Sweden's financial supervisory authority, Finansinspektionen (FI), imposed a fine of SEK 12,500,000 — equivalent to approximately $1.3 million — on Swedbank AB on 14 May 2025 after finding that the bank had violated protective security regulations during the period from July 2022 to January 2024. The decision marks the conclusion of an FI review into how Swedbank managed its obligations under Swedish protective security law, which governs how operators of security-sensitive activities identify and document risks to national security and critical infrastructure.
Swedbank is one of Sweden's four major commercial banks and a systemically important institution across the Nordic region. Its designation as a security-sensitive operator means it is subject to requirements that go beyond ordinary financial regulation, including obligations to conduct and document protective security analyses at a level of rigour that FI found to be lacking during the relevant period.
DOCUMENTATION SHORTCOMINGS AT THE ROOT
FI found that the primary failing at Swedbank was in the documentation of its protective security analyses. The authority concluded that the bank had not maintained its security documentation to the standard required under the applicable protective security legislation during the period between July 2022 and January 2024 — a span of approximately eighteen months. Documentation is a foundational requirement in protective security frameworks because it demonstrates that the organisation has systematically identified what activities or information assets need protection, assessed the threats and vulnerabilities they face, and determined appropriate countermeasures.
The regulator noted that the violations were deemed unintentional — that is, FI found no evidence that Swedbank had deliberately failed to comply with its obligations. Furthermore, FI acknowledged that no actual damage had resulted from the shortcomings. These factors are typically treated as mitigating circumstances that reduce the severity of the sanction, and FI took them into account in arriving at a fine at the lower end of the range applicable to an institution of Swedbank's size.
Swedbank confirmed that the issues identified by FI had been remedied more than a year before the fine was issued — meaning the bank had addressed the documentation gaps well within the January 2022 to May 2025 timeline and did not wait for the formal enforcement outcome before taking corrective action. This remediation track record may have further moderated FI's final determination of the penalty.
BROADER SUPERVISORY CONTEXT
FI's decision to apply protective security legislation to financial institutions reflects the Swedish legislature's view that major banks, payment system operators, and other financial market participants can constitute security-sensitive activities because their disruption or compromise could have national security implications. The framework requires such organisations to conduct formal analyses, maintain updated documentation, and implement protective measures commensurate with the risks identified.
Swedbank's enforcement history has attracted significant attention in recent years following separate proceedings related to anti-money laundering deficiencies in its Baltic operations, which led to a SEK 4 billion fine from FI in 2020. The May 2025 action involves a different regulatory framework and an unrelated set of issues, but it nonetheless adds to the compliance record of a bank that has been under sustained supervisory scrutiny.
The SEK 12.5 million fine, while modest relative to the 2020 penalty, signals that FI applies protective security requirements rigorously and is prepared to sanction Sweden's largest banks for failures in this area. For other financial institutions operating under similar designations, the Swedbank decision serves as a reminder that documentation quality in protective security analyses is subject to regulatory verification and enforcement.