
The e-Resident's digital ID is not a photo document and cannot be used to travel. Section 31(4) requires a second accepted document alongside it, so e-resident files carry an extra step and far more passport fallback.
Ownership Data Is Open but Not Always Current
Beneficial ownership is published through the e-Business Register and still openly viewable, but Estonia's national risk assessment and the MONEYVAL evaluation both record gaps in currency and accuracy. Registry facts confirm a company exists, not who controls it.
Estonian Name Forms Break Global Matching
Õ, Ä, Ö, Ü, Š and Ž are stripped from the machine-readable zone and from many international databases, and Russian-language records arrive with different transliterations. Both push clean customers into manual review and false positives.
Regulatory Update
What AMLR Changes for Identity Verification in Estonia
The EU Anti-Money Laundering Regulation (EU) 2024/1624 applies directly in Estonia from 10 July 2027, with no transposition period. It sets the due diligence rules the Money Laundering and Terrorist Financing Prevention Act framework will operate under, with AMLA, the new EU-level supervisor, established in Frankfurt.
Timeline
- End of 2026 EU-level Member State wallet issuance target
- 10 July 2027 AMLR applies, no transposition
- Late 2027 Wallet acceptance duty for certain regulated private providers, eIDAS 2.0 Article 5f
- 2028 AMLA direct supervision begins
eIDAS Routes Expressly Recognised
Article 22(6)(b) recognises eIDAS eIDs and qualified trust services. Article 22(6)(a) equally permits document-based verification.
The Ownership Test Tightens
AMLR sets the beneficial-ownership test at 25% or more, or through control, Articles 51 to 54. Estonian law reads exceeds 25 per cent, so KYB checks should confirm holdings at the 25% line before July 2027. A lower threshold, floored at 15%, may follow for designated higher-risk categories.
Existing Customers Get Re-Checked
AMLR expects existing customer records to be brought up to standard on a risk basis, not just new onboarding. Continuous monitoring keeps back-book files current between reviews.
Accountability Stays With You
Article 18 lets you outsource due diligence tasks but keeps you fully liable for what those tasks produce, so vendor evidence and clean audit trails matter more under AMLR.
FOR FINANTSINSPEKTSIOON AND FIU-SUPERVISED BUSINESSES
Streamline Finantsinspektsioon and FIU-Supervised Onboarding in Estonia
Connect identity verification, QES, optional Penny Drop and compliance evidence in one configurable workflow for businesses in the Finantsinspektsioon and Financial Intelligence Unit remit. Reduce drop-off and manual handovers while giving compliance teams a review-ready record of every decision.
1. Verify the Customer
Verify identity using the configured route, such as Estonia's notified eID scheme, a qualified trust service, NFC reading of the ID-kaart, or document and biometric checks.
2. Complete Qualified Signing
Apply and validate the QES in the same journey, keeping the signed document, verification result and evidence together. Under Section 31(3) qualified signing also carries a lawful identification basis.
3. Confirm the Payment Account
Where your risk policy or a counterparty calls for it, Penny Drop Verification confirms the customer holds the account and records the evidence of that check.
Section 31 applies to credit and financial institutions and virtual currency service providers, Section 2(5).
Section 14(1¹) requires rules of procedure before the Section 31 route is used. A notified scheme or qualified trust service is mandatory outside the EEA, above the Section 31(1) thresholds and in Section 31(1¹) cases. Estonian law provides no combined signature and account route, so step 3 is a control choice.
Shufti's IDV/KYC Solutions for Estonia
KYC Solutions
Clear onboarding for Estonian customers under the Money Laundering and Terrorist Financing Prevention Act, with age and address checked in the same flow as identity, each check completing in seconds.
Explore MoreFace Verification
Face verification binds the live person to the document with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness, stopping spoofs, masks and deepfakes.
.Age Verification
Selfie-based age estimation combined with document verification fallback where age-gated access or higher-control onboarding requires it.
.Bank Account Verification
Confirms an Estonian bank account (EE IBAN) belongs to the customer, returning the registered account holder name for matching against the verified identity.
