Resources · Reviewed 28 September 2026

AMLR 2027: what changes in customer due diligence?

From 10 July 2027, the EU Anti-Money Laundering Regulation applies directly in every Member State. The core of customer due diligence stays the same, but several requirements become more detailed and some thresholds move. Here is what the primary texts say, and what you can do now.

Today, Swedish obliged entities apply the Swedish AML Act (2017:630). From 10 July 2027, the EU Anti-Money Laundering Regulation (AMLR) applies directly. This article keeps adopted EU law and Swedish proposals apart.

What is AMLR?

AMLR is Regulation (EU) 2024/1624 of the European Parliament and of the Council of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing.

Under Article 90, it applies from 10 July 2027. For football agents and professional football clubs (Article 3(3)(n) and (o)), it applies from 10 July 2029. The Regulation is binding in its entirety and directly applicable in all Member States. It does not need to be transposed into national law to apply.

AMLR is part of the EU AML package. The package also includes Regulation (EU) 2024/1620, which establishes the new EU Anti-Money Laundering Authority (AMLA), and a new directive, (EU) 2024/1640.

What role does AMLA play?

AMLA drafts technical standards and guidelines that specify how AMLR is applied, several of them on customer due diligence. One example is the guidelines on ongoing monitoring under Article 26(5). AMLA's draft was out for consultation until 3 September 2026. Part of the detail will therefore come from AMLA, not only from the Regulation.

What is Sweden proposing?

The Swedish government published the memorandum EU:s penningtvättspaket (Fi2026/01654) on 6 July 2026. The consultation closes on 30 October 2026.

Among other things, the memorandum proposes:

  • repealing the Swedish AML Act, the Beneficial Ownership Register Act and the Act on account and safe-deposit box systems, and replacing them with new acts
  • extending the AML, counter-terrorist financing and sanctions evasion obligations to more businesses
  • more information in the beneficial ownership register, with wider responsibility for the Swedish Companies Registration Office (Bolagsverket) to keep it accurate
  • that the changes mainly enter into force on 10 July 2027.

All of this is still a proposal. Until a new law is adopted, the Swedish AML Act applies in full.

Which terms change?

Obliged entity. AMLR uses the term obliged entity. The Swedish memorandum says the Swedish term verksamhetsutövare will be replaced by ansvariga enheter, the term used in the Swedish version of the Regulation.

Business-wide risk assessment. The general risk assessment in Chapter 2, Section 1 of the Swedish AML Act corresponds to the business-wide risk assessment in Article 10 AMLR. The memorandum uses the AMLR term.

What changes in customer due diligence?

The structure will look familiar: identify the customer and beneficial owner, understand the purpose, assess the risk and keep the file current. AMLR is more detailed. These points matter most.

When must CDD be applied? (Article 19)

You must apply CDD when you establish a business relationship and when you carry out an occasional transaction of at least EUR 10,000. The Swedish AML Act currently sets the threshold at EUR 15,000 (Chapter 3, Section 4). CDD is also required when you take part in creating a legal entity, when there is a suspicion of money laundering or terrorist financing, and when you doubt customer identification data you already hold.

Article 19(6) says who counts as the customer in certain sectors. For real estate agents, both parties to the transaction are customers. See KYC for real estate agents.

Which measures are included? (Article 20)

Article 20(1) lists nine measures, and you must apply all of them. Two stand out:

  • Targeted financial sanctions. Verify whether the customer or the beneficial owners are subject to targeted financial sanctions. For a legal entity, check whether sanctioned persons control it or hold more than 50% of it (Article 20(1)(d)).
  • The customer's business. Assess the nature of the customer's business, or their employment or occupation. For undertakings, this includes whether they actually carry out activities (Article 20(1)(e)).

You decide the extent of the measures on the basis of an individual risk analysis (Article 20(2)). You must always be able to show your supervisor that the measures are appropriate to the risks (Article 20(4)).

What data must you collect? (Article 22)

Article 22 lists the minimum identification data. For a natural person, this includes all names and surnames, place and full date of birth, and nationalities. The Swedish AML Act has no equivalent detailed list.

When must identity be verified? (Article 23)

Verification must take place before you establish the business relationship or carry out the occasional transaction. Real estate agents have a specific rule. They verify after the seller or lessor accepts an offer, and in all cases before any funds or property are transferred.

How often must customer information be updated? (Article 26)

This is the biggest practical change. The Swedish AML Act sets no fixed intervals. Under Article 26(2), the period between updates depends on risk, but may never exceed one year for higher-risk customers subject to enhanced due diligence, and five years for all other customers.

Article 26(3) also requires a review when the customer's relevant circumstances change. Article 26(4) adds regular sanctions checks, at a frequency that matches your exposure. More in ongoing monitoring.

