Sweden's Finansinspektionen imposed a fine of SEK 500 million, approximately $45 million, on Klarna Bank AB in December 2024 following an investigation that found serious deficiencies in the buy-now-pay-later lender's anti-money laundering compliance programme. The penalty is the largest AML fine ever levied by Swedish authorities against a payments or fintech institution, marking a significant escalation in regulatory enforcement against digital financial services firms in the Nordic region.

The violations identified by the regulator related to the period from April 2021 to March 2022, during which Finansinspektionen found that Klarna's risk assessment and customer due diligence processes were inadequate relative to the requirements of applicable AML legislation. The fine reflects the regulator's assessment that the deficiencies were serious, systemic and of a character that warranted a financial penalty at the upper end of the available sanctioning range.

BNPL SERVICES AND MONEY LAUNDERING RISK

A specific focus of the FI's investigation was Klarna's failure to adequately assess how its buy-now-pay-later products could be exploited for money laundering or the financing of terrorism. BNPL services, which allow consumers to make purchases and defer payment, have attracted increasing regulatory scrutiny across Europe as supervisors argue that their accessibility and rapid growth create exposure to financial crime risks that traditional credit products do not present in the same form or with the same customer anonymity characteristics.

The FI's finding that Klarna's controls did not adequately address the specific money laundering vulnerabilities of its core product line represents a significant supervisory statement for the broader fintech sector. Regulators have been pressing technology-driven financial firms to demonstrate that their risk assessments are genuinely product-specific rather than generic frameworks imported from conventional banking compliance manuals. The Klarna case illustrates in concrete terms the consequences of failing to meet that increasingly non-negotiable expectation.

Customer due diligence is a foundational element of any AML programme, requiring institutions to identify their customers, understand the nature of their economic activity and apply enhanced scrutiny where risk factors are elevated. Deficiencies in this area during the review period meant that Klarna was not positioned to detect or report suspicious activity with the reliability that Swedish law requires of regulated financial institutions, a failure the FI regarded as serious given the volume of transactions processed by the platform.

RECORD FINE AND REGULATORY SIGNIFICANCE

The SEK 500 million sanction establishes a new benchmark for AML enforcement in Sweden's fintech sector. Prior enforcement actions in the Nordic region have typically resulted in smaller financial penalties, and the scale of this fine signals that Finansinspektionen is prepared to deploy the full extent of its sanctioning powers when compliance failings are judged to be serious and systemic. The decision will be studied carefully by fintech firms operating under Swedish or Nordic regulatory oversight.

For Klarna, the fine arrives at a moment of strategic importance as the company pursues a public listing. A significant regulatory sanction for historical AML failures will require the company to demonstrate remediation convincingly to Finansinspektionen and to institutional investors. The case underlines the extent to which regulatory compliance has become a material factor in the valuation and investor attractiveness of high-growth fintech firms operating across multiple European jurisdictions.