
Sets Fidify's direction and works directly with customers on how their compliance policy maps into the product. Brings finance experience from investment companies and banks in London and Stockholm.
Articles by Fredrik
AI Can Rank Your KYC Alerts. Who Checks What It Leaves at the Bottom?
AI models that score and rank KYC screening alerts can remove a large share of false positives. For management companies and TCSPs, the harder questions are who reviews the alerts ranked lowest, what historical decisions the model learned from and whether AI-written summaries match the evidence.
5 min readReadWhat is ongoing monitoring under the AMLR? Article 26 explained for fund administrators and ManCos
Ongoing monitoring under the AMLR is the duty to keep a customer's file current for as long as the relationship lasts: update it when something relevant changes, and re-check it on a risk-based schedule that cannot stretch past five years, or one year for higher-risk customers. From 10 July 2027 it is a direct obligation under Article 26 of Regulation (EU) 2024/1624.
8 min readReadAMLA Has Defined the STR Format. The Compliance Question Is Whether Your Data Fits.
AMLA opened consultation on July 2 on the STR format ITS, defining data templates obliged entities must use to automate suspicious transaction reporting. This article argues the template is not a reporting convenience but a data infrastructure specification, and that management companies and TCSPs must assess now whether their compliance systems can populate it.
7 min readReadRegTech Deployment Is Not Compliance Implementation. The Market Has Started Measuring the Difference.
Analysis of the Global State of RegTech 2026 adoption index alongside the RegTech Association's 2026 Best RegTech Implementation award category. Argues that near-universal RegTech adoption has produced a 68/100 maturity score in the best domain because deployment and implementation quality are different variables, with specific implications for management companies and TCSPs under AMLR.
7 min readReadOFAC Is a Risk Factor, Not a Decision: What the CJEU's Jenec Ruling Changes About CDD Documentation
Analysis of CJEU Case C-81/24 (Jenec), decided 11 June 2026, which held that an OFAC listing cannot automatically justify refusing a basic payment account under EU AML law. Confirms the legal requirement for documented individual risk assessment, not list-matching, as the basis for CDD decisions. Implications for management companies, TCSPs, and fund administrators.
6 min readReadThe AI Transparency Deadline That Wasn't Moved
The Digital Omnibus moved the high-risk AI deadline 16 months. Article 50 transparency obligations were not deferred. For management companies and TCSPs using biometric verification in digital KYC, AI-powered client tools, or AI-generated content, August 2026 is a live compliance deadline eight weeks away.
6 min readReadThe AI Act Window and the Classification Error: What the May 19 Guidelines Actually Resolve
Analysis of the May 7 Digital Omnibus deal that delayed high-risk AI Act enforcement 16 months, and the Commission's May 19 draft classification guidelines that define which AI systems are actually in scope. Argues that most AML/KYC AI at management companies and TCSPs falls outside the high-risk definition under Recital 58, but that AMLR documentation obligations apply regardless.
7 min readReadDORA Compliance as Data Plumbing: Why Cloud Sovereignty Became Infrastructure
An analysis of DORA compliance as a data infrastructure problem rather than a policy one. Covers exit strategy obligations under Article 28(8), the convergence of EU and global data-portability and messaging standards (ISO 20022, FAPI), and the architectural patterns (Kubernetes, IaC, S3-compatible storage) that make six-month exits actually executable. Aimed at Luxembourg TCSPs, management companies, and fund administrators evaluating cloud strategy under DORA. This is an edited replacement for the earlier draft of the same title.
7 min readReadThe MiCA Review Opens While Luxembourg's Licensing Model Is Under Threat: What Compliance Teams Should Actually Watch
Analysis of the European Commission's MiCA review consultation launched on 20 May 2026, set against the parallel proposal to centralise CASP supervision under ESMA. For Luxembourg management companies, fund administrators, and TCSPs touching tokenised assets, the convergence of MiCA, AMLR, and the Transfer of Funds Regulation is becoming a single compliance surface that depends entirely on the data layer underneath.
7 min readReadWhen the Group Compliance Manager Is an AI: What AMLR Article 16 Looks Like in a World Where Most CDD Decisions Are Made by Agents
AMLR Article 16(2) requires a compliance manager at group level. When most CDD work moves to AI agents at the subsidiary level, the role of that compliance manager changes structurally. This piece argues that the future of enterprise KYC under AI automation is not a story about replacing compliance officers, but about elevating one specific role into the convergence point for AMLR, the EU AI Act, and AMLA's supervisory expectations.
8 min readReadAMLA's New BWRA Guidelines: Why Your Self-Assessment Should Mirror the Supervisor's Scorecard
Analysis of AMLA's 16 April 2026 consultation on draft BWRA Guidelines under Article 10(4) AMLR, and how the cross-reference to the supervisor RTS under Article 40(2) AMLD reshapes how management companies, TCSPs, and fund administrators should structure their business-wide risk assessment.
7 min readReadWhat's Actually in AMLA's Article 28 CDD Standards: A Read of the Draft RTS Before the Window Closes
AMLA's draft RTS under Article 28(1) of the AMLR closes for consultation on 8 May 2026. Three provisions in the draft (on intermediary ownership layers, senior managing officials, and verification sources) reveal the structural shape of CDD under the new regime, and confirm that AMLR readiness is a data problem rather than a policy problem.
6 min readReadSynthetic Identity Fraud: Why Manual KYC Cannot Catch What It Was Not Designed to See
AI-generated synthetic identities are designed to defeat exactly the manual checks most firms still rely on. This article examines what the 2026 SmartSearch Compliance Report reveals about the gap between awareness and action, and what an effective response actually looks like.
5 min readReadPerpetual KYC: What It Means and Whether Your Firm Is Ready
Perpetual KYC promises to replace periodic reviews with continuous, event-driven monitoring. This article explains what pKYC actually involves, what infrastructure it requires, and whether the technology and regulatory environment are ready for it.
8 min readReadDocument-Driven KYC: Why Documents Are the Foundation of Effective Compliance
Document-driven KYC puts verified documents at the centre of every compliance decision. This article explains why this approach produces stronger compliance outcomes than form-based or interview-driven alternatives.
6 min readReadUBO Identification: Why Compliance Teams Still Struggle with Layered Ownership Structures
Identifying the ultimate beneficial owner behind complex holding structures, trusts, and SPVs remains one of the most time-consuming tasks in KYC compliance. This article explores why layered ownership creates persistent challenges for compliance teams on both sides of the KYC relationship, what regulators actually expect including variable thresholds and the board fallback rule, and how automation can eliminate the spreadsheet-driven recalculations that slow firms down.
12 min readReadKYC Software for Management Companies: What to Look for in 2026
Management companies face unique KYC challenges — complex entity structures, multi-jurisdictional requirements, and high document volumes. This guide explains what to look for when choosing KYC software purpose-built for the sector.
7 min readReadWhat Regulators Actually Look for During KYC Document Audits
Regulatory examinations focus on evidence, consistency, and risk-proportionate decision-making, not just process completion. This article explains what examiners actually scrutinise and how to prepare.
7 min readReadWhy Your KYC Platform Needs a Policy Engine, Not Just a Risk Score
Risk scores tell you how risky a customer is. A policy engine tells the AI how to think about risk in the first place. This article explains why configurable compliance policies are the missing layer in most KYC platforms, and how they transform AI-driven risk assessments from generic outputs into institution-specific intelligence.
9 min readRead