Anti-Money Laundering – Regulatory Guide

Publisert 13.08.2026 av

The anti-money laundering regulatory framework aims to prevent and detect money laundering and terrorist financing. The financial sector has long operated under detailed AML requirements, but the framework remains challenging because it continues to evolve and is subject to active and detailed supervisory scrutiny.

This article provides an introduction to the Norwegian AML framework and a brief update on its status as of August 2026.

1. Background and Regulatory Framework

Money laundering refers broadly to conduct involving the proceeds of criminal activity, including securing, converting or concealing such proceeds. Terrorist financing includes the financing of terrorist acts, terrorist organisations and individual terrorists.

The current Norwegian Anti-Money Laundering Act and associated regulations entered into force on 15 October 2018. The current Norwegian framework implements the Fourth Anti-Money Laundering Directive (Directive (EU) 2015/849), as amended by the Fifth Anti-Money Laundering Directive (Directive (EU) 2018/843), together with relevant EEA adaptations. The Norwegian framework is also influenced by the standards and recommendations developed by the Financial Action Task Force (FATF).

At EU level, a new AML package was adopted in 2024. It includes Regulation (EU) 2024/1624 establishing a directly applicable AML single rulebook, Directive (EU) 2024/1640 on national AML mechanisms and Regulation (EU) 2024/1620 establishing the European Anti-Money Laundering Authority (AMLA). The AML Regulation will generally apply in the EU from 10 July 2027.

For Norway, however, the new EU framework must be incorporated and implemented through the EEA and Norwegian legislative processes. A Norwegian working group submitted its implementation report in January 2026, and the Ministry of Finance subsequently consulted on proposals for a new Norwegian Anti-Money Laundering Act. The proposals have not yet entered into force.

Entities failing to comply with the Norwegian AML framework may face supervisory measures and sanctions, including orders to cease unlawful conditions, coercive fines, administrative penalties and, in serious cases, criminal sanctions.

2. Who is Subject to the Obligations?

The Norwegian AML framework applies to a defined group of reporting entities.

These include, among others, banks, credit and financing undertakings, payment institutions, investment firms, UCITS management companies, alternative investment fund managers, insurance undertakings and intermediaries within the statutory scope, and other specified financial-sector entities.

Crypto-asset service providers are also within the Norwegian AML framework. From 1 July 2025, amendments implementing Regulation (EU) 2023/1113 (TFR II) brought crypto-asset service providers within the Norwegian AML framework and introduced requirements concerning information accompanying relevant transfers of funds and crypto-assets.

Branches of foreign undertakings carrying on activities in Norway that fall within the statutory scope are subject to Norwegian AML requirements. A foreign financial institution operating through a Norwegian branch must therefore assess its obligations under Norwegian law rather than relying solely on the AML framework applicable to its head office.

The legislation also applies to a range of non-financial professions and businesses, including auditors, accountants, lawyers when carrying out specified types of transactions, real estate agents, corporate service providers and gambling service providers.

The Financial Supervisory Authority of Norway (Finanstilsynet) supervises most financial-sector reporting entities. Advokattilsynet is the AML supervisory authority for lawyers falling within the statutory scope, while Lotteritilsynet supervises gambling service providers.

For financial institutions and other regulated firms, AML compliance is closely connected with customer onboarding, governance, payment services, sanctions screening and supervisory risk. LexOslo advises Norwegian and international financial-sector clients on Norwegian finance law and regulatory matters, including AML issues.

3. Key Obligations – What Must Entities Ensure Compliance With?

The AML framework is extensive and imposes detailed requirements. The obligations are risk-based, but this does not mean that individual requirements can be disregarded where the reporting entity considers the overall risk to be low.

Some of the fundamental elements of the framework are set out below.

3.1. Enterprise-Specific Risk Assessment

Section 7 of the Norwegian Anti-Money Laundering Act requires reporting entities to identify and assess the risks of money laundering and terrorist financing associated with their business.

The assessment must take into account, among other things, the nature and scale of the entity's business, its products and services, its customers and customer groups and relevant geographical factors. It must be adapted to the particular business, documented and kept up to date.

