The EU's Anti-Money Laundering Regulation (AMLR) does not just change the rules for Nordic banks. It changes how often the rules change.
One is a project you finish. The other is a property your system has to have.
The AMLR requirements for banks in Sweden, Norway, and Denmark take effect on 10 July 2027, less than twelve months from now. The date is the easy part.
- 90–91%
The average false-positive rate Nordic banks reported over the past 12 months, according to EY's 2025 Nordic AML Transaction Monitoring Survey. It holds steady whether the bank manages €1 billion or €80 billion in assets.
- €137.8 million. The combined value of recent AML enforcement actions against Nordic banks.
Two big numbers, one shared cause. Here is how they connect, market by market.

Which AMLR requirements apply in Sweden, Norway, and Denmark
MarketRoute into AMLRApplies fromNational statusSwedenDirect. EU member state, no transposition step10 July 2027SOU 2024:58 aligns national law; Finansinspektionen publishing AMLR guidanceDenmarkDirect. EU member state, no transposition step10 July 2027Finanstilsynet has confirmed direct application of AMLR and urged early preparationNorwayIndirect. EEA incorporation plus national implementing law10 July 2027, subject to final legislationWorking group reported January 2026; consultation closed April 2026
One regulation, three routes, one date. The detail sits below.
AMLR requirements for banks in Sweden
Swedish banks take AMLR directly. As an EU member state, Sweden applies Regulation (EU) 2024/1624 without a transposition step. This means your compliance function works from the EU text itself rather than from a Swedish adaptation of it.
That is a sharper break than it sounds.
Swedish AML practice has been shaped for years by national interpretation layered on top of EU directives. AMLR removes that layer. Where Finansinspektionen previously set the operative detail, AMLA now issues the technical standards, and they apply identically in Malmö and in Milan.
Finansinspektionen has been active on enforcement in the run-up. Klarna Bank received a formal reprimand and a SEK 500 million sanction fee in December 2024, after the regulator found the bank's general risk assessment lacked any evaluation of how its own products could be exploited for money laundering. Svea Bank followed in December 2025 with a reprimand and a SEK 170 million fee, after an inspection found fundamental gaps in the risk assessments of 11 higher-risk clients out of 70 examined.
Both findings point at the same thing:
risk assessment logic that had not kept pace with what the business had already become.
AMLR requirements for banks in Denmark
Danish banks are in the same position as Swedish ones.
AMLR applies directly from 10 July 2027, and Finanstilsynet has been explicit that firms should start preparation early, given how much of the existing rulebook changes at once.
The Danish enforcement record shows the same pattern as Sweden's.
Saxo Bank accepted a DKK 313 million administrative fine in January 2026 for a breach of the Danish AML act. Danske Bank received two supervisory orders after a 2025 inspection, with the regulator rating its inherent money laundering risk as high, citing size, customer portfolio, product range, and geographic exposure. Jyske Bank received an order and a reprimand in mid-2026 – not for a missing control, but for alarm-handling delays between September 2024 and May 2025 that put timely reporting at risk.
That last one is worth sitting with:
Jyske Bank had the system. What it did not have was the throughput to act on what the system produced.
Under AMLR, that gap gets tested more often.
AMLR requirements for banks in Norway
Does AMLR apply to Norway?
Yes, though not directly.
Norway is the member of the European Economic Area (EEA) rather than the EU, so AMLR reaches Norwegian banks through EEA incorporation and national implementing legislation rather than by direct application.
The destination is the same. The path is slightly different.
The timeline is well advanced. A government working group delivered its implementation report in January 2026. A public consultation closed in April 2026. Finans Norge, the Norwegian financial industry body, has explicitly called for adopting the same 10 July 2027 date as the EU rather than lagging behind it.
For a bank operating only in Norway, this is a scheduling question. For a bank operating across more than one Nordic market, it is an architecture question. You now have two axes to keep configurable: not only what the rule says, but which version of it applies where, and on what timeline. A rule set that cannot carry jurisdiction as a variable will need parallel maintenance in perpetuity.
Norway's own enforcement history makes the stakes concrete. DNB was fined NOK 400 million by Finanstilsynet in 2021, after an inspection found significant, longstanding gaps in AML compliance – gaps the regulator considered serious enough to conclude that anti-money laundering could not have received adequate priority in the bank's governance.
The Nordic starting point is harder than most banks assume
EY surveyed 20 banks across Sweden, Norway, Denmark, and Finland between January and March 2025. The headline finding:
false positives sit at 90% for small and medium-sized banks and 91% for large ones.
Nine alerts in every ten are noise.
Read that again. Size buys almost nothing. This is not a gap between well-resourced and under-resourced institutions. It is a gap between what current systems do and what the job now requires.
The survey traces the cause to system design.
Among banks reporting dissatisfaction with their transaction monitoring systems (40% of small and medium-sized banks) the complaint was specific: a lack of flexibility in adapting models and rules.
When a rule engine cannot be retuned without a vendor change request, false positives do not get fixed. They accumulate.
What follows is a sector splitting in two:
- Large banks are automating down.
40% have automated parts of their investigation workflow, 80% have built dedicated FIU units, and 40% expect to shrink investigator headcount. - Small and medium-sized banks are hiring up.
