Summary

  • Svea Bank's Annual Report 2025 states that all remediation measures from FI's December 2025 AML sanction were "completed according to plan" and validated by the bank's own Internal Audit function, with regular reporting to Finansinspektionen.
  • FI's decision (FI dnr 23-13249) contained no remediation order and no reporting obligation, so the "plan" against which completion is measured is internally defined and never published.
  • The English annual report describes the sanction as "a warning and an administrative penalty of SEK 170 million" — a characterization that conflicts with FI's decision, which imposed a remark (anmärkning), a distinct and lower sanction level under Swedish law.
  • No regulator-confirmed closure record, external audit report or decision-linked milestone list was located as of late September 2026, and FI's 2026 sanctions listing shows no follow-up action against Svea Bank.
  • On the registry side, the abuse contact for Svea's legacy netblock 193.105.138.0/24 still displays a Verizon Sweden mailbox, unchanged in the public record since the object's last modification on 31 October 2023.

The decision that ordered nothing to repair

On 17 December 2025 at 08:00, Finansinspektionen announced that Svea Bank AB (organisation number 556158-7634) had received a remark under Chapter 15, Section 1 of the Swedish Banking and Financing Business Act (LBF) and an administrative fine of SEK 170,000,000 under Chapter 15, Section 7 [1]. The decision, docket FI dnr 23-13249, followed an investigation of the bank's anti-money-laundering compliance covering the period 30 April 2022 to 1 May 2023, limited to business aimed at legal-person customers.

The findings were substantial: deficiencies in general risk assessments, customer risk assessments, identification of beneficial owners, information on the purpose and nature of business relationships, and enhanced due diligence for high-risk customers — in two cases delayed by more than a year [2][3].

The decision's operative part is the crucial document for this investigation. It contains exactly two points — the remark and the fee. There is no föreläggande (remediation order), no reporting obligation, and no list of corrective measures whose completion FI would certify [2]. The fine, the decision notes, is invoiced once the decision gains legal force, and appeals lie to the Administrative Court in Stockholm within three weeks [2]. FI judged that the violations were not serious enough to warrant licence withdrawal or a formal warning [3].

That design matters for everything that follows. A sanction without a remediation order defines no regulator-set yardstick. When a bank later announces that remediation is "complete", it is measuring against a plan it wrote itself.

The bank's claim, in its own words

Svea Bank's response on the day of the decision, issued through CEO Lennart Ågren, said the bank would read and analyze the decision and promptly carry out any remaining measures, and pointed to heavy investment in organizational, procedural and system-strengthening AML work. The comment did not announce an appeal [4].

The fullest statement of the outcome appears in the bank's Annual Report 2025. In its "Sanction and measures taken" section, the report states that the bank worked actively before and during the supervisory case, that the measures were validated by the bank's Internal Audit function and reported regularly to Finansinspektionen, and that "All measures have now been completed according to plan" [5]. The Swedish year-end report says the same: "samtliga åtgärder är stängda enligt plan" — all measures are closed according to plan [6].

Three features of this claim determine its evidentiary weight.

First, the plan is internal. Because FI's decision imposed no remediation order, the milestones, completion criteria and scope of the "measures" exist only in the bank's own programme. No public document located for this investigation discloses what those measures were, what "completed" means for each, or who defined the criteria.

Second, the validation is internal. Internal Audit sits inside the same corporate structure that owns the claim. An assurance function can be rigorous and independent-minded, but it is not an external attestation, and nothing in the public record shows an external auditor's or the regulator's confirmation of closure. "Reported regularly to FI" is outbound disclosure; it converts to implied endorsement only if a reader assumes FI acknowledged or accepted the reports. No such acknowledgement appears in the public record [5].

Third, there is no external anchor. As of the research date in late September 2026, no regulator-confirmed closure record, external audit report, or decision-linked remediation milestone list for the AML case was located [5]. FI's sanctions listing filtered to 2026 shows no follow-up action against Svea Bank; the Svea sanction appears only under 2025, and the sole surfaced 2026 financial-firm sanction is against Ikano Bank AB — a remark plus SEK 140 million [7].

The warning that was not a warning

The English-language annual report contains a detail that is small in word count and large in information value: it describes the December 2025 sanction as "a warning and an administrative penalty of SEK 170 million" [5].

That is not what FI imposed. The decision is explicit: an anmärkning (remark), not a varning (warning) [1][2]. Under Swedish law these are distinct sanction levels, and FI itself reasoned that the violations were not serious enough to warrant the heavier sanction of a warning [3]. The Swedish-language year-end report uses anmärkning correctly [6]; the discrepancy appears in the English edition.

The error could be a translation artifact. It could also be something subtler — a characterization that softens the sanction's severity for international readers of the annual report. The distinction is not cosmetic. An anmärkning is, in FI's own scheme, the lighter of the two levels named in this decision; a warning is heavier. Reporting the sanction as a warning inflates the severity actually imposed, which reads oddly in a document otherwise keen to present the matter as closed.

Either way, the failure matters because sanction-level accuracy is a low-cost test of reporting integrity: any organization that cannot restate the regulator's sanction level correctly in its flagship English document invites questions about the care applied to the rest of its compliance narrative.

What would count as externally verifiable repair

None of this proves the remediation did not happen. The claim may be entirely true. The point is that its verification structure is inverted: the operator asserts, the operator's own audit validates, and the regulator's silence is the only external signal — and silence is ambiguous, because FI was never obliged to confirm anything.

Repair becomes externally verifiable when at least one of three conditions holds. A regulator publishes an acknowledgement, closure note or follow-up decision referencing the remediation. An external auditor or reviewer attests to the completed measures against published criteria. Or the operator publishes the remediation plan itself — the measures, criteria and completion dates — so that the "according to plan" clause can be checked against a document. As of late September 2026, none of the three exists in the public record for the Svea Bank AML case.

There is one more externally observable surface, and it is not moving. Svea Bank routes its legacy netblock 193.105.138.0/24 via AS211899, but the RIPE record for that block still displays the abuse contact — a mailbox belonging to Verizon Sweden, not to any Svea entity — with the abuse-c role pointing to Svea Billing Services AB under a legacy maintainer. Independent mirrors corroborate the same display [8][9][10]. The object's last-modified date is 31 October 2023, which predates the FI decision by more than two years; no documented repair of this custody gap was located.

A bank reporting that its control environment is strengthened has, on this one public record, left an accountability endpoint unchanged.

Prior coverage and what is new here

Earlier BTW coverage of this subject established the registry custody chain behind 193.105.138.0/24 and the absence of any documented follow-up, appeal or remediation as of late September 2026. This article adds what the prior coverage could not yet see: the bank's own post-reporting answer. The Annual Report 2025 and year-end report are the first public statements in which Svea Bank asserts completed, internally validated remediation.

Reading them against the decision text produces a new, concrete discrepancy — the "warning" mischaracterization — and a new structural finding: the absence of any decision-linked yardstick makes the completion claim formally unverifiable rather than merely unconfirmed.

Sources