A useful risk assessment should distinguish between the entity's inherent exposure, the measures implemented to mitigate that exposure, vulnerabilities in those measures and the resulting residual risk.

Industry or group-wide templates can be useful, but they should not substitute for an assessment of the reporting entity's own risk exposure. This is particularly important for Norwegian branches of international groups, where group-wide methodologies may need to be adapted to Norwegian products, customers, regulatory requirements and risk factors.

Terrorist financing should be considered separately rather than treated merely as an extension of money-laundering risk. Finanstilsynet's 2025 thematic review of ten banks emphasised the importance of understanding the factors that distinguish terrorist-financing risk from money-laundering risk and of reflecting those factors in risk assessments, customer classification and transaction-monitoring rules.

The risk assessment should draw on both internal experience and relevant external sources. For financial institutions, these will typically include assessments and guidance from Norwegian authorities, FATF and the relevant European supervisory bodies.

The assessment must be kept up to date and should be revisited where the business, products, customer base, technology or external risk environment changes.

3.2. Procedures

Reporting entities must establish operational procedures setting out how AML obligations will be implemented in practice. There should be a clear connection between the risks identified in the enterprise-specific risk assessment and the procedures adopted to address those risks.

Section 8 requires the procedures to be documented, kept up to date, adapted to the nature and scale of the business and adopted at the highest level of the reporting entity.

Procedures should explain how assessments and decisions are actually made. Checklists, system workflows or user interfaces may support compliance, but they should not replace written procedures explaining the entity's methodology, responsibilities and controls.

Procedures should also be reviewed when the risk assessment changes, when new regulatory requirements apply, when new products or technology are introduced or when experience shows that existing controls are insufficient.

3.3. Risk Classification, Customer Due Diligence and Ongoing Monitoring

Reporting entities must apply customer due diligence and ongoing monitoring on a risk-sensitive basis. Customer risk classification should therefore reflect both the enterprise-specific risk assessment and the circumstances of the individual customer relationship.

Standardised risk profiles and automated models may be used, but the reporting entity must be able to demonstrate that the measures applied are proportionate to the relevant risk.

The Norwegian framework distinguishes between standard, simplified and enhanced customer due diligence. Enhanced measures are required in higher-risk situations and must be sufficient to enable the reporting entity to understand and manage the specific risk.

Identification of beneficial owners is a central part of CDD for corporate customers. The reporting entity must identify beneficial owners and take reasonable measures to verify their identity. The assessment may involve ownership, voting rights, rights to appoint or remove board members, agreements and other mechanisms through which ultimate control may be exercised.

Reporting entities may in certain circumstances rely on CDD performed by specified third parties. Such reliance does not transfer the ultimate responsibility for compliance from the reporting entity.

Banks, credit institutions and financing undertakings are required to use electronic monitoring systems to support transaction monitoring. The systems must be appropriate for the nature and scale of the business and should reflect the entity's risk assessment.

Automated monitoring does not remove the need for professional judgement. The entity should understand the limitations of its monitoring systems, apply appropriate scenarios and thresholds and document the basis for its transaction-monitoring methodology.

3.4. Investigation and Reporting Obligation

Where circumstances may indicate that funds are connected with money laundering or terrorist financing, the reporting entity must investigate.

If the investigations do not dispel the suspicion and the statutory conditions are met, the matter must be reported to the Norwegian Financial Intelligence Unit in Økokrim.

The reporting obligation is one of the central mechanisms through which the AML framework connects the private financial sector with public enforcement against financial crime.

3.5. Internal Control and Training

Reporting entities must maintain internal controls sufficient to ensure compliance with the AML framework.

Where a risk assessment of the nature and scale of the business indicates the need, section 35 requires the reporting entity to appoint a compliance officer, conduct fitness assessments of employees and establish an independent control function.

Section 8 also requires a member of management to have particular responsibility for following up the entity's AML procedures. The allocation of responsibilities should be clear and documented.

Training is required for employees and others carrying out relevant work for the reporting entity. It must be provided regularly so that knowledge remains current.

