Financial Integrity Monitor

Sweden SE

Domains (D1–D6)
1
Sources
20
Role actions
8
Jurisdiction profile
Largely CompliantTier ARisk: IncreasingMixed

Sweden operates under the AML/CFT Act (2017:630), supervised by Finansinspektionen (FI), and is directly bound by EU AMLD/AMLR instruments and MiCA.

MoreFATF's 2017 MER found a strong legal regime undermined by weak inter-agency coordination and TF-sanctions implementation gaps; both a 2018 and 2020 follow-up upgraded several ratings, leaving 3 Recommendations partially compliant.

Key deficiencies
  • Historic lack of a national AML/CFT coordination mechanism producing fragmented risk understanding across agencies
  • Legal and practical weaknesses in implementing targeted financial sanctions to freeze terrorist assets (identified 2017, remediation status unconfirmed)
  • Beneficial ownership register (Bolagsverket) gated behind a search fee and historically criticised for incomplete verification duties on companies
  • Multi-year supervisory failure to act on known high-risk Baltic-subsidiary exposure at Swedbank and SEB before scandal broke publicly
Recent developments (18m)
  • OFAC (12 Mar 2025) and UK OFSI (14 Apr 2025) designated the Sweden-based Foxtrot Network and its leader Rawa Majid as an Iranian-backed transnational criminal organisation
  • Sweden began boarding suspected Russian shadow-fleet oil tankers in the Baltic Sea from early April 2026, prompting rerouting of sanctioned vessels away from Swedish waters
  • Sweden's MiCA transitional (grandfathering) period for existing crypto-asset service providers closed 30 September 2025, one of the shortest in the EU
  • Sweden's Supreme Court acquitted former Swedbank CEO Birgitte Bonnesen of gross swindling in the Baltic money-laundering cover-up case (21 April 2026)
  • European Commission published its 2025 Country Report on Sweden (June 2025) covering financial-sector and AML-adjacent structural issues
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

Sweden's Markets in Crypto-Assets Regulation (MiCA) authorisation pipeline for crypto-asset service providers reached a consolidation point this cycle. Finansinspektionen granted Safello full MiCA CASP authorisation on 13 October 2025, and Safello remained the only Swedish exchange holding full authorisation as of 30 June 2026. Safello's authorisation followed the standard MiCA CASP process administered by Finansinspektionen as Sweden's national competent authority, and its position as the sole full-authorisation holder as of 30 June 2026 means that, for the time being, it is the only entity that can be treated as holding an unambiguous domestic MiCA licence for the full range of regulated crypto-asset services in Sweden. Any due-diligence process that treats Swedish-domiciled crypto exchanges as fungible counterparties without checking individual authorisation status would, on this cycle's evidence, be exposed to a meaningfully higher counterparty-status risk than a process that checks status firm-by-firm. In the same window, Finansinspektionen rejected Goobit's MiCA CASP application for its BTCX brand on 2 July 2026, and GreenMerc has begun moving Trijo's Swedish customers to sister company Northcrypto in Finland following Trijo's own rejection under the regime. Read together, these three outcomes describe a structural narrowing of Sweden's domestically-authorised virtual-asset-service-provider base ahead of the transitional-regime cliff-edge, rather than three unconnected firm-level events.

Other Developments

Transitional-deadline consolidation. The pattern observed this cycle sits against the backdrop of MiCA's transitional authorisation regime, under which pre-existing Swedish crypto firms retain the right to serve domestic customers only if they secure full authorisation within the transitional window. Firms that fail to clear authorisation, as with Goobit's BTCX brand, lose the ability to serve Swedish retail customers domestically; in Trijo's case, the response has been to relocate service provision to an authorised sister entity, Northcrypto, in Finland, rather than to exit the Swedish customer relationship entirely. The consolidation is best read architecturally: it is the design of the transitional regime itself, working as intended, that is producing the narrowing, not a discrete enforcement action against any of the three firms named.

