Konto- och värdefackssystem: Who Must Connect to Mekanismen
Authorised Swedish authorities may query one platform for account and safe-deposit-box information where the purposes and conditions in sections 3 or 3a are met. That platform is the konto- och värdefackssystem, the account and safe-deposit box system that Skatteverket has run since 2020 and that its own developer pages call Mekanismen. The obligation to feed it sits with the institutions, not the state.
Lag (2020:272) om konto- och värdefackssystem is the statute that makes it work. The Act was issued on 30 April 2020 and has since been amended by SFS 2022:618, SFS 2024:890, SFS 2025:36 and SFS 2026:123. Under section 1, the current duty applies to Swedish credit institutions; Swedish securities firms authorised to receive customers’ funds on account; foreign credit institutions operating through a Swedish branch; and foreign securities enterprises operating through a Swedish branch that hold the corresponding authorisation to receive customers’ funds on account. Section 2 requires the prescribed data to remain directly and immediately searchable for five years after the service ends, while section 3b prohibits unauthorised disclosure that an authority has searched the system. Get the scope wrong, connect late, or tip off a client, and the consequence runs past a late filing into breach of a criminal-justice access mechanism.
This is Sweden’s national piece of an EU-wide design. The same konto- och värdefackssystem obligation exists, under different names, in every Member State, because the Anti-Money Laundering Directive told each country to build one. Understanding where the Swedish rules stop and the EU rules begin is the difference between a clean connection and a scoping error that surfaces only when an authority runs a search and finds nothing.
Related reading: Finansinspektionen’s 2026 AML/CFT and sanctions risk priorities for Swedish firms
The dates that matter for Mekanismen
The core obligation is already live, but the perimeter is about to widen. These are the operative dates for a Swedish reporting or compliance team:
- 30 April 2020: Lag (2020:272) issued.
- 10 September 2020: the EU deadline by which each Member State had to have its centralised automated mechanism in place, under Article 32a of the amended Anti-Money Laundering Directive.
- 17 June 2020: Förordning (2020:521) issued, delegating the technical detail to Skatteverket.
- 15 November 2021: SKVFS 2021:15 was decided; the regulations entered into force on 1 January 2022.
- 10 July 2027: the general transposition deadline for the sixth Anti-Money Laundering Directive, Directive (EU) 2024/1640, which widens the searchable perimeter.
- 10 July 2029: the date by which the Commission must interconnect the national mechanisms through the Bank Account Registers Interconnection System (BARIS).
The EU obligation behind the Swedish system
Sweden did not invent Mekanismen on its own initiative. Article 32a of Directive (EU) 2015/849, inserted by the fifth Anti-Money Laundering Directive, Directive (EU) 2018/843, told every Member State to put in place centralised automated mechanisms, such as central registries or central electronic data retrieval systems, allowing the identification in a timely manner of any natural or legal persons holding or controlling payment accounts and bank accounts identified by IBAN, and safe-deposit boxes held by a credit institution within their territory. The deadline was 10 September 2020. Lag (2020:272) is how Sweden met it.
The directive did more than mandate a system. It fixed the minimum data set. Article 32a(3) required that the mechanisms make searchable the name of the customer-account holder and of anyone acting on their behalf, the name of the beneficial owner, the IBAN and the account opening and closing dates for bank and payment accounts, and for the safe-deposit box the lessee name and the duration of the lease period. Read the Swedish field list in section 2 of Lag (2020:272) next to that article and the lineage is obvious: the national law tracks the directive almost field for field, then adds the Swedish identifiers that make a search useful, such as the personnummer.
Article 32a(3) already required the customer-account holder and beneficial owner to be identified by name together with the prescribed identification data or a unique identification number. Article 32a(4) allows Member States to add additional information fields. Sweden’s broader institutional and account coverage reflects national implementation choices under the Directive’s minimum-harmonisation framework, as set out in Proposition 2019/20:83. The same article asked the Commission, by 26 June 2020, to report on how the national mechanisms could be interconnected securely, and that report is the thread that runs directly into the interconnection system the sixth Directive later put on a statutory footing.
Under the current regime, Mekanismen is an on-demand lookup service: institutions keep the prescribed data queryable through the electronic interface, while Skatteverket states that the service and connected institutions should normally be available daily from 04:00 to 23:00. There is no periodic submission, no monthly file, no remittance date, no template code in the COREP sense. Teams that map it onto a reporting calendar are modelling the wrong obligation.
