Resources · Reviewed 28 September 2026

Periodic and event-driven review: how often and when?

Customer due diligence is not finished once the customer is onboarded. You must follow up the business relationship for as long as it lasts, both on a schedule and when something happens. This guide covers what applies today, what changes with AMLR in 2027 and how to set intervals that stand up to supervision.

The legal position is simple to summarise. The EU Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624, applies from 10 July 2027. In Sweden today, the Swedish AML Act (2017:630) applies. Both require you to keep customer due diligence (CDD) up to date throughout the business relationship. The difference is that AMLR sets maximum intervals for how long you may wait.

What does the Swedish AML Act require for ongoing monitoring?

The core rule is in Chapter 3, Section 13 of the Swedish AML Act. You must follow up ongoing business relationships on a continuous basis and when needed. The aim is to keep your knowledge of the customer current and sufficient to manage the assessed risk.

The follow-up covers what you established at onboarding:

  • the customer's identity and its verification (Chapter 3, Section 7)
  • the beneficial owner, ownership and control structure (Chapter 3, Section 8)
  • whether the customer or beneficial owner is a politically exposed person (PEP) (Chapter 3, Section 10)
  • whether the customer is established in a high-risk third country (Chapter 3, Section 11)
  • the purpose and intended nature of the business relationship (Chapter 3, Section 12)

Two more provisions belong here. Under Chapter 2, Section 3, third paragraph, the customer's risk profile must be followed up during the relationship and changed when there is reason to. Under Chapter 4, Section 1, you must monitor ongoing relationships to detect activity and transactions that deviate from what you have reason to expect.

Does the Swedish AML Act say how often to review a customer?

No. The Act sets no fixed intervals for updating CDD. Risk drives the extent. Under Chapter 3, Section 14, measures must be carried out to the extent needed given the customer's risk profile and other circumstances.

That means you set the frequency yourself, in your procedures. The procedures must be documented (Chapter 2, Section 8) and based on your business-wide risk assessment. Where risk is low, follow-up may be more limited (Chapter 3, Section 15). Where risk is high, it must be particularly extensive (Chapter 3, Section 16).

For politically exposed persons the requirement is explicit. You must apply enhanced ongoing monitoring of the relationship and monitor activity and transactions to a greater extent (Chapter 3, Section 19, first paragraph, point 2).

Also check your supervisor's regulations and guidance. They may set more detailed expectations for your sector.

What is the difference between periodic and event-driven review?

The Act speaks of follow-up that is continuous and as needed. In practice that becomes two tracks that complement each other.

Periodic review follows a schedule set by the customer's risk rating. It catches slow changes nobody has flagged, such as a replaced board member or a shift in the business.

Event-driven review starts when new information arrives. It cannot wait for the next scheduled review. If the event affects risk, change the risk profile now, not at the next annual review.

Both tracks should end up in the same customer file. Otherwise you cannot show how your knowledge of the customer has developed over time.

Which events should trigger a new review?

The list below shows common triggers in practice. It is not exhaustive, and none of the items is a verbatim legal requirement. Several link directly to the provisions above.

  • Change in ownership or beneficial owner. New owners, changed voting shares or a new beneficial owner in the register affect the information under Chapter 3, Section 8. See beneficial ownership.
  • New board, CEO or authorised signatory. New representatives must be identified and their authority verified (Chapter 3, Section 7, third paragraph).
  • A sanctions screening hit. A hit must be investigated before the relationship continues. See sanctions screening.
  • Change in PEP status. A customer or beneficial owner who becomes, or ceases to be, a PEP changes which measures apply (Chapter 3, Sections 19–20).
  • Unusual activity or transactions. Deviations you notice must be assessed through enhanced due diligence (Chapter 4, Section 2).
  • New information about the customer. Adverse media, a new line of business or details that do not match what the customer told you.
  • A new assignment or service. It may change the purpose and nature of the relationship (Chapter 3, Section 12).

What changes with AMLR in 2027?

AMLR applies from 10 July 2027 (Article 90). Two things become clearer than in the Swedish Act.

Fixed maximum intervals. Under Article 26(2), the period between updates of customer information depends on risk. It "shall not in any case exceed":

  • one year for higher-risk customers subject to enhanced due diligence (Section 4 of Chapter III)
  • five years for all other customers

Explicit triggers. Under Article 26(3), you must also review and, where relevant, update customer information when:

  • the customer's relevant circumstances change
  • you have a legal obligation during the calendar year to contact the customer to review beneficial ownership information, or to comply with Directive 2011/16/EU on administrative cooperation in taxation
  • you become aware of a relevant fact about the customer

Article 26(4) adds a regular check of whether the customer or beneficial owners are subject to targeted financial sanctions. The frequency must match your exposure. Credit and financial institutions must also check upon every new designation.

