Resources · Reviewed 1 October 2026

KYC for auditors and audit firms

Auditors are obliged entities across the EU. In Sweden, authorised and approved auditors and registered audit firms are fully covered by the Swedish AML Act, supervised by the Swedish Inspectorate of Auditors and bound by its own regulations. This guide covers what that means in an audit engagement, from who the customer is to how AML reporting fits with company law.

Are auditors covered by AML rules?

Yes. AMLR, Regulation (EU) 2024/1624, lists "auditors, external accountants and tax advisors" as obliged entities in Article 3(3)(a). It applies directly from 10 July 2027 (Article 90).

Until then, the Swedish AML Act (2017:630) applies. Chapter 1, Section 2, first paragraph, point 18 covers authorised or approved auditors and registered audit firms. Unlike for lawyers, coverage is not limited to certain services. The Swedish Inspectorate of Auditors (Revisorsinspektionen) states that auditors are fully covered.

Providers of audit services without authorisation or approval fall under point 19 instead, with notification to Bolagsverket and County Administrative Board supervision.

Sweden's national risk assessment 2024/2025 rates the sector risk for auditors as significant.

Who supervises auditors in Sweden?

The Swedish Inspectorate of Auditors. Under Section 3 a of the Swedish Auditors Act (2001:883), it supervises how auditors and registered audit firms meet their duties under the AML Act.

For breaches, the Inspectorate can issue a reminder or a warning, or revoke the authorisation or approval (Section 32 of the Auditors Act). A warning can be combined with an administrative fine (Section 32 a). For AML breaches, the maximum is the higher of twice the profit gained or the equivalent of EUR 1 million (Section 32 k).

According to the national risk assessment, the audit firm or the auditor had failed to meet their AML obligations in 61 per cent of the cases in the Inspectorate's supervisory project in 2023 and 2024.

What do the Inspectorate's regulations RIFS 2021:1 require?

The Inspectorate's AML regulations (RIFS 2021:1) have applied since 1 January 2022. They supplement the AML Act and address both the audit firm and the individual auditor.

AreaRequirement in RIFS 2021:1
Business-wide risk assessmentServices, threats, vulnerabilities and a risk rating (Section 3). Evaluated at least yearly (Section 4).
Internal controlAt least every three years, one completed engagement per auditor is reviewed (Section 6).
Identity verificationExternal verification. Certified copies when remote. Applies even to customers already known (Section 7).
Low and high riskIdentity always verified. At high risk, financial situation and source of funds always obtained (Section 8).
Ongoing reviewCDD and risk profile evaluated at least yearly (Section 9).
Risk levelsNormal, low and high at minimum. Low requires specific circumstances (Section 10).
DocumentationSame standard as the audit, organised and searchable (Sections 11–12).

The County Administrative Boards' regulations do not apply to audit work, so their list of simplified measures cannot be used there. Accounting or tax advice in the same firm may fall under the County Administrative Boards. See KYC for accounting firms.

Who is the customer in an audit engagement?

Under the Swedish AML Act, the customer is the party that has entered, or is about to enter, into a contract with you (Chapter 1, Section 8, point 4). In an audit, that is the audited company, which appoints the auditor and signs the engagement letter.

Auditors have no CDD duty towards their customers' customers. According to the national risk assessment, an auditor still normally needs to form a view of the counterparties.

When is the business relationship established?

CDD applies when the relationship is established (Chapter 3, Section 4), with identity verified before then (Section 9). For statutory audits, the Inspectorate says this may be acceptance of the engagement, election at the general meeting, registration by Bolagsverket or signing of the engagement letter. Engagement letters are often signed just before the audit report, and CDD done only then is usually too late.

Who must have the customer knowledge?

The auditor, not the audit firm, according to the Inspectorate. A support function can collect documents, but the knowledge must reach the auditor. An engagement letter signed with an electronic ID is not in itself an identity check.

Beneficial owners and PEPs

You must establish whether the customer has a beneficial owner, understand the ownership and control structure and verify the owner's identity (Chapter 3, Section 8). This does not apply to companies listed on a regulated market or their subsidiaries (second paragraph).

If there is reason to suspect the beneficial ownership register is wrong, you must notify Bolagsverket (Chapter 3, Section 5 of the Beneficial Ownership Register Act (2017:631)). The Inspectorate considers awareness of this duty to be low.

For a legal person, it is the beneficial owner's PEP status that must be assessed (Chapter 3, Section 10 of the AML Act). If you learn that a board member, CEO or finance director is a PEP, the Inspectorate says the risk profile must still reflect it. See PEP screening.

How does the independence assessment relate to CDD?

For each engagement, the auditor must assess whether anything could undermine confidence in their impartiality or independence (Section 21 a of the Auditors Act). That yields information on owners, management and related parties, but it does not replace CDD, which assesses money laundering risk. Use the information in both, but document CDD and the risk profile separately. The reporting duty does not end if you resign from the engagement, according to the Inspectorate's guidance.

When must an auditor report suspected money laundering?

You must monitor the relationship and examine deviations (Chapter 4, Sections 1–2). If there are reasonable grounds to suspect money laundering or terrorist financing, you must report to the Swedish Police Authority without delay (Chapter 4, Section 3), in practice to the Financial Intelligence Unit through goAML. According to the national risk assessment, the audit sector filed 84 reports in 2024.

