Resources · Reviewed 28 September 2026

Customer due diligence checklist and template

A step-by-step customer due diligence checklist for corporate and individual customers. Each step shows what to do, which evidence helps and which provision requires it. Adapt it to your own business-wide risk assessment and procedures.

Before you use this checklist

A template is a starting point, not a procedure. The customer's risk profile must be based on your business-wide risk assessment (Chapter 2, Section 3 of the Swedish AML Act (2017:630)). Your procedures must reflect your size, your business and the risks you have identified (Chapter 2, Section 8).

So the steps show what the law requires, but how far you go depends on the risk (Chapter 3, Section 14). The evidence column gives examples; your procedure should state what you accept. At low risk, measures may be more limited and carried out differently (Chapter 3, Section 15).

The Swedish AML Act applies today. From 10 July 2027 the EU Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624, applies directly (Article 90); the AMLR column maps each step. Background is in the KYC guide.

Checklist: corporate customer

#What to doEvidence (examples)Swedish AML ActAMLR
1Identify the company and verify its identityRegister extract or another independent, reliable sourceCh. 3, Section 7, first paragraphArt. 20(1)(a), 22(1)(b)
2Verify the identity and authority of the person representing the companyID document or electronic ID, registered signatory rights or a power of attorneyCh. 3, Section 7, third paragraphArt. 20(1)(i)
3Search the beneficial ownership registerRegister extract, datedCh. 3, Section 8, first paragraphArt. 23(4)
4Understand the ownership and control structureOwnership chart, share register, articles of association, agreementsCh. 3, Section 8, first paragraphArt. 20(1)(b)
5Verify the beneficial owner's identityID document or another reliable sourceCh. 3, Section 8, first paragraphArt. 20(1)(b)
6No beneficial owner: record the chair, CEO or equivalentDocumented investigation showing whyCh. 3, Section 8, third paragraphArt. 22(2)
7Check whether the customer or beneficial owner is a PEP, family member or close associateQuestion to the customer and a check against a source named in your procedureCh. 3, Section 10Art. 20(1)(g)
8Check whether the company is established in a high-risk third countryThe European Commission's listCh. 3, Section 11Art. 29
9Obtain the purpose and intended nature of the relationshipEngagement description, expected services, volumes and flowsCh. 3, Section 12Art. 20(1)(c)
10Set the customer's risk profileRisk assessment based on your business-wide risk assessmentCh. 2, Section 3Art. 20(2)
11High risk only: apply enhanced due diligenceFor example business activity, financial situation and source of fundsCh. 3, Section 16Art. 20(2), Chapter III Section 4
12Decide: onboard or declineDocumented decision with reasonsCh. 3, Section 1Art. 21(1) and (3)

Exception: the beneficial ownership requirements in Chapter 3, Section 8, first paragraph do not apply to a limited company whose shares are traded on a regulated market in Sweden or the EEA, or on an equivalent market outside the EEA. The same goes for its subsidiaries (Chapter 3, Section 8, second paragraph).

Steps 3–6 are covered in depth in beneficial ownership.

Checklist: individual customer

#What to doEvidence (examples)Swedish AML ActAMLR
1Identify the customer and verify their identityID document or electronic IDCh. 3, Section 7, first and second paragraphsArt. 20(1)(a), 22(1)(a)
2Someone acting for the customer: verify their identity and authorityPower of attorney or other proof of authority, ID documentCh. 3, Section 7, third paragraphArt. 20(1)(i)
3Establish whether someone else stands behind the customerThe customer's statement and your assessmentCh. 3, Section 8; Ch. 1, Section 3 of Act 2017:631Art. 20(1)(h)
4Check whether the customer is a PEP, family member or close associateQuestion to the customer and a check against a source named in your procedureCh. 3, Section 10Art. 20(1)(g)
5Check whether the customer is established in a high-risk third countryThe European Commission's listCh. 3, Section 11Art. 29
6Obtain the purpose and intended nature of the relationshipEngagement description, expected transactionsCh. 3, Section 12Art. 20(1)(c)
7Set the customer's risk profileRisk assessment based on your business-wide risk assessmentCh. 2, Section 3Art. 20(2)
8High risk only: apply enhanced due diligenceFor example financial situation and source of fundsCh. 3, Section 16Art. 20(2)
9Decide: onboard or declineDocumented decision with reasonsCh. 3, Section 1Art. 21(1) and (3)

AMLR Article 22(1)(a) sets the minimum data for an individual: all names, place and full date of birth, nationalities and usual place of residence.

Which situations require more?

