Resources · Reviewed 28 September 2026

KYC and customer due diligence: a complete guide

Customer due diligence is the core of anti-money laundering rules. You must know who your customer is, who stands behind them and what the business relationship is for. This guide walks through the requirements step by step, with the EU and Swedish legal references.

What is customer due diligence?

Customer due diligence (CDD) is the set of measures an obliged entity takes to understand its customer and the risk in the customer relationship. In everyday language it is called KYC, "know your customer".

The purpose is not to fill in a form. Under Chapter 3, Section 1 of the Swedish AML Act (2017:630), you must know enough about the customer to manage the risk in the relationship and to monitor the customer's activities and transactions. Everything you decide about the customer later builds on this.

Which rules apply: AMLR or the Swedish AML Act?

Two sets of rules matter, and the timing decides which one binds you.

  • The EU Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624, applies directly in every Member State from 10 July 2027 (Article 90). For football agents and professional football clubs it applies from 10 July 2029.
  • The Swedish AML Act (2017:630) applies in Sweden today. Chapter 3 contains the CDD rules.

In Sweden, a government memorandum (Fi2026/01654, July 2026) proposes replacing the Act. It is out for consultation until 30 October 2026. There is no bill yet.

The two frameworks share the same logic. This guide gives the Swedish reference first, because it applies now, and the AMLR article next to it. For a detailed comparison, read AMLR 2027 and customer due diligence.

Who has to carry out customer due diligence?

The rules apply to obliged entities. AMLR Article 3 lists them. They include credit and financial institutions, auditors, external accountants and tax advisors, lawyers and other independent legal professionals for certain services, and estate agents.

In Sweden, Chapter 1, Section 2 of the AML Act lists the businesses covered. Examples:

  • banking and financing business (point 1)
  • payment institutions (point 8)
  • estate agents with the relevant registration (point 14)
  • authorised or approved auditors and registered audit firms (point 18)
  • professional bookkeeping services, such as accounting firms (point 19)
  • tax advisors (point 20)
  • lawyers and other independent legal professionals, for the services in Chapter 1, Section 4 (points 21–22)

The list is longer. Check whether your business is covered. See how the requirements work in your industry.

When must you carry out customer due diligence?

When you establish a business relationship

The main rule is that CDD applies when you establish a business relationship (Chapter 3, Section 4 of the Swedish AML Act; AMLR Article 19(1)(a)). A business relationship is one that is expected to last for some time when it is established (Chapter 1, Section 8, point 1).

Verification of the customer's and the beneficial owner's identity must be complete before the relationship is established (Chapter 3, Section 9). Where the risk is low, verification may happen later if needed to avoid interrupting normal business. It must still be complete no later than when the relationship is established. AMLR Article 23 follows the same pattern.

For occasional transactions

SituationSwedish AML Act (today)AMLR (from 10 July 2027)
Occasional transactionEUR 15,000 or more, including linked transactions (Chapter 3, Section 4)EUR 10,000 or more, including linked transactions (Article 19(1)(b))
Suspicion of money laundering or terrorist financingEnhanced measures to assess the suspicion (Chapter 4, Section 2)CDD regardless of any threshold (Article 19(1)(d))
Doubts about earlier identification dataCovered by ongoing follow-up (Chapter 3, Section 13)Explicit trigger (Article 19(1)(e))

Gambling and cash trading in goods have their own thresholds in Chapter 3, Sections 5 and 6.

When something looks wrong

If you notice deviations or suspicious activity, you must assess them through enhanced due diligence (Chapter 4, Section 2). If you have reasonable grounds to suspect money laundering or terrorist financing, you must report to the Swedish Police Authority without delay (Chapter 4, Section 3).

Throughout the relationship

CDD does not end at onboarding. You must follow up ongoing business relationships regularly and when needed, so that your knowledge stays current and sufficient (Chapter 3, Section 13). The customer's risk profile must be updated when there is reason to (Chapter 2, Section 3). Under AMLR, Article 26 requires ongoing monitoring. Read more in ongoing monitoring.

What does customer due diligence involve?

MeasureWhat the law requiresSwedish AML ActAMLR
Identify and verify the customerIdentity documents, register extracts or other independent, reliable sourcesCh. 3, Section 7Art. 20(1)(a)
Verify representativesIdentity and authority of anyone acting for the customerCh. 3, Section 7, third paragraphArt. 20(1)(i)
Beneficial ownerSearch the register, understand ownership and control, verify identityCh. 3, Section 8Art. 20(1)(b)
PEP checkIs the customer or beneficial owner a PEP, family member or close associate?Ch. 3, Section 10Art. 20(1)(g)
High-risk third countryIs the customer established in a country the Commission has listed?Ch. 3, Section 11Art. 29
Purpose and natureInformation on the purpose and intended nature of the relationshipCh. 3, Section 12Art. 20(1)(c)
Customer risk profileBased on your business-wide risk assessmentCh. 2, Section 3Art. 20(2)
Ongoing monitoringRegularly and when neededCh. 3, Section 13Art. 20(1)(f), Art. 26

Beneficial owner

A beneficial owner is a natural person who ultimately owns or controls a legal person, or on whose behalf someone else acts. A register search alone is not enough for legal persons: you must also understand the ownership and control structure. Read the full guide on beneficial ownership.

