A US-headquartered group opens a Polish subsidiary and assumes that its existing global compliance framework transfers automatically. It rarely does. Polish law imposes distinct obligations – on whistleblower channels, anti-money laundering controls, and ESG disclosures – that sit alongside, and sometimes conflict with, US parent requirements. Getting the overlap wrong exposes both the local entity and its US parent to regulatory action on two continents.
United States subsidiaries operating in Poland must build a compliance programme that satisfies Polish statutory requirements while remaining consistent with US federal standards. The key Polish instruments are the Whistleblower Protection Act of 2024, the Anti-Money Laundering and Counter-Terrorism Financing Act (ustawa o przeciwdziałaniu praniu pieniędzy i finansowaniu terroryzmu, AML Act), and the Corporate Sustainability Reporting Directive as transposed into Polish law (CSRD Poland). Subsidiaries with more than 50 employees, or those meeting financial thresholds under the AML Act, must act before the deadlines described below.
This alert covers three areas: what has changed in Polish compliance law, which US subsidiaries are affected and at what thresholds, and the immediate action items your legal team should prioritise. Each section includes at least one hard deadline or monetary figure so you can calibrate urgency.
What has changed in Polish compliance requirements?
Three regulatory shifts now define the compliance environment for foreign-owned entities in Poland. First, the Whistleblower Protection Act entered into force in September 2024. It requires every employer with 50 or more employees to establish an internal reporting channel within 3 months of crossing that headcount threshold. The National Labour Inspectorate (Państwowa Inspekcja Pracy, PIP) supervises compliance, and fines for non-compliance reach PLN 5,000 per violation.
Second, the General Financial Supervision Authority (Komisja Nadzoru Finansowego, KNF) and the General Inspector of Financial Information (Generalny Inspektor Informacji Finansowej, GIIF) have intensified AML supervision of obligated institutions. Polish subsidiaries providing financial, legal, or accounting services fall within the AML Act's scope. They must maintain current risk assessments, keep beneficial ownership data up to date in the National Court Register (KRS), and file suspicious transaction reports within 24 hours of detection.
Third, CSRD Poland extends mandatory sustainability reporting to large Polish entities for financial years beginning 1 January 2025. A subsidiary qualifies as "large" if it exceeds two of three thresholds: balance sheet total of PLN 85m, net revenue of PLN 170m, or 250 employees. Reporting must follow European Sustainability Reporting Standards (ESRS). For a practical implementation roadmap, see our guide on ESRS implementation steps for Polish reporting entities.
Which US subsidiaries are affected – and at what thresholds?
Threshold analysis is the first step any compliance lawyer Warsaw-based or US-side should run. The answer depends on headcount, sector, and financial size. Three categories of US subsidiary face immediate obligations.
- 50+ employees: mandatory internal whistleblower channel under the Whistleblower Protection Act.
- AML-obligated entities: financial institutions, law firms, accountants, real estate agents, and virtual asset service providers must register with GIIF and maintain AML procedures regardless of size.
- Large entities (CSRD threshold): two of three criteria – PLN 85m balance sheet, PLN 170m revenue, 250 employees – trigger ESG reporting for FY 2025.
A US subsidiary below all three thresholds is not entirely free of compliance obligations. Polish labour law, data protection rules under GDPR, and sector-specific regulations apply universally. The practical difference is that sub-threshold entities can adopt a lighter programme – a code of conduct, a basic AML risk assessment, and a data protection officer appointment – rather than the full architecture required of larger entities.
We secured a restructuring of an AML compliance framework for a US fintech subsidiary in the Mazowieckie region (autumn 2025), allowing it to meet GIIF registration deadlines without disrupting its product launch timeline. The engagement took six weeks from scoping to sign-off.
For context on how similar issues arise in other EU jurisdictions, our note on compliance programme design for Luxembourg subsidiaries in Poland sets out a useful parallel framework.
What should your team do right now?
