A mid-sized Warsaw accounting firm onboards a new corporate client. The client's beneficial owner is a foreign national, the transaction structure is unusual, and the source of funds is unclear. Under Polish anti-money laundering law, the firm has a short window to apply enhanced due diligence, file a suspicious transaction report, and document every step – or face personal liability for its management board. The window is not forgiving.
Polish AML law is governed by the Ustawa o przeciwdziałaniu praniu pieniędzy oraz finansowaniu terroryzmu (Anti-Money Laundering and Counter-Terrorist Financing Act, AML Act). The Act transposes the EU's Fourth and Fifth AML Directives into Polish law and applies to a wide category of "obligated institutions," including banks, accountants, lawyers, real estate agents, and virtual asset service providers. Obligated institutions must implement internal AML procedures, conduct customer due diligence, identify beneficial owners, and report suspicious transactions to the Generalny Inspektor Informacji Finansowej (General Inspector of Financial Information, GIIF). Failure to comply triggers fines of up to PLN 5 million or 10% of annual turnover, whichever is higher.
This guide walks through the AML compliance framework step by step. It covers who qualifies as an obligated institution, what internal procedures must contain, how customer due diligence works in practice, and what the most common mistakes look like across three business scenarios. A checklist and FAQ close the guide.
Who qualifies as an obligated institution under the AML Act?
The AML Act defines "obligated institutions" broadly. The definition covers financial sector entities, but also a significant range of professional service providers. Getting the categorisation right is the first compliance step – and the one most commonly skipped by smaller firms entering regulated activity.
Financial institutions subject to supervision by the Komisja Nadzoru Finansowego (Polish Financial Supervision Authority, KNF) – including banks, payment institutions, and investment firms – are the obvious category. Less obvious are the non-financial obligated institutions: tax advisors, auditors, notaries, lawyers (when handling real estate or corporate transactions), real estate agents, and dealers in high-value goods where a single cash transaction exceeds EUR 10,000. Virtual asset service providers registered with the Departament Informacji Finansowej (Financial Information Department) also fall within scope.
The threshold test matters. A law firm advising on litigation is generally outside scope. The same firm advising on a real estate acquisition or company incorporation steps inside it. The distinction is activity-based, not entity-based. A single transaction can trigger obligated-institution status for an otherwise unregulated professional.
- Banks, payment institutions, and investment firms supervised by KNF
- Tax advisors, auditors, and chartered accountants
- Notaries and lawyers in transactional work
- Real estate agents and property managers
- Dealers in high-value goods (cash transactions above EUR 10,000)
Misclassification carries real risk. An entity that incorrectly concludes it falls outside the AML Act forfeits the protection that a documented compliance programme provides. GIIF inspections have increasingly targeted professional service firms – not just the banking sector. The Naczelny Sąd Administracyjny (Supreme Administrative Court, NSA) has confirmed that the activity-based test applies even to occasional transactions.
What must an internal AML procedure contain?
Once an entity qualifies as an obligated institution, it must adopt a written internal AML procedure. The procedure is not a formality. GIIF inspectors review it as the primary evidence of a functioning compliance programme, and gaps in the document translate directly into administrative liability for the management board.
The AML Act requires the internal procedure to address at least five core areas. First, risk assessment: the institution must assess and document its exposure to money laundering and terrorist financing risks, updated at least every two years. Second, customer due diligence (CDD): the procedure must specify when simplified, standard, and enhanced CDD apply, and what verification steps each level requires. Third, transaction monitoring: criteria for identifying unusual or suspicious transactions must be set out in writing, not left to individual judgment. Fourth, suspicious transaction reporting: the procedure must define the internal escalation path before a report reaches GIIF. Fifth, employee training: all staff involved in customer-facing or transaction-processing roles must receive documented AML training at least once per year.
(The training requirement is frequently underestimated. A well-drafted procedure held by a team that has never read it provides almost no defence in an inspection.)
The procedure must also designate an AML compliance officer – a named individual, not a job title. In entities with fewer than three employees, the management board member responsible for AML must be identified by name. Larger institutions supervised by KNF must appoint a senior manager at board level. For a practical model of how to structure a compliance programme across multiple jurisdictions, see our guide on compliance programme design for Switzerland subsidiaries in Poland.
How does customer due diligence work in practice?
