KYC & AML Compliance in Denmark (2026): What Fintechs Need Before Launch

Denmark's digital identity tools can smooth onboarding, but AML compliance still comes down to a risk-based record a reviewer can reconstruct — here's what that takes in 2026.

Share
KYC & AML Compliance in Denmark (2026): What Fintechs Need Before Launch
KYC & AML Compliance in Denmark (2026): What Fintechs Need Before Launch

Denmark's digital identity environment can improve customer experience, but AML compliance still depends on a risk-based decision record that a reviewer can reconstruct.

Direct answer: Danish fintechs within the AML Act's scope need a risk-based workflow that identifies customers, understands the relationship, monitors for concerns, investigates suspicions, and retains a clear record of the decision. Digital identity and remote onboarding can make evidence collection easier; they do not remove the need for CDD, escalation, and accountable review.

As of 21 July 2026. This guide is an operational overview, not legal advice.

VOVE ID helps Danish payments, BaaS, and fintech teams connect identity evidence with review workflows and an auditable decision record. The operational failure is rarely a lack of digital touchpoints. It is a workflow that splits identity evidence, risk review, escalation, and later retrieval across tools.

This guide covers what Finanstilsynet actually expects in practice — digital identity onboarding, ownership verification, and FIU reporting. For the underlying framework, see our KYC Requirements Explained 2026.

This is exactly where remote onboarding becomes difficult to defend.

Regulatory map: start with the AML Act and the right supervisory context

Denmark's AML framework is set out through the Hvidvaskloven (the AML Act) and related requirements for the businesses and people it covers. The Danish Financial Supervisory Authority (Finanstilsynet) maintains the current AML-law collection, including the Act, guidance, and reporting-related materials. Finanstilsynet's AML area is the practical entry point for a regulated firm to ground its control design in the current materials.

Not every fintech has the same regulatory perimeter. A payment firm, e-money model, investment service, or outsourced program arrangement can have different roles and obligations. Teams need to establish the activity, license position, supervision, and responsibility split before they turn an onboarding map into production requirements.

Digital identity: make convenience part of a controlled CDD process

A familiar digital identity experience can reduce friction, but it does not by itself answer every CDD question. Teams still need to decide what identity evidence they require, what additional data is needed for the relationship, how they assess risk, and when a person must intervene.

The EBA's remote-onboarding guidelines set common EU standards for sound, risk-sensitive initial CDD policies and processes. They are technology-neutral and focus on choosing, assessing, and controlling remote-onboarding tools. The EBA guidance is useful because it keeps the design question where it belongs: evidence quality, governance, reliability, and exception handling.

In practice, a remote flow should connect the customer identity record, the verification outputs, the relationship risk assessment, and a reviewer decision when the case needs one. A completed mobile step is not the same as a completed compliance case. Digital onboarding is easier to operate when every identity signal and exception feeds one connected decision record.

CDD and risk: design for the cases that do not fit the happy path

An effective workflow distinguishes a low-friction standard case from a case that needs more evidence, a higher-risk approval, or an escalation. The rules should state who can request more information, who resolves a mismatch, who makes the final decision, and what evidence is retained.

For a business customer, the process should join legal-entity information with ownership and control analysis, authorized representatives, and the expected purpose of the relationship. For an individual, it should connect the identity evidence to the risk rationale and any later changes that require review.

This means one thing: use digital identity to improve collection, not to hide an incomplete decision.

For a full breakdown of entity verification and beneficial ownership mapping, see our KYB Requirements Explained 2026.

A realistic failure: a payments platform cannot explain a remotely approved merchant

A Danish payments platform onboarding a small online merchant receives a standard remote application.

  • A digital identity step for the director
  • Company registration information
  • A short description of expected payment flows
  • A beneficial-owner declaration

Then the case changes. The declared owner does not match the ownership evidence submitted by the merchant. A reviewer requests clarification, but the request sits in a support tool. The original identity result remains in the onboarding service, while the risk rationale is written into a separate ticket.

The merchant is approved once the customer replies. Months later, the firm cannot show which ownership evidence changed, who reviewed it, or whether the related risk assessment was updated.

This is not a digital-identity failure. It is a fragmented decision-record failure.

