Skip to content
2,151 standards indexed across 19 jurisdictions View the Atlas
3 hubs live · 3 more in the pipeline See all compliance topics
Daily news + multi-week series Browse all insights
3 tools live · 4 interactive tools in development Roadmap
Spelinspektionen · AML 13 min read Jul 17, 2026

Sweden AML and CTF Requirements: What SIFS 2019:2 Means for Licensed Casino Operators

SIFS 2019:2 sets binding AML and CTF obligations for every Swedish gambling licence holder. Understand the KYC framework, enforcement approach, and the September 2026 amendment before Spelinspektionen examines your files.

Matt Denney

By

Founder, gamingcompliance.io · 15 yrs in iGaming compliance

Published Jul 17, 2026 13 min read Filed AML & KYC

SIFS 2019:2, decided by Spelinspektionen on 18 December 2019 and published on 14 January 2020, is the primary sector-specific regulation governing anti-money laundering and counter-terrorism financing obligations for gambling licence holders in Sweden. It sits within a three-tier legal architecture: the Swedish Anti-Money Laundering Act (Lagen 2017:630 om åtgärder mot penningtvätt och finansiering av terrorism), the Gambling Ordinance (Spelförordningen 2018:1475), and the Gambling Act (Spellagen 2018:1138) together provide the statutory foundation. SIFS 2019:2 translates those obligations into gambling-specific requirements. Every holder of a Swedish gambling licence under Spellagen, whether for online casino, online betting, or land-based commercial gambling, must comply with it. A September 2026 amendment, SIFS 2026:2, modifies the existing framework and requires licence holders to update their internal procedures accordingly.

The Regulatory Architecture Behind SIFS 2019:2

Sweden re-regulated its gambling market from 1 January 2019 under Spellagen (2018:1138), replacing a state monopoly with a licensed competitive model supervised by Spelinspektionen, the Swedish Gambling Authority. AML compliance was embedded in that regime from the start. Spellagen’s relevant cross-reference provision makes the obligations of Lagen (2017:630) directly applicable to gambling licence holders by statute, transposing the EU’s Fourth and Fifth Money Laundering Directives into the gambling context. Sweden’s position as an EU Member State means the entire framework is grounded in the EU directive architecture, and Spelinspektionen supervises compliance with it under the same authority that governs gambling licensing.

Spelinspektionen issued SIFS 2019:2 under the authority granted by Chapter 16 §7, points 2 and 3 of Spelförordningen (2018:1475) and the relevant provisions of the AML Ordinance (2009:92). The legal basis is unambiguous: this is a binding regulation (föreskrift), not guidance. The document also contains allmänna råd (general advice) provisions, which are interpretive in character and not legally binding in isolation, but licence holders who deviate from them must be prepared to demonstrate equivalent compliance by other means.

Scope: SIFS 2019:2 Chapter 1 §1 states that its provisions apply to those who operate gambling under a licence or registration under Spellagen (2018:1138), for the purpose of preventing gambling services from being exploited for money laundering or terrorism financing. Chapter 1 §2 lists limited exemptions, primarily certain low-risk gambling forms, from the AML Act requirements. Online casino and online betting are not exempted.

What Does SIFS 2019:2 Require? The Chapter Structure

SIFS 2019:2 is organised into chapters that map onto the risk-based approach mandated by Lagen (2017:630). Chapter 2 addresses the general risk assessment and the policies, procedures, and guidelines that licence holders must maintain. Chapter 2 §1 requires operators to identify and assess the risks in their business in accordance with the corresponding provisions of Lagen (2017:630). That risk assessment must cover all gambling products and services offered, and all other factors relevant to the business. Chapter 2 §2 specifically requires licence holders to identify which gambling services could be exploited for money laundering or terrorism financing and to describe the relevant threats and the vulnerability characteristics of each service type.

The practical demand of Chapter 2 is that the general risk assessment is not a static document. It must be reviewed whenever there are changes to the business, to the customer base, or to the threat environment, and at a minimum whenever Spelinspektionen or the relevant EU bodies publish updated risk assessments or guidance. In practice, licence holders should tie their review cycle to both internal trigger events (new product launches, new markets, change of key personnel) and external ones (FATF grey list updates, AMLA guidance, Spelinspektionen supervisory findings).

“The risk assessment shall include an evaluation of identified risks with the aim of enabling measures to be taken to prevent gambling services from being exploited for money laundering or the financing of terrorism.”, SIFS 2019:2, Chapter 2 §2 (translated from Swedish)

Customer Due Diligence Obligations

SIFS 2019:2 does not replicate the full CDD framework from Lagen (2017:630) but amplifies and tailors it for the gambling context. The fundamental obligation, that licence holders must perform customer due diligence including identity verification before or during the establishment of a business relationship, flows directly from Lagen (2017:630) Chapter 3. What SIFS 2019:2 adds is specificity about how that framework applies to online gambling accounts, gaming agents (spelombud), and the range of gambling products on offer.

