Financial Integrity Monitor

Denmark DK

Domains (D1–D6)
2
Sources
9
Role actions
8
Horizon <90d
1
Jurisdiction profile
Largely CompliantTier ARisk: StableMixed

Denmark operates under the Danish Money Laundering Act, EU AMLD IV/soon AMLR/6AMLD, and Finanstilsynet (Danish FSA) supervision.

MoreFATF's 2017 MER found sound legal foundations but weak supervisory enforcement, later improved: Denmark is compliant on 6/40 and largely compliant on 32/40 FATF Recommendations. No dedicated crypto-asset regime exists outside AML registration. Geography makes Denmark a critical maritime chokepoint for Russian shadow-fleet oil transit.

Key deficiencies
  • Historic over-reliance on police referral rather than direct, dissuasive supervisory sanctions
  • No comprehensive standalone crypto-asset regulatory framework pending MiCA/DAC8 full effect
  • 1857 Copenhagen Treaty free-passage obligations limit interdiction of shadow-fleet tankers in Danish straits
  • Weak beneficial ownership visibility for complex/foreign-owned corporate structures despite CVR register
Recent developments (18m)
  • Danske Bank's US DOJ corporate probation over the Estonia money-laundering scandal formally ended December 2025
  • Finanstilsynet referred Nordea Finans Danmark A/S to police for suspected AML breaches (May 2026)
  • Denmark intensified Port State Control inspections of Russia-linked shadow-fleet tankers transiting its straits (Feb 2025, Oct 2025)
  • Denmark joined a 14-nation coalition declaring non-compliant shadow-fleet tankers will be treated as stateless vessels (Jan 2026)

Law made at European Economic Area level that applies in Denmark is covered once, on the European Economic Area page. This page covers Denmark’s own layer: implementation, national authorities, national options and local enforcement.

Brief

Lead signal

Lead Signal

Read full brief

Lead Signal

Denmark's amended Hvidvaskloven entered into force on 15 September 2026, introducing a structural governance requirement across all AML-obliged entities: written proliferation-financing risk assessments, formal sanctions-compliance policies, and an independent AML audit function. The obligation is corroborated against the primary consolidated Act text on Retsinformation and against Finanstilsynet's legal collection page, and it applies without sector carve-out, meaning obliged entities from banking through gambling now carry an internal-governance duty that many smaller or lower-risk-tier entities previously lacked. This is architecture, not incident: the change resets the compliance floor for an entire obliged-entity population rather than responding to a single enforcement failure, and its durability sits with the primary Act rather than with any secondary guidance that could be withdrawn administratively.

Other Developments

A narrow but consequential crypto rulemaking hook sits inside the same amendment. Section 17a of the Hvidvaskloven now empowers the Business Minister to set risk-mitigation rules for crypto-asset transfers directed to or originating from self-hosted wallets. No implementing rules have yet been made under this power, but its presence in force from 15 September 2026 gives Denmark a domestic legal basis to move ahead of, or in close step with, the EU Travel Rule Regulation's own self-hosted-wallet provisions, without waiting for a further primary-legislative act. Denmark's FATF standing remains unchanged. Under the 2017 mutual evaluation, now in enhanced follow-up, Denmark is compliant on six of the forty FATF Recommendations and largely compliant on thirty-two, with two Recommendations still only partially compliant. There is no grey-list placement and no material change to this status this cycle; it is carried forward as standing context against which the new domestic obligations should be read.

Cross-Monitor Connections

The self-hosted-wallet rulemaking power under section 17a is directly relevant to World Payments Monitor's crypto and digital-asset tracking, since any rules eventually made under this power will shape how Danish-facing crypto-asset service providers handle transfers to non-custodial addresses. The AML audit-function requirement also touches the gambling-regulatory monitor's operational-obligations tracking, since gambling operators are named as obliged entities under the amended Act; that overlap is a shared underlying fact rather than a FIM-originated finding about gambling regulation, and this brief does not re-analyse the gambling-specific angle.

