Summary

  • On 17 December 2025, Finansinspektionen gave Svea Bank AB a formal remark (anmärkning) and a sanction fee of 170,000,000 kronor for breaches of core anti-money-laundering rules covering the period 30 April 2022 to 1 May 2023.
  • The decision's operative part contains only those two points; no remediation order (föreläggande) or reporting requirement appears in the retrieved operative text, and FI's sanctions framework places such orders on a separate decision track normally handled by officials rather than the board.
  • The regulator reviewed 70 customer files and found that in 38 of them Svea failed to perform the mandatory search of the national beneficial-ownership register.
  • Svea's own account — measures closed "according to plan," validated by internal audit and reported to FI — is a self-interested issuer statement without independent verification.
  • On the parallel registry channel, the abuse contact shown for Svea's legacy netblock 193.105.138.0/24 is validated by RIPE policy only for technical deliverability, never for whether reports are read or acted on; no public source documents that it processed any report for this block.
  • Both channels verify existence, not effect: a registry flag and a public penalty. The evidence that either produced a durable, documented remedy rests, today, on the sanctioned firm's own word.

The decision's operative part: two points, then the appeal clause

The decision at the centre of this case file is Finansinspektionen's (FI) sanction decision against Svea Bank AB, corporate registration number 556158–7634, under case reference FI dnr 23-13249, announced at 08:00 on 17 December 2025. Its operative section, as retrieved from the published decision document, reads in full: "1. Finansinspektionen ger Svea Bank AB (556158–7634) en anmärkning" under Chapter 15, Section 1 of the Swedish Banking and Financing Business Act (lagen 2004:297), and "2. Svea Bank AB ska betala en sanktionsavgift på 170 000 000 kronor" under Chapter 15, Section 7 of the same act.

The operative part then refers to an annex for appeal instructions.

That is the whole of what the decision orders: a formal remark and a fee. A remediation order — in Swedish regulatory language, a föreläggande — is a separate instrument. The decision text itself recites the statutory menu: FI can intervene "genom att förelägga ett kreditinstitut att vidta rättelse eller genom att ge institutet en anmärkning" — by ordering a credit institution to take remedial action, or by issuing a remark. It chose the remark.

FI's general sanctions page confirms the distinction is structural, not incidental: orders to remedy a deficiency are normally decided by the authority's officials, not by FI's board, whereas sanctions — a remark or a warning, with or without a fee — are board decisions. A board-level sanction of this shape therefore does not, by construction, carry the enforceable remediation programme that many readers assume a regulatory penalty implies.

The decision document and FI's public pages list no reporting obligation, no follow-up deadline and no injunctive measure beyond the two operative points. FI's investigation-closure page, which details the deficiencies, likewise closes the case at "an anmärkning and a sanktionsavgift of 170 million kronor." The negative claim — that no remediation order was imposed — is inferred from the retrieved operative section and from every FI page describing the outcome, none of which mentions one; this analysis states it with that documentary caveat, and the underlying decision PDF is linked below for readers who want the full text.

What the regulator found, and what it decided the violations were worth

The substance behind the sanction is concrete. FI examined Svea's anti-money-laundering compliance for 30 April 2022 to 1 May 2023, limited to customers that are legal persons. It reviewed 70 customer files, of which 11 were assessed as high risk and 59 as medium or normal risk. In 38 of the 70 cases, Svea failed to perform the mandatory search of Bolagsverket's register of beneficial owners. The recorded deficiencies also included insufficient collection of information on the purpose and nature of business relationships, and absent or tardy enhanced due diligence for high-risk customers.

FI's press release, quoting Malin Alpen, head of the Payments area, framed the failures as shortcomings "in basic parts" of the bank's money-laundering work.

The penalty calculus is equally specific. The statutory ceiling for a sanction fee is 10 percent of the company's or group's turnover; against Svea's 2024 group turnover of roughly 6,271 million kronor, the maximum was about 627 million kronor. FI set the fee at 170 million kronor after a proportionality assessment, found no determinable profit from the breaches, and judged the violations not serious enough to consider withdrawing the licence or issuing a warning — the two heavier instruments available.

It also expressly rejected Svea's argument that the bank's own completed remedial measures should justify abstaining from intervention altogether. The fee accrues to the state and is invoiced once the decision gains legal force; the decision is appealable to the Administrative Court in Stockholm within three weeks.