The three-tier CDD model that Swedish licence holders must operate is standard in form: simplified due diligence for lower-risk relationships, standard due diligence for the main customer population, and enhanced due diligence for high-risk relationships. High-risk indicators under the Swedish framework include customers identified as politically exposed persons (PEPs) or their associates, customers from FATF-listed high-risk jurisdictions, customers exhibiting unusual transaction patterns relative to their declared income or wealth, and business relationships where the source of funds cannot be verified through normal means.

The source-of-income requirement is where enforcement has concentrated most sharply. When a customer’s deposit volume cannot be explained by their taxable income, a reference point that Spelinspektionen has direct access to through Swedish tax authority data, the licence holder must have sought and obtained documentation to bridge that gap. That might include payslips, bank statements, business accounts, or other verified income evidence. The failure to do so constitutes an inadequate business relationship risk assessment and insufficient ongoing monitoring, which are breaches of SIFS 2019:2 as read with Lagen (2017:630).

What Does Sweden Require for KYC Specifically?

All Swedish online gambling licence holders must register players before those players can participate in gambling, under Chapter 12 §1 of Spellagen. That registration requirement creates a mandatory account-based model for online gambling: there are no anonymous online play arrangements available under the Swedish framework. Every registered player account is therefore a business relationship subject to AML obligations from the outset. Licence holders cannot rely on a transactional or occasional-customer CDD model for online casino players, because the relationship begins when the account is opened and ongoing monitoring is required from that point.

Identity verification at registration must use reliable methods. The SIFS 2022:3 technical guidelines confirm that when a player deposits funds, the licence holder must be able to confirm that the declared bank account or payment service belongs to that player, with electronic identification or equivalent means serving as the acceptable verification method. Sweden’s BankID infrastructure, the dominant digital identity solution used by the overwhelming majority of Swedish internet users, is the practical standard for this check, though equivalent electronic identification systems are accepted.

Chapter 13 §5 of Spellagen (2018:1138) prohibits online licence holders from accepting deposits from any source other than a payment service provider operating under the Payment Services Act (2010:751). Cash is categorically excluded. This removes a structural vulnerability present in many other jurisdictions and means that every deposit transaction is traceable to a regulated payment rail from the outset, an advantage for AML monitoring but not a substitute for it.

CDD Level When Required Key Indicators (Swedish Context)
Simplified Due Diligence Lower inherent risk, documented by risk assessment Low deposit volumes, standard verified identity, consistent payment methods
Standard Due Diligence Default for all registered player accounts Identity verification via BankID or equivalent, payment source verification
Enhanced Due Diligence High-risk relationships, mandatory for PEPs Deposits inconsistent with taxable income, FATF high-risk jurisdiction nexus, PEP status, complex or structured deposit patterns

Ongoing Monitoring and Transaction Surveillance

Lagen (2017:630) Chapter 4 requires licence holders to conduct ongoing monitoring of business relationships. SIFS 2019:2 translates this into a gambling-specific obligation to continuously monitor customer behaviour for anomalies that suggest money laundering or terrorism financing risk. For online casino operators, this means transaction monitoring systems must be capable of flagging deposit patterns that are inconsistent with a customer’s verified income profile, rapid deposit-withdrawal sequences without meaningful gambling activity, changes in the payment methods used, and structured deposits that appear designed to avoid triggering review thresholds.

Spelinspektionen’s inspection methodology focuses heavily on whether licence holders have documented the criteria used to trigger enhanced review and whether those reviews, once triggered, are properly documented and resolved. The existence of a monitoring system is not sufficient: the documented outputs of that system must demonstrate that reviews were conducted, conclusions were reached, and where necessary, suspicious transaction reports (misstänkta transaktionsrapporter) were filed with the Swedish Financial Intelligence Unit, Finanspolisen, operating within the Swedish Police Authority.

Reporting obligations for suspicious transactions flow from the relevant provisions of Lagen (2017:630) Chapter 4. Licence holders must report to Finanspolisen without delay when they know, suspect, or have reasonable grounds to suspect that a transaction or attempted transaction is connected to money laundering or terrorism financing. Tipping off the customer is prohibited. Records of all CDD measures, transaction data, and reports must be retained for five years from the date the business relationship ended or the transaction occurred.

Spelinspektionen’s Enforcement Approach

Chapter 11 of Spellagen (2018:1138) governs Spelinspektionen’s intervention powers in respect of AML violations. §17 gives the authority the power to intervene against any gambling provider that violates Lagen (2017:630) or regulations issued under it. The intervention ladder runs from a rectification order (§18, paragraph 1) through a cease and desist order or licence revocation for serious, repeated, or systematic violations (§18, paragraph 2), with warnings available where those would be sufficient (§18, paragraph 3).