Outlook

The near-term watch item is whether Denmark issues implementing rules under section 17a's self-hosted-wallet rulemaking power, which would be the first concrete test of how the new authority is actually used. Separately, Denmark's AMLR, 6AMLD and AMLA transposition and application status specific to this jurisdiction was not independently re-verified this cycle and is treated as unchanged pending confirmation; that gap should be closed in a subsequent cycle rather than assumed away. No sanctions-divergence signal was identified, consistent with Denmark's direct, non-transposed application of EU Council restrictive measures.

weekly_brief_draft · JID DK
Domain intelligence (D1–D6)

D1 Sanctions

Not covered

Sanctions is not yet covered for this jurisdiction in this report.

D2 Beneficial Ownership

Not covered

Beneficial Ownership is not yet covered for this jurisdiction in this report.

D3 Enabler Jurisdictions

Not covered

Enabler Jurisdictions is not yet covered for this jurisdiction in this report.

D4 Conflict Finance

Not covered

Conflict Finance is not yet covered for this jurisdiction in this report.

D5 Crypto, Digital Assets, and Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

Denmark's amended Hvidvaskloven, in force since 15 September 2026, carries a Denmark-specific provision of direct relevance to digital-asset infrastructure: section 17a empowers the Business Minister to lay down rules on risk-mitigating measures for crypto-asset transfers directed to or originating from a self-hosted address. This is a domestic rulemaking hook rather than a self-executing rule; no implementing regulation has yet been made under it. Its significance lies in what it enables rather than in any immediate obligation it imposes: Denmark now has a standing legal basis to regulate self-hosted-wallet exposure at the domestic level, positioned adjacent to, and potentially ahead of, the EU Travel Rule Regulation's own self-hosted-wallet provisions for crypto-asset service providers.

The architecture-over-incident read here is that this is a structural expansion of ministerial rulemaking capacity, not a response to any reported incident or enforcement failure in the Danish crypto sector. No enforcement action, exchange failure, or sanctions-evasion typology involving Danish crypto infrastructure was identified this cycle. The provision should be read as an anticipatory legal foundation: a self-hosted-wallet transfer regime that could, once implementing rules are made, close a gap in Denmark's oversight of non-custodial transfers that currently exists across much of the EU pending fuller Travel Rule Regulation implementation for such transfers.

The absence of any announced timeline for implementing rules under section 17a is itself worth registering. A ministerial rulemaking power that sits unused is common in the period immediately following its creation, and the twelve months following adoption typically produce the first indication of whether a government intends to exercise a power promptly or let it sit as a reserve authority. For now, the fact pattern is: the legal hook exists, is confirmed in force, and has not yet been operationalised.

Outlook

The principal watch item is whether Denmark's Business Ministry issues implementing rules under section 17a, and if so, whether those rules track the EU Travel Rule Regulation's self-hosted-wallet thresholds or diverge from them. A divergence would be structurally significant, creating a Denmark-specific compliance layer for crypto-asset service providers operating in or through Denmark, on top of the EU-wide Travel Rule baseline. No other Denmark-specific digital-asset development was identified this cycle.

D6 Compliance Technology & Active Defence

Not covered

Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.

D7 AML/CTF Regime

AML/CTF Regime

Continue reading

Denmark's AML/CTF regime underwent a confirmed structural tightening this cycle. Amendments to the Hvidvaskloven (LBK nr 1463 af 18/11/2025) entered into force on 15 September 2026, and the primary consolidated Act text on Retsinformation, corroborated by Finanstilsynet's legal collection page, confirms that obliged entities must now maintain written proliferation-financing risk assessments, formal sanctions-compliance policies, and an independent AML audit function. This is a governance-layer requirement rather than a transaction-reporting or threshold change: it obliges every covered entity to demonstrate, on an ongoing basis, that it has assessed its own proliferation-financing exposure and built internal audit capacity independent of its compliance function. The obligation applies across sectors without a carve-out for lower-risk-tier obliged entities, which is the architecturally significant feature of this change: it is a floor-raising exercise for the entire obliged-entity population, not a targeted intervention against a specific sector or typology.

