AML/CFT Policy

Last updated: July 24, 2026

eBusiness Solutions OÜ is a licensed Trust and Company Service Provider (TCSP) in Estonia (licence no. FIU000421). As an obliged entity under Estonian and European Anti-Money Laundering (AML) and Counter-Terrorist Financing (CFT) legislation, we strictly apply the Know Your Customer (KYC) principle prior to entering into any business relationship. We establish the identity of the client and their representatives, identify ultimate beneficial owners (UBOs), verify Politically Exposed Person (PEP) status, and screen clients against international financial sanctions lists.

We do not initiate or maintain business relationships with clients in respect of whom required customer due diligence measures cannot be conducted. All information collected is kept strictly confidential for the statutory retention period and is not disclosed to third parties, except as explicitly provided by law.

1. Legal Status

eBusiness Solutions OÜ provides registered office address, contact person, company formation, and accounting support services. These activities fall under the category of Trust and Company Services (TCSP), establishing the company as an obliged entity within the meaning of the Estonian Money Laundering and Terrorist Financing Prevention Act (RahaPTS).

The company’s operations are fully licensed and supervised by the Financial Intelligence Unit of the Republic of Estonia (Rahapesu Andmebüroo / FIU).

ParameterValue
Legal NameeBusiness Solutions OÜ
Registry Code16618432
VAT Number (KMKR)EE102672239
TCSP LicenceFIU000421
Supervisory AuthorityFinancial Intelligence Unit (FIU)
Registered AddressTornimäe tn 7-169, 10145 Tallinn, Estonia

2. What Is Anti-Money Laundering (AML)?

Money Laundering is the conversion, transfer, or disguise of property derived from criminal activity to make its origin appear legitimate. Terrorist Financing is the provision or collection of funds with the intention that they be used to commit terrorist acts or support individuals/entities involved in terrorism.

AML/CFT measures aim to prevent illicit proceeds from entering the legitimate economy and ensure corporate structures are not exploited to conceal beneficial ownership. For a corporate service provider, this carries direct operational significance: company incorporations, nominee structures, and legal addresses are frequently targeted to obscure ultimate control.

Compliance is not a mere formality. It protects legitimate clients: companies with transparent ownership structures and verifiable sources of funds undergo banking and payment institution compliance checks significantly faster.

3. Regulatory Framework

Our activities are governed by Estonian law and European Union legislation:

Estonia:

  • Money Laundering and Terrorist Financing Prevention Act (RahaPTS);

  • International Sanctions Act;

  • Guidelines and advisory notices issued by the Financial Intelligence Unit.

European Union:

  • Directive (EU) 2015/849 (AMLD IV) and Directive (EU) 2018/843 (AMLD V), as transposed into Estonian law;

  • Commission Delegated Regulation (EU) 2016/1675 regarding high-risk third countries;

  • EU Regulations on restrictive measures and international sanctions.

Readiness for the New EU AML Package:

Starting July 2027, Regulation (EU) 2024/1624 (AMLR) and Directive (EU) 2024/1640 (AMLD VI) will take full effect, with supervisory powers transitioning to the EU Anti-Money Laundering Authority (AMLA). We are proactively adjusting our internal controls to ensure full alignment ahead of time without disruption to client service.

4. Customer Due Diligence (CDD) Measures

Prior to establishing a business relationship and during its ongoing course, we apply the following due diligence measures:

  • 4.1. Identification of the Client and Representatives: Verifying identity using valid government-issued identity documents or electronic identification tools (ID-card, e-Residency, Mobile-ID, Smart-ID), as well as validating authorization representation rights.

  • 4.2. Identification of Ultimate Beneficial Owners (UBOs): Identifying natural persons who ultimately own or control the client, including the analysis of multi-layered ownership chains.

  • 4.3. Client Profile Review: Gathering information regarding current and planned business operations, corporate structures, operating jurisdictions, key counterparties, and the purpose of using our services.

  • 4.4. Verification of Source of Funds and Source of Wealth: Conducted in proportion to the assigned risk level of the specific client.

  • 4.5. PEP Status Screening: Checking the client, beneficial owners, and associated persons (family members and close associates) for Politically Exposed Person status.

  • 4.6. Sanctions Screening: Verifying records against European Union, UN, and other relevant international financial sanctions lists.

  • 4.7. Adverse Media Screening: Conducting open-source and media searches to evaluate reputational and legal risks.

5. Risk-Based Approach (RBA)

The scope of due diligence measures applied is dictated by the risk level assigned to a client based on our internal risk assessment. Factors considered include:

  • Field of Business: High-risk or regulated sectors (crypto-assets, payment services, gambling, dual-use goods trade);

  • Geographical Factors: Country of incorporation, residency of UBOs, target markets, and connections to high-risk jurisdictions under Regulation (EU) 2016/1675;

  • Complexity: Opaque or multi-tiered corporate structures;

  • PEP Status;

  • Onboarding Channel: Non-face-to-face vs. physical presence;

  • Transaction Profile: Expected nature and volume of activities.

