A mid-sized payment services provider registered in Warsaw discovered, during a routine internal review, that its transaction-monitoring procedures had not been updated since the last major amendment to Poland's anti-money laundering framework. The gap had gone unnoticed for over eighteen months. By the time the compliance team flagged the issue, the company faced a potential inspection by the General Inspector of Financial Information (Generalny Inspektor Informacji Finansowej, GIIF) – the primary supervisory authority under Polish AML law.
Polish companies designated as obligated institutions under the Anti-Money Laundering and Counter-Terrorism Financing Act (ustawa o przeciwdziałaniu praniu pieniędzy oraz finansowaniu terroryzmu, AML Act) must maintain a documented risk-assessment framework, implement internal controls, and report suspicious transactions to the GIIF. Failure to meet these obligations can result in administrative fines reaching PLN 5 million or 10% of annual turnover, whichever is higher. The National Court Register (KRS) records entities subject to these requirements, and the Polish Financial Supervision Authority (KNF) exercises parallel oversight over licensed financial institutions.
This case study traces how the firm assisted the payment services provider in remediating its AML programme within a compressed timeline, avoided a formal enforcement proceeding, and embedded transferable compliance architecture for the future. The article covers the factual background, the legal strategy deployed, the remediation process, and the lessons that apply to any Polish obligated institution.
What was the background to the AML compliance gap?
The client operated a payment platform serving both retail and corporate customers across Poland and three other EU member states. Its AML obligations were governed by the AML Act, which transposes the EU's Fourth and Fifth Anti-Money Laundering Directives into Polish law. The firm had initially built its compliance programme at launch, but subsequent amendments – particularly those tightening beneficial ownership verification and expanding the scope of politically exposed persons (PEP) screening – had not been incorporated into internal procedures.
The internal review identified three specific deficiencies. Transaction-monitoring thresholds had not been recalibrated to reflect updated regulatory guidance. The beneficial ownership register (Centralny Rejestr Beneficjentów Rzeczywistych, CRBR) checks were performed only at onboarding, with no periodic refresh cycle. PEP screening relied on a single commercial database that had not been renewed. Each gap, standing alone, might have been manageable. Together, they constituted a systemic failure that the GIIF could treat as a basis for an administrative fine.
The compliance team had approximately 60 days before a scheduled supervisory visit. That timeline shaped every strategic decision that followed. We were engaged within the first week of the internal review becoming known to the board.
How did the legal strategy address the risk of enforcement?
The starting point was a structured gap analysis mapped against the current text of the AML Act and the GIIF's published supervisory guidelines. This produced a prioritised remediation list: items that had to be resolved before the supervisory visit, items that could be addressed in a rolling programme over six months, and items requiring system-level investment beyond the immediate timeline. Setting that hierarchy prevented the client from attempting to fix everything at once – a common error that delays the most critical repairs.
Our team secured a reversal of a proposed administrative sanction exceeding PLN 800,000 for a fintech client in the Mazowieckie region (autumn 2025) by demonstrating proactive remediation steps taken before the formal inspection concluded. That precedent informed the strategy here: documented, timestamped evidence of good-faith remediation carries significant weight with the GIIF when assessing proportionality of any sanction.
The strategy therefore combined three elements. First, immediate procedural updates – revised transaction-monitoring thresholds, a refreshed PEP-screening contract, and a CRBR periodic-review cycle – were documented and adopted by board resolution within 14 days. Second, a voluntary disclosure memorandum was prepared, setting out the identified gaps and the remediation timetable. Third, staff training on the updated procedures was completed and recorded before the supervisory visit. This approach reflects the AML Act's explicit recognition that self-correction and cooperation are mitigating factors in penalty assessments.
- Gap analysis mapped to GIIF supervisory guidelines
- Board resolution adopting procedural updates within 14 days
- Voluntary disclosure memorandum with remediation timetable
- PEP screening and CRBR refresh cycles formalised
- Documented staff training completed before inspection
For businesses with cross-border operations, the complexity increases. Our work on compliance programme design for Ukraine subsidiaries in Poland illustrates how multi-jurisdictional ownership chains require additional layers of beneficial ownership mapping beyond what domestic-only entities face.
What did the remediation process involve in practice?
Execution required close coordination between the client's compliance officer, its IT team, and external legal counsel. The transaction-monitoring recalibration involved reviewing 24 months of historical transaction data to set defensible new thresholds – a task that took two weeks. The CRBR periodic-review cycle was built into the client relationship management system, triggering automatic checks every 12 months and at each material change in customer ownership structure.
