Sectors with a higher-than-average money laundering risk level include credit institutions, payment and e-money institutions, virtual asset service providers, gambling operators, and corporate service providers. A higher risk rating means that market participants in these sectors must pay increased attention to anti-money laundering (AML) measures and apply enhanced due diligence.
The risk level has risen in connection with companies registered in Estonia but with weak ties to the country, often managed by foreign nationals. A higher threat and vulnerability level is also linked to gambling operators holding Estonian licenses, whose number has doubled over the past five years. Cash-intensive sectors such as casinos, catering, and real estate continue to pose higher money laundering risks.
According to the risk assessment, the main predicate offenses were fraud (especially business email compromise schemes, or BEC frauds), as well as tax and drug-related crimes. Companies registered in Estonia are often used to commit crimes abroad, particularly in cases of tax offenses. Most money laundering cases analyzed during the assessment period involved the layering stage, in which criminal proceeds obtained abroad were moved through the Estonian financial system.
Money laundering primarily occurs through bank transfers, fictitious invoices, and loan agreements, but the use of virtual assets is increasing. In addition, there has been growth in so-called money laundering service provision, where criminal networks use intermediaries to conceal the origin of assets.
The risk of terrorist financing remains generally low, though threats arise from foreign sources, particularly Russia, as well as cross-border transactions and the use of virtual assets.
The risk assessment was prepared by the Ministry of Finance in cooperation with the Financial Intelligence Unit, law enforcement and supervisory authorities, the Ministry of Justice and Digital Affairs, the Ministry of Foreign Affairs, and the Ministry of the Interior. At the national level, this represents the largest risk assessment project in Estonia. Over one hundred public sector experts participated, alongside representatives from the private sector.
The national risk assessment forms the foundation of Estonia’s AML/CFT system, ensuring a risk-based approach. It serves as the main tool for systematically and evidence-based identifying risks, directing resources efficiently, ensuring compliance with international standards, and supporting awareness and accountability across both the public and private sectors in combating money laundering.
Next, an action plan will be developed to ensure that the conclusions and recommendations of the risk assessment lead to concrete risk mitigation measures.
The Governmental Commission for the Prevention of Money Laundering and Terrorist Financing approved the three-part risk assessment report on 30 September, and the full report is available on the Ministry of Finance’s website.
The risk level defined in the assessment depends on the interaction between threats and vulnerabilities. A threat is an event or activity pattern indicating the possibility that financial criminals might exploit Estonia’s economic environment and financial system to launder criminal proceeds. Vulnerability refers to weaknesses in the set of AML measures that make up the anti-money laundering framework.