Resources · Reviewed 28 September 2026

KYC for accounting firms: getting customer due diligence right

Accounting and bookkeeping firms are obliged entities under the Swedish AML Act and are supervised by the County Administrative Boards. This guide covers what customer due diligence means in daily practice, what supervisors keep finding, and how to build a routine that holds up.

Why are accounting firms covered by AML rules?

Across the EU, accountants are obliged entities. AMLR, Regulation (EU) 2024/1624, lists "auditors, external accountants and tax advisors" in Article 3(3)(a). It applies directly from 10 July 2027 (Article 90).

Until then, Swedish firms apply the Swedish AML Act (2017:630). Under Chapter 1, Section 2, first paragraph, point 19, the Act covers professional bookkeeping or auditing services. Point 20 covers professional advice on taxes and charges.

Most accounting firms are therefore covered, often on two grounds. If you also form companies or sell newly formed limited companies, the Act names those services specifically in Chapter 1, Section 4, second paragraph.

Swedish authorities rate the sector as high risk. In Sweden's national risk assessment 2024/2025, bookkeeping and accounting services are one of four sectors assessed as high risk from a national perspective. The reasons given are the size of the sector and the use of companies as tools for crime. Firms are expected to act as gatekeepers.

Who supervises you, and do you need to register?

In Sweden, the County Administrative Board (Länsstyrelsen) supervises external accountants and tax advisors. Three boards share the task: Stockholm, Västra Götaland and Skåne. Which one supervises you depends on your county.

Before you start, you must notify the Swedish Companies Registration Office (Bolagsverket). Under Chapter 7, Section 3 of the Swedish AML Act, you may not run the business until you have done so. Länsstyrelsen calls this Bolagsverket's AML register. If you operate without registering, Länsstyrelsen can order you to stop, and you may have to pay a conditional fine.

For breaches, Länsstyrelsen can issue an order to rectify, impose an administrative fine or, for serious, repeated or systematic breaches, order you to cease the business (Chapter 7, Section 11).

What does CDD mean for an accounting firm?

The basic rule is in Chapter 3, Section 1 of the Swedish AML Act. You may not establish or maintain a business relationship without sufficient knowledge of the customer. That knowledge must be enough to manage the risk and to monitor the customer's activity.

A client of an accounting firm is almost always a business relationship. You therefore apply CDD when the relationship is established (Chapter 3, Section 4). You must complete verification of the client's and the beneficial owner's identity before then (Chapter 3, Section 9).

New client: what you must do

  • Identify and verify the client using an identity document, a register extract or another independent and reliable source (Chapter 3, Section 7).
  • Check the representative. Verify the identity and the authority of anyone acting for the client (Chapter 3, Section 7, third paragraph).
  • Identify the beneficial owner. At a minimum, search Bolagsverket's beneficial ownership register. For a legal person, you must also understand the ownership and control structure (Chapter 3, Section 8). See our guide to beneficial ownership.
  • Assess PEP status. Is the client or the beneficial owner a politically exposed person, a family member or a close associate (Chapter 3, Section 10)?
  • Check for high-risk third countries. Is the client established in a country identified by the European Commission (Chapter 3, Section 11)?
  • Establish purpose and nature. Which services will you provide, and which transactions are normal for the client (Chapter 3, Section 12)?
  • Set a risk profile based on your general risk assessment and what you know about the client (Chapter 2, Section 3).

The engagement letter describes the services you will provide. It is a natural starting point for assessing purpose and nature. You still need to document that assessment and the risk profile in the customer file.

For a ready-made structure, see our CDD checklist.

Which risk factors are typical for accounting firms?

Chapter 2, Section 5 of the Swedish AML Act lists circumstances that may indicate high risk. The national risk assessment describes how they show up in accounting firms.

Risk factorWhat it can mean for you
Cash-intensive business (Ch. 2, s. 5(2))Criminal proceeds can be booked as sales and then paid out as salary or dividends. The assessment names construction and restaurants as examples.
Unusual or complex ownership (Ch. 2, s. 5(1))Several layers of companies make it harder to see who ultimately controls the client.
Payment from an unknown party (Ch. 2, s. 5(10))Money arrives without supporting documents and is to be "repaid" to another account.
Foreign paymentsPayments unrelated to the business, or payments to high-risk countries.
False invoicesDocuments meant to make transactions look genuine, or reverse money laundering to pay undeclared workers.
Client money accountsThe client's money passes through the firm's account, and the client does not appear as account holder.

The assessment also points to combinations of services, such as bookkeeping together with payment services or factoring. Such set-ups can attract high-risk clients.

What has supervision found?

The County Administrative Boards publish their findings and decisions. Three sources are worth reading.