Architecture over incident. No enforcement action has been identified against any of the three firms named this cycle; the outcomes described here are licensing-authorisation decisions, not sanctions. In FIM's three-pillar frame, this cycle's D5 signal sits closer to the compliance-technology and financial-innovation pillar than to a CTF or CPF finding, and it should be read as an architecture-level development in the domestic licensing perimeter rather than as an incident requiring an enforcement-risk rating.

Sourcing caveat. This finding currently rests on a single Tier 3 trade-press source rather than a Finansinspektionen register confirmation. No Sweden-specific Tier 1 verification of the Safello, Goobit and Trijo outcomes was obtained this cycle, and that gap is logged as an open item rather than absorbed into the finding's confidence rating, which remains at the Assessed tier accordingly.

Cross-Monitor Connections

The MiCA CASP authorisation consolidation identified here has a direct counterpart in the crypto monitor's own licensing coverage for Sweden, which tracks the same authorisation, rejection and migration outcomes at the crypto-asset-service-provider level; readers following the digital-asset licensing story in detail should consult that monitor's Sweden crypto-licensing brief directly rather than relying on this cross-reference alone. It also intersects with the world-payments monitor's interest in Swedish payments infrastructure, insofar as a narrowing of the domestically-authorised digital-asset firm base has downstream relevance for which entities banks and payment institutions can treat as authorised counterparties for digital-asset-linked flows. Neither adjacent domain is re-analysed here.

Outlook

The near-term marker to watch is whether further pre-MiCA Swedish crypto firms clear full authorisation, or instead follow Goobit and Trijo toward rejection or cross-border migration, as the transitional deadline closes out. A continued narrowing toward Safello as the sole fully-authorised domestic exchange would reinforce a structural consolidation thesis; a reversal, such as a second firm clearing authorisation, would weaken it. Closing the sourcing gap with a direct Finansinspektionen register check is the most immediate research priority for the next cycle, given that the current finding rests on a single secondary source describing three separate but thematically consistent firm-level outcomes. Because Sweden sits within the EEA and applies MiCA directly, the same transitional-deadline dynamic is likely to recur across other Nordic and Baltic jurisdictions on a similar timeline; whether Sweden's pattern of one authorisation against one rejection and one migration proves typical or unusual will only become clear once comparable primary-source data is available for neighbouring markets, which is outside this cycle's SE-scoped remit.

weekly_brief_draft · JID SE
Domain intelligence (D1–D6)

D1 Sanctions

Not covered

Sanctions is not yet covered for this jurisdiction in this report.

D2 Beneficial Ownership

Not covered

Beneficial Ownership is not yet covered for this jurisdiction in this report.

D3 Enabler Jurisdictions

Not covered

Enabler Jurisdictions is not yet covered for this jurisdiction in this report.

D4 Conflict Finance

Not covered

Conflict Finance is not yet covered for this jurisdiction in this report.

D5 Crypto / Digital Assets / Financial Innovation

Crypto / Digital Assets / Financial Innovation

Continue reading

Sweden's crypto-asset-service-provider landscape narrowed materially this cycle under the Markets in Crypto-Assets Regulation (MiCA) authorisation regime. Finansinspektionen, acting as Sweden's national competent authority under MiCA, granted Safello full CASP authorisation on 13 October 2025; as of 30 June 2026, Safello remained the only Swedish exchange to hold that full authorisation. This single fact carries structural weight for how the domestic digital-asset market is organised: rather than a field of several similarly-positioned exchanges each holding equivalent authorisation, Sweden's fully-licensed VASP base currently consists of one firm.

Two further outcomes sharpen this picture. Finansinspektionen rejected Goobit's MiCA CASP application for its BTCX brand on 2 July 2026, removing a previously-operating pre-MiCA firm from the domestically-authorised pool. Separately, GreenMerc has begun migrating Trijo's Swedish customers to sister company Northcrypto, domiciled in Finland, following Trijo's own MiCA rejection — an adaptive response that uses MiCA's EU passporting architecture to preserve customer access to crypto services via a cross-border entity rather than exiting the Swedish market outright. Both outcomes trace to the same transitional-authorisation mechanic: pre-MiCA registered firms may continue operating only while a complete authorisation application remains pending, and that transitional window closes for good by the mid-2026 deadline referenced across this reporting.