This sits against Denmark's standing FATF status, which is unchanged this cycle. Under the 2017 mutual evaluation, now in enhanced follow-up, Denmark is compliant on six of the forty FATF Recommendations and largely compliant on thirty-two, with two Recommendations partially compliant. Denmark is not on the FATF grey list and there is no indication this cycle of any change to that status. The three-pillar balance is worth naming explicitly here: this cycle's finding is squarely a CTF/CPF-adjacent development (the proliferation-financing risk-assessment duty) riding alongside a general AML governance upgrade, rather than an AML-only enforcement-volume story, which corrects for the usual structural under-weighting of counter-proliferation-financing signal relative to AML.

Denmark's application of the EU AML Package, the directly applicable AMLR (Regulation (EU) 2024/1624), the sixth AML Directive, and the AMLA Regulation establishing the Anti-Money Laundering Authority, was not independently re-verified at the Denmark-specific level this cycle. As an EU/EEA member state Denmark is directly bound by the AMLR, and this domestic Hvidvaskloven amendment is a national-layer development that sits adjacent to, but is distinct from, Denmark's AMLR/6AMLD/AMLA application status, which remains a gap to close in a future cycle rather than a confirmed finding either way.

On sanctions, Denmark continues to apply EU Council restrictive measures directly without domestic transposition, meaning any EU regulation listing designated persons, entities, or prohibited activities takes immediate legal effect in Denmark. No DK-specific sanctions divergence signal was identified this cycle.

Outlook

The principal item to track is how obliged entities, particularly smaller ones without an existing independent audit function, operationalise the new section 17a-adjacent governance requirements over the coming months, since the 15 September 2026 in-force date leaves limited transition runway. A secondary item is confirmation of Denmark's specific AMLR/6AMLD/AMLA transposition and supervisory-perimeter status, which this cycle's research did not resolve.

D8 Commercial Activity

Not covered

Commercial Activity is not yet covered for this jurisdiction in this report.

Regulatory horizon
In Force15 Sep 2026 · ±quarter

Hvidvaskloven amendments (proliferation-financing risk assessment, audit function)

Written PF risk assessments, sanctions-compliance policies, and an independent audit function become mandatory for obliged entities including gambling operators.
1 dated · 5 pending date · baseline fim-2026-07-08
Role action cards
MLRO

The amended Hvidvaskloven, in force since 15 September 2026, requires written proliferation-financing risk assessments, sanctions-compliance policies, and an independent AML audit function for all obliged entities.

Any obliged entity without an existing independent audit function now carries a confirmed governance gap as of 15 September 2026, and proliferation-financing risk assessments must be documented in writing rather than held informally.

1 evidence refs
Compliance

Denmark's obliged-entity governance floor rose sector-wide on 15 September 2026 without a lower-risk-tier carve-out.

Compliance functions should confirm whether existing policy frameworks already satisfy the new written sanctions-compliance-policy and PF-risk-assessment requirements, since the amendment applies without exemption by entity size or risk tier.

1 evidence refs
Legal

No material change this cycle.

No material change for this persona this cycle

Board

Denmark's AML Act now requires an independent audit function for every obliged entity, a governance-level obligation rather than a transaction-level one.

This is a structural, not episodic, requirement with reputational and governance implications if the independent audit function is not demonstrably in place.

1 evidence refs
CTO

Denmark's AML Act section 17a creates a domestic rulemaking power over self-hosted-wallet crypto transfers, though no implementing rules exist yet.

Crypto-asset infrastructure serving Danish customers should anticipate a possible domestic self-hosted-wallet rule that could sit alongside or diverge from the EU Travel Rule Regulation's own provisions.

1 evidence refs
Risk

A sector-wide AML governance floor rose in Denmark on 15 September 2026, while Denmark's AMLR/6AMLD/AMLA-specific transposition status remains unconfirmed.