Monitoring and reporting: establish the route before suspicion arises

The Danish FIU is Hvidvasksekretariatet. Its guidance says businesses and people covered by the AML Act must report when a suspicion of money laundering or terrorist financing cannot be disproved, and that reports are sent digitally through goAML. Hvidvasksekretariatet's reporting guidance is clear that a firm does not need to conduct a full criminal investigation before it reports; it needs an appropriate internal investigation and escalation process.

That makes operating design important. A team should be able to preserve the underlying alerts, facts gathered, rationale, approvals, and decision path. It should also keep role-based access tight enough that the reporting process does not become a broad internal-data channel.

The EU AML Regulation will apply from 10 July 2027 for most obliged entities. Regulation (EU) 2024/1624 should therefore shape the roadmap for teams launching in 2026, even while Danish requirements and supervisory guidance remain the current operating reference.

For a full breakdown of sanctions screening and reporting obligations, see our AML Requirements Explained 2026.

Records and privacy: evidence should be retrievable without becoming overexposed

Digital onboarding creates more evidence, not less. Teams need a deliberate policy for case access, audit logs, retention, deletion, and legal holds. The policy should meet applicable obligations and be tested against a real review request.

The best operational question is not "did the customer pass?" It is "can the team explain the evidence, risk basis, exception path, and final decision without reconstructing the case from messages?" If the answer is no, the workflow is under-designed.

How VOVE ID fits: a controlled route from evidence to review

VOVE ID supports identity verification, biometric liveness, face matching, AML screening, KYB, and transaction monitoring. It supports 2,000+ document types across 200+ countries and helps detect document-template inconsistencies, invalid MRZ checksums, barcode or QR inconsistencies, and image manipulation. AML screening is customer-configurable and its data is refreshed daily; manual review can be used where the compliance team has sufficient evidence to approve a verification.

This does not decide a Danish firm's risk appetite or replace legal and reporting judgment. It helps teams collect evidence, route exceptions, and keep an operationally useful case record.

Practical Denmark KYC and AML checklist

Governance

  • Confirm the firm's AML Act perimeter and accountable compliance owner.
  • Define the decision rights for exceptions, high-risk cases, and reporting escalation.
  • Test the remote-onboarding process against the EBA guidance and current local materials.

Onboarding and KYB

  • Connect identity evidence, relationship risk, and reviewer action in one case.
  • Verify ownership and control rather than accepting a declaration in isolation.
  • Record why a remote exception was accepted, escalated, or declined.

Monitoring and reporting

  • Set documented triggers for unusual activity and risk-profile changes.
  • Preserve the investigation facts and rationale before a reporting decision.
  • Maintain a tested goAML route to Hvidvasksekretariatet where reporting is required.

Records and privacy

  • Limit access to identity and case evidence by role.
  • Define retention, deletion, and legal-hold processes before scale creates a backlog.
  • Test whether an auditor or reviewer can reconstruct a completed case.

FAQ

Does digital identity remove AML due-diligence obligations in Denmark? No. It can improve how evidence is collected, but the firm still needs a risk-based CDD process, exception handling, and an accountable decision record.

Who receives Danish suspicious-activity reports? Hvidvasksekretariatet is Denmark's FIU. Its guidance directs entities covered by the AML Act to use goAML for reporting when a suspicion cannot be disproved.

What should a remote business-onboarding case include? It should connect the entity and ownership evidence, authorized-person details, risk assessment, exceptions, reviewer actions, and the final decision.

Why is an audit record important for digital onboarding? It lets a team explain how it reached a decision after the fact. Without it, information often sits across tools and cannot be reviewed consistently.

Conclusion

KYC and AML compliance in Denmark is not a question of whether onboarding is digital. It is whether the digital journey produces a controlled, explainable case record.

Payments and fintech teams need to connect identity, risk, escalation, and records before scale turns small exceptions into systemic gaps. Collection, verification, review, and case management are one workflow.

Want to see how VOVE ID supports a country-aware identity and compliance workflow?

Book a demo

This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. KYC/KYB/AML requirements may vary depending on jurisdiction, industry, and specific business circumstances. For up-to-date and binding compliance obligations, readers should refer to the relevant regulatory authorities or consult qualified professionals.