Zero percent (!) report any automation in alert handling, 67% still run each case end-to-end through a single investigator, and 47% expect to grow investigator headcount.
Volume is not stabilizing either.
Only 3 of the 20 banks surveyed expect alert numbers to fall, citing growing customer bases, instant payments, and new financial crime typologies.
What AMLR changes
Here is what the regulation does in practice to a Nordic bank's compliance function.
- Customer due diligence (CDD) gets sharper, non-negotiable triggers
CDD is mandatory for every business relationship, for occasional transactions of €10,000 or more, for fund transfers of €1,000 or more, for any transfer of legal entity ownership, and for any suspicion of money laundering or terrorist financing, regardless of amount - Records run on a refresh cap, not a fixed calendar
Higher-risk customers reviewed at least annually, everyone else at least every five years, plus event-triggered updates whenever something material changes. This is perpetual KYC in everything but name – continuous customer lifecycle management, not periodic batch review - PEP definitions widen considerably
Domestic politically exposed persons are treated the same as foreign ones. Regional and local authority heads are added. Siblings join the family-member definition. Enhanced due diligence extends at least 12 months after someone leaves office - Discretion narrows for high-risk third countries
Enhanced due diligence becomes mandatory. Simplified due diligence is barred outright, with no case-by-case waiver - Transaction monitoring gets its own standard
AMLA guidelines due through 2026 are expected to define what counts as effective monitoring – a materially higher bar than having a system in place
The change cadence is the real requirement
Every bank reading the list above will be tempted to treat it as a checklist. Build to the spec, clear the 2027 date, move on.
That reading misses what AMLR is.
AMLR introduces a new rhythm of rule change.
AMLA technical standards land throughout 2026. Refresh cycles replace static review calendars. Event-triggered updates require a system to react the moment a customer's risk profile shifts, not at the next scheduled review. Thresholds that look fixed today are still being finalized.
A rule engine that already struggles to keep pace with today's fixed requirements will not keep pace with a framework built to change continuously.
A system that cannot be retuned is not simply inefficient under AMLR. It is structurally incompatible with how AMLR is designed to operate.
This is why the case for change does not start with AMLR. It was already showing up in the EY data. AMLR sets the date by which it has to be resolved.
Four capabilities your compliance platform needs
Not a wish list. The minimum bar to meet AMLR's specific design.

- Dynamic risk scoring with event-triggered re-review
A customer's risk profile changes the moment something material happens. Your system needs to know it then, not at the next scheduled check - Configurable enhanced due diligence triggers
For high-risk third countries and for the widened PEP definition, including the 12-month post-office tail that most legacy systems were never built to track - Beneficial ownership logic that flexes by sector
The standard threshold sits at 25%. High-risk sectors are expected to see it lowered to 15%. A rule engine hard-coded to one number cannot serve both - Audit trails built for evidencing change, not just detection
AMLA's direction of travel is clear. What matters is not only that you caught something, but that you can show what changed in your rules and what you did in response
Test any platform, including your current one, against those four. The answers tend to arrive quickly.
How Marble fits
Marble is the compliance AI decision platform that adapts to your risk framework – not the other way around.
Customer risk assessment with dynamic risk scoring and event-triggered re-review run natively in the detection engine. EDD triggers, PEP definitions, and beneficial ownership thresholds are set by your compliance team directly, in a no-code interface – no vendor ticket, no quarterly release cycle.
When AMLA finalizes where the 15% threshold applies, your team adjusts the logic the same day.
Every rule, alert, and decision is versioned and traceable, built for a supervisor who wants evidence of adaptation rather than a log of detections. Detection, investigation, case management, and reporting sit in one workspace, so nothing falls through the gaps between systems.
Run it as SaaS, or entirely inside your own infrastructure. For a bank working under data residency constraints, where the system lives is a decision your architecture team makes – not one your vendor makes for you.
This already runs in a European regulated banking context. Treezor, a Banking-as-a-Service platform operating under EU financial regulation, uses Marble to
move from spotting a fraud pattern to a live blocking rule in minutes
– a working illustration of what a rule engine built to be retuned, rather than rebuilt, looks like in practice.
The rules are becoming living rules
AMLR does not ask Nordic banks to start a transformation they have not already begun. EY's data shows most are mid-transformation already. AMLR sets the date by which that shift has to be complete, and gives it a name.
Your infrastructure should be built the same way the rules are.
Download the full whitepaper: From Fixed Rules to Living Rules →
Frequently asked questions about AMLR requirements for banks
When do AMLR requirements apply to banks?
AMLR applies from 10 July 2027 in every EU member state, including Sweden and Denmark, with no national transposition step. Norway reaches the same date through EEA incorporation and national implementing legislation. Some crypto-specific and higher-risk provisions phase in on a different schedule.
What are the AMLR customer due diligence thresholds?
Customer due diligence is mandatory for every business relationship, for occasional transactions of €10,000 or more, for fund transfers of €1,000 or more, for any transfer of legal entity ownership, and for any suspicion of money laundering, regardless of amount. Several supporting standards remain in consultation.
What does AMLR change for transaction monitoring?
AMLR replaces fixed review calendars with risk-linked refresh caps – annually for higher-risk customers, every five years otherwise – plus event-triggered updates whenever a customer's profile materially changes. AMLA guidelines due through 2026 are expected to define what counts as effective monitoring.