Risk functions should treat the EU AML Package application status for Denmark as an open item pending confirmation, distinct from the confirmed domestic Hvidvaskloven change.

2 evidence refs
Operations

No material change this cycle.

No material change for this persona this cycle

Audit

Denmark now mandates an independent AML audit function for obliged entities, a direct expansion of the internal-audit scope for covered firms.

Audit functions should confirm that the newly mandated independent AML audit capability is documented and operationally distinct from the compliance function it audits, as required from 15 September 2026.

1 evidence refs
Decision lens
MLRO

The amended Hvidvaskloven, in force since 15 September 2026, requires written proliferation-financing risk assessments, sanctions-compliance policies, and an independent AML audit function for all obliged entities.

Compliance

Denmark's obliged-entity governance floor rose sector-wide on 15 September 2026 without a lower-risk-tier carve-out.

Legal

No material change this cycle.

Board

Denmark's AML Act now requires an independent audit function for every obliged entity, a governance-level obligation rather than a transaction-level one.

CTO

Denmark's AML Act section 17a creates a domestic rulemaking power over self-hosted-wallet crypto transfers, though no implementing rules exist yet.

Risk

A sector-wide AML governance floor rose in Denmark on 15 September 2026, while Denmark's AMLR/6AMLD/AMLA-specific transposition status remains unconfirmed.

Operations

No material change this cycle.

Audit

Denmark now mandates an independent AML audit function for obliged entities, a direct expansion of the internal-audit scope for covered firms.

Shared evidence: 2 refs
Scenario sketches

AMLA direct-supervision transition and Denmark's obliged-entity governance floor

Illustrative scenario for analytical orientation only: as the AMLA Regulation (Reg (EU) 2024/1620) moves cross-border obliged entities toward direct or indirect AMLA-level supervision, alongside the directly applicable AMLR (Reg 2024/1624) and per-state 6AMLD transposition, a national governance-floor measure such as Denmark's new independent-audit-function requirement could interact with that transition in one of two illustrative directions. Under one path, AMLA supervisory guidance converges with, and effectively absorbs, national governance floors like Denmark's, producing a harmonised EU-wide audit-function standard that leaves little room for national divergence. Under an alternative path, national governance floors continue to run ahead of or alongside AMLA's own supervisory expectations, producing a patchwork where Denmark's obliged entities face both a national audit-function duty and a distinct AMLA-level supervisory ask, layered rather than merged. This is illustration of a structural possibility, not an observed development and not a prediction of which path Denmark or the EU will take.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion Architecturestable
T2 · EU AML Package / AMLAwatch
T3 · FATF Grey Liststable
T4 · Beneficial-Ownership Register Statusno_change
T5 · Crypto & Digital-Asset Integritymaterial_change
T6 · Sanctions Regime Divergencestable
Registers

Enforcement actions

  • Danske Bank's corporate criminal probation stemming from its 2022 guilty plea for conspiring to commit bank fraud in the Estonia money-laundering matter was formally concluded, ending all outstanding US formal processes tied to the non-resident portfolio scandal. 15 Dec 2025
  • Following a June 2023 inspection that found the unit lacked sufficient knowledge about a large group of its customers, Finanstilsynet reported Nordea Finans Danmark to police and requested a criminal investigation into suspected AML breaches. 4 May 2026
  • The Danish Maritime Authority began Port State Control checks on tankers anchored outside Skagen deemed not to be in innocent passage, escalated again in October 2025, to enforce maritime safety, environmental and seafarer-welfare compliance on shadow-fleet vessels. 5 Feb 2025
  • Denmark joined 13 other European nations, via a statement issued by the UK Department for Transport, warning that shadow-fleet tankers in the Baltic and North Seas lacking valid flag documentation, safety and insurance records will be treated as stateless vessels under international maritime law. 27 Jan 2026
  • EU Member States designated 41 additional shadow-fleet vessels, bringing the total close to 600, following earlier December 2025 designation of 9 shadow-fleet enablers and a joint declaration on maritime law enforcement against the shadow fleet in waters including the Danish straits. 18 Dec 2025