.Address Verification
Shufti verifies Estonian address-bearing documents, including utility invoices, telecom bills and bank statements from major Estonian issuers. Proof-of-address checks remain common in regulated onboarding.
.Document Verification
Verification of the ID-kaart, the elamisloakaart residence permit card and the Estonian passport, including NFC chip reading and Estonian-language extraction. Remains a permitted route for remote verification under AMLR.
.Identity Verification
Shufti confirms every customer is real and present, not a spoofed or synthetic identity. Biometric face matching and liveness detection run against 10,000+ actively processed document types.
.KYB Solutions
Shufti checks businesses as deeply as the people behind them, supporting your risk-based approach under the Act on both sides of the file. Shufti checks registry records, beneficial ownership and VAT details in real time, then screens the controllers against 4,000+ global watchlists for sanctions and adverse media exposure.
Explore MoreBusiness Verification
Automated validation of e-Business Register data, the eight-digit registrikood, the EE-prefixed VAT number and management board members. Estonia issues no separate company tax number, so the registry code carries the identifier through the whole file.
.Enhanced Due Diligence (EDD)
Structured risk profiling for non-resident ownership chains, company service provider structures and higher-risk sectors, supporting Estonia's risk-based obligations under the Act.
.AML Screening
Shufti screens customers and transactions in 240+ countries and territories, flagging sanctions, PEP and adverse media matches as they happen. Ongoing monitoring surfaces suspicious activity in time to meet Estonian reporting obligations.
Explore More
AI Compliance Copilot
Helps compliance teams review verification and AML data, investigate alerts, and understand the reasoning behind risk signals. It brings relevant case information together to support faster, more consistent compliance decisions.
.
Transaction Monitoring
Ongoing transaction monitoring calibrated to Estonian and cross-border flows flags anomalies against AML rules, supporting the risk-based controls expected by Finantsinspektsioon and the Financial Intelligence Unit.
.Supported Verification Methods for Estonia
Every Verification Route Estonia Uses, in One Platform
Shufti supports the full range of remote verification routes used in Estonia, from the EUDI Wallet and the notified eID scheme to document and biometric checks. Each method below shows what is live today and what is ready for the 2027 rollout.
EUDI Wallet
Wallet-ready · from 2027AMLR Article 22(6)(b) recognises eIDAS eID means, including the EUDI Wallet.
Notified eID
LiveeIDAS HighEstonia's notified eID scheme covers the ID-kaart, the residence permit card, Digi-ID, the e-Resident Digi-ID, Mobiil-ID and the diplomatic identity card, all at eIDAS assurance level high, and Shufti verifies these today.
Docless Database eIDV
LiveDatabase-driven checks against permitted reference data sources confirm identity in seconds for low-risk onboarding, with no document upload. Shufti escalates to stronger checks as risk rises.
NFC Chip Verification
LiveShufti reads the secure chip in the ID-kaart issued from 2018, the elamisloakaart residence permit card and the Estonian passport. This is the high-assurance capture route where a card reader is not to hand.
Document and Face Biometric
LiveAn AMLR Article 22(6)(a) route, available under Section 31(3¹) where a notified scheme or qualified trust service cannot be used. Document authentication of the ID-kaart, residence permit card and passport, paired with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness.
Qualified Electronic Signature
LiveSection 31(3) of the Act allows a qualified trust service meeting Regulation (EU) 910/2014 to be used for remote identification in its own right. Shufti runs eIDAS-qualified signing through a qualified trust service provider on the EU Trusted List. Estonia is among the notified eIDs supported for QES signing, so the identity check runs through the Estonian eID.
Independent Validation
Shufti's Recognition Across Independent Evaluations

Ranked Exceptional in the Liminal Index 2026 for age estimation
View Report
Differentiated by Gartner on document diversity and country coverage
Read more
Certified at iBeta Level 3 PAD with 0% APCER
Read Blog
Broadest global reach in the 2025 KuppingerCole Extended IDV report
Download Report
Ranked Top 5 in the DHS RIVR 2025 for identity validation
Read Blog
Ranked Exceptional for age verification by Liminal Index 2026
View Report
Recognised as a Leader across four G2 Summer 2026 reports
View ReportEvidence-Ready Checks Across People & Businesses
Verifications with robust evidentiary support
Individual Documents We Verify
Shufti verifies six primary individual Estonian documents.
