About this template
AML/KYC & Anti-Money Laundering Compliance 2026/2027 – complete 2-in-1 package in Swedish + English
A comprehensive working and documentation package for Swedish obliged entities subject to anti-money laundering and counter-terrorist financing rules. The package connects business-wide risk assessment, customer due diligence (KYC), beneficial ownership, PEP checks, customer risk classification, enhanced due diligence, ongoing monitoring, suspicion assessment, goAML, confidentiality, internal controls, training, data protection and record retention into one coherent compliance workflow.
2-in-1: seven documents are included in both Swedish and English. You receive 14 document templates in Word + PDF plus an advanced Excel register – a total of 29 delivery files. The Word/PDF series comprises 40 A4 pages across the Swedish and English versions per format series.
The package is based on the current Swedish Anti-Money Laundering and Counter-Terrorist Financing Act (2017:630), relevant supervisory guidance and the risk environment described by Swedish authorities in 2026. EU AMLR Regulation (EU) 2024/1624 will mainly apply from 10 July 2027. The 2027 material is therefore clearly separated as preparation and gap analysis and does not imply that proposed Swedish 2027 legislation is already in force.
What is included in the package
| Document | Swedish | English | Purpose |
|---|---|---|---|
| Compliance plan & scope assessment | 3 pages | 3 pages | Scope, supervision, responsibilities, annual cycle and 2027 change control. |
| Business-wide AML/CFT risk assessment | 3 pages | 3 pages | Products/services, customer types, distribution, geography, threats and vulnerabilities. |
| KYC, beneficial owner & PEP | 3 pages | 3 pages | Identity, authority, UBO, ownership structure, purpose and nature, PEP and high-risk third countries. |
| Customer risk & enhanced due diligence | 2 pages | 2 pages | Risk profile, EDD, senior approval and documented customer acceptance. |
| Monitoring, suspicion assessment & goAML | 2 pages | 2 pages | Deviation analysis, reporting decisions, confidentiality and goAML workflow. |
| Procedures, internal controls, training & data protection | 3 pages | 3 pages | Roles, control plan, training, retention and model risk. |
| Detailed user guide | 4 pages | 4 pages | Step-by-step guidance, common supervisory deficiencies and EU 2027 preparation. |
| AML/KYC Compliance Register – Excel | XLSX | Dashboard + business risk, customers, KYC, PEP, monitoring, SAR/goAML decisions, retention, controls and 2027 gap analysis. | |
A documented policy is not enough unless it is connected to the business's actual risks and customer cases. The package therefore links business-wide risk assessment → customer risk → KYC/UBO/PEP → monitoring → suspicion assessment → goAML → internal control and retention. The Excel register also provides an operational dashboard for ongoing follow-up.
Who is the package for?
The package is intended for businesses that are actually subject to Swedish anti-money laundering legislation. Whether the rules apply depends on the business type and sector. Relevant sectors can include financial firms and certain accounting, bookkeeping, tax, company-service, real-estate brokerage, gambling and other regulated activities. Using a template does not in itself make a company an obliged entity. Always verify Chapter 1, Section 2 of the Swedish Anti-Money Laundering Act and the supervisory authority and regulations applicable to the specific business.
Business-wide risk assessment – the foundation
Swedish AML legislation requires an obliged entity to assess how its products and services may be used for money laundering or terrorist financing and the level of that risk. The assessment should consider products and services, customers, distribution channels and geographical risk factors and be detailed enough to support procedures and other risk-mitigation measures.
The template helps document:
- the size, nature and scope of the business,
- products and services,
- customer types and ownership structures,
- remote, intermediary and digital distribution,
- geographical exposure,
- threats and vulnerabilities,
- inherent and residual risk,
- the design and effectiveness of controls,
- action plans and responsibilities.
Current guidance from the County Administrative Board states that the business-wide risk assessment should be evaluated regularly, at least annually, and more often where necessary because the business or risk environment changes.
KYC – identity, authority and beneficial ownership
The KYC template goes beyond a basic customer form. It documents the customer's identity, representatives and authority, beneficial owner, ownership and control structure, the purpose and intended nature of the business relationship and expected customer behaviour.
Under current Swedish law, the investigation of beneficial ownership should at least include a search of the Swedish beneficial ownership register where applicable. A registry match may not be sufficient in every situation; further independent verification can be required depending on the risk.
PEP – more than a checkbox
If the customer or beneficial owner is a politically exposed person, additional measures apply. The package therefore includes a dedicated PEP gate covering:
- PEP status, family members and known close associates,
- appropriate measures to establish source of wealth and source of funds,
- enhanced ongoing monitoring,
- approval by an authorised senior decision-maker,
- follow-up of former PEPs.
Current Swedish rules require PEP-related measures to continue for 18 months after the person ceases to hold the relevant public function and thereafter where the remaining risk is still high.
Customer risk and enhanced due diligence – EDD
A customer's risk profile should be based on both the business-wide risk assessment and the specific customer due diligence performed. The package helps document customer type, ownership, geography, PEP status, distribution channel, products/services, transaction or activity patterns, financial circumstances and source of funds.
Higher-risk situations require more extensive controls. For high-risk third countries, the templates contain dedicated fields for additional customer and UBO information, purpose and nature, financial circumstances, source of funds and senior-management approval.