Enhanced Due Diligence (EDD) is applied in high-risk scenarios: we request additional documentation, formal proof of source of funds, and detailed business rationale for complex ownership structures. Final approval to onboard high-risk clients rests exclusively with executive management.

6. Ongoing Monitoring of Business Relationships

Compliance checks do not end at onboarding. Throughout the business relationship, we:

  • Maintain up-to-date information on the client and UBOs through periodic reviews;

  • Monitor changes in ownership structures, management boards, and business scope;

  • Conduct re-screening against evolving international sanctions lists;

  • Assess whether ongoing corporate activities align with declared business profiles.

Review frequency depends on the assigned risk level: higher risk ratings trigger more frequent updates.

7. Reporting Suspicious Activity

Where facts indicate potential money laundering, terrorist financing, or sanctions circumvention, we are legally bound to submit a Suspicious Activity Report (SAR) to the Financial Intelligence Unit.

Notice to Clients: Applicable law strictly prohibits informing the client or third parties about the submission of an SAR, or that a regulatory inquiry is being conducted (tipping-off prohibition). This is an absolute statutory obligation that we must strictly comply with without exception.

8. Prohibited Clients and Refusal of Service

eBusiness Solutions OÜ will refuse onboarding, decline service, or terminate existing business relationships in the following cases:

  • Failure to complete mandatory Customer Due Diligence measures due to missing, incomplete, or false documentation;

  • Reasonable suspicion of client involvement in money laundering, terrorist financing, or other illegal activity;

  • Inclusion of the client, beneficial owner, or related entity in international sanctions lists;

  • Reasonable grounds to believe an applicant acts as a nominee to conceal the real UBO;

  • Deliberately complex or opaque ownership structures lacking clear economic rationale;

  • Significant share capital represented by bearer shares;

  • Substantial ties to high-risk jurisdictions listed under Regulation (EU) 2016/1675 without a legitimate, verifiable commercial purpose;

  • Business operations inconsistent with Estonian or EU legal standards.

Refusal to enter into a business relationship on these grounds does not constitute discrimination and is non-appealable through standard administrative procedures, as it is mandated by statutory obligations.

9. Internal Compliance Framework

  • 9.1. Internal Rules: In addition to this public policy, the company enforces internal Rules of Procedure and Risk Assessment policies drafted in full accordance with RahaPTS. These internal manuals are confidential to maintain control effectiveness and are disclosed solely to supervisory authorities upon request.

  • 9.2. Compliance Officer: The company has appointed a designated AML Compliance Officer registered with the FIU, responsible for CDD oversight, regulatory liaison, and SAR filings.

  • 9.3. Employee Training: All personnel involved in client management undergo routine AML/CFT training regarding red flags, regulatory changes, and sanctions enforcement.

  • 9.4. Payment Controls: Payment for services is accepted strictly via cashless bank transfers from accounts opened in the name of the client or their legal entity. Cash transactions are prohibited.

10. Data Retention and Confidentiality

Documents and data gathered during CDD procedures are retained throughout the business relationship and for 5 years following its termination. This period may be extended by order of the supervisory authority as prescribed by law.

Data is stored in compliance with GDPR rules and security standards. Information may be disclosed solely to:

  1. Contractual partners—strictly as necessary to fulfill AML/CFT legal requirements;

  2. State supervisory bodies—where mandated by law;

  3. Judicial authorities—under a binding court order.

For further details on personal data processing, please review our [Privacy Policy].

11. Client Cooperation

The speed and efficiency of KYC onboarding directly depend on client cooperation. Clear documentation, prompt responses, and transparent business disclosures minimize delays.

In practice, delays are rarely caused by regulatory strictness itself, but by incomplete file submissions or discrepancies between stated and actual activities. If you have questions regarding document requirements for your setup, you are welcome to contact us prior to application.

12. Policy Amendments

We reserve the right to periodically update this policy to reflect changes in legislation, regulatory guidance, or internal compliance protocols. The current version is published on this page with the date of the latest revision.

13. Contact Details

For inquiries regarding this Policy or AML/CFT compliance procedures:

  • Company Name: eBusiness Solutions OÜ

  • Registry Code: 16618432

  • VAT Number (KMKR): EE102672239

  • TCSP Licence: FIU000421

  • Supervisory Authority: Financial Intelligence Unit (FIU)

  • Email: info@legaladdressinestonia.com

  • Phone: +372 5691 0000

  • Address: Tornimäe tn 7-169, 10145 Tallinn, Estonia