The customer or beneficial owner is a PEP

In addition to the steps above, you must always (Chapter 3, Section 19):

  1. take appropriate measures to establish the source of the assets in the relationship,
  2. apply enhanced ongoing monitoring, and
  3. obtain approval from a senior decision-maker before entering into or ending the relationship.

This also covers family members and close associates. See PEP screening.

The customer is established in a high-risk third country

Enhanced due diligence is mandatory (Chapter 3, Section 17). It must at least include enhanced monitoring and obtaining:

  • additional information on the customer and the beneficial owner,
  • additional information on the purpose and nature of the relationship,
  • information on the financial situation and the source of funds, and
  • approval from a senior decision-maker.

Sanctions

Under the Swedish AML Act, sanctions screening sits outside the CDD rules, though residence in a sanctioned country may indicate high risk (Chapter 2, Section 5, point 7). Under AMLR, sanctions screening of the customer and beneficial owners becomes a CDD measure (Article 20(1)(d)). See sanctions screening.

When should you complete the checklist?

  • New business relationship. Measures are taken when the relationship is established (Chapter 3, Section 4). Identity verification of the customer and beneficial owner must be complete before then (Chapter 3, Section 9).
  • Occasional transactions. From EUR 15,000 today, including smaller linked transactions that together reach that amount (Chapter 3, Section 4). Under AMLR the threshold is EUR 10,000 (Article 19(1)(b)).
  • During the relationship. Regularly and when needed, so your knowledge stays current and sufficient (Chapter 3, Section 13). Update the risk profile when there is reason to (Chapter 2, Section 3).
  • When something looks wrong. Apply enhanced measures to assess whether there are reasonable grounds for suspicion (Chapter 4, Section 2).

See ongoing monitoring and customer risk assessment.

What should you document?

Keep records of CDD measures for five years (Chapter 5, Section 3). The period runs from when the measure was taken or, for a business relationship, from when it ended. You may keep them longer where necessary to prevent, detect or investigate money laundering, but no more than ten years in total (Chapter 5, Section 4).

For each customer, keep at least:

  • identity evidence for the customer, representatives and beneficial owners
  • the register search and your analysis of ownership and control
  • the PEP and high-risk third country checks
  • the purpose and nature of the relationship
  • the risk profile and the reasons for it
  • any enhanced measures and what they showed
  • the decision, who made it and when
  • follow-ups and changes to the risk profile over time

You must also be able to say quickly whether you have had a business relationship with a given person in the past five years, and its nature (Chapter 4, Section 7). AMLR Article 21(3) also requires records of decisions and reasons, including refusals.

What if you cannot complete CDD?

If you cannot complete the checklist, you must not establish or maintain the relationship or carry out the transaction (Chapter 3, Section 1). Document the decision. If you have reasonable grounds to suspect money laundering, report to the Swedish Police Authority, even if the transaction does not go ahead (Chapter 4, Section 3).

From template to process

AKT runs the KYC process and brings documents, screening, risk assessment and the decision together in one customer file with a full audit trail. Onboarding, periodic and event-driven review happen in the same file, and a person makes the decision. See the platform or the set-up for accounting firms.

Frequently asked questions.

Is there an official CDD template?

No. The Swedish AML Act prescribes no form. It sets out the measures you must take and requires documented procedures for how you take them (Chapter 2, Section 8). A template works when it follows your business-wide risk assessment and procedures.

Is the beneficial ownership register enough?

Not for legal persons. The register search is a minimum. You must also understand the ownership and control structure and verify the beneficial owner's identity (Chapter 3, Section 8).

Can an accounting firm use the same checklist for every client?

The same structure, yes. The depth must follow the customer's risk profile (Chapter 3, Section 14). At low risk measures may be more limited; at high risk they must be especially thorough.

Who should approve a high-risk customer?

For PEPs and customers in high-risk third countries, the Act requires approval from a senior decision-maker (Chapter 3, Sections 17 and 19). That is a board member, the CEO or another officer with enough knowledge of the risk exposure and authority to act on it (Chapter 1, Section 8, point 9). For other high-risk customers, your procedure should name who decides.

How long must we keep the checklist and evidence?

Five years from the end of the relationship, or from the measure for an occasional transaction (Chapter 5, Section 3). Longer is allowed where necessary to counter money laundering, up to ten years (Chapter 5, Section 4).

See how simple KYC can be.

Book a walkthrough and watch a customer file come together.

  1. 01You book a demo
  2. 02We prepare a relevant example
  3. 03We show the complete workflow

After the demo, you decide whether to continue with a pilot. Nothing is activated automatically.

Prefer email? contact@aktkyc.com

Book a demo of AKT

Make the demo more relevant (optional)
Required

When you submit the form, we use the details to respond to your request and plan the demo. Read our privacy policy.