5 key takeaways
- AML/CFT compliance is the most scrutinised area in KNF licence applications and supervisory inspections – and the most common cause of delay, supplementation requests and enforcement action
- Polish AML obligations derive from EU law – the 6th Anti-Money Laundering Directive and AMLD implementation – plus the Polish AML Act (ustawa o przeciwdziałaniu praniu pieniędzy)
- Every fintech with KNF authorisation must appoint a designated AML officer (AMLCO) physically present in Poland – a nominal appointment does not satisfy KNF
- Transaction monitoring must be calibrated to the entity’s actual product and customer base – generic typologies and off-the-shelf systems that have not been configured for the entity’s risk profile are a frequent gap
- GIIF reporting (Generalny Inspektor Informacji Finansowej) requires suspicious activity reports in Polish, following specific format requirements – this is a practical operational challenge for non-Polish entities
As one of Poland’s leading fintech lawyers with direct experience representing clients before KNF and advising on AML/CFT frameworks for payment institutions, EMIs and crypto-asset businesses, I work regularly with fintechs navigating the gap between what their AML programme looks like on paper and what KNF expects to see in practice. AML compliance in Poland is not a documentation exercise – it is an operational framework that KNF and GIIF will test against your actual business. This post explains what is required, where the gaps most commonly appear, and what to prioritise.
AML Compliance Fintech Poland KNF: The Legal Framework
Polish AML obligations for fintechs derive from three overlapping sources:
| Source | What it covers |
|---|---|
| Polish AML Act (ustawa o przeciwdziałaniu praniu pieniędzy i finansowaniu terroryzmu) | Core Polish AML/CFT obligations, GIIF reporting, supervisory powers |
| EU AMLD framework (currently 6AMLD) | Harmonised EU AML/CFT standards, beneficial ownership, PEP requirements |
| Sector-specific regulation (PSD2, MiCA, MiFID II) | AML/CFT requirements specific to payment, crypto and investment businesses |
Specifically, entities subject to KNF authorisation – payment institutions, EMIs and CASPs – are obliged institutions (instytucje obowiązane) under the Polish AML Act. Consequently, they must implement a full AML/CFT compliance framework as a condition of authorisation and ongoing operation.
AML Compliance Fintech Poland KNF: What KNF Expects
Risk assessment
Every obliged institution must conduct a documented AML/CFT risk assessment covering its products, customers, geographic exposure and distribution channels. Furthermore, the risk assessment must be reviewed and updated regularly – not treated as a one-off exercise. Specifically, KNF expects the risk assessment to reflect the entity’s actual business model, not a generic template.
Common gap: risk assessments that list risk factors without actually assessing the entity’s specific exposure – KNF reads risk assessments against the business plan and asks whether the risks identified are realistic for this business.
Customer due diligence (KYC)
KNF requires documented KYC procedures covering:
- Standard CDD: identity verification, beneficial ownership identification, purpose and nature of the business relationship
- Simplified CDD: for lower-risk customers where proportionality applies – but KNF expects documented justification for any simplified approach
- Enhanced CDD: mandatory for high-risk customers including PEPs, correspondent banking relationships, and customers from high-risk jurisdictions
- Ongoing monitoring: periodic review of customer profiles and transaction patterns
Additionally, digital onboarding must comply with eIDAS standards for remote identity verification – entities cannot rely on informal digital verification processes that would not withstand regulatory scrutiny.
Designated AML officer (AMLCO)
Every obliged institution must appoint a designated AML officer responsible for implementing the AML/CFT programme. Specifically, KNF expects the AMLCO to:
- Be physically present in Poland
- Have relevant AML/CFT experience and qualifications
- Be a senior enough position to have real authority within the organisation
- Have direct access to the management board
Common gap: appointing an AMLCO who is technically competent but based outside Poland, or who holds AML responsibility as a secondary function alongside a full-time primary role. KNF takes AMLCO appointments seriously and will ask detailed questions about the individual’s availability and authority.
Transaction monitoring
Transaction monitoring must be calibrated to the entity’s specific product and customer base. Consequently, deploying an off-the-shelf transaction monitoring system without configuring it for the entity’s risk profile is a frequent and serious gap that KNF identifies in supervisory inspections.