Which institutions must connect
Section 1 of Lag (2020:272) defines the obliged population narrowly, and the boundary is where scoping errors happen. An institution, for the purposes of the Act, is either a credit institution, including a foreign credit institution that carries on business from a branch in Sweden, or a securities firm (värdepappersbolag) and foreign securities enterprise that carries on business from a branch in Sweden and that holds authorisation to receive customers’ funds on account.
The client-funds authorisation condition on securities firms is the trap. A Swedish värdepappersbolag is inside the perimeter only if it is authorised to receive customers’ funds on account. A firm that provides investment services but routes all client money to a separate credit institution, and holds no such authorisation itself, falls outside section 1. Mapping every MiFID firm into scope merely because it holds client assets overstates the population; the statutory test is the specific authorisation to receive customers’ funds on account, not the holding of securities.
For a foreign credit institution or securities enterprise, only business carried on through a Swedish branch is within the current Swedish mechanism; pure cross-border business into Sweden without a branch is outside section 1. For a Swedish credit institution or securities firm authorised to receive customers’ funds on account, accounts and safe-deposit boxes attributable to outbound cross-border business conducted without a foreign branch are included, while those held at a foreign branch or foreign subsidiary are excluded. The customer’s country of residence does not alter those rules.
Skatteverket frames the trigger operationally: an institution that provides, or within the past five years has provided, accounts or safe-deposit boxes covered by the Act has to make that data available. The five-year tail carries real weight here, and it is the reason a firm that has wound down its deposit book still has to keep the platform populated, which the next section takes up.
The data your entry must make searchable
Section 2 of the Act sets out exactly what the konto- och värdefackssystem has to expose, and it separates the fields by the kind of subject or object being searched. For natural persons, the system must give access to the name and the personnummer or samordningsnummer, or the date of birth where no such number exists, for every holder of an account or safe-deposit box, and the corresponding data for any representative of a holder.
For legal persons, the fields are the company name, any special company name (särskilt företagsnamn) and, where applicable, the organisationsnummer for every holder, together with the name and personnummer or samordningsnummer, or date of birth, of the holder’s beneficial owners (verkliga huvudmän) and authorised representatives (fullmaktshavare). The beneficial-owner and proxy fields are the ones that break when a firm treats Mekanismen as an account-number lookup. For an active account or box lease, the searchable data must reflect the current holders, representatives, proxies and beneficial owners. After the service ends, the searchable data must reflect the persons who held those roles when it ended; earlier historical changes in those roles are not part of the query result.
For accounts, the searchable fields are the IBAN, or another number identifying the account where no IBAN exists, plus the dates the account was opened and closed. For safe-deposit boxes, section 2 requires the rental-period duration alongside the holder-identification data. In the operational interface, Skatteverket also uses a value identifying the box (värdefacksidentifikation); no standardised designation exists, and the same designation may produce more than one result. The mechanism does not disclose the contents of the box. Any power to inspect contents comes from separate procedural law.
The Swedish list maps onto the directive minimum and adds national identifiers. If you are building or auditing the data feed, the practitioner’s checklist is holder identity, representative identity, beneficial-owner identity for legal persons, account identifier, account lifecycle dates, box-identification value and box lease duration, together with the requirement that both current and any previous identification numbers remain searchable where identifiers have changed. Every one of those has to be reachable through the query interface for the search to return a complete answer.
Five years after the service ends
The retention rule in the second paragraph of section 2 is the one that is easy to under-scope. An institution has to ensure the section 2 data stays directly and immediately searchable in the konto- och värdefackssystem until five years have passed from the point the service was terminated. Closing an account or ending a box lease starts the five-year clock on the data-searchability obligation.
This is why decommissioning a deposit product keeps the searchability obligation live. A firm that closes its retail deposit book on a given date still has to keep those closed accounts and their holders searchable for five years afterwards, which means the connection to Skatteverket, the query interface, and the underlying data cannot simply be switched off when the last account closes. The forthcoming EU rules keep the same five-year floor and allow Member States to extend it by up to a further five years in specific cases, so the direction of travel is toward longer, not shorter, searchability.
How institutions connect to the konto- och värdefackssystem
Lag (2020:272) sets the obligation; the operational detail lives one and two levels down. Section 8 empowers the Government, or the authority it designates, to issue regulations on how institutions give access to data and how authorities obtain it. Förordning (2020:521) om konto- och värdefackssystem carries that delegation to Skatteverket, and Skatteverket’s own regulations, SKVFS 2021:15, set the technical rules an institution has to meet.
