The new EU Anti-Money Laundering Regulation (AMLR) — what it means for accounting and audit firms

Noah Mannberg
The EU has adopted a new anti-money-laundering package that will reshape how AML compliance works across the union — including for Swedish accounting and audit firms. Its centrepiece is the Anti-Money Laundering Regulation (AMLR): unlike the previous directives, a regulation applies directly in every member state, without national transposition. The package also includes a sixth directive (AMLD6), covering supervision and national mechanisms, and establishes a new EU authority, AMLA, to coordinate and oversee AML supervision across the union.
From national law to a single EU rulebook
Today, Swedish firms work under the Swedish Anti-Money Laundering Act, which implements the EU directives. With AMLR, the core obligations — customer due diligence, beneficial-ownership investigation, risk assessment, record-keeping — will instead follow directly from EU law, uniform across member states. Swedish law will still govern parts of the framework, such as supervision, but the substance of day-to-day compliance moves to the regulation.
What changes for firms
For accounting and audit firms the direction of travel is clear: more prescriptive and more uniform customer due diligence requirements, sharper rules on identifying beneficial owners, and stricter expectations on the risk assessment and on documentation. Obligations that today leave room for interpretation become more precisely specified — which favours firms whose client files are already structured, complete and traceable, and exposes those relying on ad-hoc spreadsheets.
The timeline
The regulation starts to apply in the main from 2027, with technical standards and detailed guidance being specified on an ongoing basis by the Commission and AMLA. Exact requirements at the level of individual procedures will therefore continue to take shape — but the framework and its direction are settled, and waiting for the final details before acting leaves little time to adapt.
What firms should do now
Three preparations pay off regardless of how the details land. Review the business-wide risk assessment so it genuinely reflects the firm’s services and client base — it remains the foundation for everything else. Digitise the customer due diligence files, so that identity checks, beneficial-ownership investigations and risk classifications live in one structured place rather than in scattered documents. And secure traceability: the ability to show what was assessed, by whom, when and on what grounds. Vidd is being built with these requirements in view, so that firms meeting today’s Swedish rules are also positioned for the EU rulebook that follows.