An Ekobrottsberedskap: fixed-price assessment, what you get and when review has a fixed scope: a documented check of internal controls, reporting lines and record-keeping against a company's exposure to economic crime. It excludes representation in an ongoing police matter. Delivery time depends on entity size and how complete the documentation is at the outset.
Who this concerns
A board, a CFO or a compliance function asks for this review after a signal has appeared but before anyone has decided what to do about it: an unusual payment pattern flagged by the bank, a whistleblower report that names a specific individual, a request for documents from an authority that has not yet escalated into a formal matter, or an upcoming ownership change that surfaces a legacy issue nobody previously looked at closely.
None of these signals amounts to a police matter on its own. What they share is the same question: is the exposure real, and if it is, where does it sit inside the organisation. A fixed-scope, fixed-price review answers that question without committing the company to representation in a proceeding that may never open. It sits within the broader field of economic crime defence work generally: what a company does in the window between a signal and a formal step taken by an authority.
What the law says
Under Swedish law as it currently stands, criminal liability for economic crime attaches to the individual who acted, not automatically to the company itself. A company can still carry its own consequences, from a company-level fine tied to how the offence arose out of the business, to a standing duty to preserve documents and cooperate with an authority once contact has been made, regardless of whether any individual is ultimately charged.
That distinction shapes how a preparedness review is built. It does not ask whether an offence has been committed, that question belongs to a prosecutor and, eventually, a court. It asks whether the company's own records, reporting lines and internal controls would hold up if that question were ever put to them, and whether the people who sit closest to the exposure understand their own position before an authority makes contact.
How it works in practice
What the review actually covers
The assessment maps exposure across four areas: the paper trail behind transactions that could be characterised as economic crime if viewed from the outside, the reporting line that would apply if a concern surfaced internally, the state of retention and access controls over the records an authority would ask for first, and the position of the individuals whose signature or approval sits closest to the transactions in question.
Internal controls and documentation
A working file of contracts, approvals and correspondence is reviewed against what a company would need to produce if asked. Gaps get flagged as gaps, not filled in during the review itself. The point is to know where the file is thin before an authority finds that out first.
Reporting lines and escalation
Who inside the organisation would hear about a concern first, and what happens to it after that, is mapped and tested against what actually happened the last time something similar surfaced, if anything did. A reporting line that exists only on an organisational chart is treated as a gap, not as a control.
Individual exposure
Directors, signatories and anyone whose approval sits on the transactions under review are named in the output, not in general terms. Each is given a plain description of where their own exposure would begin if the matter escalated, separate from the company's exposure, and separate from the limits that discharge from liability places on a board once that question is formally put.
What is not included
The review does not include representation if questioning as a suspect or as a witness has already started, drafting of a defence strategy for a named individual, or attendance at a search of the company's premises once one has been ordered. Those are separate mandates, scoped once there is an actual proceeding to respond to, not a preparedness question to answer.
Where anti-money laundering obligations sit
For a company that falls under anti-money laundering duties that apply to non-financial firms, the review checks whether those duties are being met as a matter of course, not only when a transaction looks unusual. A company that only thinks about this obligation after a signal has already missed the point of having it.
What is checked, in practical terms
- Signature authority against the approvals actually on file for the transactions in question
- Whether a reporting channel for internal concerns exists in practice, not only in policy
- Retention of the documents an authority would request first, and how quickly they can be produced
- Whether any set-off arrangement, kvittning, recorded in the accounts is documented in a way that would survive scrutiny
- Individual exposure for each signatory, kept separate from the company's own position
How the fixed scope is set
The fee is fixed once the scope is agreed, not before. Scope depends on the number of entities involved, the number of individuals whose position needs a separate answer, and how complete the existing documentation already is. A single company with clean records and one reporting line is a narrower mandate than a group structure with several subsidiaries and a history of undocumented approvals.
Does a clean assessment protect directors from personal liability?
No single review removes personal exposure. What it does is separate the company's position from each director's own position and show where discharge from liability actually limits a board's exposure, so that a director knows where their own answer needs to differ from the company's answer, if it ever comes to that.
Does the review check compliance with anti-money laundering duties?
Where the company falls within scope, yes. The review checks whether the duties that apply to non-financial firms are met as a matter of course, and flags gaps in the same file used to check other exposure, rather than as a separate exercise.
Is a set-off entry relevant to an economic crime review?
It can be. A kvittning entry that nets one obligation against another sometimes obscures the underlying transaction rather than clarifying it, which is exactly the kind of entry the documentation review is built to catch.
The numbers
There is no published price list attached to this assessment, and none is given here. What is fixed is the scope: once the number of entities, the number of individuals under review and the state of the existing documentation are known, the fee for that defined scope does not move during delivery. What varies from one engagement to the next is exactly what determines that scope, not a rate card.
Delivery time follows the same logic. It is not set against a calendar date but by how much of the underlying file already exists in usable form and how many individuals need a separate answer about their own position. A single entity with an organised file moves through the review faster than a group structure with several reporting lines and gaps in the record, but neither timeline is fixed in advance of scoping.
Where it usually goes wrong
This assessment stops being the right instrument the moment an authority has already made contact. A search of the company's premises that has already been ordered, or questioning as a suspect or as a witness that has already started, both move the matter from a preparedness question to an active proceeding, and a fixed-scope assessment is the wrong shape for that. What is needed at that point is representation in the proceeding itself, not a review of what the company's records would show if asked.
A second place this goes wrong is when the review is treated as a substitute for fixing what it finds. A documented gap in a reporting line, once identified, still exists until someone closes it. The review states where the file is thin; it does not thicken the file.
A third failure mode sits with groups that include a foreign parent or a counterparty outside Sweden. Documentation held abroad, correspondence in a language other than Swedish, and approvals that ran through a foreign entity all change what the review can actually verify from the material available, and that limitation is stated in the output rather than papered over.
What to do next
Reading this sets out what the review covers, what it does not, and how its scope is set. It does not replace the review itself, and it stops short of the point where an authority has already made contact: if a search of the company's premises has already happened or is imminent, that is a different mandate entirely, and a faster one.
Where a signal exists but no formal step has been taken yet, the next move is an assessment call: a conversation about the entities involved, the individuals whose position needs a separate answer, and the state of the existing file, from which the fixed scope and the fixed fee for this particular company are set. Get in touch to arrange that call.