Beneficial ownership (Articles 51–52)

The Swedish presumption in the Beneficial Ownership Register Act (lag (2017:631)) covers anyone controlling more than 25% of the votes (Chapter 1, Section 4). Article 52 AMLR covers direct or indirect ownership of 25% or more of the shares, voting rights or other ownership interest, including rights to a share of profits. The threshold stays at 25%, but the wording differs.

By 10 July 2029, the Commission will assess whether a lower threshold should apply to certain higher-risk categories of companies. That threshold would be at most 15%, unless the Commission concludes on the basis of risk that a higher one is more proportionate, in any case below 25%. Under Article 51, control via other means must be identified independently of, and in parallel to, ownership interest.

Politically exposed persons (Articles 42 and 45)

Article 42 requires senior management approval to establish or continue a business relationship with a PEP. You must also take adequate measures to establish the source of wealth and source of funds, and conduct enhanced ongoing monitoring.

When a person leaves a prominent public function, Article 45 requires measures until the risk no longer exists, and for at least 12 months. The Swedish AML Act currently says 18 months (Chapter 3, Section 20).

Records and retention (Articles 21(3) and 77)

You must record your CDD actions, including decisions, supporting documents and justifications, also when you refuse or terminate a relationship (Article 21(3)). You keep the records for five years from the end of the relationship, the occasional transaction or the refusal (Article 77(3)). This broadly matches today's five-year rule (Chapter 5, Section 3).

Summary: Swedish AML Act today, AMLR from 2027

AreaSwedish AML Act todayAMLR from 10 July 2027
TermVerksamhetsutövareObliged entity (ansvarig enhet)
Business risk assessmentGeneral risk assessment (Ch. 2, s. 1)Business-wide risk assessment (Art. 10)
Occasional transactionEUR 15,000 (Ch. 3, s. 4)EUR 10,000 (Art. 19(1)(b))
Updating customer dataOngoing and as needed, no fixed intervals (Ch. 3, s. 13)Max 1 year with EDD, max 5 years for others (Art. 26(2))
Sanctions checkNot listed among the CDD measures in Ch. 3Part of CDD (Art. 20(1)(d), 26(4))
Beneficial ownerMore than 25% of votes (Ch. 1, s. 4, Act 2017:631)25% or more of shares, votes or other ownership interest (Art. 52)
Former PEP18 months (Ch. 3, s. 20)At least 12 months (Art. 45(2))
Retention5 years (Ch. 5, s. 3)5 years (Art. 77(3))

What should you do now?

These are practical suggestions, not legal advice.

  1. Map your customer base against Article 26. Which customers have not been reviewed for more than five years? Which high-risk customers have not been reviewed for more than a year? Give each one a date before July 2027.
  2. Check your risk classification. The AMLR intervals are tied to enhanced due diligence. You must be able to explain the classification customer by customer. See our customer risk assessment guide.
  3. Compare your data fields with Article 22. Are place of birth or nationality missing from your forms?
  4. Build sanctions checks into CDD, with a documented frequency.
  5. Review your PEP procedure, especially the approval level and how you handle former PEPs.
  6. Record decisions and reasons, including for customers you turn down.
  7. Follow the Swedish consultation and AMLA's guidelines. Both can affect the details.

One customer file

AKT runs the KYC process and brings documents, screening, risk assessment and the decision together in one customer file with a full audit trail. Onboarding, periodic and event-driven review happen in the same file, and a person makes the decision. Read more about the platform.

Frequently asked questions.

When does AMLR apply?

Under Article 90, AMLR applies from 10 July 2027. For football agents and professional football clubs, it applies from 10 July 2029. It applies directly in every Member State, without national transposition.

Is the Swedish AML Act being repealed?

Government memorandum Fi2026/01654 proposes repealing it and replacing it with new acts from 10 July 2027. The consultation runs until 30 October 2026. There is no bill yet, so the Swedish AML Act applies in full for now.

Does the beneficial ownership threshold change?

The threshold stays at 25%. AMLR refers to 25% or more of the shares, voting rights or other ownership interest. The current Swedish presumption refers to more than 25% of the votes. The Commission may later set a lower threshold for certain higher-risk categories.

Must every customer be reviewed more often?

Not necessarily. AMLR sets outer limits: one year for customers subject to enhanced due diligence and five years for everyone else. Within those limits, the interval must follow the risk.

What is an obliged entity?

It is the AMLR term for a business that must comply with the AML rules. In Sweden today, the AML Act uses the term *verksamhetsutövare*. Article 3 AMLR lists the obliged entities.

See how simple KYC can be.

Book a walkthrough and watch a customer file come together.

  1. 01You book a demo
  2. 02We prepare a relevant example
  3. 03We show the complete workflow

After the demo, you decide whether to continue with a pilot. Nothing is activated automatically.

Prefer email? contact@aktkyc.com

Book a demo of AKT

Make the demo more relevant (optional)
Required

When you submit the form, we use the details to respond to your request and plan the demo. Read our privacy policy.