WebinarShufti x AML IntelligenceHow AMLR Extends KYC Across the Customer Lifecycle25th Sep | 02:00 PM UTCREGISTER NOW Shufti x AML IntelligenceHow AMLR Extends KYC Across the Customer Lifecycle25th Sep | 02:00 PM UTCREGISTER NOW How AMLR Extends KYC Across the LifecycleRegister Gavel on AMLR rule bookAMLR applies 10 July 2027. See your stack against every obligationBook a Demo AMLR applies 10 July 2027. See your stack against every obligationBook A Demo AMLR applies 10 July 2027 — see your stackBook Demo Globe with pKYC, Onboarding, Screening and Transactions labelsShufti’s Glocal PlatformGlobal Coverage. Local Depth. Full Compliance Lifecycle.Explore More Global Coverage. Local Depth. Full Compliance Lifecycle.Explore More Glocal Platform — Global Coverage. Local Depth.Explore Shufti x ACFEWebinarAI has changed fraud. Now we need to change how we fight it.Microphone icon for Shufti and ACFE fraud webinar5th October, 2026Register Now Shufti x ACFEAI has changed fraud. Now we need to change how we fight it.5th October, 2026Register Now AI has changed fraud — change how we fight itRegister INNOVATION DROPSUMMER
EDITION
20
26
Qualified Electronic Signature
WATCH NOW
INNOVATION DROP - Qualified Electronic SignatureWatch Now Innovation Drop — Qualified Electronic SignatureWatch
INNOVATION DROPSUMMER
EDITION
20
26
Transaction Trust Monitoring
WATCH NOW
INNOVATION DROP - Transaction Trust MonitoringWatch Now Innovation Drop — Transaction Trust MonitoringWatch
INNOVATION DROPSUMMER
EDITION
20
26
Travel Rule Compliance
WATCH NOW
INNOVATION DROP - Travel Rule ComplianceWatch Now Innovation Drop — Travel Rule ComplianceWatch
Gavel on AMLR rule bookAMLR Applies 10 July 2027. Don't Wait for the Deadline to Find the GapsBook Consultation AMLR Applies 10 July 2027. Don't Wait for the Deadline to Find the GapsBook Consultation AMLR Applies 10 July 2027 — Find the GapsConsult Bank card and cashBank Account Verification: Get Secure Payouts with Confirmed OwnershipSee How It Works Bank Account Verification: Get Secure Payouts with Confirmed OwnershipSee How It Works Bank Account Verification — Secure PayoutsSee How Geo Compliance Ties Verified Location to a Verified IdentityBook A Demo Geo Compliance Ties Verified Location to a Verified IdentityBook A Demo Geo Compliance — Verified Location, Verified IdentityBook Demo Journey Builder dot gridConfigure Verification Flows as Per Your Needs with Journey BuilderSee How It Works Configure Verification Flows as Per Your Needs with Journey BuilderSee How It Works Journey Builder — Configure Verification FlowsSee How Shufti MCP toggle with ChatGPT and ClaudeShufti MCP: Verification Tools, Ready to Use Inside Claude or ChatGPTExplore Agent Shufti MCP: Verification Tools, Ready to Use Inside Claude or ChatGPTExplore Agent Shufti MCP — Verification Tools Inside Claude or ChatGPTExplore

us

216.73.216.133

Get AMLR-ready in Estonia without rebuilding your compliance stack

Onboard customers and businesses, support trusted digital identities and QES, and manage ongoing compliance through one integrated platform.

ESTONIA KYC, KYB AND AML

Scale Identity Verification and KYC Operations in Estonia

Verify Estonian customers and businesses through Estonia's notified eID scheme, Smart-ID, NFC, QES, identity documents, biometrics and KYB. Reduce manual review, maintain consistent audit evidence and run one connected workflow designed to support the Money Laundering and Terrorist Financing Prevention Act, known in Estonia as RahaPTS, today and AMLR from 10 July 2027.