Monitoring, deviations and suspicion assessment
Ongoing monitoring is a separate part of the package. A case begins with what has actually been observed and what behaviour was expected. The workflow then documents enhanced KYC, any explanation received, relevant links, source of funds/assets and known risk typologies.
If the assessment results in reasonable grounds to suspect money laundering or terrorist financing, relevant circumstances must be reported to the Swedish Police Authority without delay in accordance with applicable Swedish law. The Swedish Financial Intelligence Unit uses goAML for reports from obliged entities.
Confidentiality / tipping-off
The package keeps suspicion logs separate from customer-facing KYC documentation. An obliged entity must not improperly disclose to the customer or an outside party that a suspicion assessment is being or has been carried out or that information has been submitted to the authorities.
Data protection and record retention
Current Swedish AML legislation contains specific rules on personal-data processing. Documents and information relating to customer due diligence and relevant transactions are normally retained for five years from the statutory starting point. Where necessary to prevent, detect or investigate money laundering or terrorist financing, certain information can be retained longer, but under the current rules the total period must not exceed ten years.
The Excel workbook therefore includes a separate retention register that calculates the ordinary five-year date and distinguishes it from a separately documented decision on extended retention.
Internal controls, training and model risk
The governance document includes roles for management, AML responsibility, central compliance functions and independent review where justified by the size and nature of the business. It also contains a control plan for KYC files, customer risk, PEP/EDD, monitoring, goAML decisions, access rights, retention and training.
If the business uses models for risk assessment, risk classification or monitoring, a dedicated control point covers model-risk management and quality assurance.
The Excel register – operational compliance, not just documents
The included XLSX workbook contains:
- Dashboard with key indicators,
- Business Risk Assessment,
- Products & Services,
- Customer Register,
- KYC & UBO,
- PEP & High Risk,
- Monitoring,
- Suspicion Decision Log,
- Retention,
- Training & Controls,
- 2027 Gap Analysis,
- Evidence Checklist and sources.
Risk levels, retention dates and several control indicators are formula-driven. The workbook is designed to function as a living operational register rather than a static example.
EU AMLR from 10 July 2027 – clearly separated from current Swedish law
Regulation (EU) 2024/1624 has been adopted and will mainly apply from 10 July 2027. During 2026, the Swedish Government also presented proposals to adapt Swedish law, including proposals to replace the current Swedish AML Act and expand certain obligations.
Because final Swedish legislation may still change, the package's 2027 section is designed as a gap analysis and change-control plan. It clearly distinguishes between:
- requirements that apply under Swedish law in 2026,
- EU rules that have been adopted but apply from 2027,
- Swedish legislative proposals that must be re-verified after final parliamentary decisions.
Current risk environment in 2026
The national risk assessment published in 2026 describes a higher overall risk of money laundering and terrorist financing in Sweden than five years earlier. The package is therefore designed so that current official information and the organisation's own experience can be incorporated into the risk model instead of relying on old standard assumptions.
Frequently asked questions
Is this a KYC template for every company?
No. The package is primarily designed for obliged entities subject to AML legislation. Other businesses may have separate reasons to identify customers, but should not treat the package as proof that AML legislation applies to them.
Does the package include a business-wide risk assessment?
Yes. It is one of the core components and covers products/services, customers, distribution channels, geography, threats, vulnerabilities, controls and residual risk.
Are beneficial ownership and PEP checks included?
Yes. The KYC documents cover UBO/beneficial ownership, ownership structure, PEPs, family members/known close associates, EDD and authorised senior approval.
Can I report directly to the Swedish Financial Intelligence Unit using the template?
The template supports internal assessment and documentation. The actual report is submitted through the Financial Intelligence Unit's goAML system under the applicable process. The package does not replace goAML registration or official reporting forms.
How long should KYC records be retained?
Under current Swedish AML legislation, relevant KYC and transaction information is normally retained for five years from the statutory starting point. Specific circumstances may justify a longer period, up to ten years under the current rules.
Are the 2027 rules already Swedish law?
No. AMLR is adopted EU law and will mainly apply from 10 July 2027. Swedish legislative proposals from 2026 must be distinguished from finally enacted Swedish law. The package therefore contains a separate 2027 gap analysis.
Is Excel included?
Yes. This is one of the products where Excel adds significant functionality through live customer records, risk logs, monitoring, retention tracking and implementation follow-up.
Format and delivery
- 14 document templates – 7 Swedish + 7 English.
- 28 document files – DOCX + PDF.
- 1 advanced Excel workbook (XLSX).
- 29 files in total.
- 40 A4 pages per format series across Swedish + English.
- Digital product – no physical item is shipped.
Legal basis and official sources
- Swedish Anti-Money Laundering and Counter-Terrorist Financing Act (2017:630)
- County Administrative Board – business-wide risk assessment
- Swedish Police / Financial Intelligence Unit – goAML and reporting
- Swedish Financial Supervisory Authority – national risk assessment 2026
- Swedish Government – EU anti-money laundering package Fi2026/01654
- Regulation (EU) 2024/1624 – AMLR
- Directive (EU) 2024/1640 – AMLD6
