The customer risk assessment is the hub of customer due diligence (CDD). It decides whether you may apply simplified due diligence, whether you must apply enhanced due diligence and how closely you follow up. The EU Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624, applies from 10 July 2027. In Sweden today, the Swedish AML Act (2017:630) applies. The principle is the same in both: measures must be proportionate to risk.
What does the Swedish AML Act require?
The core rule is in Chapter 2, Section 3 of the Swedish AML Act. You must assess the money laundering and terrorist financing risk associated with the customer relationship. The Act calls the result the customer's risk profile.
The provision contains three requirements:
- The risk profile must be based on your business-wide risk assessment and your knowledge of the customer.
- Where needed, you must take into account the circumstances in Chapter 2, Sections 4 and 5, your supervisor's regulations and other circumstances in the individual case.
- The risk profile must be followed up during the business relationship and changed when there is reason to.
Part of the input comes from the purpose and intended nature of the business relationship. Under Chapter 3, Section 12, that information must form the basis for assessing the customer's risk profile.
The risk profile then sets the extent of CDD (Chapter 3, Section 14):
- Low risk: you may apply simplified due diligence (Chapter 3, Section 15).
- High risk: you must carry out particularly extensive checks and add measures that mitigate the risk, such as information on the source of the customer's funds (Chapter 3, Section 16).
Supervisors may issue regulations on the risk classification of customers (Chapter 8, Section 1, point 4). Check whether your supervisor has its own regulations or guidance.
How does the risk profile relate to the business-wide risk assessment?
The business-wide risk assessment (Chapter 2, Section 1) describes how your products and services could be used for money laundering or terrorist financing. It must consider products and services, customers, distribution channels and geographical risk factors.
The risk profile applies the same analysis to one customer. A service rated higher risk in your business-wide assessment should show in the profiles of customers who buy it. The Stockholm County Administrative Board, a Swedish supervisor, puts it this way in its guidance: weigh in the risk factors you identified in your business-wide risk assessment.
The link runs both ways. Under the EBA's guidelines, customer assessments should also inform the business-wide risk assessment, though they cannot replace it.
Which risk factors should you weigh?
The Swedish AML Act gives examples of circumstances that may indicate low risk (Chapter 2, Section 4) and high risk (Chapter 2, Section 5). The lists are not exhaustive. The EBA's risk factor guidelines (EBA/GL/2021/02) group factors into customers, countries or geographical areas, products and services, and delivery channels. Transactions are best assessed together with the purpose and nature of the relationship.
| Category | Example questions | Basis |
|---|---|---|
| Customer | Is the ownership structure unusual or excessively complex for the business? Is the business cash-intensive? Are there nominee shareholders? | Swedish AML Act Ch. 2 s. 5(1)–(3) |
| Customer | Does the customer operate in a sector often associated with high corruption risk, such as construction or public procurement? | EBA/GL/2021/02, guideline 2.4 |
| Products and services | What does the customer buy, and how did you rate that service in your business-wide assessment? | Ch. 2 s. 1 |
| Geography | Resident in the EEA? Resident in a state without effective AML systems, with significant corruption or subject to sanctions? | Ch. 2 s. 4(2)–(4) and s. 5(5)–(8) |
| Delivery channel | Is the relationship conducted remotely without methods that reliably verify identity? | Ch. 2 s. 5(9) |
| Transactions | Is the service paid for by someone unknown or unconnected to the customer? Do the flows match the purpose and nature? | Ch. 2 s. 5(10) and Ch. 3 s. 12 |
Some situations always require enhanced due diligence, whatever the other factors say. One example is a customer established in a high-risk third country (Chapter 3, Section 17). For politically exposed persons, see our guide to PEP screening.
How do you combine the factors?
The EBA guidelines are addressed to credit and financial institutions. Finansinspektionen, the Swedish financial supervisor, complies with them and treats them as equivalent to Swedish general guidelines. For other obliged entities they offer a useful structure.
