Compliance, sanctions and cyber security work at Lodline covers three linked obligations for companies operating in or through Sweden: anti-money laundering duties, sanctions screening and export controls, and cyber security incident reporting. The practice runs as fixed-price products for defined questions and as scoped advisory work for open matters, with a preliminary assessment deciding which route fits.
Who this concerns
The practice concerns companies whose Swedish operations create exposure in at least one of the three areas above, not necessarily all three at once. A payments firm may need an anti-money laundering programme review with no cyber security question in sight. A manufacturer supplying defence and security clients may need sanctions and export control advice without a live money laundering issue. A group running a shared IT estate across several jurisdictions may need cyber incident reporting readiness independent of either.
Foreign-owned Swedish subsidiaries are a recurring client profile. A group compliance framework written for a US, German or UK parent rarely maps directly onto Swedish notification duties, screening thresholds, or the accountability a Swedish board is expected to carry personally. The gap tends to surface at the worst moment: during an actual incident, a sanctions hit on a counterparty, or a supervisory request for evidence that a written policy is also a working one.
This work sits inside Lodline's broader practice overview, which groups compliance, sanctions and cyber security alongside the areas it most often intersects with in a live matter, including corporate and data protection questions.
What the law says
Sweden implements EU sanctions regimes and applies anti-money laundering, terrorist financing prevention and cyber security incident reporting duties under Swedish law as it currently stands. These obligations run across separate regulatory tracks rather than one consolidated compliance code. Anti-money laundering and know-your-customer duties attach to regulated financial and payment businesses and to certain non-financial sectors named by the applicable regime. Sanctions obligations attach to any company transacting with a listed person, entity, vessel or jurisdiction, regardless of sector or company size. Cyber security incident reporting attaches to operators of essential or important services and to any organisation handling personal data where an incident affects that data.
None of the three tracks is optional because a company is small or privately held. Obligation attaches to the activity, not to turnover or headcount, and the enforcement exposure follows the same logic: a missed screening step or an unreported incident carries the same legal consequence for a small supplier as for a listed group, even where the practical response differs by size.
How it works in practice
Anti-money laundering and know-your-customer programmes
Scope here starts with whether the company falls under an anti-money laundering obligation at all, and if it does, what tier of customer due diligence applies to its customer base. Work typically covers a risk assessment specific to the business model, customer onboarding checks calibrated to that risk assessment, ongoing monitoring once a customer relationship is live, and a reporting line for suspicious activity that someone in the organisation actually owns. A programme that stops at onboarding and does not monitor existing relationships is common, and it is also the first thing a supervisory review tests.
Sanctions screening, licensing and trade controls
Screening needs to reach beneficial owners and intermediaries, not only the counterparty named on an invoice. Companies moving dual-use or defence-related goods carry an additional layer: export licensing decisions that depend on end use and end user, not only on the product classification. Indirect exposure through freight forwarders, agents or logistics partners is where screening programmes most often have a blind spot, because the sanctioned party never appears as the direct contracting counterparty.
Cyber security incident detection and reporting
The technical side of detection is usually the part companies have already invested in. The part that fails is the decision side: who has the authority, once a suspicious event is flagged, to classify it as a qualifying incident and start the reporting clock, without waiting for a committee to convene first. Work here covers building that decision chain, defining what counts as a qualifying event for this specific business, and coordinating the cyber reporting duty with any parallel personal data breach duty triggered by the same event.
Personal data transfers and third-country risk
Transfers of personal data outside the EEA raise a separate question from either sanctions or cyber security: whether the transfer has a documented legal basis and, where required, a transfer impact assessment covering the receiving jurisdiction. This is a narrow, well-defined question in most cases, which is why it is one of the areas offered as a fixed-price assessment rather than open-ended advisory work.
Fixed-price products and scoped advisory work
Some questions in this practice have a single, definable deliverable and a fixed price: a specific transfer assessment, a specific sanctions exposure check on a named counterparty list, a defined policy review against current obligations. Building or repairing a programme from scratch, or responding to an incident already underway, does not fit a fixed unit because the starting point, an incomplete customer file, a supply chain with several intermediaries, an event already in progress, is different in every matter. That work is scoped after a preliminary assessment and billed against the actual time and complexity involved. Short analyses of recurring questions in this area are collected in the practice briefings.
