D1 Sanctions
Sanctions is not yet covered for this jurisdiction in this report.
Denmark operates under the Danish Money Laundering Act, EU AMLD IV/soon AMLR/6AMLD, and Finanstilsynet (Danish FSA) supervision.
Law made at European Economic Area level that applies in Denmark is covered once, on the European Economic Area page. This page covers Denmark’s own layer: implementation, national authorities, national options and local enforcement.
Sanctions is not yet covered for this jurisdiction in this report.
Beneficial Ownership is not yet covered for this jurisdiction in this report.
Enabler Jurisdictions is not yet covered for this jurisdiction in this report.
Conflict Finance is not yet covered for this jurisdiction in this report.
Denmark's amended Hvidvaskloven, in force since 15 September 2026, carries a Denmark-specific provision of direct relevance to digital-asset infrastructure: section 17a empowers the Business Minister to lay down rules on risk-mitigating measures for crypto-asset transfers directed to or originating from a self-hosted address. This is a domestic rulemaking hook rather than a self-executing rule; no implementing regulation has yet been made under it. Its significance lies in what it enables rather than in any immediate obligation it imposes: Denmark now has a standing legal basis to regulate self-hosted-wallet exposure at the domestic level, positioned adjacent to, and potentially ahead of, the EU Travel Rule Regulation's own self-hosted-wallet provisions for crypto-asset service providers.
The architecture-over-incident read here is that this is a structural expansion of ministerial rulemaking capacity, not a response to any reported incident or enforcement failure in the Danish crypto sector. No enforcement action, exchange failure, or sanctions-evasion typology involving Danish crypto infrastructure was identified this cycle. The provision should be read as an anticipatory legal foundation: a self-hosted-wallet transfer regime that could, once implementing rules are made, close a gap in Denmark's oversight of non-custodial transfers that currently exists across much of the EU pending fuller Travel Rule Regulation implementation for such transfers.
The absence of any announced timeline for implementing rules under section 17a is itself worth registering. A ministerial rulemaking power that sits unused is common in the period immediately following its creation, and the twelve months following adoption typically produce the first indication of whether a government intends to exercise a power promptly or let it sit as a reserve authority. For now, the fact pattern is: the legal hook exists, is confirmed in force, and has not yet been operationalised.
The principal watch item is whether Denmark's Business Ministry issues implementing rules under section 17a, and if so, whether those rules track the EU Travel Rule Regulation's self-hosted-wallet thresholds or diverge from them. A divergence would be structurally significant, creating a Denmark-specific compliance layer for crypto-asset service providers operating in or through Denmark, on top of the EU-wide Travel Rule baseline. No other Denmark-specific digital-asset development was identified this cycle.
Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.
Denmark's AML/CTF regime underwent a confirmed structural tightening this cycle. Amendments to the Hvidvaskloven (LBK nr 1463 af 18/11/2025) entered into force on 15 September 2026, and the primary consolidated Act text on Retsinformation, corroborated by Finanstilsynet's legal collection page, confirms that obliged entities must now maintain written proliferation-financing risk assessments, formal sanctions-compliance policies, and an independent AML audit function. This is a governance-layer requirement rather than a transaction-reporting or threshold change: it obliges every covered entity to demonstrate, on an ongoing basis, that it has assessed its own proliferation-financing exposure and built internal audit capacity independent of its compliance function. The obligation applies across sectors without a carve-out for lower-risk-tier obliged entities, which is the architecturally significant feature of this change: it is a floor-raising exercise for the entire obliged-entity population, not a targeted intervention against a specific sector or typology.
This sits against Denmark's standing FATF status, which is unchanged this cycle. Under the 2017 mutual evaluation, now in enhanced follow-up, Denmark is compliant on six of the forty FATF Recommendations and largely compliant on thirty-two, with two Recommendations partially compliant. Denmark is not on the FATF grey list and there is no indication this cycle of any change to that status. The three-pillar balance is worth naming explicitly here: this cycle's finding is squarely a CTF/CPF-adjacent development (the proliferation-financing risk-assessment duty) riding alongside a general AML governance upgrade, rather than an AML-only enforcement-volume story, which corrects for the usual structural under-weighting of counter-proliferation-financing signal relative to AML.