Report 2026:14. The boards in Skåne, Stockholm and Västra Götaland summarised their findings, focusing on the general risk assessment. Common failings: the assessment is missing, or confused with the risk assessment of individual clients. Firms use a template without adapting it, or group clients by sector without explaining why. The report also flags a risk many firms share: a close relationship with a client can weaken the checks.

A decision from May 2026. Länsstyrelsen Stockholm imposed an administrative fine of SEK 160,000 on an accounting company. It rejected the firm's CDD procedures. Stating that identity, beneficial ownership and PEP checks must be carried out was not enough. The procedures had to describe which measures are taken in which situations and how they are documented. CDD produced only after Länsstyrelsen's order did not count. For one low-risk client, there was no documented risk assessment at all.

The decision list. Länsstyrelsen Stockholm's page on interventions and sanctions lists several decisions against accounting companies in 2025–2026. According to the national risk assessment, the boards find compliance failings in most supervisory cases in the sector.

The lesson is concrete. Your CDD must rest on your general risk assessment, follow written procedures and be documented at the time you carry it out.

Checklist: CDD for a new client

  • Client's identity verified, with a copy or register extract saved
  • Representative's identity and authority verified
  • Beneficial ownership register searched and ownership chain understood
  • Beneficial owner's identity verified
  • PEP assessment done for the client and the beneficial owner
  • High-risk third country check done
  • Purpose and nature described: services, expected transactions, any client money handling
  • Risk profile set and justified with reference to the general risk assessment
  • Enhanced measures applied where risk is high, such as questions on source of funds (Ch. 3, s. 16)
  • Date of each measure recorded

How often should you review clients?

You must monitor ongoing business relationships continuously and as needed. The aim is to keep your knowledge of the client current and sufficient for the risk (Chapter 3, Section 13). You must change the risk profile when there is reason to (Chapter 2, Section 3, third paragraph).

The Swedish AML Act sets no fixed intervals. According to Länsstyrelsen's guidance, the client's risk profile is one of the factors that drives frequency. In practice you need two tracks:

  • Periodic review, more frequent for high risk than for low risk.
  • Event-driven review when something changes: a new owner or representative, a new line of business, unexpected deposits or new foreign payments.

You must investigate anomalies with enhanced measures (Chapter 4, Section 2). If you have reasonable grounds to suspect money laundering, you must report to the Swedish Police Authority without delay (Chapter 4, Section 3). You keep CDD records for five years after the relationship ends (Chapter 5, Section 3). More in ongoing monitoring.

What changes in 2027?

From 10 July 2027, AMLR applies directly. It sets outer limits for updating customer information: one year for higher-risk clients subject to enhanced due diligence, five years for all others (Article 26(2)). It also requires CDD when you take part in creating a legal entity (Article 19(1)(c)). See AMLR 2027 and customer due diligence.

How AKT supports the work

AKT runs the KYC process and brings documents, screening, risk assessment and the decision together in one customer file with a full audit trail. Onboarding, periodic and event-driven review happen in the same file, and a person makes the decision. Read more about AKT for accounting firms.

Frequently asked questions.

Is a sole-trader bookkeeper covered by the Swedish AML Act?

Yes. The Act applies to natural and legal persons who provide bookkeeping services professionally (Chapter 1, Section 2, first paragraph, point 19). Your size affects how extensive your risk assessment and procedures need to be, not whether the rules apply.

Do we need CDD for clients we have had for many years?

Yes. The rules apply to all business relationships, and your knowledge must be kept current (Chapter 3, Section 13). In one decision, Länsstyrelsen stressed that CDD applies to all clients, whatever their risk level. A long relationship can itself be a vulnerability.

Is a search in the beneficial ownership register enough?

The search is the minimum. For a legal person, you must also take steps to understand the ownership and control structure. If the client has a beneficial owner, you must verify that person's identity (Chapter 3, Section 8).

Which County Administrative Board supervises our firm?

It depends on your county. Länsstyrelsen in Stockholm, Västra Götaland and Skåne share the supervision. Länsstyrelsen's website shows which counties belong to which board.

Can we use a CDD template?

Yes, as support. The boards have criticised documents that follow a template without being adapted to the firm. You must fill the template with your own risk assessment and your own procedures.

See how simple KYC can be.

Book a walkthrough and watch a customer file come together.

  1. 01You book a demo
  2. 02We prepare a relevant example
  3. 03We show the complete workflow

After the demo, you decide whether to continue with a pilot. Nothing is activated automatically.

Prefer email? contact@aktkyc.com

Book a demo of AKT

Make the demo more relevant (optional)
Required

When you submit the form, we use the details to respond to your request and plan the demo. Read our privacy policy.