What the law actually requires of you.

This is an English version of our Swedish page. A plain-language walkthrough: who is covered, what the checks must include and the most common mistakes.

It covers more than banks.

Which authority supervises you depends on what you do, not on how large you are. If you are covered, customer due diligence is not optional: it must be completed before the business relationship begins and kept up to date for as long as it continues.

Accounting and bookkeeping firms, and tax advisers
County Administrative Board (Länsstyrelsen)Registered in the Swedish Companies Registration Office's (Bolagsverket) anti-money laundering register
Approved and authorised auditors, and registered audit firms
Swedish Inspectorate of Auditors (Revisorsinspektionen)Separate from accounting and bookkeeping services
Estate agents
Swedish Estate Agents Inspectorate (Fastighetsmäklarinspektionen)
Advokats (members of the Swedish Bar Association) and advokat firms
Swedish Bar Association (Advokatsamfundet)
Legal services firms that are not advokat firms
County Administrative Board (Länsstyrelsen)
Company formation agents, administrators and trust-like services
County Administrative Board (Länsstyrelsen)
Car dealers and other traders in goods accepting cash payments above the threshold
County Administrative Board (Länsstyrelsen)
Pawnbrokers
County Administrative Board (Länsstyrelsen)
Crypto firms and other financial operators
Swedish Financial Supervisory Authority (Finansinspektionen)Not the County Administrative Board
Gambling companies
Swedish Gambling Authority (Spelinspektionen)Not the County Administrative Board

Six things the law requires.

The extent is determined by the risk of the business and of the individual customer relationship.

Identify the customer.

Who are you doing business with? The customer's identity must be verified using an identity document, a register extract or other reliable means. Where contact takes place remotely, the method needs to be able to establish identity reliably. Exactly what is required depends on the sector, the situation and the risk.

Verify the beneficial owner.

You must establish who ultimately owns or controls the customer. As a general rule, a person is presumed to exercise ultimate control if they directly or indirectly control more than 25 per cent of the votes, but other forms of control may also be decisive. The Swedish Companies Registration Office's (Bolagsverket) register is a starting point. You need to make your own assessment and document it.

Assess PEP status and relevant risks.

You must assess whether the customer or the beneficial owner is a politically exposed person, a family member or a known close associate. Relevant sanctions screening needs to be handled in accordance with the sanctions rules that apply in the individual case.

Understand the purpose of the relationship.

You must obtain information on the purpose and intended nature of the business relationship. The information should help you understand which activities and transactions can be expected and form the basis of the customer's risk profile. Where the risk is higher, more information may be needed, for example about the customer's financial situation or the source of funds.

Classify the risk and adapt.

Every customer must be given a risk profile. Higher risk means enhanced measures: more questions, more documentation, more frequent follow-up. Lower risk may mean simplified measures.

Monitor on an ongoing basis.

Customer due diligence must be kept up to date. If the customer changes owners, business or behaviour, the assessment must be reviewed. Ongoing monitoring is therefore a central part of the work, not a one-off check.

Four recurring mistakes.

The check is done once and forgotten.

Ongoing business relationships must be monitored continuously and as needed. Older documentation therefore needs to be reviewable when the customer or the risk picture changes.

The beneficial owner is copied from the register.

The Swedish Companies Registration Office's (Bolagsverket) register is a starting point. The law requires your own investigation and assessment.

The documentation is scattered.

The check may have been done and still be hard to follow. Consolidated documentation makes it possible to show what information was available and what measures were taken.

The assessment lacks reasoning.

A risk classification without visible reasons is hard to review. Document which circumstances were taken into account and why the measures were proportionate to the risk.

What happens if you get it wrong?

The supervisory authorities carry out inspections and may impose administrative fines. Published decisions show amounts ranging from tens of thousands of kronor to several million. In addition, supervision may lead to orders to take corrective action.

There is also a practical business reason to get it right: businesses may need to show banks, quality reviews and supervisory authorities how customer due diligence has been carried out. A coherent, reasoned customer file makes that dialogue easier.

Part of a wider requirement.

The Swedish Act (2017:630) on Measures against Money Laundering and Terrorist Financing requires more than customer due diligence, including a risk assessment of the business as a whole, internal procedures and staff training. AKT handles the part that recurs with every new customer and every follow-up.

See how the requirements become a workflow.

We show you how documentation, checks, risk assessment and reasoning come together in a traceable customer file.

  1. 01You book a demo
  2. 02We prepare a relevant example
  3. 03We show the complete workflow

After the demo, you decide whether to continue with a pilot. Nothing is activated automatically.

Prefer email? contact@aktkyc.com

Book a demo of AKT

Make the demo more relevant (optional)
Required

When you submit the form, we use the details to respond to your request and plan the demo. Read our privacy policy.