Skip to main content

An AML officer, a contact person, and the duty that stays with your board

Most companies that ask for an outsourced AML officer are asking the wrong question first. The question that decides everything else is which class of obliged entity you are in, because Estonian law makes the appointment compulsory for some and optional for others, and it never makes the underlying duty optional for anyone.

Where it is compulsory, the Money Laundering and Terrorist Financing Prevention Act sets real conditions on who may hold the seat. Under § 17(5) the contact person must work permanently in Estonia, must have the education, professional suitability, abilities, personal qualities and experience the role requires, and must have an impeccable reputation. The appointment is coordinated with the Financial Intelligence Unit, and under § 17(6) the FIU may check the candidate against state databases and ask their employer about them.

Where it is optional, nothing is saved by leaving the seat empty. Section 17(9) is the part of the Act that gets missed: if no contact person is appointed, the contact person's tasks are performed by the management board, or by the board member designated under § 17(1), or by the branch manager, or by the sole trader. The duty does not lapse for want of an appointment. It moves onto the people who signed the register entry.

List of jurisdictions

You can view the full list of jurisdictions where this service is provided.

Who must appoint a contact person, and who only may

Money Laundering and Terrorist Financing Prevention Act, consolidated text in force from 20 July 2026, read 12 August 2026. The compulsory group in § 17(2) is credit institutions, financial institutions as defined in § 6(2), and the activity-licence categories in § 70(1).

Your businessIs a contact person compulsory?What follows
Payment institution, e-money institution, currency exchange provider, investment firm, fund manager, creditor or credit intermediary, crowdfunding service provider, life insurer or insurance broker, savings and loan association, credit institutionCompulsory. Each of these is a financial institution under § 6(2), so § 17(2) applies directlyThe contact person is subordinated directly to the management board, has the competence, the resources and the access to information in every structural unit that the tasks require, works permanently in Estonia, and the appointment is coordinated with the FIU and notified to the FIU and to the supervisory authority
Crypto-asset service provider authorised under MiCACompulsory. Since 30 December 2024 a CASP within the meaning of Article 3(1)(15) of Regulation (EU) 2023/1114 is a financial institution under § 6(2)3¹), which puts it in the § 17(2) groupThe same conditions as any other financial institution. Note that the old virtual-currency entries, § 2(1)10) and the FIU licence ground in § 70(1)4), were repealed with effect from 1 July 2026: the authorisation and the supervision now sit with Finantsinspektsioon under MiCA, but the contact person duty under this Act was untouched by that repeal
Trust and company service provider, pawnbroker, buyer or wholesaler of precious metals, precious-metal products or precious stonesCompulsory. These are the § 70(1) categories that need an FIU activity licence, and § 17(2) names themThe contact person is part of the licence file, not an afterthought to it. Section 70(3)(6) requires the application to state the contact person's name, personal identification code or date and place of birth, citizenship, address, position and contact details, alongside the § 14 procedural rules and internal control rule
Estate agent, rental intermediary where the agreed use fee is at least EUR 10,000 a month, accounting service provider, accounting or tax adviser, sworn auditor, trader paid at least EUR 10,000 in cash, art dealer at or above EUR 10,000, organiser of gambling other than commercial lotteriesOptional. Section 17(3) permits an obliged entity outside the § 17(2) group to appoint a contact person, but does not require itEvery other duty still applies in full: the § 13 risk assessment, the § 14 procedural rules and internal control rule, and the § 49 duty to report to the FIU immediately and no later than two working days. And under § 17(9), appointing nobody leaves those tasks with the management board itself
Non-profit association or foundation paid or paying more than EUR 5,000 in cash, or dealing with a jurisdiction named in § 37(4)(3)Does not apply. Section 17(10) excludes the § 2(3) and § 2(4) entities from the contact person rules entirelyThe exclusion is from § 17 only. The organisation is still an obliged entity for the due diligence, retention and reporting duties that brought it into the Act in the first place

What can sit outside your company, and what cannot

The outsourcing rules are in § 24, the contact person rules in § 17. Where a row says this is our reading, that is exactly what it is: the Act does not address an external contact person in terms, and we would rather say so than sell you a position the statute does not describe.

The workCan it sit outside your company?Basis
The § 17(2) contact person position itselfNo, in our reading. The Act describes the tasks as performed by an employee or by a structural unit, requires the person to work permanently in Estonia, lets the FIU approach the candidate's employer, and lets the obliged entity terminate the employment contract for loss of trust. An external contractor is nowhere in that picture§ 17(4), § 17(5), § 17(6). Our reading, not a quotation
Responsibility for complying with the ActNever. It stays with you even where the activity is lawfully outsourced, and no contract moves it§ 24(7)
Applying the customer due diligence measuresYes, by written contract, to another obliged entity, to an association whose members are obliged entities, or to another person who applies equivalent due diligence and retention requirements and is contractually bound to make the data available to the supervisor§ 24(2) and § 24(3)
Drafting the risk assessment, the procedural rules and the internal control ruleDrafted outside, adopted inside. They must be proportionate to the nature, scale and complexity of your business and they must be established by your own senior management, which is a decision nobody can take for you§ 13, § 14(1), § 14(3)
Ongoing monitoring, customer file work, staff training and preparing reportsYes, on the same written contract, and the supervisory authority has to be told in advance of the scope of the outsourced activity and of the conclusion and the termination of the contract§ 24(3), § 24(4)
Anything routed to a person established in a high-risk third countryProhibited outright, whether as outsourcing or as reliance on data that person collected§ 24(6)

How the engagement runs:

01

Settle the scope question in writing

Which paragraph of § 2 catches you, whether you are a financial institution under § 6(2), and whether that puts you in the compulsory § 17(2) group or the optional § 17(3) one. It takes a conversation and a look at what you actually sell, and it is the answer that decides the size of everything after it. We put it in writing, so it can be shown to a bank, an investor or a supervisor.

