Before you use this checklist
A template is a starting point, not a procedure. The customer's risk profile must be based on your business-wide risk assessment (Chapter 2, Section 3 of the Swedish AML Act (2017:630)). Your procedures must reflect your size, your business and the risks you have identified (Chapter 2, Section 8).
So the steps show what the law requires, but how far you go depends on the risk (Chapter 3, Section 14). The evidence column gives examples; your procedure should state what you accept. At low risk, measures may be more limited and carried out differently (Chapter 3, Section 15).
The Swedish AML Act applies today. From 10 July 2027 the EU Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624, applies directly (Article 90); the AMLR column maps each step. Background is in the KYC guide.
Checklist: corporate customer
| # | What to do | Evidence (examples) | Swedish AML Act | AMLR |
|---|---|---|---|---|
| 1 | Identify the company and verify its identity | Register extract or another independent, reliable source | Ch. 3, Section 7, first paragraph | Art. 20(1)(a), 22(1)(b) |
| 2 | Verify the identity and authority of the person representing the company | ID document or electronic ID, registered signatory rights or a power of attorney | Ch. 3, Section 7, third paragraph | Art. 20(1)(i) |
| 3 | Search the beneficial ownership register | Register extract, dated | Ch. 3, Section 8, first paragraph | Art. 23(4) |
| 4 | Understand the ownership and control structure | Ownership chart, share register, articles of association, agreements | Ch. 3, Section 8, first paragraph | Art. 20(1)(b) |
| 5 | Verify the beneficial owner's identity | ID document or another reliable source | Ch. 3, Section 8, first paragraph | Art. 20(1)(b) |
| 6 | No beneficial owner: record the chair, CEO or equivalent | Documented investigation showing why | Ch. 3, Section 8, third paragraph | Art. 22(2) |
| 7 | Check whether the customer or beneficial owner is a PEP, family member or close associate | Question to the customer and a check against a source named in your procedure | Ch. 3, Section 10 | Art. 20(1)(g) |
| 8 | Check whether the company is established in a high-risk third country | The European Commission's list | Ch. 3, Section 11 | Art. 29 |
| 9 | Obtain the purpose and intended nature of the relationship | Engagement description, expected services, volumes and flows | Ch. 3, Section 12 | Art. 20(1)(c) |
| 10 | Set the customer's risk profile | Risk assessment based on your business-wide risk assessment | Ch. 2, Section 3 | Art. 20(2) |
| 11 | High risk only: apply enhanced due diligence | For example business activity, financial situation and source of funds | Ch. 3, Section 16 | Art. 20(2), Chapter III Section 4 |
| 12 | Decide: onboard or decline | Documented decision with reasons | Ch. 3, Section 1 | Art. 21(1) and (3) |
Exception: the beneficial ownership requirements in Chapter 3, Section 8, first paragraph do not apply to a limited company whose shares are traded on a regulated market in Sweden or the EEA, or on an equivalent market outside the EEA. The same goes for its subsidiaries (Chapter 3, Section 8, second paragraph).
Steps 3–6 are covered in depth in beneficial ownership.
Checklist: individual customer
| # | What to do | Evidence (examples) | Swedish AML Act | AMLR |
|---|---|---|---|---|
| 1 | Identify the customer and verify their identity | ID document or electronic ID | Ch. 3, Section 7, first and second paragraphs | Art. 20(1)(a), 22(1)(a) |
| 2 | Someone acting for the customer: verify their identity and authority | Power of attorney or other proof of authority, ID document | Ch. 3, Section 7, third paragraph | Art. 20(1)(i) |
| 3 | Establish whether someone else stands behind the customer | The customer's statement and your assessment | Ch. 3, Section 8; Ch. 1, Section 3 of Act 2017:631 | Art. 20(1)(h) |
| 4 | Check whether the customer is a PEP, family member or close associate | Question to the customer and a check against a source named in your procedure | Ch. 3, Section 10 | Art. 20(1)(g) |
| 5 | Check whether the customer is established in a high-risk third country | The European Commission's list | Ch. 3, Section 11 | Art. 29 |
| 6 | Obtain the purpose and intended nature of the relationship | Engagement description, expected transactions | Ch. 3, Section 12 | Art. 20(1)(c) |
| 7 | Set the customer's risk profile | Risk assessment based on your business-wide risk assessment | Ch. 2, Section 3 | Art. 20(2) |
| 8 | High risk only: apply enhanced due diligence | For example financial situation and source of funds | Ch. 3, Section 16 | Art. 20(2) |
| 9 | Decide: onboard or decline | Documented decision with reasons | Ch. 3, Section 1 | Art. 21(1) and (3) |
AMLR Article 22(1)(a) sets the minimum data for an individual: all names, place and full date of birth, nationalities and usual place of residence.