Banner Image for Estonia
Trusted by 2000+ businesses that make identity decisions at scale
cashew gemone HERO Gaming Bitget IronFX PENN National Rakuten Witzeal Noteris banxy

Operational Performance for Estonia KYC

Our Numbers Speak Volumes

98.94%

First-pass
verification rate

< 10 sec

Median
verification time

6

Estonian ID methods
supported

THE ESTONIA VERIFICATION GAP

Estonia IDV/KYC Challenges

The Everyday eID and the Notified eID Are Not the Same Thing

The Everyday eID and the Notified eID Are Not the Same Thing

Smart-ID is the credential many Estonian customers reach for first. It is a private-sector scheme, not an eIDAS-notified scheme under Section 31(3), so using it for remote identification depends on meeting Section 31(3¹)'s conditions where a Section 31(3) route cannot be used.

E-Residency Onboarding Needs a Second Document

E-Residency Onboarding Needs a Second Document

The e-Resident's digital ID is not a photo document and cannot be used to travel. Section 31(4) requires a second accepted document alongside it, so e-resident files carry an extra step and far more passport fallback.

Ownership Data Is Open but Not Always Current

Ownership Data Is Open but Not Always Current

Beneficial ownership is published through the e-Business Register and still openly viewable, but Estonia's national risk assessment and the MONEYVAL evaluation both record gaps in currency and accuracy. Registry facts confirm a company exists, not who controls it.

Estonian Name Forms Break Global Matching

Estonian Name Forms Break Global Matching

Õ, Ä, Ö, Ü, Š and Ž are stripped from the machine-readable zone and from many international databases, and Russian-language records arrive with different transliterations. Both push clean customers into manual review and false positives.

Regulatory Update

What AMLR Changes for Identity Verification in Estonia

The EU Anti-Money Laundering Regulation (EU) 2024/1624 applies directly in Estonia from 10 July 2027, with no transposition period. It sets the due diligence rules the Money Laundering and Terrorist Financing Prevention Act framework will operate under, with AMLA, the new EU-level supervisor, established in Frankfurt.

Timeline

  • End of 2026 EU-level Member State wallet issuance target
  • 10 July 2027 AMLR applies, no transposition
  • Late 2027 Wallet acceptance duty for certain regulated private providers, eIDAS 2.0 Article 5f
  • 2028 AMLA direct supervision begins

eIDAS Routes Expressly Recognised

Article 22(6)(b) recognises eIDAS eIDs and qualified trust services. Article 22(6)(a) equally permits document-based verification.

The Ownership Test Tightens

AMLR sets the beneficial-ownership test at 25% or more, or through control, Articles 51 to 54. Estonian law reads exceeds 25 per cent, so KYB checks should confirm holdings at the 25% line before July 2027. A lower threshold, floored at 15%, may follow for designated higher-risk categories.

Existing Customers Get Re-Checked

AMLR expects existing customer records to be brought up to standard on a risk basis, not just new onboarding. Continuous monitoring keeps back-book files current between reviews.

Accountability Stays With You

Article 18 lets you outsource due diligence tasks but keeps you fully liable for what those tasks produce, so vendor evidence and clean audit trails matter more under AMLR.

FOR FINANTSINSPEKTSIOON AND FIU-SUPERVISED BUSINESSES

Streamline Finantsinspektsioon and FIU-Supervised Onboarding in Estonia

Connect identity verification, QES, optional Penny Drop and compliance evidence in one configurable workflow for businesses in the Finantsinspektsioon and Financial Intelligence Unit remit. Reduce drop-off and manual handovers while giving compliance teams a review-ready record of every decision.

1. Verify the Customer

Verify identity using the configured route, such as Estonia's notified eID scheme, a qualified trust service, NFC reading of the ID-kaart, or document and biometric checks.

2. Complete Qualified Signing

Apply and validate the QES in the same journey, keeping the signed document, verification result and evidence together. Under Section 31(3) qualified signing also carries a lawful identification basis.