02

Build the framework, not a template

A § 13 risk assessment across the four statutory categories: customers, jurisdictions, products and services, and the channels through which you reach customers. Then § 14 procedural rules covering all six minimum contents, from the due diligence procedure and the customer risk model to the instruction for identifying politically exposed and sanctioned persons and the procedure for new technologies and sales channels. Then the internal control rule that says how compliance with all of it is checked.

03

Put a person in the seat who will survive the check

For a § 17(2) entity that means a candidate who works permanently in Estonia and can evidence education, professional suitability and an impeccable reputation, because the FIU coordinates the appointment and may check the person against state databases and ask their employer. We recruit and prepare the candidate, assemble the file, and take the appointment through coordination and the notifications to the FIU and the supervisory authority.

04

Run it, on the statutory clock

Reporting to the FIU immediately and no later than two working days from the suspicion. Reporting every transaction where a monetary obligation above EUR 32,000 is settled in cash, again within two working days, whether it is one payment or linked payments across a year. Periodic written overviews to the board, because § 17(7) requires them and their absence is the first thing an inspection notices. Staff training, and the review of whether the rules still match the business.

05

Stand behind it when someone looks

The framework goes into the licence application where one is running, and it is what an inspection reads first. Where a supervisor has already made a finding, we run the remediation against the finding rather than rewriting the manual and hoping. Breach of the § 13 and § 14 requirements, or simply failing to implement rules you have adopted, carries a fine of up to EUR 1,000,000, and up to EUR 5,000,000 or 10 per cent of consolidated turnover where the entity is a subject of financial supervision.

On price, we will give you a straight answer about why there is no straight answer. What this work costs is driven by which class you are in, whether an appointment has to be coordinated with the FIU, how many customers and transactions the monitoring actually covers, whether a licence application is running alongside, and whether we are building a framework from nothing or repairing one after a supervisory finding. A published monthly figure that ignored all five would be a number chosen for the search result rather than for you. We scope first and quote in writing, and the quote holds.

The question we are asked most often is whether one person can serve several companies. Nothing in § 17 caps the number of entities a person may serve, but every appointment has to satisfy § 17(2) and § 17(5) on its own terms, and an entity whose contact person has no realistic capacity to organise the collection and analysis of information across the whole of its business has not met the requirement, whatever the appointment letter says. The EU AML Regulation is more explicit about the boundary: from 10 July 2027 an obliged entity may appoint as compliance officer someone who performs that function in another entity only where the two are inside the same group and where the entity's size and low risk justify it.

That Regulation is worth planning for now rather than in 2027. It splits the role in two: a compliance manager, who is one member of the management body in its management function, and a compliance officer, appointed by that body, of sufficiently high hierarchical standing, running the day-to-day AML and sanctions work, acting as the contact point for competent authorities and reporting suspicious transactions to the FIU. Where the nature, risk and size of the business justify it the same natural person may hold both, and where the obliged entity is one individual, that individual holds them. Firms that build the Estonian framework properly now will be adjusting titles and reporting lines in 2027. Firms that bought a template will be starting over.

What we provide:

  • A written scope opinion: which paragraph of § 2 catches you, and whether § 17(2) or § 17(3) applies
  • The § 13 risk assessment across all four statutory risk categories, documented and kept current
  • The § 14 procedural rules covering all six minimum contents, and the internal control rule
  • Sanctions screening procedures, and the responsible person required by the International Sanctions Act
  • Recruitment and preparation of a contact person who meets the § 17(5) conditions
  • Coordination of the appointment with the Financial Intelligence Unit, and the notifications that follow
  • The contact person and compliance sections of an FIU activity-licence application under § 70(3)
  • Ongoing monitoring, customer file work, and the periodic written overviews the board is owed
  • Reporting support against the two-working-day deadline and the EUR 32,000 cash reporting duty
  • Staff training, and the review of the rules whenever the business changes
  • Remediation after a supervisory finding, run against the finding itself
  • Readiness work for the EU AML Regulation as it applies from 10 July 2027

Frequently asked questions

We are ready to take on non-standard projects

Averium builds AML frameworks that hold up under inspection, and will tell you in the first conversation whether the law requires you to appoint anyone at all.

NN

Nadezhda Nikitina

DG

Dmitry Grigorjev

AK

Artemii Kupriianov

JB

Julia Bezgodko

AM

Alina Malitskaya

AP

Aleksey Pravotorov

EP

Egor Pekarsky

Get in touch
with us

Tell us about your problem and our team will reply within one business day.

By clicking the "send" button, you agree to the privacy policy and the processing of personal data by Averium, within the framework of the GDPR rules.