View All Supported DocumentsEstonian ID Card (ID-kaart)
The primary photo document for Estonian citizens and for EU citizens permanently resident in Estonia, issued by the Police and Border Guard Board under the Identity Documents Act. It carries digital identification and digital signing certificates, and cards issued from 2018 read contactlessly over the PACE-protected channel.
Digital ID (Digi-ID)
An electronic-only credential with no photograph, used for e-services and signing. Issuance to Estonian residents ended on 1 May 2025 and cards issued before that date stay valid until they expire, so it appears in onboarding as a signing and authentication means rather than a photo identity document.
Residence Permit Card (Elamisloakaart)
The primary photo document for third-country nationals with an Estonian residence permit or right of residence. It is an EU uniform residence permit in ID-1 format with an ICAO-compliant contactless chip holding the facial image and fingerprints, and it carries the eID function.
E-Resident Digital ID (e-Residendi digi-ID)
A digital credential for foreign nationals using Estonian e-services and company tools from outside Estonia. It is not a travel document and not a photo identity document, and Section 31(4) of the Act requires a second accepted document alongside it for remote identification, so KYC usually needs a passport as well.
Estonian Passport (Eesti kodaniku pass)
The biometric, ICAO-compliant travel document issued by the Police and Border Guard Board. It carries a contactless chip with the facial image and two fingerprints, which makes it the practical fallback in remote and non-resident onboarding.
Estonian Driving Licence (Juhiluba)
An EU-model licence issued by the Estonian Transport Administration. It is accepted as an identification basis under Section 21(3) of the Act. The governing regulation provides for no chip, so it is verified through document checks.
Entity Identity
E-Business Register Extract
Proves legal existence, legal form, status, registry code and registered details. The register is maintained by the registration department of Tartu County Court and the portal is run by the Centre of Registers and Information Systems, which makes it the usual starting point for KYB baselining.
Registration Certificate
Certificate-style registry output confirming the entity is entered in the Estonian register. Used where a counterparty wants formal registration evidence sitting in the KYB file rather than a screenshot of a lookup.
Management Board and Representation Details
Shows who can bind the company in practice. Shufti uses it to validate signatory authority, which cuts the KYB exceptions caused by the wrong representative applying.
Annual Report Filing Status
A transparency and operational health signal during KYB, and a useful one for higher-risk sectors, dormant entities and structures with non-resident control.
Tax Identity
Company Registration Code (Registrikood)
The non-recurrent eight-digit identifier assigned on entry in the commercial register. Estonia issues no separate company tax number for registered legal persons, so the registrikood carries the identity across the register, the Tax and Customs Board and the KYB file.
VAT Number (KMKR number)
The VAT identification number is EE followed by nine digits. Once granted it is published and checkable through the Tax and Customs Board and VIES, and it is used in invoicing, tax checks and onboarding review.
Tax Standing or Tax Debt Certificate
Useful in supplier due diligence, lending and enhanced review where teams need evidence of tax standing or arrears beyond basic VAT registration.
Ownership & Control (UBO)
Beneficial Owner Data (UBO) in the Business Register
Beneficial ownership is filed and published through the e-Business Register under Sections 76 to 78 of the Act. Shufti checks control data against it, applying the AMLR test at 25% or more, or via control.
UBO Verification Approach (Register Metadata)
The published dataset records how the beneficial owner's identity was established, which helps teams evidence the control check rather than simply restating a name from the register.
Shareholder Data or Share Register Evidence
Used to test ownership layers, reconcile control and support escalation where shareholder, board and beneficial owner evidence does not line up. Section 20(2⁴) of the Act requires the registrar to be notified where what you find differs from what is published.
Non-Resident and Branch Registration Evidence
For branches and permanent establishments, tax registration can require documented authorisation and supporting filings with the Estonian Tax and Customs Board.
Sector Licence or Activity Licence
For regulated sectors, licence evidence shows the business is permitted to operate. Crypto-asset service providers now hold a Finantsinspektsioon authorisation under MiCA rather than a Financial Intelligence Unit authorisation.