Training should be adapted to the person's role and the entity's actual risk exposure. Generic e-learning alone may therefore be insufficient where employees or management require more specific knowledge of the entity's products, customers, systems and procedures.

3.6. Customer Relationships, De-risking and Sanctions Screening

AML requirements can affect whether a reporting entity may establish or continue a customer relationship, but the rules do not provide a general basis for avoiding categories of customers merely because they present elevated risk.

In HR-2024-761-A, the Norwegian Supreme Court held that the assessment under section 24(4) must focus on the specific CDD measures that cannot be carried out. The Court also emphasised the requirement to identify beneficial owners. Following further proceedings, the Borgarting Court of Appeal held in LB-2024-184938 in June 2025 that the insurer was required to terminate the customer relationships because the applicable CDD requirements could not be fulfilled.

A related perspective appears in HR-2024-1184-A. Although that case was decided under the Insurance Contracts Act, the Supreme Court expressly considered the AML framework and held that general concerns relating to trust, social responsibility or business policy were not in themselves sufficient to justify non-renewal of the insurance relationship.

The interaction between AML requirements and de-risking has also been addressed at EU level. In Case C-81/24 Jenec, decided on 11 June 2026, the Court of Justice held that inclusion of a customer on a United States OFAC sanctions list is not, for that reason alone, sufficient to refuse access to a payment account with basic features without an individual assessment of the relevant AML/CFT risk.

For banks and other financial institutions, sanctions screening and third-country risk information may therefore be relevant inputs into the risk assessment, but they should not automatically replace the individual AML analysis required by the applicable legal framework.

This distinction is particularly important because sanctions legislation applies alongside, but is legally distinct from, the AML framework.

4. Regulatory Developments

The Norwegian and European AML framework is undergoing substantial change.

New EU AML framework. The EU's AML Regulation, AMLD6 and AMLA Regulation will significantly increase harmonisation across Europe. The principal provisions of the AML Regulation apply in the EU from 10 July 2027. Norway is currently considering how the package should be implemented through the EEA and Norwegian law.

AMLA. AMLA is established and operating from Frankfurt and is developing technical standards and common supervisory methodologies. Direct supervision of selected financial institutions is scheduled to begin in 2028. The implications for Norway will depend on the EEA and implementation arrangements.

Crypto-assets and transfers. Norway implemented TFR II and the new crypto-asset framework from 1 July 2025. Crypto-asset service providers are now reporting entities under Norwegian AML legislation, and requirements apply to information accompanying relevant transfers of funds and crypto-assets.

High-risk jurisdictions. FATF and the EU regularly update their respective designations and lists of jurisdictions presenting elevated money-laundering and terrorist-financing risks. Reporting entities should have procedures for identifying relevant changes and assessing their impact on customer risk classification, enhanced due diligence and ongoing monitoring. Country-risk assessments and internal procedures should therefore be based on current authoritative sources rather than static lists that may become outdated.

More generally, the continuing development of the AML framework makes it important that risk assessments, customer-classification models, procedures and monitoring systems are treated as living compliance tools and updated as the regulatory and risk environment evolves..



(Initially published 30 March 2025 – Updated August 2026)

How LexOslo can assist

Finance law is at the core of LexOslo's practice. We advise banks, other financial institutions and regulated businesses on Norwegian finance law and regulatory matters, including anti-money laundering requirements.

Our work can include advice on enterprise-specific risk assessments, AML procedures and governance, customer due diligence and onboarding issues, beneficial ownership, customer termination and de-risking, and regulatory questions arising in connection with Norwegian operations or cross-border financial services.

Harald Sætermo has more than 25 years of experience from legal practice and banking, including as in-house counsel at one of Northern Europe's largest financial institutions.

If you require Norwegian law assistance in connection with a specific AML or financial regulatory matter, please contact LexOslo.

 

Harald Sætermo, Attorney-at-Law
Email: has@lexoslo.no
Phone: +47 906 50 410

All our articles are subject to our copyright and liability provisions, which can be read here.

Related articles
13.08.2026
Legal due diligence in Norway: key considerations for foreign investors
Read more