Article 21(3) requires you to record your CDD actions, including decisions, supporting documents and justifications. The records must be updated whenever CDD is reviewed under Article 26.

The EU Anti-Money Laundering Authority (AMLA) has consulted on draft guidelines on ongoing monitoring (Article 26(5)). The consultation closed on 3 September 2026. Follow the final guidelines when they are published. For the wider picture, see AMLR 2027: what changes for customer due diligence?

A practical model: risk level, interval and scope

The table shows a method, not a legal requirement. The Swedish AML Act sets no intervals. The only statutory limit is AMLR's maximum from 10 July 2027: one year for customers under enhanced due diligence and five years for everyone else. Adapt the intervals to your business-wide risk assessment and your supervisor's guidance.

Risk levelExample intervalWhat you review
High (enhanced due diligence, PEP, high-risk third country)At least yearly. From 2027, no more than one year under AMLR Art. 26(2)(a).Everything in the standard review, plus source of funds, transaction patterns against expected behaviour and a documented decision to continue the relationship.
MediumFor example every two or three yearsIdentity, representatives, beneficial owner, PEP and sanctions status, purpose and nature, whether activity matches what was expected.
Low (simplified due diligence)For example every five years. From 2027, no more than five years under AMLR Art. 26(2)(b).Check that the information still holds: register details, beneficial owner, sanctions and PEP status.
All levelsOn every trigger eventWhatever the event affects, and whether the risk rating should change.

Two pitfalls are common. First, an event is logged but the risk rating is never reassessed. Second, periodic reviews are postponed without a decision. Both show up at once in a supervisory review. How to build the risk rating is covered in customer risk assessment.

How do you document each review?

In Sweden, records of CDD measures must be kept for five years (Chapter 5, Section 3). The period runs from when the measures were carried out or, where a business relationship was established, from when it ended.

A review you cannot show has, in practice, not happened. Document each review with:

  1. the date and what triggered it (schedule or event)
  2. which information was checked and against which source
  3. what has changed since the last review
  4. the risk rating before and after, with the rationale
  5. the decision: continue, continue with enhanced due diligence, or exit
  6. who made the decision
  7. the date of the next scheduled review

Keep it all in one customer file

AKT runs the KYC process and brings documents, screening, risk assessment and the decision together in one customer file with a full audit trail. Onboarding, periodic and event-driven review happen in the same file, and a person makes the decision. Read more about the platform.

Frequently asked questions.

How often must CDD be updated under the Swedish AML Act?

The Act sets no fixed interval. Under Chapter 3, Section 13, you must follow up the relationship continuously and when needed, so that your knowledge is current and sufficient for the risk. You set the frequency in your documented procedures, based on the customer's risk profile.

What applies from 2027?

From 10 July 2027, Article 26(2) AMLR applies. Customer information must be updated at a risk-based interval. It may never exceed one year for higher-risk customers under enhanced due diligence, or five years for all other customers.

Is periodic review enough?

No. The Swedish AML Act also requires follow-up when needed, and the risk profile must change when there is reason (Chapter 2, Section 3). Article 26(3) AMLR explicitly requires a review when the customer's relevant circumstances change or a relevant fact becomes known.

What should we do if a review reveals deviations?

Deviations must be assessed through enhanced due diligence under Chapter 4, Section 2 of the Swedish AML Act. If there are reasonable grounds to suspect money laundering or terrorist financing, you must report to the Swedish Police Authority without delay (Chapter 4, Section 3).

How long must reviews be kept?

Under Chapter 5, Section 3 of the Swedish AML Act, five years, counted from the end of the business relationship. Article 77(3) AMLR also sets five years, counted among other things from the date the business relationship ends.

See how simple KYC can be.

Book a walkthrough and watch a customer file come together.

  1. 01You book a demo
  2. 02We prepare a relevant example
  3. 03We show the complete workflow

After the demo, you decide whether to continue with a pilot. Nothing is activated automatically.

Prefer email? contact@aktkyc.com

Book a demo of AKT

Make the demo more relevant (optional)
Required

When you submit the form, we use the details to respond to your request and plan the demo. Read our privacy policy.