3. Confirm the Payment Account

Where your risk policy or a counterparty calls for it, Penny Drop Verification confirms the customer holds the account and records the evidence of that check.

Section 31 applies to credit and financial institutions and virtual currency service providers, Section 2(5).

Section 14(1¹) requires rules of procedure before the Section 31 route is used. A notified scheme or qualified trust service is mandatory outside the EEA, above the Section 31(1) thresholds and in Section 31(1¹) cases. Estonian law provides no combined signature and account route, so step 3 is a control choice.

Shufti's IDV/KYC Solutions for Estonia

KYC Solutions

Clear onboarding for Estonian customers under the Money Laundering and Terrorist Financing Prevention Act, with age and address checked in the same flow as identity, each check completing in seconds.

Explore More
Face Verification

Face Verification

Face verification binds the live person to the document with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness, stopping spoofs, masks and deepfakes.

.
Age Verification

Age Verification

Selfie-based age estimation combined with document verification fallback where age-gated access or higher-control onboarding requires it.

.
Bank Account Verification

Bank Account Verification

Confirms an Estonian bank account (EE IBAN) belongs to the customer, returning the registered account holder name for matching against the verified identity.

.
Address Verification

Address Verification

Shufti verifies Estonian address-bearing documents, including utility invoices, telecom bills and bank statements from major Estonian issuers. Proof-of-address checks remain common in regulated onboarding.

.
Document Verification

Document Verification

Verification of the ID-kaart, the elamisloakaart residence permit card and the Estonian passport, including NFC chip reading and Estonian-language extraction. Remains a permitted route for remote verification under AMLR.

.
Identity Verification

Identity Verification

Shufti confirms every customer is real and present, not a spoofed or synthetic identity. Biometric face matching and liveness detection run against 10,000+ actively processed document types.

.

KYB Solutions

Shufti checks businesses as deeply as the people behind them, supporting your risk-based approach under the Act on both sides of the file. Shufti checks registry records, beneficial ownership and VAT details in real time, then screens the controllers against 4,000+ global watchlists for sanctions and adverse media exposure.

Explore More
Business Verification

Business Verification

Automated validation of e-Business Register data, the eight-digit registrikood, the EE-prefixed VAT number and management board members. Estonia issues no separate company tax number, so the registry code carries the identifier through the whole file.

.
Enhanced Due Diligence (EDD)

Enhanced Due Diligence (EDD)

Structured risk profiling for non-resident ownership chains, company service provider structures and higher-risk sectors, supporting Estonia's risk-based obligations under the Act.

.

AML Screening

Shufti screens customers and transactions in 240+ countries and territories, flagging sanctions, PEP and adverse media matches as they happen. Ongoing monitoring surfaces suspicious activity in time to meet Estonian reporting obligations.

Explore More
AI Compliance Copilot

AI Compliance Copilot

Helps compliance teams review verification and AML data, investigate alerts, and understand the reasoning behind risk signals. It brings relevant case information together to support faster, more consistent compliance decisions.

.
Transaction Monitoring

Transaction Monitoring

Ongoing transaction monitoring calibrated to Estonian and cross-border flows flags anomalies against AML rules, supporting the risk-based controls expected by Finantsinspektsioon and the Financial Intelligence Unit.

.

Supported Verification Methods for Estonia

Every Verification Route Estonia Uses, in One Platform

Shufti supports the full range of remote verification routes used in Estonia, from the EUDI Wallet and the notified eID scheme to document and biometric checks. Each method below shows what is live today and what is ready for the 2027 rollout.

EUDI Wallet

Wallet-ready · from 2027

AMLR Article 22(6)(b) recognises eIDAS eID means, including the EUDI Wallet.

Notified eID

LiveeIDAS High

Estonia's notified eID scheme covers the ID-kaart, the residence permit card, Digi-ID, the e-Resident Digi-ID, Mobiil-ID and the diplomatic identity card, all at eIDAS assurance level high, and Shufti verifies these today.