Because MiCA authorisation carries EU-wide passporting rights, Sweden's consolidation pattern cannot be read in isolation from the wider Nordic and Baltic authorisation landscape; a firm rejected or unauthorised in Sweden may still access Swedish customers indirectly through a passported entity authorised elsewhere in the EEA, as the Trijo-to-Northcrypto migration illustrates. This dynamic means that a simple count of domestically-authorised firms understates the number of entities that can lawfully serve Swedish crypto customers, even as it accurately describes the shrinking pool of firms directly supervised by Finansinspektionen for Swedish-domiciled crypto-asset activity.

From a financial-innovation perspective, this is a consolidation story rather than an innovation story in the conventional sense — no new product category, on-chain activity class or stablecoin instrument was identified in Sweden this cycle. The innovation-relevant signal is structural: the domestic market for retail-facing crypto-asset services is concentrating around a single authorised counterparty, which has implications for market resilience and for any downstream financial institution or payment provider that treats Swedish crypto exchanges as a class rather than checking authorisation status firm by firm.

This finding is currently supported by a single Tier 3 trade-press source describing all three outcomes; no Sweden-specific Tier 1 confirmation from a Finansinspektionen public register was obtained this cycle. Because all three data points derive from the same secondary source, this is properly assessed rather than treated as confirmed, notwithstanding the internal consistency of the pattern across three separate firms. No enforcement action was identified against any of the three named firms this cycle — the underlying events are licensing-authorisation and licensing-rejection decisions, not sanctions or penalties.

Outlook

The clearest forward marker for the next cycle is whether any additional pre-MiCA Swedish crypto firm clears full authorisation, or instead follows Goobit and Trijo toward rejection or cross-border migration, as the transitional deadline closes definitively. A continued narrowing toward Safello as sole fully-authorised domestic exchange would reinforce the consolidation thesis identified this cycle; the emergence of a second or third fully-authorised Swedish CASP would weaken it materially. The most immediate research priority is closing the sourcing gap with a direct Finansinspektionen register check, given that the current finding rests entirely on a single secondary source. Any due-diligence or onboarding process treating Swedish-domiciled crypto exchanges as a fungible class, rather than verifying authorisation status firm-by-firm, should treat this cycle's finding as a prompt to revisit that assumption.

D6 Compliance Technology & Active Defence

Not covered

Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.

D7 AML/CTF Regime

Not covered

AML/CTF Regime is not yet covered for this jurisdiction in this report.

Regulatory horizon
No dated horizon items this cycle. 3 items tracked without a confirmed date.
3 pending date · baseline fim-2026-07-08
Role action cards
MLROAssessed

Sweden's domestic MiCA CASP pool narrowed to one fully-authorised exchange this cycle.

Safello is now the only Finansinspektionen-authorised Swedish crypto exchange, while Goobit's BTCX brand was rejected and Trijo is migrating customers to a Finnish sister entity. MLROs with Swedish crypto counterparties should confirm current authorisation status rather than assuming continuity of pre-MiCA registration.

3 evidence refs
ComplianceAssessed

MiCA CASP authorisation outcomes for Swedish exchanges diverged materially this cycle.

One authorisation (Safello), one rejection (Goobit/BTCX), and one cross-border migration (Trijo to Northcrypto) narrow the set of firms that can be treated as domestically authorised counterparties in Sweden.

3 evidence refs
LegalAssessed

Goobit's BTCX rejection and Trijo's cross-border migration raise counterparty-continuity questions.

Contracts referencing a Swedish-domiciled crypto counterparty may need review where that counterparty has been rejected under MiCA or has migrated service provision to a sister entity in another EEA state.

2 evidence refs
BoardAssessed

Sweden's domestic crypto-exchange market is consolidating around a single authorised firm.

Concentration of full MiCA authorisation in one Swedish exchange (Safello) is a structural market-consolidation signal relevant to any strategic exposure to Nordic digital-asset counterparties.

3 evidence refs
CTOAssessed

A Swedish crypto firm's rejection is being resolved via cross-border migration to a sister platform.

Trijo's move of Swedish customers to Northcrypto in Finland implies a technical migration of customer accounts and infrastructure across an EEA border, a pattern worth tracking for platform-architecture and data-residency implications.