Specifically, KNF expects to see:
- Documented monitoring rules and thresholds appropriate to the entity’s customer and transaction profile
- An escalation process for alerts – from automated detection through analyst review to GIIF reporting decision
- Records of monitoring alerts, analyst reviews and outcomes
- Periodic tuning of monitoring rules based on actual alert outcomes
GIIF reporting
Suspicious activity reports (SARs) must be submitted to GIIF – Generalny Inspektor Informacji Finansowej – in Polish, following GIIF’s specified format requirements. Furthermore, the submission is made through GIIF’s dedicated IT system. Consequently, non-Polish entities must ensure they have Polish-language reporting capability and staff familiar with GIIF’s requirements.
Practical challenge: GIIF reporting deadlines are strict – a suspicious transaction must be reported within 24 hours of the suspicion arising in certain cases. Consequently, the operational capability to identify, escalate, document and report a suspicious transaction within that window must be built into the entity’s processes, not left as a theoretical framework.
AML Compliance for Crypto Businesses in Poland
Crypto-asset businesses face additional AML/CFT complexity. Specifically:
Travel Rule: under FATF Travel Rule requirements implemented in EU law, CASPs must collect and transmit originator and beneficiary information for transfers of crypto-assets above €1,000. Consequently, the entity must have systems capable of collecting, verifying and transmitting Travel Rule data – and must manage relationships with counterparty CASPs that may or may not be Travel Rule compliant.
VASP-specific risk: crypto-asset businesses present specific AML risks including anonymity of transactions, use of mixing services, high-risk jurisdictions and cross-chain transfers. Consequently, KNF expects crypto-specific risk typologies and monitoring rules – not generic financial institution AML processes applied without adaptation.
Transaction monitoring for blockchain: monitoring blockchain transactions requires tools capable of analysing on-chain data, identifying wallet clusters associated with sanctions or illicit activity, and escalating high-risk transactions. Specifically, KNF expects entities to use blockchain analytics tools appropriate to the volume and nature of their crypto-asset activity.
AML Compliance Fintech Poland KNF: The Most Common Gaps
Based on my experience advising fintechs on KNF licensing and supervisory interactions, these are the gaps that most frequently cause problems:
1. Generic AML documentation not tailored to the business The most common and most serious gap. KNF will not accept a generic AML policy – it expects documentation that reflects this entity’s products, customers, risks and processes.
2. AMLCO not physically in Poland or not sufficiently senior An AMLCO who is nominally appointed but not genuinely active and present does not satisfy KNF’s requirements.
3. Transaction monitoring not configured for the entity’s risk profile Off-the-shelf systems without entity-specific configuration generate alerts that are either too many (overwhelming analysts) or too few (missing genuine risks).
4. No documented process for GIIF reporting Having a policy that says “suspicious transactions will be reported to GIIF” is insufficient – the entity needs a documented operational process with clear escalation paths, timelines and responsibilities.
5. KYC procedures not aligned with digital onboarding reality KYC policies that describe in-person verification processes for entities that onboard entirely digitally – or that describe verification requirements that the entity’s technology cannot actually implement.
What to Do If You Have a Gap
If your AML/CFT framework has gaps – whether identified by KNF in a licensing review, a supervisory inspection, or your own internal audit – the most important thing is to address them systematically. Specifically:
- Commission an independent AML/CFT gap analysis against KNF’s expectations and the Polish AML Act
- Prioritise gaps by risk — KNF and GIIF reporting failures carry the most serious regulatory exposure
- Remediate documentation and operational processes together — a new policy that the team does not follow is not a remedy
- Where a gap involves the AMLCO appointment, address this as a matter of urgency
If you have questions about AML compliance for your fintech business in Poland, get in touch. For more on fintech regulation, see the FinTech, Banking & Financial Regulation practice area page.
Related posts:
- KNF Licensing in Poland: A Practical Guide for Fintech Companies
- DORA Compliance Poland KNF
- CASP as a Service Under MiCA in Poland
- Fintech Legal Advice in Poland: What to Look for in a Fintech Lawyer
- Fintech, AI Act and NIS2 Lawyer in Poland
Katarzyna Szczudlik is a Partner at Schoenherr in Warsaw and one of Poland’s leading fintech lawyers, ranked by Chambers & Partners (FinTech) and Legal 500 EMEA. She advises payment institutions, EMIs and crypto-asset businesses on KNF licensing and AML/CFT compliance in Poland. Get in touch.