LODLINE
EN / SV

compliance-sanctions-cyber

Anti-money-laundering duties for non-financial firms: step by step

Anti-money-laundering duties for non-financial firms: step by step run through six stages: confirming scope, completing a firm-wide risk assessment, applying customer due diligence, verifying beneficial ownership, monitoring the relationship, and reporting to the financial intelligence unit once suspicion arises. Each stage leaves a record a supervisor will ask to see; skipping one does not remove the duty to complete the next.

Who this concerns

The duties described here attach to a specific list of business types, not to non-financial firms in general. In Sweden that list covers real estate agents and brokers, accountants and auditors, providers of company formation and administration services, trust and company service providers, dealers in goods where a client pays in cash above a set threshold (art, antiques, jewellery, precious metals, motor vehicles), providers of gambling services, and lawyers and other independent legal professionals when they act in specified transactions: buying or selling real property or a business, managing client funds, securities or other assets, or setting up, running or managing a company, trust or similar structure.

A firm outside this list does not carry the reporting duty even if it occasionally handles large payments; a firm inside it carries the duty even on a single transaction. The compliance, sanctions and cyber practice at Lodline sits at the point where this classification question is usually raised: a firm that has never thought of itself as an obliged entity discovers, mid-transaction, that it is one.

Where the counterparty, the client's ultimate owner, or a parent company sits outside Sweden, two things change. First, due diligence on the beneficial owner has to reach through the foreign layer rather than stop at the first foreign holding company; a foreign corporate registry rarely gives the same assurance as the Swedish one. Second, a transaction routed through a jurisdiction with weaker AML supervision triggers enhanced due diligence almost automatically, regardless of the size of the deal.

What the law says

Sweden's anti-money laundering framework rests on domestic legislation implementing the EU's anti-money laundering directives, and it is enforced sector by sector rather than by a single regulator. Real estate agents answer to the Estate Agents Inspectorate; auditors to the Auditors' Inspectorate; lawyers to the Swedish Bar Association's own supervisory structure; most other obliged non-financial entities, including company service providers, dealers in high-value goods and gambling operators, answer to the relevant county administrative board. Suspicious activity reports go to Finanspolisen, the national financial intelligence unit, regardless of which sector supervisor a firm answers to day to day.

The duties themselves fall into three families under Swedish law as it currently stands: preventive duties (risk assessment and customer due diligence, performed before or at the start of a relationship), reporting duties (filing a report once suspicion crystallises, without waiting for confirmation), and record-keeping duties (retaining the documents that show the first two families were actually carried out). A firm that completes due diligence but keeps no record of having done so is, from a supervisor's point of view, in the same position as a firm that never did it.

How it works in practice

The sequence below is the order supervisors expect to see followed, not a menu.

Step 1: Confirm whether the firm is an obliged entity

Classification is done by activity, not by industry label. A firm offering company formation as one service among many is an obliged entity for that service line even if the rest of its business is unregulated. Document the classification decision itself: which activity brings the firm into scope, and on what basis.

Step 2: Build the firm-wide risk assessment

The risk assessment sits above individual client files. It maps the firm's exposure by client type, product, delivery channel and geography, and it has to be revisited when any of those change materially, not left as a document written once at onboarding. A firm that cannot produce a current risk assessment on request has, in practice, no defensible basis for the due diligence choices it makes downstream.

Step 3: Set the customer due diligence policy before opening a file

The policy decides, in advance, what triggers standard due diligence, what triggers simplified measures, and what triggers enhanced measures. Writing this after the fact, client by client, is the single most common gap a supervisor finds; it converts a systematic control into a series of individual judgment calls that cannot be reconstructed later.

Step 4: Carry out due diligence before the relationship starts

Identity is verified against a reliable, independent source; the purpose and intended nature of the relationship is recorded, not assumed; and, for a corporate client, the ownership and control structure is mapped down to the natural person or persons who ultimately own or control it.

Step 5: Verify the beneficial owner, including through the register

Every Swedish company above the relevant thresholds is required to register its verklig huvudman (beneficial owner) with Bolagsverket, and checking that register is part of due diligence, not a substitute for it. The register reflects what the company has declared; it does not verify that the declaration is accurate. A firm relying on the register entry alone, without cross-checking it against the client's own documentation, has not completed this step.

Step 6: Monitor the relationship, not only the onboarding

Ongoing monitoring means comparing actual activity against the profile built at onboarding and flagging deviations, whether the deviation is a sudden increase in transaction value, a change in the counterparties involved, or a change in the ownership structure itself. A relationship that was low-risk at onboarding does not stay low-risk by default.

Step 7: Recognise the trigger for a suspicious activity report

The trigger is suspicion, not proof. A firm does not need to establish that laundering has occurred; it needs to notice that a transaction or client relationship does not fit the pattern the firm would expect, and to act on that observation rather than explain it away internally. Waiting for certainty before reporting is itself a failure to comply.