Languages We Cover
Document Text Handling
Estonian is the official language and Estonian documents use Latin script. Shufti parses Estonian natively and supports mixed intake where customers present foreign passports and records alongside Estonian documents.
Name Matching Controls
Estonian uses Õ, Ä, Ö, Ü, Š and Ž. Matching reconciles the diacritic-bearing visual inspection zone name with the stripped machine-readable zone form, so variants such as Mägi and Magi are reviewed, logged and resolved consistently.
Evidence Consistency Across Steps
Document, selfie and screening evidence stay aligned by anchoring to stable identifiers such as the eleven-digit isikukood, even where foreign records add transliteration variance.
Governance & Controls
Audit-Ready Decisions, Lower Operational Drag
Fewer Avoidable Re-submissions
Capture tuned to Estonian ID formats, plus chip extraction from the ID-kaart and the residence permit card, cuts avoidable re-submissions and the retry loops that lose applicants.
Cleaner Audit Trails
Structured logs aligned to the five-year retention rule in Section 47 of the Money Laundering and Terrorist Financing Prevention Act and to Financial Intelligence Unit reporting duties keep every onboarding decision audit-ready.
Better Name Matching Outcomes
Matching handles Estonian diacritics, machine-readable zone stripping and cross-script transliteration, which lowers false positives and the analyst review they generate.
One Workflow, One Back Office
KYC, KYB and AML screening are consolidated in one operational case view, so one back office team works on every customer file.
National ID-First Flow Design
ID-kaart-first onboarding reflects Estonia's national identity ecosystem, captures the isikukood consistently, and switches cleanly to passport fallback for non-resident and e-resident cases.
Continuous Compliance
Compliance that does not stop at onboarding
AMLR treats customer due diligence as a continuing obligation. Perpetual monitoring keeps the customer picture current between reviews, so risk is caught when it appears, not at the next annual check.
Surface Changes as it happens
DetectPerpetual monitoring flags risk when it appears, not at the next annual review. Behavioural biometrics, background fraud signals, and ongoing sanctions and PEP screening watch every active relationship.
Step up when the signal fires
VerifyWhen a signal fires, re-verification confirms the person or the ownership change using the same live methods above, so a flag turns into a resolved decision.
Keep the file audit-ready
ComplyEvery check and decision is logged to the record-keeping standard in Section 47 of the Act, so the file is organised and retrievable for internal audit and supervisory review.
Perpetual KYC
pKYCKeeps individual customer risk current with behavioural biometrics, background fraud signals and ongoing AML screening, so back-book records stay standard-ready for the AMLR remediation.
Perpetual KYB
pKYBMonitors beneficial ownership data and the e-Business Register, so a shift past the 25% or more UBO threshold or a change of control is caught between reviews.
Built To Fit Estonia's Compliance Landscape
Financial Intelligence Unit (Rahapesu Andmebüroo)
An independent government authority under the Ministry of Finance since 1 January 2021. It receives suspicious and unusual transaction reports, and under Section 64(1) of the Act it is the default AML supervisor for obliged entities that Finantsinspektsioon does not supervise, other than advocates and notaries, who answer to the Bar Association board and the Ministry of Justice and Digital Affairs. Shufti helps teams keep the records, rationale and escalation trail that reporting and audit need.
Finantsinspektsioon
Supervises banks, insurers, investment firms, payment and e-money institutions, fund managers and crowdfunding providers, and since 1 July 2026 crypto-asset service providers authorised under MiCA. Shufti supports risk-based due diligence, consistent screening records and decisions that are ready for supervisory review.
Ministry of Finance (Rahandusministeerium)
Owns Estonia's AML policy framework, controls the beneficial ownership database and publishes the national money laundering and terrorist financing risk assessment. Shufti helps firms turn that risk-based model into structured KYB, UBO and evidence-led onboarding controls.
Ministry of Foreign Affairs (Välisministeerium)
Coordinates national implementation of international sanctions under Section 10 of the International Sanctions Act and publishes designations under the Government of the Republic sanctions. Shufti helps firms show how sanctions checks, controller screening and escalation were carried out in practice.