What the decision does not contain is any ordered change. The bank must pay, and it carries a public mark. Nothing in the operative text compels it to fix, prove or report anything on a regulator-set schedule.

The bank's account: remediation on its own terms

Svea Bank's public response deserves careful reading because it is the only account of remediation on offer. In its market announcement on 17 December 2025, the bank confirmed the remark and the fee, described its own remediation as extensive, and said it would "read through and analyse the decision and as soon as possible take the any measures that remain to be done." Its 2025 year-end report goes further: all measures were "closed according to plan," continuously validated by internal audit and reported to FI.

Notice the direction of agency in that language. The remaining measures are ones the bank will itself identify by analysing the decision — not measures listed in the decision, because the decision lists none. The validation is internal audit's, reporting to the regulator that imposed no external verification regime. Every element of the remediation story is self-reported, and no independent source located for this investigation corroborates it. This is not an accusation of falsehood; it is an observation about who owns the evidence.

When a sanction carries no ordered programme, the burden of proving durable repair does not move to an external verifier. It stays where it started: with the sanctioned firm.

The registry channel: validated deliverability, unverified operation

The second accountability channel in this case runs through the internet number registry rather than the financial regulator. Svea's legacy routed network block 193.105.138.0/24 — registered under the netname SVEA-EKONOMI-SE and announced by AS211899 — presents, in independent mirrors of the RIPE Database, an abuse contact that is a shared, carrier-era mailbox on the Verizon Business/UUNET lineage, inherited from an earlier corporate life of the address space.

The same mailbox address appears as the abuse contact for netblocks belonging to operators with no connection to Svea, including Moore Europe Capital Management, IP-Only Networks AB and Rackspace Ltd.

RIPE policy does require that this attribute be checked — at least once a year, under the framework documented in RIPE-705 and the policy proposals 2017-02 and 2019-04. But the validation tests only technical deliverability: syntax, domain existence, mail-server configuration. It never verifies that anyone reads the mailbox, answers reports, escalates them or remediated the underlying abuse. No public source located for this investigation documents that this mailbox received, answered, escalated or remediated a single report for this block.

The parallel with the sanction decision is exact and, for the purposes of this analysis, the most useful finding of the file. Both accountability channels produce a verifiable signal — an annual registry validation flag, a public board-level penalty — and both stop short of verifying effect. The registry knows the mailbox can receive mail; it does not know whether it works. The regulator knows the bank broke the rules and has paid for it; it did not order the fixes, so it cannot enforce their completion. In both cases the measurable artefact of accountability is upstream of the outcome that matters.

What a durable remedy would require on each channel

On the registry channel, a durable remedy would look like evidence that the abuse contact is a functioning process: a documented ownership of the mailbox by the current registrant, a response or ticketing record, or a registry validation regime that samples operational responsiveness rather than deliverability. None of that is required by current policy, and none is observable in public sources for this block.

On the regulatory channel, the open question is whether the December 2025 decision becomes final unchallenged — the three-week appeal window to the Administrative Court in Stockholm was still running at the time of writing — and whether FI subsequently issues a separate föreläggande on the official-level track. A separate order, if it comes, would convert the sanction from a signal into an enforceable programme with an external counterparty. Until then, the only remediation narrative available is the bank's own, validated by its own internal audit, on a timeline it set.

The comparison against prior coverage of this same target is worth stating plainly. Earlier reporting this week established the shared Verizon-lineage abuse mailbox, the limits of RIPE's annual validation, and the SEK 170 million sanction as a separate accountability channel from the registry surface. What this file adds is the decision text itself: the sanction imposed no ordered remediation programme, and FI's own framework places such orders on a structurally different decision track. Prior coverage treated the sanction as the accountability event that fired; the decision text shows it fired as a penalty, not as an order.

Sources

The full fact set for this investigation rests on the following public documents: the Finansinspektionen sanction decision against Svea Bank AB (PDF) and its duplicate published copy; FI's sanction announcement page and investigation-closure page; FI's distributed press release; FI's general sanctions framework page; secondary legal and business coverage from Dagens Juridik and Dagens Industri; FI's news item on the sanction fee; Svea Bank's own market announcement and 2025 year-end report; and the RIPE policy documents RIPE-705, proposal 2019-04 and proposal 2017-02.