Customer due diligence is the operational core of AML compliance. It determines what information the obligated institution must collect, verify, and retain before – and during – a business relationship. Three levels apply: simplified, standard, and enhanced. Choosing the wrong level, or failing to escalate to enhanced CDD when required, is among the most penalised errors in GIIF inspections.
Standard CDD applies to most business relationships. It requires identifying the customer (name, registered address, tax identification number), identifying the beneficial owner – any natural person holding more than 25% of shares or voting rights – and verifying both identities against reliable, independent sources. The Centralny Rejestr Beneficjentów Rzeczywistych (Central Register of Beneficial Owners, CRBR) is the primary source for Polish entities. Discrepancies between CRBR data and information provided by the customer must be flagged and documented.
Enhanced CDD is mandatory in three situations: the customer or transaction involves a high-risk third country (as listed by the European Commission); the customer is a politically exposed person (PEP) or a family member or close associate of one; or the institution's own risk assessment identifies elevated risk. Enhanced CDD requires establishing the source of funds, obtaining senior management approval before onboarding, and conducting ongoing monitoring at shorter intervals than standard relationships.
We secured a reversal of a GIIF-initiated administrative proceeding for a financial services client in the Mazowieckie region (autumn 2025). The proceeding had been triggered by incomplete beneficial owner verification during a corporate restructuring. Proper CRBR cross-referencing and a documented risk escalation trail were central to the successful outcome.
Simplified CDD is available only for low-risk customers explicitly identified in the AML Act – primarily certain public-sector entities and listed companies on regulated markets. Institutions that apply simplified CDD to customers outside these categories face the same liability as if no CDD had been conducted.
Three business scenarios: manufacturing, IT, and foreign investor
Abstract compliance obligations become clearer when mapped to specific business contexts. The three scenarios below illustrate how the AML Act's requirements translate into day-to-day decisions for different types of Polish companies.
Manufacturing company (Silesia). A mid-sized manufacturer sells industrial equipment. A new distributor wants to pay EUR 12,000 in cash for a single shipment. The transaction crosses the EUR 10,000 threshold that triggers obligated-institution status for high-value goods dealers. The manufacturer must: verify the distributor's identity and beneficial owner, document the source of funds, and retain records for five years. If the distributor is incorporated in a high-risk third country, enhanced CDD applies before the transaction proceeds. Failing to document this process – even if the transaction itself is legitimate – constitutes a breach of the AML Act.
IT company (Małopolska). A software firm provides services to corporate clients across the EU. It does not handle cash and does not provide financial services. In most cases, it falls outside the AML Act's scope. However, if the firm provides accounting, bookkeeping, or tax advisory services as part of its offer, it may qualify as an obligated institution for those activities specifically. The activity-based test applies. Compliance counsel should review the service catalogue annually as the firm's offering evolves.
Foreign investor (Lower Silesia). A German investor acquires a Polish subsidiary through a local holding structure. The acquisition involves a law firm acting as the notary's counterpart and a tax advisor structuring the transaction. Both the law firm and the tax advisor qualify as obligated institutions for this transaction. The investor's beneficial ownership must be verified against CRBR, and if the investor is a PEP or connected to a high-risk jurisdiction, enhanced CDD applies. For lease-related due diligence in the same transaction, see our analysis of office lease review key points for Poland tenants.
Our team obtained interim protective measures for a German investor's subsidiary in Lower Silesia (spring 2026) in a matter where incomplete AML documentation had been used to challenge the validity of a share transfer. Proper record retention – five years from the end of the business relationship – proved decisive.
What are the most common AML compliance mistakes?
GIIF inspections and administrative proceedings reveal patterns. The same errors appear repeatedly across sectors and entity sizes. Identifying them in advance is more cost-effective than correcting them under enforcement pressure.
The first and most frequent mistake is treating the internal AML procedure as a one-time document. The AML Act requires a risk assessment update at least every two years. Institutions that drafted a procedure in 2021 and have not revisited it since are almost certainly non-compliant – the European Commission's high-risk country list has changed, CRBR coverage has expanded, and GIIF guidance has been updated. A static document does not satisfy a dynamic obligation.
The second mistake is incomplete beneficial owner identification. Many institutions verify the customer's legal identity but stop short of tracing the beneficial owner chain to the natural person level. Holding structures, nominee arrangements, and foreign intermediaries are all common in Polish corporate practice. The 25% threshold applies to the ultimate natural person, not the immediate shareholder. Stopping one level up forfeits the legal protection that correct identification provides.
