PRACTICE AREAS

compliance that works in practice, not just on paper AML Compliance

We advise US-managed Polish obliged institutions on AML program design, compliance audits, and regulatory engagement with GIIF.

COMMON ISSUES

where internationally-managed Polish entities get AML wrong

Polish AML compliance isn’t a documentation exercise – it’s an operational program that has to work in practice.

The entity has AML documentation but no working compliance process The most common AML compliance gap in Polish entities isn't missing documentation - it's documentation that doesn't match what the organization actually does.

Compliance Audits

We audit how your AML program actually runs day to day, then close the gap between what your documents say and what your team does.
The firm doesn't know whether it's an obliged institution or which obligations apply Polish AML law defines obliged institutions (instytucje obowiązane) broadly, and the category includes entities that management may not assume are covered.

Obligation Mapping

We assess your entity against Poland's obliged-institution criteria and map exactly which AML obligations apply, so nothing gets missed by assumption.
Management is personally liable for AML failures Polish AML law imposes personal liability on management board members for failures in the entity's AML compliance - fines, professional bans, and criminal liability for serious violations.

Board Reporting

We build AML programs with reporting built in, so your management board has real visibility and a clear record of oversight - without tracking every transaction themselves.

WHO THIS IS FOR

US companies with obliged institutions in Poland

You operate a Polish fintech, payment processor, or e-money institution

Payment and e-money institutions in Poland are obliged institutions with full AML program requirements — customer due diligence, risk assessment, GIIF reporting, transaction monitoring, and staff training. US-managed Polish payment entities need a program that meets Polish regulatory expectations, not US BSA standards.

  • Compliance Officer
  • Sales Manager
  • Operations Director

You operate a Polish crypto asset service provider (CASP) or virtual currency exchange

Polish crypto entities have been obliged institutions since 2021. The regulatory framework is evolving with EU MiCA implementation. A Polish CASP needs AML documentation, KYC procedures, and GIIF reporting capability that reflects the entity's specific business model.

  • Finance Controller
  • Founder

Your Polish subsidiary provides real estate, accounting, or corporate services

Real estate agents, accounting firms, auditors, tax advisors, and some corporate service providers are obliged institutions in Poland. US companies whose Polish subsidiaries provide these services may be running AML obligations they haven't assessed.

  • Compliance Manager
  • Finance Director

MOST OFTEN COMMISSIONED BY

  • internationally-managed Polish fintechs and payment institutions regulated by KNF
  • PE funds whose Polish portfolio companies are obliged institutions
  • crypto operators with Polish CASP registrations
  • companies whose Polish subsidiaries provide real estate, accounting, or professional services
  • GCs overseeing compliance across Polish subsidiary portfolios

OUTCOMES

what you can expect

A functioning Polish AML compliance program provides

Visibility

Management can prove real oversight - current risk assessments, met obligations, documented training.

Scope

Scoped to your actual obligations - not too broad, not too narrow, never overbuilt.

Clarity

The people making daily calls know the standard and apply it consistently.

Reporting

GIIF reports go out correctly and on time - silence isn't proof of clean.

Readiness

Built to work in practice, so a GIIF inspection holds up.

HOW WE WORK TOGETHER

How we work with international companies on Polish AML compliance

We work with international entities directly – advising the management board, the compliance officer, and the operational team on the Polish AML obligations that apply to the specific entity and business model.

Assess

We confirm your obliged-institution status, map the obligations that apply, and check your current program against Polish AML law.

Build

We build or overhaul the program - risk assessment, CDD, GIIF reporting, controls, and the documentation that makes it work.

Train

We train the team on what actually applies - customer ID, risk assessment, red flags, and escalation.

Maintain

We keep the program running - regulatory updates, periodic reviews, GIIF support, and management reporting.

BLOG

knowledge base

Practical reads on Polish and EU law, written for the people actually running the business – not studying it.

YOU OFTEN ASK

FAQ

On AML, most questions come down to two things – what applies, and who’s personally liable. Here are the answers we give most often.

The EU is implementing a comprehensive AML reform package that includes the establishment of AMLA (the EU Anti-Money Laundering Authority), a new EU-level AML Regulation (directly applicable across all member states, without national transposition), and updated AMLD6 requirements. AMLA will have direct supervisory authority over certain categories of high-risk obliged institutions across the EU from 2026. The EU AML Regulation will create more uniform AML standards across member states. Polish obliged institutions need to monitor both the Polish AML Act and the EU-level reform timeline — requirements will be tightening, and the AML program needs to be structured to evolve with the regulatory environment.

Polish AML Act obligations include: customer due diligence (identification, verification, and ongoing monitoring of business relationships); risk assessment (entity-level assessment of money laundering and terrorist financing risks); enhanced due diligence for high-risk customers, PEPs, and high-risk jurisdictions; internal controls and AML policies and procedures; suspicious transaction reporting to GIIF (Główny Inspektor Informacji Finansowej); staff training; designation of a compliance officer responsible for the AML program; and periodic review of the AML risk assessment. The specific obligations and their intensity depend on the entity’s business model and risk profile.

The Polish AML Act (Ustawa o przeciwdziałaniu praniu pieniędzy i finansowaniu terroryzmu) defines a broad range of obliged institutions that must implement AML compliance programs. The list includes: banks and credit institutions; payment institutions and e-money institutions; investment firms; insurance companies; auditors, tax advisors, and accounting firms; notaries and lawyers (in specific transaction types); real estate agents; gambling companies; crypto asset service providers and virtual currency exchanges; and certain corporate service providers. The scope is broader than many US companies assume — and the classification as an obliged institution triggers the full range of AML obligations under the Act.

GIIF (Główny Inspektor Informacji Finansowej — the General Inspector of Financial Information) is Poland’s financial intelligence unit and the primary AML supervisory authority. GIIF has authority to: receive and analyze suspicious transaction reports (STRs) from obliged institutions; conduct inspections of obliged institutions’ AML compliance programs; impose administrative fines for AML Act violations; refer cases for criminal prosecution for serious violations; and share financial intelligence with law enforcement and international FIU partners. GIIF inspections test the operational reality of the AML program, not just the documentation — inspectors interview staff and review transaction records to assess whether the program functions in practice.

The Polish AML Act creates specific personal liability for management board members and other persons managing the obliged institution. Liability applies for: failure to implement an internal AML compliance program; failure to designate an AML compliance officer; providing false information to GIIF; and failure to apply customer due diligence measures. Fines can be imposed personally on management board members. In cases of serious violation — particularly involving actual money laundering facilitation — criminal liability can apply. US executives managing Polish obliged institutions remotely are within scope of this liability framework if they are management board members of the Polish entity.