1 evidence refs
RiskAssessed

Counterparty concentration risk has increased in Sweden's domestic crypto-exchange market.

With Safello as the sole fully-authorised domestic exchange, any risk model treating Swedish crypto exchanges as a fungible class should be updated to reflect single-counterparty concentration.

3 evidence refs
OperationsAssessed

Onboarding and screening lists referencing Swedish crypto counterparties need a status refresh.

Goobit/BTCX's rejection and Trijo's migration mean any static counterparty list including these entities as Swedish-authorised firms is now out of date.

2 evidence refs
AuditPossible

This cycle's MiCA authorisation findings rest on a single secondary source.

The Safello, Goobit and Trijo outcomes are sourced from one Tier 3 trade-press article; audit trails referencing these findings should note the absence of a direct Finansinspektionen register confirmation this cycle.

3 evidence refs
Decision lens
MLRO

Sweden's domestic MiCA CASP pool narrowed to one fully-authorised exchange this cycle.

Compliance

MiCA CASP authorisation outcomes for Swedish exchanges diverged materially this cycle.

Legal

Goobit's BTCX rejection and Trijo's cross-border migration raise counterparty-continuity questions.

Board

Sweden's domestic crypto-exchange market is consolidating around a single authorised firm.

CTO

A Swedish crypto firm's rejection is being resolved via cross-border migration to a sister platform.

Risk

Counterparty concentration risk has increased in Sweden's domestic crypto-exchange market.

Operations

Onboarding and screening lists referencing Swedish crypto counterparties need a status refresh.

Audit

This cycle's MiCA authorisation findings rest on a single secondary source.

Shared evidence: 3 refs
Scenario sketches

AMLA / EU AML Package supervisory transition (standing illustrative sketch)

Illustrative orientation only: as the EU AML Package matures, supervision of cross-border obliged entities could gradually shift from purely national authorities toward a hybrid regime in which the Anti-Money Laundering Authority exercises direct supervision of a first cohort of high-risk entities, alongside the directly-applicable AML Regulation and per-Member-State transposition of the sixth AML Directive. Such a shift could change where evasion typologies migrate, as entities and intermediaries recalibrate around which layer of supervision — national or EU-level — is most binding for their activity. This is architecture-level illustration, not a prediction about Sweden specifically and not an observed development this cycle.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion Architectureno_changeNo material change found this cycle within the pooled search budget for SE.
T2 · EU AML Package / AMLAwatchAMLR applies directly in Sweden from 10 July 2027; AMLD6 requires transposition by 10 July 2027 with staggered FIU-access (July 2025) and BO-register (July 2026) deadlines; AMLA began assuming tasks mid-2025 and starts IT-services build-out in 2026, with direct supervision from January 2028.
T3 · FATF Grey Listmaterial_change19 June 2026 Plenary: Iraq and Bosnia and Herzegovina added; Algeria and Namibia removed. Grey list now stands at 22 jurisdictions; black list unchanged. Sweden itself is not grey-listed.
T4 · Beneficial-Ownership Register Statusno_changeNo SE-specific BO-register development surfaced this cycle; AMLD6's July 2026 transposition deadline is upcoming but not yet realised.
T5 · Crypto & Digital-Asset IntegritywatchMiCA transitional period for pre-existing Swedish CASPs closed 30 June 2026; only Safello holds full Swedish CASP authorisation as of this cycle's FI update; two applicants refused and appealing.
T6 · Sanctions Regime Divergenceno_changeNo SE-specific EU/US/UK autonomous-listing divergence signal surfaced this cycle.
Registers

