Ikano Bank's AML Fine: The EDD Failures KYC Teams Must Fix
Sweden's Finansinspektionen fined Ikano Bank SEK 140M in June 2026. These three EDD failures are what regulators are now targeting across the EU.

On 17 June 2026, Ikano Bank AB received a formal remark and an administrative fine of SEK 140 million — approximately €13 million — from Sweden's financial supervisory authority, Finansinspektionen. The decision named four discrete failures in the bank’s anti-money laundering programme. Peer supervisors are already treating each finding, which is precise and recorded in a public enforcement notice, as a reference for the output adequate AML controls must produce.
This is not a fringe institution. Founded in 1995 by Ingvar Kamprad, the creator of IKEA, Ikano Bank is a licensed bank with consumer credit, savings, and payment products and operations across Europe. Supervisors did not catch it operating outside the rules. They caught it running an AML programme that had quietly become obsolete as the rulebook around it changed.
That distinction is why the case rewards a close read.
The Four Violations
Finansinspektionen organised the enforcement decision around four specific deficiencies. Procedural nits they are not. They describe a compliance programme that existed on paper and failed to function in practice:
| # | Violation | Core Failure |
|---|---|---|
| 1 | Incomplete product risk assessment | No separate TF exposure analysis for corporate clients |
| 2 | Outdated ML/TF typologies | Updated regulatory guidance not integrated into controls |
| 3 | Inadequate Enhanced Due Diligence | Purpose, source of funds, source of wealth, and UBO not gathered |
| 4 | Regulatory intelligence gap | FIU and authority guidance excluded from the general risk assessment |
Taken together, those four violations describe a single structural problem: a compliance programme assembled correctly at some point, then left to drift. Documentation was present. Processes were present. Missing was the operational discipline — or the tooling — required to keep them current.
Failure 1: A Risk Assessment That Left Corporate Clients Out
A separate, realistic analysis of how corporate customers could misuse the bank’s products for terrorist financing was absent from Ikano Bank's general risk assessment, Finansinspektionen found. Distinct exposure patterns for the corporate book as a distinct population had not been assessed.
EU AML law is why this matters. Both current directives and the incoming AMLR require obliged entities to assess risk across the actual mix of their customer base rather than an assumed average. Structural risks on the corporate side differ from those on the retail side: shell company layering, misuse of commercial credit flows, complex beneficial ownership chains. Equating a €50,000 SME trade credit line with a €50,000 personal savings account fails the segmentation standard.
Finansinspektionen's finding confirms a signal already coming from multiple supervisors: averaging customer segments into a single consolidated risk score does not satisfy the requirement. Exposure to this finding sits with any firm that cannot show segment-specific risk analysis for material customer populations — corporate, retail, high-value, non-resident.
Failure 2: Money Laundering Typologies Left Stale
Swedish authorities had published updated money laundering and terrorist financing methods that the bank had not integrated, the regulator found. New typologies identified by the national FIU and other supervisory bodies had not been reflected in revised internal control frameworks.
Availability of the information was not the issue. Incorporation was.
Call that a structural compliance failure rather than an oversight. Typology reports, risk bulletins, and national threat assessments are issued regularly by Swedish authorities — as they are by AMLA at the EU level. The AML framework explicitly establishes the duty to receive this information, review it, and convert it into operational control adjustments.
23 Level 2 and Level 3 technical standards are committed for publication by AMLA, which became operational on 1 July 2025, before the AMLR becomes fully applicable in July 2027. Several of those standards contain updated guidance on risk categorisation and monitoring requirements. Reading the publications without operationalising them produces the same failed test Ikano Bank failed.
“Do we receive regulatory intelligence?” is not the practical question for compliance teams. “Do we have a documented process for reviewing, approving, and implementing regulatory updates within a defined window?” is. An informal answer — updates get read when someone has time — makes the Ikano Bank outcome a precedent.
AMLA's draft ongoing monitoring guidelines were published two weeks before this enforcement action and set out the specific framework AMLA has proposed for keeping risk classifications and customer information current. Guideline 2 addresses exactly the operational gap in which the Ikano Bank failure sits.
Failure 3: Enhanced Due Diligence Missing the Enhanced Part
KYC teams across Europe feel this violation most directly.
Finansinspektionen found that the inputs needed to implement Enhanced Due Diligence had not been gathered: purpose of the business relationship, source of funds, source of wealth, and beneficial ownership details. A named process called EDD existed. The substance that gives EDD meaning did not.
Document collection is not what EDD is. Investigation is — a structured attempt to understand not only who a customer is, but why this product is in use, where the money originates, and who ultimately controls and benefits from the relationship. For higher-risk customers, the FATF Recommendations and every EU directive built on them are explicit about the EDD requirement:
- Purpose of business relationship: What outcome is the customer seeking? Does observed transaction behaviour match that stated purpose?
- Source of funds: Where did the assets used in this relationship originate — salary, business revenue, sale of property, inheritance? Verification burden differs for each.
- Source of wealth: Where did the customer's overall wealth originate? Separate from source of funds, this needs its own analysis for high-net-worth and business clients.
- Beneficial ownership: Who ultimately owns or controls a legal-entity customer? Who takes the economic benefit of the relationship?
Ikano Bank could not show consistent collection of these fields. An EDD programme with gaps is the wrong description. An EDD programme that did not function is the right one.
AMLA's CDD technical standards set out what data regulators now expect these fields to contain, and how the AMLR will standardise collection across all 27 EU member states. The standards define minimum content requirements for each field and the verification approach expected for different customer risk categories.
Failure 4: Regulatory Intelligence Left Out of the Risk Model