Independent Validation

Shufti's Recognition Across Independent Evaluations

Liminal

Ranked Exceptional in the Liminal Index 2026 for age estimation

View Reportarrow-icon
Gartner

Differentiated by Gartner on document diversity and country coverage

Read morearrow-icon
iBeta

Certified at iBeta Level 3 PAD with 0% APCER

Read Blogarrow-icon
KuppingerCole

Broadest global reach in the 2025 KuppingerCole Extended IDV report

Download Reportarrow-icon
Homeland Security

Ranked Top 5 in the DHS RIVR 2025 for identity validation

Read Blogarrow-icon
Liminal

Ranked Exceptional for age verification by Liminal Index 2026

View Reportarrow-icon
Liminal

Recognised as a Leader across four G2 Summer 2026 reports

View Reportarrow-icon

Evidence-Ready Checks Across People & Businesses

Verifications with robust evidentiary support

Individual Documents We Verify

Shufti verifies six primary individual Estonian documents.

View All Supported Documents

Estonian ID Card (ID-kaart)

The primary photo document for Estonian citizens and for EU citizens permanently resident in Estonia, issued by the Police and Border Guard Board under the Identity Documents Act. It carries digital identification and digital signing certificates, and cards issued from 2018 read contactlessly over the PACE-protected channel.

zaigzagaimagesnew-img

Digital ID (Digi-ID)

An electronic-only credential with no photograph, used for e-services and signing. Issuance to Estonian residents ended on 1 May 2025 and cards issued before that date stay valid until they expire, so it appears in onboarding as a signing and authentication means rather than a photo identity document.

zaigzagaimagesnew-img

Residence Permit Card (Elamisloakaart)

The primary photo document for third-country nationals with an Estonian residence permit or right of residence. It is an EU uniform residence permit in ID-1 format with an ICAO-compliant contactless chip holding the facial image and fingerprints, and it carries the eID function.

zaigzagaimagesnew-img

E-Resident Digital ID (e-Residendi digi-ID)

A digital credential for foreign nationals using Estonian e-services and company tools from outside Estonia. It is not a travel document and not a photo identity document, and Section 31(4) of the Act requires a second accepted document alongside it for remote identification, so KYC usually needs a passport as well.

zaigzagaimagesnew-img

Estonian Passport (Eesti kodaniku pass)

The biometric, ICAO-compliant travel document issued by the Police and Border Guard Board. It carries a contactless chip with the facial image and two fingerprints, which makes it the practical fallback in remote and non-resident onboarding.

zaigzagaimagesnew-img

Estonian Driving Licence (Juhiluba)

An EU-model licence issued by the Estonian Transport Administration. It is accepted as an identification basis under Section 21(3) of the Act. The governing regulation provides for no chip, so it is verified through document checks.

zaigzagaimagesnew-img
zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img
zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img

Entity Identity

E-Business Register Extract

Proves legal existence, legal form, status, registry code and registered details. The register is maintained by the registration department of Tartu County Court and the portal is run by the Centre of Registers and Information Systems, which makes it the usual starting point for KYB baselining.

zaigzagaimagesnew-img

Registration Certificate

Certificate-style registry output confirming the entity is entered in the Estonian register. Used where a counterparty wants formal registration evidence sitting in the KYB file rather than a screenshot of a lookup.

zaigzagaimagesnew-img

Management Board and Representation Details

Shows who can bind the company in practice. Shufti uses it to validate signatory authority, which cuts the KYB exceptions caused by the wrong representative applying.

zaigzagaimagesnew-img

Annual Report Filing Status

A transparency and operational health signal during KYB, and a useful one for higher-risk sectors, dormant entities and structures with non-resident control.

zaigzagaimagesnew-img

Tax Identity

Company Registration Code (Registrikood)

The non-recurrent eight-digit identifier assigned on entry in the commercial register. Estonia issues no separate company tax number for registered legal persons, so the registrikood carries the identity across the register, the Tax and Customs Board and the KYB file.