Enforcement actions

  • OFAC designated the Sweden-based Foxtrot Network and its leader Rawa Majid as a Transnational Criminal Organization under E.O. 13581/13886, citing links to Iranian state-directed hostile activity and secondary sanctions risk. 12 Mar 2025
  • The UK designated the Foxtrot Network and Majid under the Iran (Sanctions) Regulations 2023, citing involvement in hostile Iranian-directed activity destabilising the UK and other countries, including facilitating serious organised crime. 14 Apr 2025
  • Sweden's Supreme Court acquitted Bonnesen of gross swindling, overturning a 15-month prison sentence related to allegedly misleading statements about Swedbank's AML deficiencies in its Baltic operations during the Danske Bank-adjacent laundering scandal. 21 Apr 2026
  • FI fined Klarna SEK 500 million (~$50 million) after an audit found significant deficiencies in Klarna's general risk assessment and customer due-diligence procedures relating to money-laundering and terrorist-financing exposure. 11 Dec 2024
  • Sweden began actively boarding and checking papers of suspected sanctioned shadow-fleet tankers transiting the Baltic Sea, part of a wider Joint Expeditionary Force effort to interdict and inspect vessels evading the oil price cap and flag-state rules. 7 Apr 2026

Sanctions changes

  • The EU Council sanctioned an additional 41 vessels of Russia's shadow fleet, bringing the total designated fleet to almost 600, subjecting them to a port-access ban and a ban on maritime-transport-related services across the bloc, including Sweden's ports and territorial waters. 18 Dec 2025
  • The EU's 20th sanctions package against Russia introduced a shadow-fleet scrapping clause, mandatory 'no-Russia' end-use clauses in EU tanker sales, listed Murmansk/Tuapse ports and a third-country port (Indonesia) for shadow-fleet links, and expanded the Russian-bank transaction ban to 70 banks plus four third-country banks in Kyrgyzstan, Laos and Azerbaijan. 23 Apr 2026
  • OFAC and UK OFSI both designated the Sweden-based Foxtrot Network and Rawa Majid within weeks of each other (March and April 2025) under their respective Iran/TCO sanctions authorities, but no corresponding EU-level designation of the network under an EU Iran-sanctions instrument has been identified, leaving a listing-scope gap for EU-domiciled counterparties. 14 Apr 2025

Regulatory horizon (register)

  • EU AML Regulation (AMLR) becomes directly applicable in Sweden
  • AMLA direct-supervision perimeter extends to Swedish high-risk entities
  • Sweden's next FATF biennial AML/CFT progress update

Active schemes

  • [HIGH] Iran-backed Foxtrot Network gang financing hybrid proxy violence
  • [CRITICAL] Russian shadow-fleet Baltic oil transit via Swedish waters
  • [HIGH] Nordic bank Baltic-subsidiary correspondent laundering legacy
Sources
  1. FATF
  2. FATF
  3. FATF
  4. U.S. Department of the Treasury (OFAC)
  5. UK Government (FCDO/OFSI)
  6. UK OFSI
  7. Council of the European Union
  8. European Commission
  9. European Commission
  10. Council of the European Union
  11. European Commission (Sweden-specific national data)
  12. European Commission
  13. UNODC (hosting Sweden's official national submission)
  14. OCCRP
  15. OCCRP
  16. Bloomberg
  17. Bloomberg
  18. OCCRP
  19. Elliptic
  20. UK Government
Coverage gaps
Swedbank and SEB's Baltic subsidiaries processed tens of bil…
Swedbank and SEB's Baltic subsidiaries processed tens of billions of euros in high-risk non-resident flows for roughly a decade before FI imposed record fines (2019-2020); internal red flags reportedly dated to 2016 or earlier without triggering timely group-level or supervisory intervention.
FATF's 2017 MER found Sweden lacks a national AML/CFT coordi…
FATF's 2017 MER found Sweden lacks a national AML/CFT coordination mechanism, meaning different competent authorities do not share a common understanding of risk or respond to it in a coordinated way; no confirmed public evidence of full remediation has been located in this window.
The 2017 FATF MER identified legal and practical weaknesses …
The 2017 FATF MER identified legal and practical weaknesses in Sweden's implementation of targeted financial sanctions to freeze terrorist assets, flagged as requiring urgent attention; subsequent follow-up reports have not been located confirming full closure of this deficiency.
Public, primary-sourced detail on Finansinspektionen's post-…
Public, primary-sourced detail on Finansinspektionen's post-MiCA direct enforcement actions against Swedish crypto-asset service providers (beyond the general transitional-period closure) is limited in open-source reporting available for this baseline.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.