Politically exposed persons

If the customer or beneficial owner is a PEP, you must always establish the source of the assets, apply enhanced ongoing monitoring and obtain approval from a senior decision-maker (Chapter 3, Section 19). The same applies to family members and close associates. See PEP screening.

Sanctions

Today, sanctions screening sits outside the CDD rules in the Swedish AML Act. A customer resident in a country subject to sanctions is a factor that may indicate high risk (Chapter 2, Section 5, point 7). Under AMLR, checking whether the customer or beneficial owners are subject to targeted financial sanctions becomes a CDD measure (Article 20(1)(d)). See sanctions screening.

Simplified, standard and enhanced due diligence

The extent of the measures follows the risk. They must be carried out to the extent needed given the customer's risk profile and other circumstances (Chapter 3, Section 14; AMLR Article 20(2)).

  • Standard measures are the starting point for every customer.
  • Simplified due diligence may apply where the risk is low. Checks can be more limited and carried out differently (Chapter 3, Section 15). They do not disappear.
  • Enhanced due diligence is required where the risk is high. Checks must be especially thorough and can include the source of the customer's funds (Chapter 3, Section 16). It is mandatory for customers established in a high-risk third country (Chapter 3, Section 17).

How to set the risk level is covered in customer risk assessment.

What happens if you cannot complete customer due diligence?

You must not establish or maintain the business relationship, or carry out an occasional transaction (Chapter 3, Section 1). An existing relationship you no longer understand well enough should not continue. AMLR Article 21(1) also requires you to terminate the relationship and consider reporting to the financial intelligence unit.

There is an exception for lawyers, other independent legal professionals, auditors and tax advisors when they defend or represent a client in legal proceedings or ascertain the client's legal position (Chapter 3, Section 1, second paragraph; AMLR Article 21(2)).

How should you document and retain CDD?

You must have documented procedures and guidelines for CDD (Chapter 2, Section 8). Records must be kept for five years (Chapter 5, Section 3). The period runs from when the measures were taken or, for a business relationship, from when it ended. You may keep records longer where necessary to prevent, detect or investigate money laundering, but no more than ten years in total (Chapter 5, Section 4).

AMLR Article 77(3) keeps the five-year period and adds a new starting point: the date you refused a relationship or transaction. Article 21(3) requires records of your decisions and the reasons for them.

Record your assessments, not just the documents you collected. The assessment shows that your measures matched the risk. A practical list is in the CDD checklist.

Keep KYC in one customer file

AKT runs the KYC process and brings documents, screening, risk assessment and the decision together in one customer file with a full audit trail. Onboarding, periodic and event-driven review happen in the same file, and a person makes the decision. See how the platform works.

Frequently asked questions.

What is KYC under the Swedish AML Act?

KYC, or customer due diligence, is the set of measures you need to manage the risk in a customer relationship and monitor the customer's activity. It covers identity checks, beneficial ownership, PEP checks, purpose and nature, and ongoing follow-up. The rules are in Chapter 3 of the Swedish AML Act (2017:630).

Must CDD be completed before the first engagement?

Yes. Identity verification of the customer and beneficial owner must be complete before the relationship is established. Where the risk is low it may be finished later, but no later than when the relationship is established (Chapter 3, Section 9).

How long must CDD records be kept?

Five years from when the measure was taken or, for a business relationship, from when it ended (Chapter 5, Section 3). You may keep them longer where necessary to counter money laundering, up to ten years in total (Chapter 5, Section 4).

Can we skip CDD for low-risk customers?

No. Where the risk is low, you may apply simplified due diligence, which can be more limited and carried out differently (Chapter 3, Section 15). The obligation itself still applies.

What if the customer will not provide the information we ask for?

Without sufficient knowledge of the customer, you must not establish or maintain the relationship (Chapter 3, Section 1). If you have reasonable grounds to suspect money laundering, you must also report to the Swedish Police Authority (Chapter 4, Section 3).

See how simple KYC can be.

Book a walkthrough and watch a customer file come together.

  1. 01You book a demo
  2. 02We prepare a relevant example
  3. 03We show the complete workflow

After the demo, you decide whether to continue with a pilot. Nothing is activated automatically.

Prefer email? contact@aktkyc.com

Book a demo of AKT

Make the demo more relevant (optional)
Required

When you submit the form, we use the details to respond to your request and plan the demo. Read our privacy policy.