Immediate action falls into three tracks. Each has a concrete deadline or cost consequence attached. Delay on any track forfeits the ability to cure non-compliance before a supervisory visit or whistleblower complaint triggers an investigation – an irreversible reputational and financial consequence.
Track 1 – Whistleblower channel: If your Polish entity employs 50 or more people and has not yet established an internal reporting channel, you are already in breach. The channel must cover reports of breaches of Polish law and EU law. It must guarantee confidentiality and prohibit retaliation. Implement within 30 days of reading this alert.
Track 2 – AML programme review: Obligated institutions must update their risk assessment annually. If your last review predates the 2024 amendments to the AML Act, it is out of date. A current risk assessment must reflect the entity's actual client base, transaction types, and geographic exposure. Budget 4 to 6 weeks for a thorough review with external counsel.
Track 3 – CSRD gap analysis: Large subsidiaries reporting for FY 2025 must complete a double-materiality assessment before drafting their ESRS-compliant sustainability statement. Starting this process in Q1 2026 is already late. Prioritise data collection on climate, social, and governance metrics immediately.
- Confirm headcount and financial thresholds against all three regulatory triggers.
- Appoint a compliance officer or designate an existing manager with formal authority.
- Map US parent policies against Polish statutory requirements and identify conflicts.
- Establish a whistleblower channel with a documented procedure and a named recipient.
- Schedule an AML risk assessment update with external AML specialists.
Our team assisted a US technology group's Polish subsidiary in Silesia (winter 2025) in designing an integrated compliance programme covering all three tracks in parallel. The project was completed in eight weeks and passed a subsequent PIP inspection without findings.
For cross-border enforcement context – including how Polish courts treat US-origin legal obligations – our analysis of enforcing a United States judgment in Poland step by step provides relevant background on jurisdictional interaction.
Your specific situation carries consequences that a generic global compliance policy cannot address. Failing to localise your programme before a supervisory visit precludes the voluntary remediation credit that Polish regulators extend to proactive entities.
If your US subsidiary in Poland employs 50 or more people, operates in an AML-regulated sector, or approaches the CSRD thresholds – we will conduct a threshold assessment, identify conflicts between US parent policies and Polish law, and deliver a prioritised action plan: info@kordeckipartners.com.
Frequently asked questions
Q: Does a US parent's existing global compliance programme satisfy Polish legal requirements?
A: Not automatically. Polish law imposes specific procedural requirements – for example, the whistleblower channel must be established under a documented internal procedure approved by the workforce representative body or works council where one exists. A global policy that lacks these elements will not satisfy the Whistleblower Protection Act, even if it covers equivalent conduct. Local adaptation is always required.
Q: How long does it take to build a compliant programme from scratch?
A: A basic programme covering whistleblower channels, AML procedures, and a GDPR-compliant data protection framework typically takes 6 to 10 weeks with dedicated external counsel. The timeline extends if the entity is AML-obligated and requires GIIF registration, or if CSRD reporting applies and a double-materiality assessment has not yet been started. Starting earlier reduces both cost and risk.
Q: Is it a misconception that only financial institutions need AML compliance in Poland?
A: Yes. The AML Act covers a broad range of obligated institutions, including law firms, tax advisors, accountants, real estate agents, notaries, and virtual asset service providers. A US subsidiary providing any of these services in Poland – even as an ancillary activity – falls within the AML Act's scope and must maintain a current risk assessment, a compliance officer, and internal AML procedures. Sector classification, not size, determines AML obligation.
KORDECKI & Partners is a law firm based in Warsaw and Krakow, advising business clients across 30 jurisdictions. Our team combines expertise in Polish and international law with a practical approach to compliance programme design, ESG reporting, and AML advisory. We work with Polish entrepreneurs, foreign investors, and in-house legal teams. To discuss your situation, contact info@kordeckipartners.com.
Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. KORDECKI & Partners assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@kordeckipartners.com.