Are auditors covered by AML rules?
Yes. AMLR, Regulation (EU) 2024/1624, lists "auditors, external accountants and tax advisors" as obliged entities in Article 3(3)(a). It applies directly from 10 July 2027 (Article 90).
Until then, the Swedish AML Act (2017:630) applies. Chapter 1, Section 2, first paragraph, point 18 covers authorised or approved auditors and registered audit firms. Unlike for lawyers, coverage is not limited to certain services. The Swedish Inspectorate of Auditors (Revisorsinspektionen) states that auditors are fully covered.
Providers of audit services without authorisation or approval fall under point 19 instead, with notification to Bolagsverket and County Administrative Board supervision.
Sweden's national risk assessment 2024/2025 rates the sector risk for auditors as significant.
Who supervises auditors in Sweden?
The Swedish Inspectorate of Auditors. Under Section 3 a of the Swedish Auditors Act (2001:883), it supervises how auditors and registered audit firms meet their duties under the AML Act.
For breaches, the Inspectorate can issue a reminder or a warning, or revoke the authorisation or approval (Section 32 of the Auditors Act). A warning can be combined with an administrative fine (Section 32 a). For AML breaches, the maximum is the higher of twice the profit gained or the equivalent of EUR 1 million (Section 32 k).
According to the national risk assessment, the audit firm or the auditor had failed to meet their AML obligations in 61 per cent of the cases in the Inspectorate's supervisory project in 2023 and 2024.
What do the Inspectorate's regulations RIFS 2021:1 require?
The Inspectorate's AML regulations (RIFS 2021:1) have applied since 1 January 2022. They supplement the AML Act and address both the audit firm and the individual auditor.
| Area | Requirement in RIFS 2021:1 |
|---|---|
| Business-wide risk assessment | Services, threats, vulnerabilities and a risk rating (Section 3). Evaluated at least yearly (Section 4). |
| Internal control | At least every three years, one completed engagement per auditor is reviewed (Section 6). |
| Identity verification | External verification. Certified copies when remote. Applies even to customers already known (Section 7). |
| Low and high risk | Identity always verified. At high risk, financial situation and source of funds always obtained (Section 8). |
| Ongoing review | CDD and risk profile evaluated at least yearly (Section 9). |
| Risk levels | Normal, low and high at minimum. Low requires specific circumstances (Section 10). |
| Documentation | Same standard as the audit, organised and searchable (Sections 11–12). |
The County Administrative Boards' regulations do not apply to audit work, so their list of simplified measures cannot be used there. Accounting or tax advice in the same firm may fall under the County Administrative Boards. See KYC for accounting firms.
Who is the customer in an audit engagement?
Under the Swedish AML Act, the customer is the party that has entered, or is about to enter, into a contract with you (Chapter 1, Section 8, point 4). In an audit, that is the audited company, which appoints the auditor and signs the engagement letter.
Auditors have no CDD duty towards their customers' customers. According to the national risk assessment, an auditor still normally needs to form a view of the counterparties.
When is the business relationship established?
CDD applies when the relationship is established (Chapter 3, Section 4), with identity verified before then (Section 9). For statutory audits, the Inspectorate says this may be acceptance of the engagement, election at the general meeting, registration by Bolagsverket or signing of the engagement letter. Engagement letters are often signed just before the audit report, and CDD done only then is usually too late.
Who must have the customer knowledge?
The auditor, not the audit firm, according to the Inspectorate. A support function can collect documents, but the knowledge must reach the auditor. An engagement letter signed with an electronic ID is not in itself an identity check.
Beneficial owners and PEPs
You must establish whether the customer has a beneficial owner, understand the ownership and control structure and verify the owner's identity (Chapter 3, Section 8). This does not apply to companies listed on a regulated market or their subsidiaries (second paragraph).
If there is reason to suspect the beneficial ownership register is wrong, you must notify Bolagsverket (Chapter 3, Section 5 of the Beneficial Ownership Register Act (2017:631)). The Inspectorate considers awareness of this duty to be low.
For a legal person, it is the beneficial owner's PEP status that must be assessed (Chapter 3, Section 10 of the AML Act). If you learn that a board member, CEO or finance director is a PEP, the Inspectorate says the risk profile must still reflect it. See PEP screening.
How does the independence assessment relate to CDD?
