Sweden: fintech & payments regulation

Regulated

Finansinspektionen regulates fintech; DORA & AML updates drive compliance

Lead regulator
Finansinspektionen
Also involved
Swedish FSA (FI) · FRA (Financial Supervisory Authority) · Datainspektionen (Data Protection)
Core law
Payment Services Act (2010:751)
Entry capital
SEK 300,000 (Registered PSP)
Approval timeline
3-6 months for full authorization
Customer assets
Segregated in separate bank accounts
Data protection
GDPR · Datainspektionen
Sandbox
Yes - Finansinspektionen Regulatory Sandbox

Sweden maintains a robust, EU-aligned fintech regime supervised by Finansinspektionen (FI). The landscape is governed primarily by the Payment Services Act and the Electronic Money Act, implementing EU directives (PSD2, EMD2). Recent regulatory focus has shifted toward operational resilience (DORA) and enhanced AML reporting. The market is open to both domestic and EEA passporting, with strict capital and governance requirements enforced by FI.

Which licence do you need?

Your activityRequirementCapitalTimelineAuthority
Payment processing / gatewayLicencePayment Institution[1][2]

Requires authorization under Payment Services Act; DORA compliance mandatory.

SEK 300,000 (Registered) / SEK 150,000,000 (Institution)3-6 monthsFinansinspektionen
E-money & wallet issuanceLicenceElectronic Money Institution[3][4]

Initial capital requirement set by EMD2 implementation; safeguarding rules apply.

SEK 3,000,0003-6 monthsFinansinspektionen
Domestic money transferLicencePayment Institution[1][5]

Domestic transfers fall under Payment Services Act; capital depends on volume.

SEK 300,000 (Registered) / SEK 150,000,000 (Institution)3-6 monthsFinansinspektionen
Cross-border remittanceLicencePayment Institution[1][6]

Cross-border payments require authorization; AML/CTF rules strictly enforced.

SEK 300,000 (Registered) / SEK 150,000,000 (Institution)3-6 monthsFinansinspektionen
Agent networkUncertainverify with regulator

Agent arrangements permitted but specific regulatory status for agents unclear.

Open banking / account informationLicencePayment Institution / AISP/PISP[1][4]

AISPs and PISPs require authorization under PSD2 implementation.

SEK 300,000 (Registered) / SEK 150,000,000 (Institution)3-6 monthsFinansinspektionen
Foreign-exchange servicesRegistrationRegistered Currency Exchange[7][8]

Currency exchange requires registration under Certain Financial Operations Act.

Finansinspektionen

New — what changed recently

  • 2026-02-25FFFS 2025:7Amended regulations for currency exchange operations, updating reporting and operational standards.[7]
  • 2026-02-25FFFS 2025:4Updated operational and compliance requirements for payment institutions and registered PSPs.[1]
  • 2026-02-25FFFS 2025:5Revised rules for electronic money institutions, including outsourcing and safeguarding notifications.[3]
  • 2025-09-17DORA AlignmentAmended regulations to align payment service providers with EU Digital Operational Resilience Act.[2]

Market-entry checklist

  1. 1Secure FI AuthorizationSubmit comprehensive business plan and ownership details to Finansinspektionen.
  2. 2Meet Capital RequirementsDeposit initial capital (e.g., SEK 300,000 for Registered PSP) into a blocked account.
  3. 3Implement DORA ComplianceEstablish IT organization and operational risk management frameworks per EU DORA.
  4. 4Establish AML FrameworkCreate internal rules and risk assessments aligned with the Anti-Money Laundering Act.
  5. 5Set Up Fund SafeguardingSegregate customer funds in separate bank accounts as required by Payment Services Act.
This guide is compiled automatically from 8 primary-source documents published by Sweden's regulators, reviewed by RegAlert, and refreshed monthly (last updated 2026-07-12). It is not legal advice — always confirm requirements with the regulator or local counsel before acting.