The financial penalty framework, set out in §21a of Spellagen as amended by SFS 2024:255, provides for pecuniary penalties at a minimum of SEK 5,000 and a maximum of the highest of three limbs: ten percent of the licence holder’s turnover in the preceding financial year, twice the profit made from the infringement where determinable, or an amount equivalent to one million euros in Swedish kronor. For a mid-size licensed operator, the ten percent of turnover limb will routinely produce a figure substantially higher than the euro equivalent floor, making AML penalty exposure material.

Penalty ceiling: Under Spellagen §21a (as amended by SFS 2024:255), the maximum AML pecuniary penalty is the highest of: 10% of the preceding year’s turnover, twice the profit from the infringement, or the SEK equivalent of €1 million. There is no upper cap expressed as a fixed-kronor amount for larger operators.

Spelinspektionen’s inspection methodology is proactive. The regulator selects sample populations from licence holder customer data, including, as confirmed by the 2025 enforcement actions, lists of the highest-depositing customers within specific age cohorts, and tests whether CDD and source-of-income procedures were followed for those accounts. This approach means the inspection focus is on demonstrated compliance in real transactions, not just on the existence of written policies. Licence holders whose written procedures are adequate but whose actual customer files lack supporting documentation for large or unusual deposits will fail the examination.

The 2025 Enforcement Round: Betsson, Snabbare, and Spooniker

The most significant recent enforcement illustration of SIFS 2019:2 obligations in practice is the 2025 penalty round against Betsson, Snabbare, and Spooniker. According to SBC News, reporting in July 2026, all three operators had penalty fees upheld by the Swedish Administrative Court following appeals. The court agreed with Spelinspektionen’s position that the companies “committed serious violations of the money laundering regulations through insufficient customer due diligence measures”.

Betsson received a warning and a SEK 6.5 million fine. According to SBC News, Spelinspektionen’s investigation was triggered by a review of the fifty customers aged 18 to 29 who had made the largest total deposits during the 2023 calendar year. In one highlighted case, a customer had made 163 deposits totalling SEK 491,950 between September and December 2023, despite a taxable annual income insufficient to justify that deposit volume. The failure to identify this discrepancy and conduct enhanced due diligence was the foundation of the breach finding. The enforcement outcome confirms that Spelinspektionen treats source-of-income verification for young, high-volume depositors as a core, not peripheral, obligation under SIFS 2019:2.

The Swedish Administrative Court agreed that the companies had committed serious violations of the money laundering regulations through insufficient customer due diligence measures, upholding penalty fees originally issued in May 2025.

SIFS 2026:2: What Changes from 1 September 2026

SIFS 2026:2, titled “Föreskrifter om ändring i Spelinspektionens föreskrifter och allmänna råd (SIFS 2019:2) om åtgärder mot penningtvätt och finansiering av terrorism”, amends the base regulation and enters into force on 1 September 2026. Licence holders must ensure their AML policies, risk assessments, and procedures have been updated to reflect the amended provisions before that date. The amendment is available as a PDF on Spelinspektionen’s official website. Compliance officers at Swedish-licensed operators should read the amended text against their current documented framework and identify any gaps requiring policy revision, system changes, or staff retraining before the September effective date.

The September 2026 effective date is not isolated. It lands two months after SIFS 2026:3, the Spelpaus API regulation, entered into force on 1 August 2026. Licence holders managing both implementation streams simultaneously should treat September 2026 as the close of a back-to-back compliance sprint covering both responsible gambling controls and the amended AML framework.

Interaction with EU AMLA

Sweden’s domestic AML framework for gambling now operates within a rapidly evolving EU supervisory architecture. AMLA, the EU’s Anti-Money Laundering Authority, launched a public consultation on 13 July 2026, running until 27 September 2026, on draft Regulatory Technical Standards to determine how supervisory authorities assess inherent money laundering and terrorism financing risks across the non-financial sector, including gambling. Spelinspektionen has formally endorsed participation in that consultation process.

For Swedish licence holders, AMLA’s emergence means that Spelinspektionen’s risk-based approach will increasingly be benchmarked against harmonised EU standards. The RTS being developed by AMLA are designed to prevent disproportionate compliance burdens by avoiding direct replication of financial-institution mandates onto gambling operators, but they will establish a common methodological floor for how supervisory bodies across EU member states assess gambling sector AML risks. Sweden is already compliant with the Fourth and Fifth Money Laundering Directives via Lagen (2017:630), but the incoming RTS layer may require adjustments to how risk ratings are documented and categorised internally. Compliance officers should monitor the AMLA consultation and its outputs as part of forward planning for the post-2026 regulatory environment.