How does this fit with the Swedish Companies Act?

The Swedish Companies Act (2005:551) has its own procedure for suspected crimes: inform the board, then a prosecutor (Chapter 9, Sections 42–44). The Inspectorate notes that the threshold for an AML report is lower.

If you are to report under Chapter 4, Section 3 or 6 of the AML Act, the Companies Act steps must not be taken (Chapter 9, Section 42, third paragraph). You may not disclose an assessment or a report to the customer (Chapter 4, Section 9 of the AML Act).

Which exemptions apply to auditors?

Two exemptions apply to authorised and approved auditors who defend or represent a client in legal proceedings, or assess the client's legal position. The ban in Chapter 3, Section 1, first paragraph then does not apply (second paragraph), nor do the reporting and disclosure duties (Chapter 4, Section 8). The exemptions do not mention audit.

Which risk factors are typical in audit engagements?

Risk factorWhy it matters
Companies used as tools for crimeFalse invoices, undeclared wages, criminal proceeds mixed into turnover.
Repeated bankruptciesA risk indicator according to the risk assessment, as is a representative behind several short-lived companies.
Front men and straw menSomeone other than the registered representative acts, or the representative lacks industry knowledge.
Foreign owners and board membersCan make beneficial owners harder to identify.
Changes of auditorThe customer changes auditor every year or uses different auditors across the group.
Overvalued assetsFor example contributions in kind, or property booked above its purchase price.

The Inspectorate warns against rating a customer low risk only because it handles little cash. See customer risk assessment.

What changes with AMLR in 2027?

From 10 July 2027, AMLR applies directly (Article 90).

Auditors are obliged entities under Article 3(3)(a). The English text reads "auditors, external accountants and tax advisors". The Swedish Official Journal text reads "Revisorer, externa revisorer och skatterådgivare": auditors, external auditors and tax advisors. For auditors, coverage is clear, but accounting firms should read both language versions.

Four changes are particularly relevant:

  • Update intervals. At least every five years, and yearly for higher-risk customers under enhanced due diligence (Article 26(2)). RIFS 2021:1 already requires yearly evaluation. Compare in the review interval tool.
  • Register discrepancies. Reported within 14 calendar days (Article 24(1)).
  • The exemptions remain in Articles 21(2), 24(4) and 70(2), but not if the auditor takes part in money laundering, advises on it or knows the client seeks such advice.
  • More detailed rules. According to the Inspectorate, the EU authority AMLA is drafting technical standards with more detailed CDD requirements.

See AMLR 2027 and customer due diligence.

Checklist: CDD for a new audit engagement

  • Start of the business relationship identified, and CDD completed before it
  • Company verified against a certificate of registration or register extract (RIFS 2021:1, Section 7)
  • Representative's identity and authority verified and copied
  • Beneficial owner established and verified, or the listed-company exemption documented, and register discrepancies notified
  • PEP assessment for the beneficial owner, with known PEPs on the board and in management considered
  • High-risk third country check and sanctions screening
  • Purpose and nature of the engagement, the customer's business and counterparties described
  • Risk profile set to normal, low or high, justified against the business-wide risk assessment
  • At high risk: financial situation and source of funds documented (RIFS 2021:1, Section 8)
  • Independence assessment completed, with CDD documented separately
  • Next evaluation dated, within one year

Key terms are explained in the glossary.

How AKT supports the work

AKT runs the KYC process and brings documents, screening, risk assessment and the decision together in one customer file with a full audit trail. Onboarding, periodic and event-driven review happen in the same file, and a person makes the decision. Read more about AKT for accounting and audit.

Frequently asked questions.

Does an auditor need to register with Bolagsverket's AML register?

Not for audit work. The duty to notify in Chapter 7, Section 3 of the Swedish AML Act applies to the businesses listed in Chapter 7, Section 1, and point 18 is not among them. If your firm also provides accounting or tax advice, that part may be subject to the notification duty.

Can we use the County Administrative Boards' regulations in the audit?

No. Audit work falls under RIFS 2021:1. The Inspectorate has pointed out that the County Administrative Boards' list of simplified measures cannot be used in audit work.

Should we inform the board before reporting to the Financial Intelligence Unit?

No. If the auditor is to report under the AML Act, the steps in Chapter 9, Sections 43 and 44 of the Companies Act must not be taken. You may not disclose to the customer that a report has been made (Chapter 4, Section 9 of the AML Act).

How often must CDD be reviewed?

At least once a year during an ongoing engagement, and more often if the risk requires it (RIFS 2021:1, Section 9). The date, considerations and conclusions of each evaluation must be documented.

How long must CDD records be kept?

Five years after the business relationship ends (Chapter 5, Section 3 of the AML Act). The Inspectorate notes that this differs from the Auditors Act's rules on keeping audit documentation. Information gathered earlier in the relationship may not be deleted just because newer information exists.

See how simple KYC can be.

Book a walkthrough and watch a customer file come together.

  1. 01You book a demo
  2. 02We prepare a relevant example
  3. 03We show the complete workflow

After the demo, you decide whether to continue with a pilot. Nothing is activated automatically.

Prefer email? contact@aktkyc.com

Book a demo of AKT

Make the demo more relevant (optional)
Required

When you submit the form, we use the details to respond to your request and plan the demo. Read our privacy policy.