In short, the guidelines say:
- Take a holistic view. A single risk factor does not automatically move a customer into a higher or lower category (guideline 3.3).
- Weighting is allowed. You may weight factors differently. The weighting must not be driven by one factor or by profitability, and it must not make it impossible for any customer to be high risk (guideline 3.6).
- Scores can be overridden. Automatically generated risk scores must be open to override. Document the reason for any override (guideline 3.6(e)).
- Choose a scale that fits. High, medium and low is common, but other categories can be used (guideline 3.8).
The Swedish AML Act only names low and high risk. Many obliged entities use a middle level, such as standard risk, for customers who receive standard due diligence.
Example: risk assessment of a limited company
Fictitious example. The company, figures and assessments are invented to show the method.
An accounting firm receives an enquiry from a construction company, here called the Company. It wants bookkeeping, payroll and year-end accounts.
| Factor | What the firm found | Effect |
|---|---|---|
| Customer | Construction company, twelve employees, trading since 2019. The EBA names construction as a sector with high corruption risk. | Raises |
| Owners and beneficial owners | Two individuals in Sweden own 60% and 40% directly. Matches the beneficial ownership register. No PEP, no sanctions hit. | Neutral |
| Service | Bookkeeping and payroll, standard risk in the business-wide assessment. | Neutral |
| Geography | Resident and operating in Sweden. Subcontractors within the EEA. | Lowers |
| Delivery channel | Met in person, identity verified with Swedish e-ID. | Neutral |
| Transactions | The customer pays from its own account. No cash handling, according to the customer. | Neutral |
Overall rating: standard risk. The sector raises the risk. It is offset by a simple, verified ownership structure, Swedish residence and traceable payments. Nothing in the file justifies enhanced due diligence, and the sector makes simplified due diligence inappropriate.
Measures: standard CDD and follow-up at the firm's interval for standard risk. The firm notes that cash handling, new owners or payments from unknown third parties must trigger a new assessment.
Same company, different facts. Now assume the shares are held through a company outside the EEA, the ownership chain cannot be explained and invoices are paid by an unconnected company. Several circumstances under Chapter 2, Section 5, points 1 and 10 may then indicate high risk. The overall rating becomes high risk. The firm must carry out particularly extensive checks and gather information on the customer's business, financial situation and source of funds (Chapter 3, Section 16). If adequate customer knowledge cannot be achieved, the relationship must not be established (Chapter 3, Section 1).
How do you document the rationale?
A rating without a rationale cannot be reviewed. Write so that an outsider can follow the reasoning. Show:
- which information you used and where it came from
- which risk factors you identified, both raising and lowering
- how you weighed them and why one factor outweighed another
- the risk rating and the measures it leads to
- whether you overrode an automatic score, and why
- who made the decision and when
- which events should trigger a new assessment
In Sweden, the records must be kept for five years (Chapter 5, Section 3). How to keep the profile current is covered in ongoing monitoring. A ready structure for the file is in our CDD checklist.
What are the common mistakes?
- The same rating for everyone. Then no real assessment is being made.
- No link to the business-wide assessment. Factors you identified yourself do not show in customer profiles.
- Scores only. A number alone does not show how risk was assessed.
- The profile is never updated. The law requires follow-up and change when there is reason.
- Simplified due diligence as a shortcut. It may only be used when risk is assessed as low, and the measures do not disappear.
What changes with AMLR in 2027?
Under Article 20(2) AMLR, you must set the extent of CDD "on the basis of an individual analysis of the risks of money laundering and terrorist financing". The analysis must consider the customer and the relationship, your business-wide risk assessment and the risk variables and factors in Annexes I to III. Where you identify an increased risk, you must apply enhanced due diligence. The method in this guide therefore still works after 10 July 2027, but check your factor lists against the annexes.
How AKT supports the work
AKT runs the KYC process and brings documents, screening, risk assessment and the decision together in one customer file with a full audit trail. Onboarding, periodic and event-driven review happen in the same file, and a person makes the decision. See the platform and accounting firms.