EU’s new AML package: key changes and recent EU and Swedish developments

news
05 Oct 2026
Insights

On 10 July 2027, large parts of the EU’s new regulatory package on anti-money laundering and countering the financing of terrorism ("AML Package") will begin to apply. The AML package was adopted by the EU in spring 2024 and consists of the Sixth Anti-Money Laundering Directive  ("AMLD6"), the new Anti-Money Laundering Regulation  ("AMLR") and the regulation establishing the EU Authority for Anti-Money Laundering and Countering the Financing of Terrorism ("AMLAR"). The AML package represents a comprehensive reform of the EU’s anti-money laundering framework and marks a clear shift towards a more harmonised and uniform system within the EU. At the same time, stricter requirements are being introduced in several areas, and supervision is being partly centralised from national to EU level through the new EU Authority for Anti-Money Laundering and Countering the Financing of Terrorism ("AMLA").

For businesses already covered by the current anti-money laundering framework, the new requirements primarily mean that internal policies and processes may need to be adapted. At the same time, the scope of the framework is changing, with the result that some businesses not currently covered may become covered, while others may fall outside its scope. The final delineation will, however, depend in part on how the framework is implemented in Swedish legislation.

Key changes under the AML package

The AML package introduces a more detailed and comprehensive framework than the current framework, while introducing new obligations for the obliged entities concerned.

The principal changes include the following:

  • Expanded scope of obliged entities. The scope is extended to cover additional categories of obliged entities, including certain financial institutions, holding companies and traders.
  • New requirements relating to targeted financial sanctions. A common framework is introduced for internal policies and controls relating to targeted financial sanctions. Obliged entities must assess the risk of such sanctions being evaded or not implemented and establish appropriate measures and controls.
  • Stricter requirements for customer due diligence, ongoing monitoring and record-keeping. The information to be obtained and verified concerning the customer and its beneficial owner as part of customer due diligence measures will be more extensive and detailed. More detailed requirements are also introduced for the ongoing monitoring and follow-up of business relationships and for record-keeping.
  • Stricter requirements for governance, organisation and internal controls. Under the current framework, obliged entities must adapt their organisation and allocation of responsibilities to the risks of their business. At the same time, the requirements for internal policies, control procedures and the business-wide risk assessment are becoming more detailed.
  • New outsourcing requirements. The requirements for engaging external service providers are clarified, with tasks permitted to be outsourced only if certain conditions are met and the supervisory authority has been notified before the engagement begins.
  • New requirements for cross-border activities. Obliged entities that intend to carry out activities in another Member State for the first time must notify the competent authority in their home Member State.
  • Limits to large cash payments. A limit of EUR 10 000 is introduced for making or accepting cash payments in exchange for goods or services.
  • Lower threshold for when customer due diligence measures must be applied. The threshold for customer due diligence measures in respect of occasional transactions is lowered from EUR 15 000 to EUR 10 000, whether the transaction is carried out in a single operation or through linked transactions. For cash transactions, certain customer due diligence measures must be applied if the value is at least EUR 3 000. Separate lower thresholds apply in certain cases, including transfers of funds, crypto-asset transactions and gambling services.
  • Establishment of AMLA (the new EU Authority). AMLA will have both a coordinating role and direct supervisory responsibility for selected high-risk operators in the financial sector. National supervisors will remain responsible for the supervision of other obliged entities.

Member States will retain some discretion to adopt national rules when implementing AMLD6 and where the AMLR permits national choices. The detailed content and application of certain requirements will also be further developed through delegated acts, technical standards and guidelines at EU level.

The AMLR will be directly applicable from 10 July 2027. However, in respect of football agents and professional football clubs, it will apply from 10 July 2029. AMLD6 must generally be transposed into national law by 10 July 2027. Certain provisions have earlier or later transposition deadlines, including the rules on registers of beneficial ownership information, which were required to be transposed by 10 July 2025 or 10 July 2026, and the rules on a national single access point for real estate information, which must be transposed by 10 July 2029.

New categories of businesses are covered

The AML package expands the range of obliged entities subject to the AML framework compared with the current rules.

Certain holding companies are brought within the scope of the new framework. Financial holding companies, mixed financial holding companies, financial mixed activity holding companies, insurance holding companies and insurance mixed-activity holding companies are included in the definition of a financial institution. Non-financial mixed activity holding companies with at least one obliged entity subsidiary are also within scope.

The categories of traders within scope also change. Under the current framework, traders are covered to the extent that payments are made or received in cash in an amount of EUR 10 000 or more. That approach has proved ineffective, partly because of poor understanding and application of the requirements. As a result of the new EUR 10 000 limit on cash payments, persons trading in goods will as a general rule no longer be covered by the framework, except where they are covered under national rules. Instead, traders in certain types of goods are covered, including precious metals, precious stones and cultural goods, as well as traders in other high-value goods, including jewellery, watches, motor vehicles, aircraft and watercraft.