We also assisted the client in assessing whether its compliance programme design for Italy subsidiaries in Poland offered any structural lessons for the domestic programme. The comparison proved useful: the Italian subsidiary's programme included a whistleblower compliance channel that the Warsaw entity had not yet established. Under Polish law implementing the EU Whistleblowing Directive, obligated institutions above certain thresholds are required to maintain internal reporting channels. Adding this element strengthened the overall compliance architecture.
We obtained interim protection of the client's operational licence during the inspection period for a payment services client in Lower Silesia (spring 2026) by framing the remediation evidence as a complete and contemporaneous record. The same documentation discipline was applied here. Every procedural update carried a board-approval date, a responsible officer signature, and a training-completion log. The GIIF inspector reviewed the file over two days. No formal enforcement proceeding was opened.
What are the transferable lessons for Polish obligated institutions?
The most direct lesson is that AML compliance is not a one-time implementation exercise. The AML Act is amended regularly, and GIIF supervisory guidelines are updated between legislative cycles. An obligated institution that built its programme correctly at launch but has not reviewed it in 18 months is almost certainly operating with at least one material gap. A periodic review – at minimum annually, and after any significant regulatory change – is the baseline expectation.
The second lesson concerns documentation discipline. The GIIF does not expect perfection. It does expect evidence that the institution identified its obligations, assessed its risks, and took proportionate steps. A gap discovered and remediated with a clear paper trail is treated differently from a gap discovered during an inspection with no prior internal awareness. For companies that also face ESG reporting obligations under CSRD Poland requirements, this same documentation logic applies: the obligation exists whether or not the company has a system to track it.
The third lesson is about speed. Once a gap is identified, the clock starts. Delay in engaging legal counsel, delay in board-level sign-off, and delay in staff training all narrow the window for voluntary remediation to carry mitigating weight. For any obligated institution facing a potential inspection or an identified compliance gap, the question of whether to engage a compliance lawyer Warsaw should be answered within days, not weeks. If enforcement proceedings are already in motion, the disputes practice in Poland provides the litigation and regulatory defence capability that the situation may require.
What to prepare before an AML supervisory visit:
- Current risk-assessment document with date of last review
- Evidence of CRBR and PEP screening procedures and refresh cycles
- Transaction-monitoring threshold documentation and calibration rationale
- Staff training records for the past 24 months
The specific facts of your company's AML compliance position determine whether a gap can be remediated voluntarily or whether a formal response strategy is needed. Delay in that assessment forfeits the mitigating value of proactive remediation – an irreversible consequence once an inspection has commenced.
To receive an expert assessment of your AML compliance programme or to prepare for a GIIF supervisory visit, contact info@kordeckipartners.com.
Frequently asked questions
Q: Which Polish companies are obligated institutions under the AML Act?
A: The AML Act designates a broad range of entities as obligated institutions, including banks, payment services providers, currency exchange offices, notaries, accountants, tax advisers, real estate agents, and certain corporate service providers. Each category carries specific obligations calibrated to the risk profile of the sector. If you are uncertain whether your business falls within scope, a preliminary legal assessment typically takes no more than two to three business days.
Q: What is a common misconception about AML compliance timelines?
A: Many companies believe that AML compliance obligations only become active once the GIIF formally notifies them of an inspection. This is incorrect. The obligation to maintain a current risk assessment, implement internal controls, and report suspicious transactions arises continuously from the moment the entity qualifies as an obligated institution. Waiting for a supervisory trigger before building the programme means the institution is already in breach.
Q: How much does AML programme remediation typically cost?
A: Cost depends on the scope of the gaps identified. Procedural updates and documentation work for a single-entity programme can often be completed within a fixed-fee engagement over four to six weeks. System-level changes – such as integrating automated CRBR checks or upgrading transaction-monitoring software – involve additional IT investment that varies by platform. Legal fees for the compliance and documentation work are generally a fraction of the administrative fines that a deficient programme risks attracting.
KORDECKI & Partners is a law firm based in Warsaw and Krakow, advising business clients across 30 jurisdictions. Our team combines expertise in Polish and international law with a practical approach to AML compliance, ESG reporting, and regulatory investigations. We work with Polish entrepreneurs, foreign investors, and in-house legal teams. To discuss your situation, contact info@kordeckipartners.com.
Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. KORDECKI & Partners assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@kordeckipartners.com.