LODLINE
EN / SV

compliance-sanctions-cyber

Anti-money-laundering duties for non-financial firms: cost and likely outcome

Anti-money-laundering duties for non-financial firms: cost and likely outcome turn on how the business is classified under Swedish law as it currently stands. Real estate agents, accountants, company service providers and dealers in high-value goods must assess risk, verify customers and report suspicions to the relevant authority, at a cost that stays low until an inspection finds the risk assessment missing.

Who this concerns

The duties fall on a defined list of non-financial actors, not on business generally. Real estate agents, accountants and auditors, tax advisers, company and trust service providers, dealers in art and other high-value goods above the relevant threshold, and certain gambling operators are treated in Swedish law as verksamhetsutövare, a regulated party under the anti-money-laundering framework, regardless of whether the firm sees itself as being in the "compliance business" at all. A property agency that closes a handful of transactions a year sits in exactly the same regulatory category as a large accountancy practice, even though the two carry very different exposure.

The trigger is usually a specific transaction or client relationship that raises the question rather than an abstract concern about compliance in general: a cash-heavy buyer, a client structure with several layers of nominee ownership, or a counterparty whose funds arrive from a jurisdiction the firm cannot easily place. That is the situation this material addresses, and it sits within the wider compliance, sanctions and cyber practice rather than being a standalone question.

The position changes once a foreign element enters the picture. Where the counterparty, the ultimate owner, or the parent company sits outside Sweden, the firm's own risk assessment has to extend to that jurisdiction specifically: sanctions exposure, the quality of beneficial ownership disclosure available there, and whether the counterparty's home regulator applies a comparable standard. A group-wide policy drafted for a different jurisdiction does not automatically satisfy the Swedish obligation, and firms that assume it does are usually the ones an inspection catches first.

What the law says

Under Swedish law as it currently stands, the obligations on non-financial verksamhetsutövare sit on a risk-based structure rather than a fixed checklist. The core duties are consistent across sectors even though the supervisory body differs: a documented, firm-specific risk assessment covering the business's clients, products, delivery channels and geographic exposure; customer due diligence carried out before the business relationship starts, and at a level proportionate to the risk identified; verification of beneficial ownership through the register maintained for that purpose; ongoing monitoring of the relationship rather than a one-off check at onboarding; and a duty to report suspicious activity to the relevant financial intelligence authority without alerting the client.

Supervision is sector-specific. Real estate agents typically answer to a different supervisory body than accountants and auditors, who in turn answer to a different one than company service providers. This matters practically because guidance, inspection focus and appetite for enforcement action differ between supervisors even though the underlying statutory duty is the same. A firm that has only ever dealt with one supervisor's expectations can misjudge what a different one will focus on if the business model changes.

Larger firms carry an additional duty to appoint a person responsible for compliance with these obligations and, in many cases, a central point of contact for the supervisory authority. Smaller firms are not exempt from the substantive duties, only from some of the structural requirements that apply once headcount or turnover cross a threshold set out in the applicable regulation.

How it works in practice

Building the risk assessment first

Everything downstream depends on a documented risk assessment that actually reflects the firm's client base, not a template copied from a sector guidance note. An assessment that has not been updated since the firm changed its client mix, expanded into a new type of transaction, or started accepting a new payment method is treated by supervisors as effectively absent.

Setting due diligence tiers by risk

Not every client warrants the same depth of check. The assessment should produce distinct tiers: standard due diligence for low-risk domestic clients, and enhanced due diligence for higher-risk categories such as politically exposed persons, cash-intensive transactions, or clients connected to jurisdictions the firm's own assessment flags as elevated risk.

Enhanced due diligence for politically exposed persons

Where a client, a beneficial owner, or a close associate of either holds or has held a prominent public function, the file needs a documented source-of-funds and source-of-wealth check, senior sign-off on taking the client on, and more frequent review than a standard file. This is one of the areas supervisors test most consistently, precisely because it is the easiest to skip when the relationship looks otherwise unremarkable.

Ongoing monitoring, not a one-off check

A due diligence file completed at onboarding and never revisited is a common finding in enforcement decisions. Monitoring needs a trigger logic: a change in transaction pattern, a change in beneficial ownership, or the passage of a set review period should each prompt a fresh look at the file.

Appointing a responsible officer and reporting line

The person responsible for reporting suspicious activity needs both the authority to report without needing sign-off from a client-facing colleague, and a documented internal escalation route that does not depend on that one person being available. Firms that route everything through a single individual create a single point of failure that becomes visible the moment that person is unreachable when a report needs to go out.