zaigzagaimagesnew-img

VAT Number (KMKR number)

The VAT identification number is EE followed by nine digits. Once granted it is published and checkable through the Tax and Customs Board and VIES, and it is used in invoicing, tax checks and onboarding review.

zaigzagaimagesnew-img

Tax Standing or Tax Debt Certificate

Useful in supplier due diligence, lending and enhanced review where teams need evidence of tax standing or arrears beyond basic VAT registration.

zaigzagaimagesnew-img
zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img
zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img

Ownership & Control (UBO)

Beneficial Owner Data (UBO) in the Business Register

Beneficial ownership is filed and published through the e-Business Register under Sections 76 to 78 of the Act. Shufti checks control data against it, applying the AMLR test at 25% or more, or via control.

zaigzagaimagesnew-img

UBO Verification Approach (Register Metadata)

The published dataset records how the beneficial owner's identity was established, which helps teams evidence the control check rather than simply restating a name from the register.

zaigzagaimagesnew-img

Shareholder Data or Share Register Evidence

Used to test ownership layers, reconcile control and support escalation where shareholder, board and beneficial owner evidence does not line up. Section 20(2⁴) of the Act requires the registrar to be notified where what you find differs from what is published.

zaigzagaimagesnew-img

Non-Resident and Branch Registration Evidence

For branches and permanent establishments, tax registration can require documented authorisation and supporting filings with the Estonian Tax and Customs Board.

zaigzagaimagesnew-img

Sector Licence or Activity Licence

For regulated sectors, licence evidence shows the business is permitted to operate. Crypto-asset service providers now hold a Finantsinspektsioon authorisation under MiCA rather than a Financial Intelligence Unit authorisation.

zaigzagaimagesnew-img

Languages We Cover

Document Text Handling

Estonian is the official language and Estonian documents use Latin script. Shufti parses Estonian natively and supports mixed intake where customers present foreign passports and records alongside Estonian documents.

zaigzagaimagesnew-img

Name Matching Controls

Estonian uses Õ, Ä, Ö, Ü, Š and Ž. Matching reconciles the diacritic-bearing visual inspection zone name with the stripped machine-readable zone form, so variants such as Mägi and Magi are reviewed, logged and resolved consistently.

zaigzagaimagesnew-img

Evidence Consistency Across Steps

Document, selfie and screening evidence stay aligned by anchoring to stable identifiers such as the eleven-digit isikukood, even where foreign records add transliteration variance.

zaigzagaimagesnew-img
zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img zaigzagaimagesnew-img

Governance & Controls

Audit-Ready Decisions, Lower Operational Drag

Fewer Avoidable Re-submissions

Capture tuned to Estonian ID formats, plus chip extraction from the ID-kaart and the residence permit card, cuts avoidable re-submissions and the retry loops that lose applicants.

5-box-image-1

Cleaner Audit Trails

Structured logs aligned to the five-year retention rule in Section 47 of the Money Laundering and Terrorist Financing Prevention Act and to Financial Intelligence Unit reporting duties keep every onboarding decision audit-ready.

5-box-image-2

Better Name Matching Outcomes

Matching handles Estonian diacritics, machine-readable zone stripping and cross-script transliteration, which lowers false positives and the analyst review they generate.

5-box-image-3

One Workflow, One Back Office

KYC, KYB and AML screening are consolidated in one operational case view, so one back office team works on every customer file.

5-box-image-4

National ID-First Flow Design

ID-kaart-first onboarding reflects Estonia's national identity ecosystem, captures the isikukood consistently, and switches cleanly to passport fallback for non-resident and e-resident cases.

5-box-image-5

Continuous Compliance

Compliance that does not stop at onboarding

AMLR treats customer due diligence as a continuing obligation. Perpetual monitoring keeps the customer picture current between reviews, so risk is caught when it appears, not at the next annual check.

Surface Changes as it happens

Detect

Perpetual monitoring flags risk when it appears, not at the next annual review. Behavioural biometrics, background fraud signals, and ongoing sanctions and PEP screening watch every active relationship.