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Supervises personal data processing under GDPR and Estonia's Personal Data Protection Act. Shufti supports tighter retention control, data minimisation and safer handling of onboarding evidence.
Police and Border Guard Board (Politsei- ja Piirivalveamet)
Issues Estonia's core identity documents, including the ID-kaart, the residence permit card and the e-Resident digital ID, and is the authority named for the notified Estonian eID scheme. Shufti supports document checks built around local fields, formats and document change cycles, including the card generation issued from 17 November 2025.
Centre of Registers and Information Systems (Registrite ja Infosüsteemide Keskus, RIK)
Develops and runs the e-Business Register portal, while register force sits with the registration department of Tartu County Court. Shufti helps bring registry facts, ownership data and representation details into one KYB workflow.
Estonian Tax and Customs Board (Maksu- ja Tolliamet)
Manages tax registration, VAT status and non-resident registration relevant to company onboarding, and administers the cash declaration duty at the EU border. Shufti helps teams capture and retain the tax-linked evidence used in higher-confidence KYB reviews.
AMLA (EU Anti-Money Laundering Authority)
The new EU-level supervisor has been established in Frankfurt since July 2025. It begins direct supervision of selected high-risk cross-border entities from 2028 and shapes the technical standards under AMLR.
Deployment Option
No in-country public cloud region is listed for Estonia, so deployment runs in nearby EU regions or on-premise. Either option keeps Estonian customer data in-region and supports GDPR accountability.
Regulatory Alignment
Aligned with the due diligence, beneficial ownership and record-keeping duties in the Money Laundering and Terrorist Financing Prevention Act, with GDPR and the Personal Data Protection Act principles applied throughout, and AMLR applying from 10 July 2027.
Retention Controls
Section 47(1) of the Act sets a five-year minimum retention period running from termination of the business relationship. Section 47(3) runs the same period from the transaction or the reporting duty, and Section 47(6) applies it to the remote identification record captured under Section 31. Section 47(7) requires deletion once the period expires unless a supervisor extends it. From 10 July 2027 AMLR Article 77 keeps a five-year baseline with case-by-case extensions, so the Estonian position may be largely unchanged.
Encryption & Security
Encryption in transit and at rest, access controls and audit logging support Article 32 GDPR and the Personal Data Protection Act under our ISO 27001 certification.
Scope of Our Role
Shufti acts as a data processor providing verification technology, not legal or regulatory advice. Customer due diligence and the choice of verification method remain with the obliged entity, documented in its own risk assessment.
Automated Decisions and Biometric Data
The controller sets the lawful basis for processing. Biometric data used for unique identification engages Article 9 GDPR, and human review is available in the workflow.
Data and Privacy Controls in Estonia
Estonia AML Sources That Strengthen Decisions
We screen against 215+ sanction regimes, 4,000+ watchlists, 100,000+ adverse-media sources, and 6M+ PEPs across Estonia and globally. A few of them are:
Finantsinspektsioon
Rahapesu Andmebüroo
Rahandusministeerium
Välisministeerium
e-Äriregister
Registrite ja Infosüsteemide Keskus (RIK)
Maksu- ja Tolliamet
Politsei- ja Piirivalveamet
Andmekaitse Inspektsioon
Riigi Infosüsteemi Amet (RIA)
FATF
EU Sanctions Map
UN Security Council Consolidated List
European Banking Authority (EBA)
EU AMLA (Anti-Money Laundering Authority)
MONEYVAL
SEE SHUFTI IN YOUR ESTONIA WORKFLOW
Turn Estonian Verification Requirements into a Smoother Customer Journey
Share your customer types, risk rules and current onboarding process. A Shufti specialist will show you how to connect identity verification, KYB, QES, optional Penny Drop and ongoing monitoring, reducing operational hand-offs while keeping decision evidence organised for review.
Frequently Asked Questions
Which identity documents can be used for Estonian onboarding?
Customers can use the ID-kaart, including its chip and notified eID function, the elamisloakaart residence permit card and the Estonian passport, and the driving licence is accepted as an identification basis under Section 21(3) of the Money Laundering and Terrorist Financing Prevention Act. Shufti supports document, eID, NFC and biometric verification within one configurable workflow.