In practice, connecting means building and operating a machine-to-machine query interface that Skatteverket can call in real time. Authentication uses mutual TLS together with an OAuth2 client-credentials grant, and the institution exchanges keys and certificates with Skatteverket that have to be stored so they are inaccessible to unauthorised persons. The service is expected to be available daily between 04:00 and 23:00, to return a response within ten seconds of receiving a request, and any longer planned interruption has to be notified to Skatteverket at least five working days in advance.
Before connection, Skatteverket states that the institution must have a completed API, a completed technical solution capable of answering Mekanismen queries, a test environment containing relevant test data, and completed internal tests.
SKVFS 2021:15 sets the availability window, latency threshold and interruption-notice requirements as the regulated service level. A mechanism that answers most of the time, or that takes a minute to return a hit, does not meet SKVFS 2021:15 even if the underlying data is perfect. Because Mekanismen exists to give investigators a timely answer, an interface that is slow or intermittently down defeats the statutory purpose of immediate access, which is the standard the whole system is measured against.
Which authorities can search, and on what basis
Sections 3 and 3a name who may look, and the distinction between them is doing real legal work. Section 3 gives a defined set of authorities a direct right to take part of the data through the system. After the amendment by SFS 2026:123, that set covers the Police Authority, the Security Service (Säkerhetspolisen), a prosecution authority, the Swedish Customs (Tullverket), the Coast Guard (Kustbevakningen) and Skatteverket where the data is needed in a criminal preliminary investigation or to answer a Europol request; the Police Authority, the Security Service, a prosecution authority, Swedish Customs and Skatteverket for investigations into independent confiscation (självständigt förverkande); the police, Security Service, Customs and Skatteverket for preventing or detecting the serious crime listed in Annex I to the Europol Regulation (EU) 2016/794; a prosecution authority in mutual legal assistance and European Investigation Order matters; and the Police Authority and the Swedish Economic Crime Authority (Ekobrottsmyndigheten) acting as asset-recovery offices.
Behind that list sits an EU requirement that the national financial intelligence unit have immediate and unfiltered access to the mechanism, set out in Article 32a(2) of the directive. In Sweden that access is delivered through the Police Authority, which section 3 lists among the authorities with a direct right to search, so the domestic architecture routes the FIU function through the police entry, with no separately named unit in the statute.
Section 3a works differently, and reading it as a second list of the same kind is a mistake. It provides that certain authorities shall get access through the system only if, under some other statute, they already have the right to request the data. Skatteverket is listed there for audit and control work and for Sweden’s obligations under EU administrative cooperation in taxation; the Enforcement Authority (Kronofogdemyndigheten) for tracing property for attachment, provisional attachment or payment security, supervising business bans, cross-border account-preservation procedures, and EU administrative cooperation on information exchange between social-security institutions; and the Payments Authority (Utbetalningsmyndigheten), added by SFS 2025:36, for its in-depth reviews. The system is a delivery channel for those authorities, not the source of their power to see the data. The substantive right to access lives in their own legislation; Mekanismen only routes it.
The prohibition on telling the customer
Section 3b, inserted by SFS 2022:618, imposes a confidentiality duty that catches the institution and its people directly. An institution, its board members or its employees may not improperly disclose to the customer, or to any outsider, that an authority has run a search under section 3 or section 3a in the konto- och värdefackssystem. Liability for a breach follows from Chapter 20, section 3 of the Criminal Code (brottsbalken), which is the offence of breach of professional secrecy.
This is a tipping-off rule with a trigger distinct from the suspicious-transaction prohibition AML officers already know: the fact that an authority searched a record, whether or not any report was ever filed. A relationship manager who sees an unusual pattern of official interest and mentions it to the client may have breached section 3b regardless of whether any suspicious-transaction report was ever in play. Staff training that covers only the transaction-reporting tipping-off ban leaves this exposure uncovered.
The data-protection posture around searches is aligned with that secrecy. Section 6 provides that notice that personal data is being processed under section 5 may not be given to the individual, and it disapplies the right to object under Article 21(1) of the General Data Protection Regulation for processing under this law. Section 4 confines Skatteverket’s role as data controller to the processing it itself performs in the system, and section 7 requires logs to be kept of the personal data processed, where that duty does not already follow from Chapter 3, section 5 of the Criminal Data Act (brottsdatalagen 2018:1177). The design keeps the subject of a search from learning about it while preserving an audit trail for oversight.
