The legal position is simple to summarise. The EU Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624, applies from 10 July 2027. In Sweden today, the Swedish AML Act (2017:630) applies. Both require you to keep customer due diligence (CDD) up to date throughout the business relationship. The difference is that AMLR sets maximum intervals for how long you may wait.
What does the Swedish AML Act require for ongoing monitoring?
The core rule is in Chapter 3, Section 13 of the Swedish AML Act. You must follow up ongoing business relationships on a continuous basis and when needed. The aim is to keep your knowledge of the customer current and sufficient to manage the assessed risk.
The follow-up covers what you established at onboarding:
- the customer's identity and its verification (Chapter 3, Section 7)
- the beneficial owner, ownership and control structure (Chapter 3, Section 8)
- whether the customer or beneficial owner is a politically exposed person (PEP) (Chapter 3, Section 10)
- whether the customer is established in a high-risk third country (Chapter 3, Section 11)
- the purpose and intended nature of the business relationship (Chapter 3, Section 12)
Two more provisions belong here. Under Chapter 2, Section 3, third paragraph, the customer's risk profile must be followed up during the relationship and changed when there is reason to. Under Chapter 4, Section 1, you must monitor ongoing relationships to detect activity and transactions that deviate from what you have reason to expect.
Does the Swedish AML Act say how often to review a customer?
No. The Act sets no fixed intervals for updating CDD. Risk drives the extent. Under Chapter 3, Section 14, measures must be carried out to the extent needed given the customer's risk profile and other circumstances.
That means you set the frequency yourself, in your procedures. The procedures must be documented (Chapter 2, Section 8) and based on your business-wide risk assessment. Where risk is low, follow-up may be more limited (Chapter 3, Section 15). Where risk is high, it must be particularly extensive (Chapter 3, Section 16).
For politically exposed persons the requirement is explicit. You must apply enhanced ongoing monitoring of the relationship and monitor activity and transactions to a greater extent (Chapter 3, Section 19, first paragraph, point 2).
Also check your supervisor's regulations and guidance. They may set more detailed expectations for your sector.
What is the difference between periodic and event-driven review?
The Act speaks of follow-up that is continuous and as needed. In practice that becomes two tracks that complement each other.
Periodic review follows a schedule set by the customer's risk rating. It catches slow changes nobody has flagged, such as a replaced board member or a shift in the business.
Event-driven review starts when new information arrives. It cannot wait for the next scheduled review. If the event affects risk, change the risk profile now, not at the next annual review.
Both tracks should end up in the same customer file. Otherwise you cannot show how your knowledge of the customer has developed over time.
Which events should trigger a new review?
The list below shows common triggers in practice. It is not exhaustive, and none of the items is a verbatim legal requirement. Several link directly to the provisions above.
- Change in ownership or beneficial owner. New owners, changed voting shares or a new beneficial owner in the register affect the information under Chapter 3, Section 8. See beneficial ownership.
- New board, CEO or authorised signatory. New representatives must be identified and their authority verified (Chapter 3, Section 7, third paragraph).
- A sanctions screening hit. A hit must be investigated before the relationship continues. See sanctions screening.
- Change in PEP status. A customer or beneficial owner who becomes, or ceases to be, a PEP changes which measures apply (Chapter 3, Sections 19–20).
- Unusual activity or transactions. Deviations you notice must be assessed through enhanced due diligence (Chapter 4, Section 2).
- New information about the customer. Adverse media, a new line of business or details that do not match what the customer told you.
- A new assignment or service. It may change the purpose and nature of the relationship (Chapter 3, Section 12).
What changes with AMLR in 2027?
AMLR applies from 10 July 2027 (Article 90). Two things become clearer than in the Swedish Act.
Fixed maximum intervals. Under Article 26(2), the period between updates of customer information depends on risk. It "shall not in any case exceed":
- one year for higher-risk customers subject to enhanced due diligence (Section 4 of Chapter III)
- five years for all other customers
Explicit triggers. Under Article 26(3), you must also review and, where relevant, update customer information when:
- the customer's relevant circumstances change
- you have a legal obligation during the calendar year to contact the customer to review beneficial ownership information, or to comply with Directive 2011/16/EU on administrative cooperation in taxation
- you become aware of a relevant fact about the customer
Article 26(4) adds a regular check of whether the customer or beneficial owners are subject to targeted financial sanctions. The frequency must match your exposure. Credit and financial institutions must also check upon every new designation.
Article 21(3) requires you to record your CDD actions, including decisions, supporting documents and justifications. The records must be updated whenever CDD is reviewed under Article 26.
The EU Anti-Money Laundering Authority (AMLA) has consulted on draft guidelines on ongoing monitoring (Article 26(5)). The consultation closed on 3 September 2026. Follow the final guidelines when they are published. For the wider picture, see AMLR 2027: what changes for customer due diligence?
A practical model: risk level, interval and scope
The table shows a method, not a legal requirement. The Swedish AML Act sets no intervals. The only statutory limit is AMLR's maximum from 10 July 2027: one year for customers under enhanced due diligence and five years for everyone else. Adapt the intervals to your business-wide risk assessment and your supervisor's guidance.
| Risk level | Example interval | What you review |
|---|---|---|
| High (enhanced due diligence, PEP, high-risk third country) | At least yearly. From 2027, no more than one year under AMLR Art. 26(2)(a). | Everything in the standard review, plus source of funds, transaction patterns against expected behaviour and a documented decision to continue the relationship. |
| Medium | For example every two or three years | Identity, representatives, beneficial owner, PEP and sanctions status, purpose and nature, whether activity matches what was expected. |
| Low (simplified due diligence) | For example every five years. From 2027, no more than five years under AMLR Art. 26(2)(b). | Check that the information still holds: register details, beneficial owner, sanctions and PEP status. |
| All levels | On every trigger event | Whatever the event affects, and whether the risk rating should change. |
Two pitfalls are common. First, an event is logged but the risk rating is never reassessed. Second, periodic reviews are postponed without a decision. Both show up at once in a supervisory review. How to build the risk rating is covered in customer risk assessment.
How do you document each review?
In Sweden, records of CDD measures must be kept for five years (Chapter 5, Section 3). The period runs from when the measures were carried out or, where a business relationship was established, from when it ended.
A review you cannot show has, in practice, not happened. Document each review with:
- the date and what triggered it (schedule or event)
- which information was checked and against which source
- what has changed since the last review
- the risk rating before and after, with the rationale
- the decision: continue, continue with enhanced due diligence, or exit
- who made the decision
- the date of the next scheduled review
Keep it all in one customer file
AKT runs the KYC process and brings documents, screening, risk assessment and the decision together in one customer file with a full audit trail. Onboarding, periodic and event-driven review happen in the same file, and a person makes the decision. Read more about the platform.