How does Shufti support Finantsinspektsioon and FIU-supervised businesses in Estonia?
Shufti connects identity verification, KYB, AML screening, QES, account verification and decision evidence in one configurable workflow. This helps businesses in either supervisory remit reduce manual hand-offs, standardise compliance records and prepare clearer evidence for internal audit and applicable supervisory review.
What documents are required for KYB in Estonia?
Typically an e-Business Register extract, the eight-digit registrikood, the EE-prefixed VAT number, management board and representation details, and beneficial ownership data published through the register. Shufti verifies these in real time and screens the controllers behind them against sanctions and PEP lists.
Can Smart-ID or Mobiil-ID be used to identify a customer under Estonian AML rules?
Mobiil-ID sits inside Estonia's eIDAS-notified scheme at high assurance and meets Section 31(3). Smart-ID is a private-sector scheme assessed by RIA at high assurance, not eIDAS-notified. Where Section 31(3) cannot be used, a Smart-ID-based workflow must meet all Section 31(3¹) conditions and be documented in the firm's procedures.
How are Estonian name variants handled in screening?
Matching reconciles the diacritic-bearing name on the document with the stripped machine-readable zone form, so Õ, Ä, Ö, Ü, Š and Ž resolve correctly and variants such as Mägi and Magi do not generate false positives. Cross-script transliteration of Russian-language names is handled the same way, with the match rationale logged for review.
How long must AML records be retained in Estonia?
Section 47 of the Money Laundering and Terrorist Financing Prevention Act sets a minimum of five years. For identification and business relationship records the period runs from termination of the business relationship, and for transaction and reporting documents it runs from the transaction or the reporting duty. Records must be deleted once the period expires unless a supervisor extends it.
Is EU-region data hosting available?
Yes. Shufti offers EU-based cloud regions so Estonian customer data stays in-region in line with GDPR and the Personal Data Protection Act. No in-country public cloud region is listed for Estonia, so deployment runs in nearby EU regions or on-premise where residency requirements are stricter.
What changes for Estonia under AMLR from July 2027?
AMLR applies directly, so no Estonian transposition law is needed for the Regulation itself. It recognises eIDAS-notified eIDs, the EUDI Wallet and qualified trust services for remote verification, expressly permits document plus biometric checks, sets the beneficial ownership test at 25% or more, and introduces an EU-wide cash cap of 10,000 euros.
Can video identification still be used to onboard customers in Estonia?
From 1 July 2024 the Section 31 regime was eased. Video-based checks now run as tools meeting Section 31(3¹) conditions where a 31(3) route cannot be used, and the FIU has asked firms to update their rules of procedure.
When will the EUDI Wallet be usable for onboarding in Estonia?
Member States must provide a wallet within 24 months of the 4 December 2024 implementing acts. Under Regulation (EU) 2024/1183 Article 5f, public services accept wallets from end-2026, certain regulated private providers from end-2027. RIA opened the procurement for Estonia's wallet service provider on 18 May 2026 and no award or go-live date has been published. Shufti is built to accept wallet-based verification as the Estonian wallet goes live, so onboarding flows will not need to be rebuilt.
Let’s Build Trust Into Your Business
1B+Verifications Processed
240+Regions Actively Processed
99.7%Accuracy Rate
Samer Al Tamimi
CEO of Safwa Bank
“We take our client’s privacy very seriously and always look for new innovative solutions to ensure a safe banking experience. Working with Shufti feels like a breath of fresh air, as their 100% in-house tech keeps our customer’s data free from vulnerabilities and fully safe and protected.”
Trusted. Compliant. Certified
Explore Shufti For Your Business
Get a personalised demo from our experts.
PROVEN PLAYBOOKS
Explore Practical KYC & AML Resources
10 July, 2026
Identity Verification in Europe: eIDAS 2.0 & EUDI Wallet
A practitioner's guide to verifying identity in Europe, covering eIDAS 2.0, the EUDI Wallet, docless eIDV and how to choose an eID provider for onboarding in the EU.
Product Guide