What the sixth Directive changes by 2027
The current Swedish system implements the previous Article 32a account-register regime. Directive (EU) 2024/1640 must generally be transposed by 10 July 2027. On 6 July 2026, the Swedish Government published memorandum Fi2026/01654 proposing that Lag (2020:272) be repealed and replaced by a new law under which Skatteverket would operate a central register. The memorandum is under consultation until 30 October 2026 and is not binding law.
First, Article 16 expands the EU minimum to virtual IBANs, securities accounts and crypto-asset accounts held by credit institutions or financial institutions. Sweden’s July 2026 memorandum proposes a central register and an expanded institution definition covering, among others, central securities depositories, fund companies, credit institutions, investment firms, payment institutions, electronic-money institutions, alternative investment fund managers, crypto-asset service providers and certain other financial businesses, including specified foreign firms operating through Swedish branches. It separately proposes bringing gambling licensees and gaming accounts into the register from a separately proposed effective date. Those national provisions remain proposals and may change before enactment.
Second, the national mechanisms will be interconnected through BARIS by 10 July 2029. Under Article 16, all information listed in Article 16(3), including identity data, account identifiers, opening and closing dates and safe-deposit-box lease data, must be available through BARIS to other Member States’ FIUs, AMLA for joint analyses and supervisory authorities under the access conditions stated there; nationally added information is excluded. Directive (EU) 2024/1654 separately provides cross-border BARIS access for designated competent authorities in serious-crime cases.
Third, the retention floor is confirmed and can be extended. Article 16 keeps information searchable for five years after an account is closed and allows Member States, in specific cases, to require or permit retention for up to a further five years where that is necessary and proportionate for preventing, detecting, investigating or prosecuting money laundering or terrorist financing. The EU package that Article 16 sits inside is the same reform that Luxembourg and every other Member State is working through; our note on the EU Anti-Money Laundering Regulation and what it changes sets out the wider architecture, and the MiCAR reporting obligations for crypto-asset service providers are the reference point for the crypto-asset accounts now entering the register’s scope.
For teams that already run Sweden’s other AML obligations, this fits a familiar pattern of expanding data expectations; the same trajectory shows up in Sweden’s periodic AML reporting due from 2027.
Frequently Asked Questions
Is connecting to the konto- och värdefackssystem a reporting return with a deadline?
Under Lag (2020:272) currently in force, there is no periodic return: the institution keeps the prescribed data searchable on demand. The current operational rules nevertheless include at least five working days’ advance notice for longer planned service interruptions. The July 2026 memorandum proposes a future central register with an initial submission and recurring submissions at intervals to be set in secondary rules; that proposal is not yet binding.
Does a securities firm without authorisation to receive customers’ funds on account have to connect?
Under Lag (2020:272) currently in force, a värdepappersbolag is an institution only if it is authorised to receive customers’ funds on account. Sweden’s July 2026 memorandum proposes defining Swedish investment firms and corresponding foreign firms operating through a Swedish branch as institutions under the new register law, with submission duties determined by the covered account types the firm actually provides. The proposal is not yet enacted.
What happens to the obligation when we close an account or a customer ends a box lease?
The five-year clock in section 2 starts. The holder and account or box data has to remain directly and immediately searchable for five years from the date the service was terminated. Decommissioning a deposit product does not release a firm from the connection during that window.
Can we tell a customer that the police or the tax agency searched their record?
No. Section 3b prohibits an institution, its board members and its employees from improperly disclosing to the customer or any outsider that an authority has made a search under section 3 or 3a. A breach can be prosecuted under Chapter 20, section 3 of the Criminal Code. This is separate from, and additional to, the suspicious-transaction tipping-off rules.
Does the system let authorities see what is inside a safe-deposit box?
No. Mekanismen exposes holder-identification data, the box-identification value used in the interface and the rental-period duration; it does not expose the contents. Any power to inspect the contents comes from separate procedural law, not from Lag (2020:272).
How does a foreign bank operating in Sweden know whether it is in scope?
For a foreign credit institution, the current Swedish test is whether it carries on business through a branch in Sweden. A foreign securities enterprise is in scope only if it carries on business through a Swedish branch and has the corresponding authorisation to receive customers’ funds on account. Pure cross-border business without a Swedish branch is outside section 1; any obligation in the firm’s home jurisdiction must be assessed under that jurisdiction’s law. A group cannot assume that a home-jurisdiction mechanism discharges the duty for a Swedish branch.
What identifiers does a search rely on, and why does data quality matter so much?