For each engagement, the auditor must assess whether anything could undermine confidence in their impartiality or independence (Section 21 a of the Auditors Act). That yields information on owners, management and related parties, but it does not replace CDD, which assesses money laundering risk. Use the information in both, but document CDD and the risk profile separately. The reporting duty does not end if you resign from the engagement, according to the Inspectorate's guidance.
When must an auditor report suspected money laundering?
You must monitor the relationship and examine deviations (Chapter 4, Sections 1–2). If there are reasonable grounds to suspect money laundering or terrorist financing, you must report to the Swedish Police Authority without delay (Chapter 4, Section 3), in practice to the Financial Intelligence Unit through goAML. According to the national risk assessment, the audit sector filed 84 reports in 2024.
How does this fit with the Swedish Companies Act?
The Swedish Companies Act (2005:551) has its own procedure for suspected crimes: inform the board, then a prosecutor (Chapter 9, Sections 42–44). The Inspectorate notes that the threshold for an AML report is lower.
If you are to report under Chapter 4, Section 3 or 6 of the AML Act, the Companies Act steps must not be taken (Chapter 9, Section 42, third paragraph). You may not disclose an assessment or a report to the customer (Chapter 4, Section 9 of the AML Act).
Which exemptions apply to auditors?
Two exemptions apply to authorised and approved auditors who defend or represent a client in legal proceedings, or assess the client's legal position. The ban in Chapter 3, Section 1, first paragraph then does not apply (second paragraph), nor do the reporting and disclosure duties (Chapter 4, Section 8). The exemptions do not mention audit.
Which risk factors are typical in audit engagements?
| Risk factor | Why it matters |
|---|---|
| Companies used as tools for crime | False invoices, undeclared wages, criminal proceeds mixed into turnover. |
| Repeated bankruptcies | A risk indicator according to the risk assessment, as is a representative behind several short-lived companies. |
| Front men and straw men | Someone other than the registered representative acts, or the representative lacks industry knowledge. |
| Foreign owners and board members | Can make beneficial owners harder to identify. |
| Changes of auditor | The customer changes auditor every year or uses different auditors across the group. |
| Overvalued assets | For example contributions in kind, or property booked above its purchase price. |
The Inspectorate warns against rating a customer low risk only because it handles little cash. See customer risk assessment.
What changes with AMLR in 2027?
From 10 July 2027, AMLR applies directly (Article 90).
Auditors are obliged entities under Article 3(3)(a). The English text reads "auditors, external accountants and tax advisors". The Swedish Official Journal text reads "Revisorer, externa revisorer och skatterådgivare": auditors, external auditors and tax advisors. For auditors, coverage is clear, but accounting firms should read both language versions.
Four changes are particularly relevant:
- Update intervals. At least every five years, and yearly for higher-risk customers under enhanced due diligence (Article 26(2)). RIFS 2021:1 already requires yearly evaluation. Compare in the review interval tool.
- Register discrepancies. Reported within 14 calendar days (Article 24(1)).
- The exemptions remain in Articles 21(2), 24(4) and 70(2), but not if the auditor takes part in money laundering, advises on it or knows the client seeks such advice.
- More detailed rules. According to the Inspectorate, the EU authority AMLA is drafting technical standards with more detailed CDD requirements.
See AMLR 2027 and customer due diligence.
Checklist: CDD for a new audit engagement
- Start of the business relationship identified, and CDD completed before it
- Company verified against a certificate of registration or register extract (RIFS 2021:1, Section 7)
- Representative's identity and authority verified and copied
- Beneficial owner established and verified, or the listed-company exemption documented, and register discrepancies notified
- PEP assessment for the beneficial owner, with known PEPs on the board and in management considered
- High-risk third country check and sanctions screening
- Purpose and nature of the engagement, the customer's business and counterparties described
- Risk profile set to normal, low or high, justified against the business-wide risk assessment
- At high risk: financial situation and source of funds documented (RIFS 2021:1, Section 8)
- Independence assessment completed, with CDD documented separately
- Next evaluation dated, within one year
Key terms are explained in the glossary.
How AKT supports the work
AKT runs the KYC process and brings documents, screening, risk assessment and the decision together in one customer file with a full audit trail. Onboarding, periodic and event-driven review happen in the same file, and a person makes the decision. Read more about AKT for accounting and audit.