Step up when the signal fires

Verify

When a signal fires, re-verification confirms the person or the ownership change using the same live methods above, so a flag turns into a resolved decision.

Keep the file audit-ready

Comply

Every check and decision is logged to the record-keeping standard in Section 47 of the Act, so the file is organised and retrievable for internal audit and supervisory review.

Perpetual KYC

pKYC

Keeps individual customer risk current with behavioural biometrics, background fraud signals and ongoing AML screening, so back-book records stay standard-ready for the AMLR remediation.

Perpetual KYB

pKYB

Monitors beneficial ownership data and the e-Business Register, so a shift past the 25% or more UBO threshold or a change of control is caught between reviews.

REGULATORY ALIGNMENT

Built To Fit Estonia's Compliance Landscape

Global-Coverage_Dark-Theme

Financial Intelligence Unit (Rahapesu Andmebüroo)

An independent government authority under the Ministry of Finance since 1 January 2021. It receives suspicious and unusual transaction reports, and under Section 64(1) of the Act it is the default AML supervisor for obliged entities that Finantsinspektsioon does not supervise, other than advocates and notaries, who answer to the Bar Association board and the Ministry of Justice and Digital Affairs. Shufti helps teams keep the records, rationale and escalation trail that reporting and audit need.

Global-Coverage_Dark-Theme-1

Finantsinspektsioon

Supervises banks, insurers, investment firms, payment and e-money institutions, fund managers and crowdfunding providers, and since 1 July 2026 crypto-asset service providers authorised under MiCA. Shufti supports risk-based due diligence, consistent screening records and decisions that are ready for supervisory review.

Global-Coverage_Dark-Theme-2

Ministry of Finance (Rahandusministeerium)

Owns Estonia's AML policy framework, controls the beneficial ownership database and publishes the national money laundering and terrorist financing risk assessment. Shufti helps firms turn that risk-based model into structured KYB, UBO and evidence-led onboarding controls.

Global-Coverage_Dark-Theme

Ministry of Foreign Affairs (Välisministeerium)

Coordinates national implementation of international sanctions under Section 10 of the International Sanctions Act and publishes designations under the Government of the Republic sanctions. Shufti helps firms show how sanctions checks, controller screening and escalation were carried out in practice.

Global-Coverage_Dark-Theme-1

Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)

Supervises personal data processing under GDPR and Estonia's Personal Data Protection Act. Shufti supports tighter retention control, data minimisation and safer handling of onboarding evidence.

Global-Coverage_Dark-Theme-2

Police and Border Guard Board (Politsei- ja Piirivalveamet)

Issues Estonia's core identity documents, including the ID-kaart, the residence permit card and the e-Resident digital ID, and is the authority named for the notified Estonian eID scheme. Shufti supports document checks built around local fields, formats and document change cycles, including the card generation issued from 17 November 2025.

Global-Coverage_Dark-Theme-2

Centre of Registers and Information Systems (Registrite ja Infosüsteemide Keskus, RIK)

Develops and runs the e-Business Register portal, while register force sits with the registration department of Tartu County Court. Shufti helps bring registry facts, ownership data and representation details into one KYB workflow.

Global-Coverage_Dark-Theme

Estonian Tax and Customs Board (Maksu- ja Tolliamet)

Manages tax registration, VAT status and non-resident registration relevant to company onboarding, and administers the cash declaration duty at the EU border. Shufti helps teams capture and retain the tax-linked evidence used in higher-confidence KYB reviews.

Global-Coverage_Dark-Theme

AMLA (EU Anti-Money Laundering Authority)

The new EU-level supervisor has been established in Frankfurt since July 2025. It begins direct supervision of selected high-risk cross-border entities from 2028 and shapes the technical standards under AMLR.

Deployment Option

No in-country public cloud region is listed for Estonia, so deployment runs in nearby EU regions or on-premise. Either option keeps Estonian customer data in-region and supports GDPR accountability.