Denmark's application of the EU AML Package, the directly applicable AMLR (Regulation (EU) 2024/1624), the sixth AML Directive, and the AMLA Regulation establishing the Anti-Money Laundering Authority, was not independently re-verified at the Denmark-specific level this cycle. As an EU/EEA member state Denmark is directly bound by the AMLR, and this domestic Hvidvaskloven amendment is a national-layer development that sits adjacent to, but is distinct from, Denmark's AMLR/6AMLD/AMLA application status, which remains a gap to close in a future cycle rather than a confirmed finding either way.
On sanctions, Denmark continues to apply EU Council restrictive measures directly without domestic transposition, meaning any EU regulation listing designated persons, entities, or prohibited activities takes immediate legal effect in Denmark. No DK-specific sanctions divergence signal was identified this cycle.
The principal item to track is how obliged entities, particularly smaller ones without an existing independent audit function, operationalise the new section 17a-adjacent governance requirements over the coming months, since the 15 September 2026 in-force date leaves limited transition runway. A secondary item is confirmation of Denmark's specific AMLR/6AMLD/AMLA transposition and supervisory-perimeter status, which this cycle's research did not resolve.
Commercial Activity is not yet covered for this jurisdiction in this report.
Any obliged entity without an existing independent audit function now carries a confirmed governance gap as of 15 September 2026, and proliferation-financing risk assessments must be documented in writing rather than held informally.
Compliance functions should confirm whether existing policy frameworks already satisfy the new written sanctions-compliance-policy and PF-risk-assessment requirements, since the amendment applies without exemption by entity size or risk tier.
No material change for this persona this cycle
This is a structural, not episodic, requirement with reputational and governance implications if the independent audit function is not demonstrably in place.
Crypto-asset infrastructure serving Danish customers should anticipate a possible domestic self-hosted-wallet rule that could sit alongside or diverge from the EU Travel Rule Regulation's own provisions.
Risk functions should treat the EU AML Package application status for Denmark as an open item pending confirmation, distinct from the confirmed domestic Hvidvaskloven change.
No material change for this persona this cycle
Audit functions should confirm that the newly mandated independent AML audit capability is documented and operationally distinct from the compliance function it audits, as required from 15 September 2026.
The amended Hvidvaskloven, in force since 15 September 2026, requires written proliferation-financing risk assessments, sanctions-compliance policies, and an independent AML audit function for all obliged entities.
Denmark's obliged-entity governance floor rose sector-wide on 15 September 2026 without a lower-risk-tier carve-out.
No material change this cycle.
Denmark's AML Act now requires an independent audit function for every obliged entity, a governance-level obligation rather than a transaction-level one.
Denmark's AML Act section 17a creates a domestic rulemaking power over self-hosted-wallet crypto transfers, though no implementing rules exist yet.
A sector-wide AML governance floor rose in Denmark on 15 September 2026, while Denmark's AMLR/6AMLD/AMLA-specific transposition status remains unconfirmed.
No material change this cycle.
Denmark now mandates an independent AML audit function for obliged entities, a direct expansion of the internal-audit scope for covered firms.
Illustrative scenario for analytical orientation only: as the AMLA Regulation (Reg (EU) 2024/1620) moves cross-border obliged entities toward direct or indirect AMLA-level supervision, alongside the directly applicable AMLR (Reg 2024/1624) and per-state 6AMLD transposition, a national governance-floor measure such as Denmark's new independent-audit-function requirement could interact with that transition in one of two illustrative directions. Under one path, AMLA supervisory guidance converges with, and effectively absorbs, national governance floors like Denmark's, producing a harmonised EU-wide audit-function standard that leaves little room for national divergence. Under an alternative path, national governance floors continue to run ahead of or alongside AMLA's own supervisory expectations, producing a patchwork where Denmark's obliged entities face both a national audit-function duty and a distinct AMLA-level supervisory ask, layered rather than merged. This is illustration of a structural possibility, not an observed development and not a prediction of which path Denmark or the EU will take.
Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.
| Tracker | Status | Note |
|---|---|---|
| T1 · Russian Sanctions-Evasion Architecture | stable | |
| T2 · EU AML Package / AMLA | watch | |
| T3 · FATF Grey List | stable | |
| T4 · Beneficial-Ownership Register Status | no_change | |
| T5 · Crypto & Digital-Asset Integrity | material_change | |
| T6 · Sanctions Regime Divergence | stable |