Sanctions changes

  • The EU's 19th Russia sanctions package added 117 additional shadow-fleet vessel listings (total 557), a total LNG import ban, a full transaction ban on Rosneft/Gazprom Neft, and first-time crypto sanctions on the A7A5 stablecoin ecosystem — all bearing directly on tankers and financial flows transiting the Danish straits. 23 Oct 2025
  • EU Council sanctioned 9 shadow-fleet enablers (shipping companies in the UAE, Vietnam and Russia) followed days later by 41 additional vessel listings, alongside an EU-Member-State joint declaration on using international maritime law to counter shadow-fleet threats to critical undersea infrastructure — directly relevant given Denmark's straits chokepoint role. 15 Dec 2025
  • FATF's June 2025 plenary added the British Virgin Islands and Bolivia to its Jurisdictions Under Increased Monitoring list and removed Croatia, Mali and Tanzania, altering the enhanced-due-diligence obligations Danish financial institutions must apply to counterparties in those jurisdictions. 13 Jun 2025
  • The European Commission adopted Delegated Regulations (EU) 2026/46 and (EU) 2026/83 amending the EU high-risk third-country AML/CFT list, affecting the enhanced-due-diligence obligations Danish obliged entities must apply to counterparties in newly listed or delisted jurisdictions. 4 Dec 2025

Regulatory horizon (register)

  • AMLA first risk-based direct-supervision entity selection
  • AMLR (Reg 2024/1624) direct application and 6AMLD transposition
  • DAC8 crypto-asset reporting first exchange deadline
  • Denmark's next FATF 5th-round mutual evaluation
  • EU further shadow-fleet vessel listings and full maritime services ban

Active schemes

  • [CRITICAL] Russian shadow-fleet oil transit through Danish straits
  • [HIGH] Danske Bank Estonia non-resident portfolio laundering
  • [HIGH] Nordea Denmark customer-due-diligence failures
  • Danish crypto-asset regulatory perimeter gap
  • Danish shipping-inspection brand used for occupied-Ukraine grain
Sources
  1. FATF (multilateral first-party assessment of Denmark)
  2. FATF
  3. Finanstilsynet (Danish Financial Supervisory Authority)
  4. Council of the European Union
  5. Bloomberg News
  6. Bloomberg News
  7. Bloomberg News
  8. Elliptic
  9. ICIJ
Coverage gaps
Denmark's FATF assessment found supervisory sanctions were '…
Denmark's FATF assessment found supervisory sanctions were 'not proportionate and dissuasive,' with an over-reliance on police referral rather than direct supervisory enforcement; the recurring pattern of Finanstilsynet referring cases to police (Nordea 2024, Nordea Finans Danmark 2026) rather than imposing direct administrative sanctions suggests this structural deficiency persists.
The 1857 Copenhagen Treaty guarantees free passage through t…
The 1857 Copenhagen Treaty guarantees free passage through the Danish straits, meaning Denmark lacks direct legal authority to stop or search shadow-fleet tankers absent a specific safety, environmental or documentation trigger, despite hundreds of these vessels transiting Danish waters carrying sanctioned Russian oil annually.
Denmark has no comprehensive standalone cryptoasset regulato…
Denmark has no comprehensive standalone cryptoasset regulatory framework; CASPs are captured only via piecemeal AML registration, financial-instrument classification, or payments-act provisions, pending full MiCA/DAC8 effect, leaving supervisory gaps in licensing and market-conduct oversight relative to fully-regulated EU peers.
Open-source Tier 1-3 reporting in the 18-month window surfac…
Open-source Tier 1-3 reporting in the 18-month window surfaced no Denmark-specific terrorist-financing prosecution or FIU/PET (Danish Security and Intelligence Service) enforcement case comparable in visibility to the AML/sanctions-evasion and Danske/Nordea material, despite Denmark's stated CTF risk exposure noted in its 2017 MER.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.