The Swedish fields include the personnummer or samordningsnummer for individuals and the organisationsnummer for entities, which is what lets a search resolve to a specific person rather than a common name. Under the sixth Directive, only data that is up to date and corresponds to the actual account or box may be exposed through the interconnection, so a stale or mismatched identifier is a compliance defect, not a cosmetic one.
What does BARIS change for a Swedish institution’s own connection?
BARIS will interconnect Sweden’s national mechanism with those of other Member States. Under the July 2026 memorandum, covered institutions would submit prescribed information to a central Skatteverket register rather than permanently retain the current live-query architecture, subject to transitional rules and final legislation. From 10 July 2029, BARIS access will include the Article 16(3) data for other Member States’ FIUs, AMLA for joint analyses and supervisory authorities; Directive (EU) 2024/1654 also provides cross-border access for designated competent authorities in serious-crime cases.
Related Articles
- Finansinspektionen 2026 AML/CFT and Sanctions Risk Priorities: what Sweden’s supervisor expects firms to prioritise in financial-crime reporting this year.
- Sweden’s Periodic AML Reporting from 2027: the new recurring AML data obligation and how it sits alongside the account register.
- The EU Anti-Money Laundering Regulation: What Changes: the single rulebook and directive package behind the register expansion.
- AMLA Direct Supervision of Obliged Entities: how the new EU authority will supervise and use interconnected data.
- MiCAR Reporting Obligations for CASPs: the crypto-asset framework relevant to the crypto-asset accounts entering the register.
Key Takeaways
- Lag (2020:272) makes Skatteverket’s konto- och värdefackssystem (Mekanismen) a live, searchable identity layer that obliged institutions must keep populated, not a periodic reporting return.
- The obliged population is credit institutions and securities firms authorised to receive customers’ funds on account, including qualifying foreign firms operating through Swedish branches; that specific client-funds authorisation is the decisive test for securities firms.
- Section 2 fixes the statutory data: holder and representative identity, beneficial owners and proxies for legal persons, IBAN or other account identifier with opening and closing dates, and the rental-period duration for safe-deposit boxes; Skatteverket’s operational interface also uses a value identifying the box.
- Data must stay directly and immediately searchable for five years after a service is terminated, so decommissioning a deposit book does not switch off the connection.
- SKVFS 2021:15 sets a real service level: mutual-TLS and OAuth2 client-credentials authentication, availability daily 04:00 to 23:00, a response within ten seconds, and five working days’ notice of planned downtime.
- Section 3b prohibits an institution, its board members and employees from unauthorised disclosure that an authority searched under section 3 or 3a; Chapter 20, section 3 of the Criminal Code addresses liability for breach.
- Directive (EU) 2024/1640 Article 16 widens the perimeter to securities accounts, crypto-asset accounts and virtual IBANs; Sweden must transpose it by 10 July 2027, with BARIS interconnection due by 10 July 2029.
Sources and References
- Lag (2020:272) om konto- och värdefackssystem, Sveriges riksdag (consolidated, amended through SFS 2026:123)
- Förordning (2020:521) om konto- och värdefackssystem, Sveriges riksdag
- SKVFS 2021:15, Skatteverkets föreskrifter om konto- och värdefackssystem, Skatteverket
- Skatteverket, Utvecklingsområde konto- och värdefackssystem (Mekanismen)
- Proposition 2019/20:83, Ett nytt konto- och värdefackssystem
- Directive (EU) 2018/843 (fifth Anti-Money Laundering Directive), Article 32a
- Directive (EU) 2024/1640 (sixth Anti-Money Laundering Directive), Article 16 and Article 78
- EU:s penningtvättspaket, memorandum Fi2026/01654, Finansdepartementet, 6 July 2026
- Consultation on memorandum Fi2026/01654, responses due 30 October 2026
- Regulation (EU) 2016/794 (Europol Regulation), Annex I
The continuous obligation after you connect
Under Lag (2020:272) currently in force, institutions must maintain searchability, the five-year tail and the section 3b confidentiality duty. The 6 July 2026 memorandum proposes a new central register, an expanded institution and account perimeter, initial and recurring submissions, and repeal of Lag (2020:272) on 10 July 2027. Under the proposed transitional rule, the repealed Act would continue to apply to institutions connected when the new law enters into force, only for corresponding information not yet registered in the new register, for a transition period to be specified in the final legislation. The memorandum is under consultation and is not binding, but the national draft is now available for assessment.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