The third mistake is failing to document the decision not to report. When an institution reviews a transaction and concludes it does not meet the threshold for a suspicious transaction report, that conclusion must be documented. An undocumented non-report is indistinguishable from a missed report in an inspection. The obligation to retain documentation applies equally to reports filed and to reports not filed.
- Outdated risk assessment (not reviewed within the two-year cycle)
- Beneficial owner chain not traced to the natural person level
- Simplified CDD applied to customers outside the statutory list
- No documented escalation trail for enhanced CDD decisions
- Employee training records incomplete or missing
Whistleblower compliance intersects with AML here. Under the Ustawa o ochronie sygnalistów (Whistleblower Protection Act), obligated institutions with 50 or more employees must also maintain internal reporting channels for AML-related concerns. Failure to implement these channels is a separate compliance breach, distinct from the AML Act obligations themselves. ESG reporting frameworks under CSRD Poland requirements increasingly treat AML governance as a material compliance indicator.
For a detailed look at how AML obligations have evolved across reporting cycles, see our earlier analysis at AML compliance obligations for Polish companies.
Specific advice for your company's situation requires analysis of its activity profile, client base, and transaction types. Generalised checklists do not substitute for that analysis – and acting on an incorrect self-assessment forfeits the good-faith compliance defence in GIIF proceedings.
To receive an expert assessment of your company's AML compliance status, contact info@kordeckipartners.com.
What to prepare: AML compliance checklist
Before an inspection or before onboarding a new high-risk client, the following documents and processes should be in place. This checklist applies to most obligated institutions outside the financial sector. Supervised entities under KNF face additional requirements.
- Written internal AML procedure, reviewed within the last two years
- Named AML compliance officer with documented appointment
- Customer due diligence records for all active business relationships (retained for five years)
- Beneficial owner verification cross-referenced against CRBR
- Annual employee training records with attendance documentation
The checklist is a starting point, not a complete compliance framework. Institutions operating in multiple jurisdictions, handling virtual assets, or serving PEP clients face layered obligations that require bespoke analysis. A compliance lawyer in Warsaw with experience across the AML Act and related ESG and whistleblower frameworks can map the full obligation set against the institution's actual activity profile.
Your company's specific AML exposure depends on factors that a general guide cannot resolve – transaction volume, client geography, ownership structure, and the nature of services provided all affect which obligations apply and at what intensity. Acting on incomplete information precludes the good-faith defence and forecloses the ability to self-correct before GIIF initiates proceedings.
For a tailored strategy on AML compliance programme implementation, reach out to info@kordeckipartners.com.
Frequently asked questions
Q: How long does it take to implement a compliant internal AML procedure from scratch?
A: For a professional services firm outside the financial sector, a baseline internal procedure can typically be drafted and adopted within four to six weeks. This assumes the firm can provide its service catalogue, client risk profile, and organisational chart at the outset. Supervised institutions under KNF face additional approval steps that extend the timeline. Budget for an annual review cycle from the date of adoption.
Q: Does a small company with only three employees need a full AML compliance programme?
A: Size does not determine scope – activity does. A three-person tax advisory firm qualifies as an obligated institution regardless of headcount. The AML Act does provide that in entities with fewer than three employees, the management board member responsible for AML must be identified by name rather than a separate compliance officer appointed. However, the obligation to adopt a written procedure, conduct CDD, and file suspicious transaction reports applies in full. The misconception that small firms are exempt is one of the most common errors seen in GIIF inspections.
Q: What is the cost of an AML compliance audit for a mid-sized Polish company?
A: Cost depends on the entity's size, sector, and the existing state of its compliance documentation. For a professional services firm with 20 to 50 employees, an initial AML compliance gap analysis typically requires between 15 and 30 hours of legal work. Remediation – drafting or updating the internal procedure, training staff, and implementing monitoring processes – adds further time. Firms that have never implemented a formal programme should expect a more substantial initial investment than those updating an existing framework.
KORDECKI & Partners is a law firm based in Warsaw and Krakow, advising business clients across 30 jurisdictions. Our team combines expertise in Polish and international law with a practical approach to AML compliance, ESG reporting, and internal investigations. We work with Polish entrepreneurs, foreign investors, and in-house legal teams navigating the AML Act, CSRD Poland requirements, and whistleblower compliance frameworks. To discuss your situation, contact info@kordeckipartners.com.
Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. KORDECKI & Partners assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@kordeckipartners.com.