Staff training that matches the actual risk

Generic training modules bought off the shelf rarely map onto the firm's actual client base. Training that references the sector's real risk indicators, and that staff can point to when asked how they were expected to recognise a suspicious pattern, carries more weight in a supervisory review than a completion certificate alone.

Record-keeping and retention

Client identification documents, the risk assessment underpinning each file, and any internal analysis that led to a decision not to report all need to be retained and retrievable, not merely stored somewhere. An inspection that asks for a specific file and receives an incomplete one is treated the same way as an inspection that finds no file at all.

What to check before a supervisory visit

  • Whether the firm-wide risk assessment has been updated since the last material change to the client base or product range
  • Whether every active file has a documented due diligence level consistent with its risk tier
  • Whether beneficial ownership has been verified against the register rather than taken on the client's own statement
  • Whether the person responsible for reporting has actually filed reports where the internal analysis called for one, or whether the function exists only on paper
  • Whether staff training references the firm's own risk indicators rather than a generic module
  • Whether adjacent regulatory obligations, such as an environmental permit, miljötillstånd, have been reviewed alongside the anti-money-laundering file where the client's business depends on one, since supervisors increasingly cross-reference overlapping licensing regimes

Who decides what counts as privileged material in an AML investigation?

Where a firm's own review of a client relationship becomes an internal investigation, questions arise quickly about what can be withheld from a supervisor or a later inquiry. The answer depends on who commissioned the review, in what capacity, and for what purpose, which is addressed in detail in protection of privileged material.

Can weak anti-money-laundering controls trigger shareholder disputes in a Swedish limited company?

Yes, in practice this is a recurring pattern. A supervisory finding or a reporting failure that exposes the company to fines or reputational damage often becomes the basis for a minority shareholder claim that the board failed in its duties, a scenario covered in shareholder conflicts in a Swedish limited company.

Does the Cyber Security Act apply to the same non-financial firms as the anti-money-laundering rules?

Not automatically, and the two regimes have different scopes. Some firms captured by anti-money-laundering duties also fall within the Cyber Security Act's scope depending on their size and sector, which is explained in the entities the Cyber Security Act covers, and the two obligations are best reviewed together rather than in isolation.

The numbers

There is no single figure that answers what compliance costs for a non-financial firm, and any number quoted without reference to the firm's own client base and transaction volume should be treated with caution. What can be said reliably is what drives the cost up or down. A firm with a small, stable client base and simple transactions spends most of its budget on the initial risk assessment and periodic review, and relatively little on ongoing monitoring tooling. A firm with a high volume of transactions, frequent new clients, or clients connected to higher-risk jurisdictions spends proportionally more on due diligence tooling, on enhanced checks for politically exposed persons, and on staff time reviewing flagged files.

Timelines follow the same logic. How long it takes to bring a firm's AML programme to a defensible standard depends on how far the current programme is from that standard, on the size of the client base that needs re-screening, and on the supervisory body's own processing capacity where registrations or approvals are involved. A firm asking how long remediation will take should expect the answer to depend on those specific factors rather than on a fixed period.

Where it usually goes wrong

The most common failure is treating the risk assessment as a document produced once and filed away, rather than a working tool that gets revisited when the business changes. A close second is assuming that a policy written for a parent company's home jurisdiction, or for a different sector supervisor, transfers directly. It does not: the Swedish supervisory expectation for a real estate agent differs materially from that for a company service provider, even where both sit under the same statutory duty.

There is also a reverse case worth naming. Not every business that touches money is in scope. A firm that merely processes payments on behalf of a client without itself acting as the verksamhetsutövare for that transaction, or a business whose only exposure to high-value goods falls below the threshold set in the applicable regulation, may not carry these duties at all. Applying the full weight of the regime to a business that is not actually in scope wastes budget that would be better spent elsewhere, and getting this classification wrong in either direction is itself a recurring source of dispute with a supervisor.

A further boundary sits at group structure. A Swedish subsidiary of a foreign group cannot rely on the group's central compliance function to satisfy the Swedish reporting duty on its behalf; the duty attaches to the Swedish entity, and a supervisor reviewing a Swedish file will not accept "our head office handles this" as an answer.

What to do next

Reading this far establishes where the obligation sits, what it requires, and where firms most often get the classification or the depth of due diligence wrong. What it cannot do is tell a specific firm whether its current risk assessment, its client files, or its escalation route would survive a supervisory visit; that requires looking at the actual documents. Firms whose supplier or subcontractor arrangements carry a comparable compliance exposure often find it useful to review both together, which is covered in security requirements on suppliers and subcontractors. Where the question is specifically whether the current programme would hold up under review, the next step is a scoped assessment; arrange a scope and exposure review rather than continuing to guess at the gap.

Request a preliminary assessment