Regulatory Alignment

Aligned with the due diligence, beneficial ownership and record-keeping duties in the Money Laundering and Terrorist Financing Prevention Act, with GDPR and the Personal Data Protection Act principles applied throughout, and AMLR applying from 10 July 2027.

Retention Controls

Section 47(1) of the Act sets a five-year minimum retention period running from termination of the business relationship. Section 47(3) runs the same period from the transaction or the reporting duty, and Section 47(6) applies it to the remote identification record captured under Section 31. Section 47(7) requires deletion once the period expires unless a supervisor extends it. From 10 July 2027 AMLR Article 77 keeps a five-year baseline with case-by-case extensions, so the Estonian position may be largely unchanged.

Encryption & Security

Encryption in transit and at rest, access controls and audit logging support Article 32 GDPR and the Personal Data Protection Act under our ISO 27001 certification.

Scope of Our Role

Shufti acts as a data processor providing verification technology, not legal or regulatory advice. Customer due diligence and the choice of verification method remain with the obliged entity, documented in its own risk assessment.

Automated Decisions and Biometric Data

The controller sets the lawful basis for processing. Biometric data used for unique identification engages Article 9 GDPR, and human review is available in the workflow.

Data and Privacy Controls in Estonia

BUILT FOR COMPLIANCE TEAMS

Estonia AML Sources That Strengthen Decisions

We screen against 215+ sanction regimes, 4,000+ watchlists, 100,000+ adverse-media sources, and 6M+ PEPs across Estonia and globally. A few of them are:

SEE SHUFTI IN YOUR ESTONIA WORKFLOW

Turn Estonian Verification Requirements into a Smoother Customer Journey

Share your customer types, risk rules and current onboarding process. A Shufti specialist will show you how to connect identity verification, KYB, QES, optional Penny Drop and ongoing monitoring, reducing operational hand-offs while keeping decision evidence organised for review.

INDEPENDENTLY AUDITED. GLOBALLY CERTIFIED.

Certified to Global Standards

Frequently Asked Questions

Which identity documents can be used for Estonian onboarding?

Customers can use the ID-kaart, including its chip and notified eID function, the elamisloakaart residence permit card and the Estonian passport, and the driving licence is accepted as an identification basis under Section 21(3) of the Money Laundering and Terrorist Financing Prevention Act. Shufti supports document, eID, NFC and biometric verification within one configurable workflow.

How does Shufti support Finantsinspektsioon and FIU-supervised businesses in Estonia?

Shufti connects identity verification, KYB, AML screening, QES, account verification and decision evidence in one configurable workflow. This helps businesses in either supervisory remit reduce manual hand-offs, standardise compliance records and prepare clearer evidence for internal audit and applicable supervisory review.

What documents are required for KYB in Estonia?

Typically an e-Business Register extract, the eight-digit registrikood, the EE-prefixed VAT number, management board and representation details, and beneficial ownership data published through the register. Shufti verifies these in real time and screens the controllers behind them against sanctions and PEP lists.

Can Smart-ID or Mobiil-ID be used to identify a customer under Estonian AML rules?

Mobiil-ID sits inside Estonia's eIDAS-notified scheme at high assurance and meets Section 31(3). Smart-ID is a private-sector scheme assessed by RIA at high assurance, not eIDAS-notified. Where Section 31(3) cannot be used, a Smart-ID-based workflow must meet all Section 31(3¹) conditions and be documented in the firm's procedures.

How are Estonian name variants handled in screening?

Matching reconciles the diacritic-bearing name on the document with the stripped machine-readable zone form, so Õ, Ä, Ö, Ü, Š and Ž resolve correctly and variants such as Mägi and Magi do not generate false positives. Cross-script transliteration of Russian-language names is handled the same way, with the match rationale logged for review.

How long must AML records be retained in Estonia?