The interaction between the AMLA framework and existing national regimes like SIFS 2019:2 will be a central compliance management issue for operators licensed across multiple EU jurisdictions. A licence holder that also holds an MGA licence, for example, will need to consider how harmonised AMLA standards interact with FIAU guidance in Malta and with Spelinspektionen’s specific Swedish requirements simultaneously. Qualified legal counsel familiar with both jurisdictions should be engaged when calibrating a cross-border AML programme against converging EU standards. A detailed breakdown of AML obligations across other major jurisdictions is available in our AML and Financial Compliance hub.

What Licence Holders Should Have in Place

A documented, current general risk assessment covering all gambling products and customer segments, reviewed at least annually and whenever material business or regulatory changes occur, is the minimum foundation under SIFS 2019:2 Chapter 2. That document must exist in written form, be accessible during a Spelinspektionen inspection, and reflect the actual product and customer profile of the business, not a generic template.

The customer risk assessment and onboarding procedure must have clear documented criteria for when enhanced due diligence is triggered. Deposit volume relative to verified income is the most operationally sensitive criterion in the Swedish context. Licence holders should have automated monitoring logic that flags accounts where cumulative deposits exceed a defined multiple of the customer’s verified income profile, with a documented human review process triggered at each threshold breach.

Suspicious transaction reporting processes must be documented, assigned to a named Money Laundering Reporting Officer or equivalent, and tested. The MLRO must have direct access to all customer files and transaction data necessary to assess and file a report. Training records demonstrating that all customer-facing and AML-relevant staff have received current training on Swedish AML obligations must be maintained.

Payment channel controls must ensure compliance with the cash prohibition in Chapter 13 §5 of Spellagen. Where e-wallets or payment aggregators are used, the licence holder must verify that the underlying funding source is a regulated payment service and not a credit facility, a requirement that became even more operationally significant following the introduction of Sweden’s credit ban on 1 May 2026, under which licence holders must also block credit-funded deposits. For context on how Sweden’s broader compliance framework has evolved in parallel with AML reforms, see our analysis of Sweden’s channelization challenges and the SIFS 2026:3 Spelpaus API requirements.

Source: Spelinspektionen, SIFS 2019:2, Spelinspektionens föreskrifter och allmänna råd om åtgärder mot penningtvätt och finansiering av terrorism, decided 18 December 2019, published 14 January 2020. Amendment: SIFS 2026:2, effective 1 September 2026.

Key Resources

SIFS 2019:2, Spelinspektionens föreskrifter och allmänna råd om åtgärder mot penningtvätt och finansiering av terrorism. Decided 18 December 2019, published 14 January 2020. Available in Swedish on Spelinspektionen’s official website.

SIFS 2026:2, Amendment to SIFS 2019:2. Effective 1 September 2026. PDF available via Spelinspektionen.

Spellagen (2018:1138), Sweden’s Gambling Act, consolidated to SFS 2024:255. AML intervention provisions at Chapter 11 §§17, 21a. Cash prohibition at Chapter 13 §5.

Lagen (2017:630) om åtgärder mot penningtvätt och finansiering av terrorism, Sweden’s AML Act, implementing the EU Fourth and Fifth Money Laundering Directives. The parent statutory obligation for all SIFS 2019:2 requirements.

Gambling Laws and Regulations Report 2026, Sweden (ICLG), Authoritative jurisdiction-level overview of Sweden’s gambling regulatory framework including AML provisions.

AMLA public consultation on draft RTS, Launched 13 July 2026, closes 27 September 2026. Available at amla.europa.eu. Relevant to all EU-licensed operators, including those holding Swedish licences.

If you operate a Swedish gambling licence and need assistance interpreting SIFS 2019:2 obligations, designing compliant CDD procedures, or preparing for a Spelinspektionen inspection, contact the Gaming Compliance team for a confidential assessment of your current AML framework.

Matt Denney

Matt Denney

Editorial · gamingcompliance.io

Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.

Related coverage · also tagged AML & KYC

Browse all →

AML & KYC

Source of Funds vs Source of Wealth: Where Operators Draw the Line and Get It Wrong

Jul 16 · 14 min read

AML & KYC

UKGC Anti-Money Laundering: What UK Licensed Operators Must Have in Place

Jul 10 · 14 min read

AML & KYC

MGA AML Requirements: Malta’s Casino Due Diligence Framework Explained

Jul 3 · 16 min read

The Tuesday brief, every week.

One email. Every regulator change we surface, every standard we re-index, every enforcement decision we read. No marketing, no fluff.

Unsubscribe with one click. We'll never share your address.