Which situations require more?
The customer or beneficial owner is a PEP
In addition to the steps above, you must always (Chapter 3, Section 19):
- take appropriate measures to establish the source of the assets in the relationship,
- apply enhanced ongoing monitoring, and
- obtain approval from a senior decision-maker before entering into or ending the relationship.
This also covers family members and close associates. See PEP screening.
The customer is established in a high-risk third country
Enhanced due diligence is mandatory (Chapter 3, Section 17). It must at least include enhanced monitoring and obtaining:
- additional information on the customer and the beneficial owner,
- additional information on the purpose and nature of the relationship,
- information on the financial situation and the source of funds, and
- approval from a senior decision-maker.
Sanctions
Under the Swedish AML Act, sanctions screening sits outside the CDD rules, though residence in a sanctioned country may indicate high risk (Chapter 2, Section 5, point 7). Under AMLR, sanctions screening of the customer and beneficial owners becomes a CDD measure (Article 20(1)(d)). See sanctions screening.
When should you complete the checklist?
- New business relationship. Measures are taken when the relationship is established (Chapter 3, Section 4). Identity verification of the customer and beneficial owner must be complete before then (Chapter 3, Section 9).
- Occasional transactions. From EUR 15,000 today, including smaller linked transactions that together reach that amount (Chapter 3, Section 4). Under AMLR the threshold is EUR 10,000 (Article 19(1)(b)).
- During the relationship. Regularly and when needed, so your knowledge stays current and sufficient (Chapter 3, Section 13). Update the risk profile when there is reason to (Chapter 2, Section 3).
- When something looks wrong. Apply enhanced measures to assess whether there are reasonable grounds for suspicion (Chapter 4, Section 2).
See ongoing monitoring and customer risk assessment.
What should you document?
Keep records of CDD measures for five years (Chapter 5, Section 3). The period runs from when the measure was taken or, for a business relationship, from when it ended. You may keep them longer where necessary to prevent, detect or investigate money laundering, but no more than ten years in total (Chapter 5, Section 4).
For each customer, keep at least:
- identity evidence for the customer, representatives and beneficial owners
- the register search and your analysis of ownership and control
- the PEP and high-risk third country checks
- the purpose and nature of the relationship
- the risk profile and the reasons for it
- any enhanced measures and what they showed
- the decision, who made it and when
- follow-ups and changes to the risk profile over time
You must also be able to say quickly whether you have had a business relationship with a given person in the past five years, and its nature (Chapter 4, Section 7). AMLR Article 21(3) also requires records of decisions and reasons, including refusals.
What if you cannot complete CDD?
If you cannot complete the checklist, you must not establish or maintain the relationship or carry out the transaction (Chapter 3, Section 1). Document the decision. If you have reasonable grounds to suspect money laundering, report to the Swedish Police Authority, even if the transaction does not go ahead (Chapter 4, Section 3).
From template to process
AKT runs the KYC process and brings documents, screening, risk assessment and the decision together in one customer file with a full audit trail. Onboarding, periodic and event-driven review happen in the same file, and a person makes the decision. See the platform or the set-up for accounting firms.