Section 47 of the Money Laundering and Terrorist Financing Prevention Act sets a minimum of five years. For identification and business relationship records the period runs from termination of the business relationship, and for transaction and reporting documents it runs from the transaction or the reporting duty. Records must be deleted once the period expires unless a supervisor extends it.

Is EU-region data hosting available?

Yes. Shufti offers EU-based cloud regions so Estonian customer data stays in-region in line with GDPR and the Personal Data Protection Act. No in-country public cloud region is listed for Estonia, so deployment runs in nearby EU regions or on-premise where residency requirements are stricter.

What changes for Estonia under AMLR from July 2027?

AMLR applies directly, so no Estonian transposition law is needed for the Regulation itself. It recognises eIDAS-notified eIDs, the EUDI Wallet and qualified trust services for remote verification, expressly permits document plus biometric checks, sets the beneficial ownership test at 25% or more, and introduces an EU-wide cash cap of 10,000 euros.

Can video identification still be used to onboard customers in Estonia?

From 1 July 2024 the Section 31 regime was eased. Video-based checks now run as tools meeting Section 31(3¹) conditions where a 31(3) route cannot be used, and the FIU has asked firms to update their rules of procedure.

When will the EUDI Wallet be usable for onboarding in Estonia?

Member States must provide a wallet within 24 months of the 4 December 2024 implementing acts. Under Regulation (EU) 2024/1183 Article 5f, public services accept wallets from end-2026, certain regulated private providers from end-2027. RIA opened the procurement for Estonia's wallet service provider on 18 May 2026 and no award or go-live date has been published. Shufti is built to accept wallet-based verification as the Estonian wallet goes live, so onboarding flows will not need to be rebuilt.

Let’s Build Trust Into Your Business

1B+Verifications Processed

240+Regions Actively Processed

99.7%Accuracy Rate

Samer Al Tamimi

CEO of Safwa Bank

Samer Al Tamimi

“We take our client’s privacy very seriously and always look for new innovative solutions to ensure a safe banking experience. Working with Shufti feels like a breath of fresh air, as their 100% in-house tech keeps our customer’s data free from vulnerabilities and fully safe and protected.”

Trusted. Compliant. Certified

cetificate-logos cetificate-logos cetificate-logos cetificate-logos

Explore Shufti For Your Business

Get a personalised demo from our experts.

    Which products would you like to check out?

    VideoIdent

    Address Verification

    eIDV (Docless)

    KYB

    AML Screening

    Deepfake Detection

    Face and ID Verification

    Age Verification

    Others

    What is your expected yearly verification volume?

    1 to 1,000

    1,001 to 5,000

    5,001 to 20,000

    20,001 to 50,000

    50,001 to 100,000

    100,001 to 1,000,000

    1,000,000+

    Valid Invalid number

    By clicking Submit, you accept our Privacy Policy and consent to marketing communications.

    PROVEN PLAYBOOKS

    Explore Practical KYC & AML Resources

    Read More
    Cover of Identity Verification in Europe: eIDAS 2.0 & EUDI Wallet

    10 July, 2026

    Identity Verification in Europe: eIDAS 2.0 & EUDI Wallet

    A practitioner's guide to verifying identity in Europe, covering eIDAS 2.0, the EUDI Wallet, docless eIDV and how to choose an eID provider for onboarding in the EU.

    Product Guide

    Read More
    Read More
    Cover of EU AMLR Guide 2027: Requirements, Scope, Deadlines

    4 August, 2026

    EU AMLR Guide 2027: Requirements, Scope, Deadlines

    Regulation (EU) 2024/1624 applies from 10 July 2027. Covers which firms fall in scope, what CDD and ownership checks demand, and how AMLR differs from AMLD6 today.

    Product Guide

    Read More
    Read More
    Cover of How to Remediate Existing Clients' Files Under EU AMLR

    9 September, 2026

    How to Remediate Existing Clients' Files Under EU AMLR

    AMLR applies from 10 July 2027 to the files you already hold. Find CDD gaps in existing customers, rank them by risk, and record decisions auditors can follow later.

    Product Guide

    Read More