The scope is also extended to crowdfunding service providers, more activities relating to crypto-asset services, and credit intermediaries for mortgage and consumer credits. It also covers investment migration operators, football agents and professional football clubs.

The Member States may also extend the scope to additional obliged entities on the basis of existing national rules and national risk assessments.

Technical standards and guidelines at EU level

The further specification of the framework at EU level will be highly significant for its practical application. This work is ongoing, and during 2026 AMLA has published draft technical standards and concluded consultations on several of them. These include technical standards on customer due diligence measures, criteria for identifying business relationships and occasional transactions, risk assessments for obliged entities in the non-financial sector, and the format for reporting suspicious transactions. The draft on reporting includes, among other things, templates for reporting suspicions tailored to different categories of obliged entities.

AMLA’s published material also includes draft guidelines on business-wide risk assessments and ongoing monitoring of business relationships. AMLA is also working to identify which entities will be subject to the Authority’s direct supervision when supervisory activities begin. In addition, further technical standards, guidelines and delegated acts are expected to provide more detailed specification of parts of the framework.

Adaptation to Swedish law

On 6 July 2026, the memorandum Fi2026/01654, EU’s Anti-Money Laundering Package, was published, containing proposals for how Swedish legislation should be adapted to the EU’s new AML package. The Money Laundering and Terrorist Financing (Prevention) Act, the Beneficial Ownership Registration Act and the Accounts and Safe-Deposit Boxes Register Act are proposed to be replaced by a new money laundering act, a new beneficial ownership act and a new act on a register of accounts, safe-deposit boxes and virtual IBANs. The term "obliged entity" is proposed to replace the term "operator" in line with the terminology in the AMLR. 

The proposal includes, among other things, that Sweden will make use of the option to bring additional businesses within the scope of the framework. Businesses operating pawnshops or trading in goods for cash are proposed to remain within scope, with a Swedish threshold of SEK 55,000 applying to the latter category. The prohibition on cash payments exceeding EUR 10 000 is proposed to be introduced without a lower Swedish threshold. Infringements may be subject to administrative fines, but will not be criminalised.

The Act on Certain Financial Activities is proposed to be repealed. The registration requirements are instead to be incorporated into the new money laundering act, under which the relevant businesses would continue to be required to register with the Swedish Financial Supervisory Authority.

Registration requirements are also proposed for certain holding companies. The Swedish Financial Supervisory Authority is proposed to be responsible for supervising financial holding companies, while supervision of non-financial mixed activity holding companies is to be exercised by the authority supervising the relevant subsidiary.

Several non-financial businesses are proposed to continue to be registered with the Swedish Companies Registration Office and to be subject to supervision by the County Administrative Boards. The County Administrative Board of Stockholm County is also proposed to have specific supervisory responsibility for lawyers and law firms.

The register of beneficial owners is proposed to be expanded, and the Swedish Companies Registration Office is to have greater responsibility for verifying the accuracy of the information. The register of accounts and safe-deposit boxes is proposed to be replaced by a register that also covers virtual IBANs and gambling accounts.

The memorandum has been circulated for consultation, with the consultation period running until 30 October 2026. The legislative amendments are proposed to enter into force mainly on 10 July 2027.

Amendments have previously been made to the Beneficial Ownership Registration Act and the Public Access to Information and Secrecy Act, including with regard to disclosure of information from the register and confidentiality of certain register information.

Changes to the annual anti-money laundering reporting to the Swedish Financial Supervisory Authority

The Swedish Financial Supervisory Authority has announced that the annual anti-money laundering reporting will be updated from 1 January 2027. The current reporting will be replaced by new questions on firms’ inherent risks and control environments, in line with the forthcoming common EU risk classification methodology. All businesses covered by the Money Laundering Act and supervised by the Swedish FSA must report using the new form.

The reporting period remains unchanged and runs from 1 January through 31 March. The first report under the new rules must relate to the reporting date of 31 December 2026 and be submitted through the Swedish FSA's reporting portal, Fidac. Further information on the content of the reporting is expected during autumn 2026.

What should businesses do now?

In view of the extensive changes, businesses should begin analysing how the new framework affects their operations. This includes reviewing internal policies and procedures, analysing existing customer due diligence processes and control functions, and assessing the need for system adaptations and organisational changes. Businesses should also ensure that outsourcing arrangements and cross-border activities comply with the new requirements and plan training for the board, management and relevant functions.

DLA Piper is monitoring developments in the EU’s new AML package and assists businesses with regulatory analyses and the adaptation of internal governance documents, policies and processes. We also support businesses in their dialogue with supervisory authorities and provide training.