Step 8: File the report and preserve the underlying record

The report goes to Finanspolisen through the reporting channel available to the firm's sector. Filing the report does not close the file: the underlying documents, the risk assessment, the due diligence file and the internal decision trail have to be kept and available for the retention period set by the applicable rules.

What to check before treating the process as complete:

  • Whether the classification decision under Step 1 is documented, not assumed.
  • Whether the risk assessment is current, not the version written at firm setup.
  • Whether the due diligence policy sets thresholds in advance, rather than being applied case by case.
  • Whether beneficial ownership has been verified against the client's own documents, not only against the register.
  • Whether monitoring has actually flagged and closed out any deviations recorded since onboarding.
  • Whether staff involved know who internally receives an internal suspicion report before it becomes an external one.
  • Whether the firm can produce, on short notice, the file that shows each of the above was done.

How this differs when a foreign parent or foreign shareholder is involved

A Swedish subsidiary of a foreign group cannot rely on due diligence performed by the parent unless that reliance is itself documented and the parent's own procedure meets the Swedish standard; a group-wide policy written for the parent's home jurisdiction is not, by itself, a defence for the Swedish entity's own file.

Frequently asked questions

What happens if a firm discovers, partway through onboarding, that it is an obliged entity and has not completed a risk assessment?

The relationship should not proceed to completion on the existing basis. The firm needs a risk assessment and a due diligence file that covers the client actually onboarded, built now rather than backdated; a backdated file is worse than an honestly late one, because it converts a gap into a misrepresentation.

Does a single high-value transaction trigger the same duties as an ongoing client relationship?

Yes, where the firm is an obliged entity for that transaction type. The duties are triggered by the activity, not by whether the relationship continues afterwards; a one-off deal above the relevant threshold carries the same due diligence and reporting duty as a standing client file.

Who inside the firm should receive an internal suspicion before it is reported externally?

A named person with the authority to decide, and a route to escalate, is the minimum. A firm without a designated internal contact leaves the decision to whoever happens to notice the anomaly, which is itself a control gap a supervisor will identify quickly.

The numbers

The regulations set specific cash-payment thresholds that bring a dealer in goods into scope, specific timeframes for filing a report once suspicion arises, and a minimum period for retaining due diligence records after a relationship ends. Those figures are set in the applicable Swedish anti-money laundering rules and are revised from time to time; a firm that builds its policy around a remembered figure rather than the current text of the rule risks working to a threshold that has since moved.

The reliable approach is to treat the categories above, cash threshold, reporting timeframe, retention period, as fixed points a policy must address, and to source the current figure for each directly from the rule in force at the time the policy is written or reviewed, under Swedish law as it currently stands.

Where it usually goes wrong

The risk assessment written once at firm setup and never revisited is the most common single gap; a firm's client base, products and geography change, and a static risk assessment stops describing the business it was written for within a year or two.

Reliance on group policy without a documented reliance decision is close behind. A Swedish entity that adopts the parent's onboarding pack wholesale, without recording why that pack meets the Swedish standard for this client and this transaction, has not completed its own due diligence file; it has borrowed someone else's.

The beneficial ownership register is treated as a verification step rather than a starting point more often than firms expect. Bolagsverket's register reflects a declaration; it does not confirm the declaration's accuracy, and a supervisor reviewing a due diligence file will ask what was checked beyond the register entry.

Internal suspicion is filtered through commercial judgment before it reaches the person who decides whether to report. A relationship manager who decides, on commercial grounds, not to escalate an anomaly to the compliance function has made a decision that belongs to someone else; the duty to report sits with the firm, not with the individual who first noticed the anomaly.

Lawyers and other legal professionals sometimes assume privilege removes the reporting duty entirely. It narrows it, for advice given in the course of legal proceedings or in assessing a client's legal position, but it does not remove the duty where the professional is acting in one of the specified transactional roles, such as company formation or managing client funds; the boundary between advice and transactional involvement is where this exception is most often misapplied.

None of these gaps are visible from outside the firm until a transaction, an audit or a supervisory visit forces the file open. By then, the choice is between a file built properly from the start and one built to explain a gap after the fact, and the second is materially harder to defend.

What to do next

Working through the eight steps above resolves the classification question and produces most of the documentation a supervisor will ask for. It does not resolve two things a firm typically cannot assess alone: whether a specific counterparty or transaction structure sits close enough to a sanctioned party or a high-risk jurisdiction to require enhanced measures, and whether an existing due diligence file would survive a supervisory review as it stands today.

The first of those is what a sanctions and counterparty screening review is built to answer, working from the counterparty list a firm already has rather than from a general policy. The second is a question worth putting to us directly: an assessment call is where we look at the specific file, not the general obligation, and say what it would take to close the gap.

Request a preliminary assessment