The fourth violation relates to the second, yet the scope is distinct. Information from authorities about ML/TF risks and methods had not been folded into the bank's general risk assessment, Finansinspektionen found. Calibration ran against the bank's own historical data and internal assumptions, with no external input — a self-referential model.
A systematic blindspot is the result. New methods outrun the pace at which any single institution accumulates experience of them. Threat-assessment typologies that supervisors publish often sit months ahead of patterns visible in one institution’s own transaction data. Until novel attack vectors have already caused material exposure, a risk model that is not continuously calibrated against external intelligence will consistently underweight them.
What the Fine Says About 2026 EU Enforcement
A visible pattern includes the Ikano Bank decision. Signed on 9 June, the UK's Money Laundering and Terrorist Financing (Amendment) Regulations 2026 point the same way. The first half of 2026 saw multiple EU regulators issue enforcement actions aimed at the effectiveness gap — whether controls work, not whether they exist.
AMLA's direct supervision model, applying to 40 selected firms from 2028, is built on exactly this evaluative framework. Which entities are operating with structural gaps is what the data collection exercise AMLA launched in early 2026 is designed to identify — risk assessments that look complete but miss key populations, EDD processes that collect some fields and omit the ones regulators actually check.
Finansinspektionen chose a formal remark, the instrument reserved for structural deficiency rather than isolated procedural error. A single mistake is not what Ikano Bank made. Over time, the programme it operated had become systemically inadequate.
The Automation Gap in EDD
Trace each of the four violations back and the same operational problem appears: the gap between what a compliance programme documents and what it actually delivers.
Degradation of manual EDD processes is predictable. Between review cycles, customer records go stale. Someone has to schedule an update before a risk assessment drafted once is revisited. Typology guidance from regulators lands in inboxes, gets read, and is never operationalised. Negligence is the wrong word. A compliance programme that depends on human bandwidth to remain current produces this result predictably.
A different path is taken by automated EDD. Customer risk classifications stay current through continuous monitoring against adverse media, sanctions, and PEP databases, without waiting for a periodic review. A new fact detected in real time — a change in beneficial ownership, an anomalous transaction, a regulatory alert — starts an EDD refresh through trigger-based workflows. Rather than being collected manually at remediation time, source of funds and wealth fields are captured at onboarding and verified through integrated data sources.
Joinble's autonomous identity agents are built around this operational model. Gathering of EDD fields happens at onboarding; updates follow a cadence tied to customer risk classification rather than a shared calendar. The risk scoring engine receives regulatory intelligence continuously. Built in real time, the audit trail is not reconstructed under enforcement pressure.
A guarantee against regulatory scrutiny this is not. The specific operational gaps that Finansinspektionen has now documented, publicly, as costing one European bank €13 million are, however, the ones it closes.
See our KYC guide for 2026 for a complete picture of what a modern KYC programme should deliver from the ground up.
FAQ
What exactly did Ikano Bank do wrong in its AML programme?
Four failures were identified by Finansinspektionen: (1) product risk assessment incomplete, with no separate TF exposure analysis for corporate clients; (2) updated ML/TF typologies from Swedish supervisory authorities not integrated; (3) Enhanced Due Diligence inadequate — purpose of relationship, source of funds, source of wealth, and beneficial ownership data missing; and (4) regulatory intelligence left out of the general risk assessment. Assessment of the violations was structural, not isolated.
Why was Ikano Bank fined SEK 140 million specifically?
Swedish AML law allows Finansinspektionen to impose administrative fines of up to 10% of annual turnover. Severity of the violations and Ikano Bank's revenue base are what the SEK 140 million figure reflects. Issued alongside the fine was a formal remark — reserved for cases in which the regulator identifies systemic deficiency rather than a one-time procedural failure.
How does this enforcement action relate to AMLA's 2026 guidelines?
On 3 June 2026, two weeks before the Ikano Bank decision, AMLA published draft ongoing monitoring guidelines. How often customer information must be updated, what constitutes a mandatory refresh trigger, and how risk classifications must remain current — the failures Finansinspektionen identified — are exactly what those guidelines address. An early enforcement example of non-compliance with this framework is what the Ikano Bank case provides.
What is Enhanced Due Diligence and when must it be applied?
Higher-risk customers trigger EDD — typically politically exposed persons, customers from high-risk jurisdictions, non-face-to-face relationships, and business models with elevated ML/TF exposure. Purpose of the business relationship, source of funds, source of wealth, and beneficial ownership must be collected and verified. Some fields filled and others left blank does not satisfy EDD.
Can automated systems satisfy EDD requirements under EU AML law?
Yes. A technologically neutral position has been adopted by AMLA: effective identification and escalation of ML/TF risks is what matters. More reliably and more consistently than manual review cycles, automated EDD systems can satisfy the obligation when they collect verified source-of-funds and beneficial ownership data at onboarding, monitor adverse media and PEP databases continuously, and refresh customer records on a risk-based cadence.
What should compliance teams do immediately in response to this case?
Audit whether separate, documented exposure analyses exist in your general risk assessment for each material customer segment (including corporate). Confirm a defined, time-bound process for receiving and implementing regulatory typology guidance. Verify that all four required fields — purpose, source of funds, source of wealth, and beneficial ownership — are present in EDD records for every higher-risk customer in the portfolio.
Related Articles

FATF June 2026 Grey List: Iraq, Bosnia & KYC EDD
FATF added Iraq and Bosnia-Herzegovina to its June 2026 grey list. Here is what compliance teams must update in their KYC programs and EDD workflows.

AI Agents in Bank Compliance: Inside FINRA's 2026 Warning
FINRA's 2026 report flags AI agents as a new supervisory risk. Yet banks are deploying them for AML at scale. What compliance teams must know now.

Companies House ID Deadline: What KYB Teams Must Know
All existing UK directors and PSCs must verify their identity at Companies House by 18 November 2026. This is what every KYB compliance team must prepare.