200 Newest first. riskCalculated is the system’s indication and riskDecided the PERSON’s decision — two fields on purpose, because AMLR art. 76(5)(b) requires meaningful human intervention to be identifiable. ⚠️ The values are the Danish domain terms (UNDER_INDSAMLING, SKAERPET, HOEJ) and are not translated: the AML act’s concepts have no agreed English vocabulary, and an invented one would look canonical without being it.application/json
Possible errors 5
HTTP
Code
Meaning
400
invalid_cursor
The cursor is malformed, expired or belongs to another list shape.
401
invalid_api_key
The API key is missing, invalid, expired or revoked.
403
api_not_included
The organisation’s plan does not include API access.
On an existing customer. ⚠️ If your template carries a legal-basis gate you must answer it here — fetch the questions from GET /v1/customer-checks/legal-basis. An answer of UNDTAGET means the work falls outside the AML act and NOTHING is created (422 not_in_scope): a check must not exist with personal data in it if there is no basis for holding them. 409 already_active when the customer already has a check running.
200 The gates on your standard template, with both Danish and English wording and each option’s outcome (OMFATTET | UNDTAGET | FORKERT_MODUL — three outcomes, not two). An EMPTY list is a valid answer: your template carries no gate, and legalBasis must then be omitted.application/json
Possible errors 4
HTTP
Code
Meaning
401
invalid_api_key
The API key is missing, invalid, expired or revoked.
403
api_not_included
The organisation’s plan does not include API access.
200 ⚠️ Deliberately narrower than the portal’s own view: no rejection reason and no rejection category. A reason can reveal that a suspicious-activity report was considered, and disclosing that is a criminal offence under the Danish AML act § 38. THAT the check was rejected is the fact you act on.application/json
Possible errors 4
HTTP
Code
Meaning
401
invalid_api_key
The API key is missing, invalid, expired or revoked.
403
api_not_included
The organisation’s plan does not include API access.
200 source + derived together ARE the § 15a discrepancy: LEGAL_EJER/REGISTRERET_REEL_EJER are the REGISTRY’s claims, REEL_EJER with derived: true is your own conclusion. ⚠️ No national identity number, not even masked — hasNationalId tells you whether one is on file.application/json
Possible errors 4
HTTP
Code
Meaning
401
invalid_api_key
The API key is missing, invalid, expired or revoked.
403
api_not_included
The organisation’s plan does not include API access.
200 Metadata only, including the database-computed sha256. ⚠️ There is deliberately no download: these are passport and driving-licence scans, and the portal’s own download sits behind a NAMED person with the right to handle customer checks, while an API key is a bearer credential you may hand to an integrator. The metadata answers what an integration actually needs — is the customer still missing something?application/json
Possible errors 4
HTTP
Code
Meaning
401
invalid_api_key
The API key is missing, invalid, expired or revoked.
403
api_not_included
The organisation’s plan does not include API access.
Not the same as POST /v1/customer-checks on the same customer: the review inherits the previous template, copies the customer’s answers — except the ownership list and identity numbers, which must be obtained afresh — and links the two checks in the audit trail. ⚠️ The legal-basis gate must be answered AGAIN if your template carries one: it is not inherited, because whether the work is in scope is exactly the kind of thing a review exists to re-examine. Only from an APPROVED check (409 not_approved) and only from the LATEST one (409 superseded).