How a compliance matter runs at Lodline
A matter starts with a preliminary assessment call, where the actual question is separated from the assumed one: which of the three tracks applies, what documentation already exists, and whether a fixed-price product answers it or the work needs to be scoped. Scoped matters move into a defined work plan with named deliverables and checkpoints, rather than open-ended retainer hours. Fixed-price products are delivered against a single agreed brief with no further scoping call required.
What to check before a preliminary assessment
- Which of the three regulatory tracks actually applies to the current activity, rather than which one was assumed to apply
- Whether beneficial ownership records used for screening are current, not carried over from onboarding
- Whether the screening tool in use reaches indirect counterparties, agents and logistics partners, not only direct contracting parties
- Whether the cyber incident reporting chain has a named decision owner and has been tested, not only documented
- Whether cross-border personal data flows have a recorded legal basis on file
- Whether a group compliance framework has been mapped against Swedish-specific obligations, rather than assumed to transfer as written
FAQ
#### Does compliance work at Lodline cover clients in the defence and security sector specifically?
Yes. Companies supplying defence and security sector clients typically carry export control and sanctions exposure on top of standard anti-money laundering duties, because the end use and end user of the goods or services matter as much as the customer's identity. Screening and licensing work for this sector is scoped around the specific products and export destinations involved, rather than treated as a generic sanctions check.
#### What is a husrannsakan and why does it matter for compliance planning?
A husrannsakan is a search of premises carried out by Swedish authorities under a legal search order. Companies in regulated or sanctions-exposed sectors sometimes build this scenario into incident response planning: who has authority to respond on site, what must be preserved rather than altered, and how legal counsel is brought in before any document or device is handed over. See the glossary entry on husrannsakan for how the procedure itself works.
#### How does a kontrollbalansräkning obligation interact with sanctions or compliance exposure?
A kontrollbalansräkning is a control balance sheet a Swedish board must prepare once share capital has fallen below a set threshold, triggering separate personal duties for the board. It is not a sanctions or compliance instrument in itself, but the financial distress that triggers it often coincides with the period a company is also managing a live sanctions or compliance issue, which is why boards facing one rarely want to face both without coordinated advice. See the glossary entry on kontrollbalansräkning.
The numbers
None of the three areas in this practice is governed by a single headline figure that applies across the board. Screening thresholds, incident reporting windows and export licensing categories vary by sector, by the nature of the counterparty, and by whether personal data is involved, and each is set under Swedish law as it currently stands rather than by a number this page can state in the abstract without reference to a specific case.
What can be said in general terms: a fixed-price product covers one clearly defined question, such as whether a specific data transfer outside the EEA needs a documented legal basis. Building or repairing a programme, or responding to a live incident, is scoped work priced against the actual time and complexity of that matter, because the starting point is never the same twice.
Where it usually goes wrong
The three areas are usually run as separate projects with separate owners, and that is where gaps open. A screening tool that checks direct counterparties but not intermediaries, agents or logistics providers passes an internal audit and still misses the exposure that later becomes a real problem. An anti-money laundering programme built around onboarding but silent on ongoing monitoring looks complete on paper and fails the moment a customer's risk profile changes after the relationship has started.
Cyber security incident reporting fails less often on detection than on decision-making: nobody has been given clear authority to decide, inside the reporting window, whether an event qualifies for notification, so the window closes while the question is still being escalated internally.
Foreign parent frameworks create their own version of this problem. A global sanctions policy written for a US or EU headquarters usually assumes one point of screening and one regulator. Swedish subsidiaries with local suppliers, local payroll and local incident reporting duties operate under a parallel set of obligations the parent framework does not cover, and the gap is usually found by a Swedish authority before it is found internally.
Self-guided review closes part of this. It does not close the part that depends on reading an actual contract, an actual screening log or an actual incident timeline against the current legal position, which is where a preliminary assessment starts.
What to do next
A preliminary assessment is the starting point for matters in this practice: a structured review of which of the three areas actually applies, what is already in place, and whether the right route is a fixed-price product or scoped advisory work. Book a preliminary assessment to start that review.
Companies with a narrow, defined question, for example whether a specific transfer of personal data outside the EEA needs a documented legal basis, can go directly to the relevant fixed-price data transfer product instead of a full assessment. Broader programme reviews, sanctions exposure across a supply chain, or an incident already underway are scoped after the initial call.