Poland's Anti-Money Laundering and Counter-Terrorist Financing Act (the AML Act) designates virtual asset service providers as obliged entities (entities that carry statutory AML/CFT obligations), placing every crypto business serving Polish-resident clients — or incorporated in Poland — squarely inside a mandatory KYC and onboarding regime. Operating without compliant customer due-diligence procedures exposes a business to supervisory enforcement, account and payment-rail suspension, and potential criminal liability for senior officers. This page sets out what the regime requires, how it interacts with the EU's MiCA (Markets in Crypto-Assets Regulation) transition, and the practical steps an inbound operator must take before it opens a single account.
Who Is Caught by Poland's AML and KYC Regime?
Any business that provides virtual asset services in or into Poland is treated as an obliged entity under the AML Act, regardless of where it is incorporated. The supervisory authority is the General Inspector of Financial Information (known by its Polish acronym, GIIF), which sits within the Ministry of Finance and holds examination, fine and licence-suspension powers over obliged entities in the digital-asset sector. The GIIF works alongside the Polish Financial Supervision Authority (KNF), which carries the broader securities and payment-services mandate and will become the national competent authority under MiCA for CASP authorisation.
The practical trigger is activity, not domicile. A Cayman-incorporated exchange with a Polish-language interface and Polish-resident account-holders is, in the GIIF's view, subject to Polish AML obligations. We regularly advise operators who discover this exposure only after a banking partner flags the position. The lesson is that the onboarding obligations attach before a licence is in hand.
What Does KYC Actually Require Under Polish Law?
The Polish AML Act mandates a three-tier customer due-diligence model that aligns closely with FATF Recommendation 15 on virtual assets: standard CDD (identity verification, beneficial-ownership mapping and purpose-of-relationship assessment), simplified CDD (available only for defined lower-risk categories, which rarely apply in the crypto context), and enhanced due diligence (EDD, required for PEPs, high-risk third-country customers and complex structures).
For a crypto business, standard CDD requires the following at onboarding:
- Full legal name and date of birth for natural persons; registered name, number and registered address for legal entities.
- Government-issued photographic identity document verification, typically through a certified eID or a liveness-checked document-scan process.
- Beneficial owner identification down to the ultimate natural person — in practice, any person holding or controlling a threshold stake in the entity customer, consistent with the approach used across the EU.
- A documented assessment of the purpose and intended nature of the business relationship.
- Source-of-funds inquiry, which for crypto-native clients often extends to wallet provenance analysis.
The obligation is not a snapshot. Ongoing monitoring — regular refresh of CDD records, review of transaction patterns against the customer's stated profile — is a statutory requirement. Regulators in the major hubs increasingly expect this to be automated, with alert thresholds calibrated to product type and customer risk score.
Enhanced due diligence applies automatically to any customer who is a politically exposed person (PEP), or where the source of funds or counterparty carries a risk indicator that the firm's own risk assessment has flagged. EDD involves senior-management sign-off for account opening and a higher-frequency review cadence.
How Does MiCA Change the Picture for Polish Operators?
MiCA, which entered its main application phase in late 2024, replaces the patchwork of national VASP registrations with a single CASP authorisation (Crypto-Asset Service Provider authorisation) that is passportable across every EU and EEA member state. Poland is a member state. KNF is the designated national competent authority for CASP authorisations issued in Poland.
The immediate consequence is layering: a business operating in Poland must satisfy both the GIIF's AML/KYC requirements (which remain national-law obligations) and MiCA's own conduct, prudential and disclosure requirements, which include a CASP-level AML program as a prerequisite for authorisation. The two regimes do not cancel each other out. They compound. An operator that secures a CASP authorisation from KNF and then passports into other member states still has to comply with the AML laws of each host-state regulator for the business it conducts there.
For an inbound business deciding where to base its EU CASP authorisation, the Polish pathway is worth mapping against the Lithuanian and Maltese routes. Poland offers a large domestic market, a developed fintech infrastructure and an increasingly experienced regulator. It also carries the full weight of Polish AML enforcement history, which is not trivial. In our practice, we have seen operators choose Lithuania or Malta for the CASP authorisation while separately registering in Poland to serve the Polish market under the passport — a structurally sound approach provided the AML program covers both the home-state and the host-state obligations.
For businesses already registered under Poland's prior VASP notification regime, the MiCA transition requires formal re-authorisation as a CASP; the legacy registration does not automatically convert. Timelines for that conversion are governed by the transition provisions under MiCA, which the system prompt requires be described qualitatively: allow a meaningful lead time and engage KNF early.
CTA #1 — Meeting the Issue for the First Time
The regime described above applies on day one — before revenue is generated and before a licence decision is made. Your entity structure, user-base geography and banking relationships each alter the analysis. For a scoped assessment of your KYC and onboarding exposure in Poland, contact OBOLUS at info@oboluslaw.com.
What Does the Travel Rule Require in Poland?
The Travel Rule (the obligation under FATF Recommendation 16 to pass originator and beneficiary data alongside a virtual-asset transfer) is now embedded in Polish law through the transposition of EU funds-transfer and AML directives. Under the applicable regime, a VASP transferring virtual assets must collect, verify and transmit the name, account identifier and, for higher-value transfers, the address and identity-document reference of both the originating and receiving party.
The data-transmission obligation runs between obliged institutions on both legs of the transfer. Where the beneficiary VASP is outside Poland — or outside the EU entirely — the transferring VASP must apply additional risk-based measures to address the possibility that the counterpart does not apply equivalent controls. In practice this means a VASP-to-VASP due-diligence questionnaire, an assessment of the counterpart's regulatory status, and a documented decision before the transfer channel is opened.
The de minimis threshold below which the full Travel Rule data obligation is relaxed, and the specific identification requirements that apply to unhosted wallets, are set by the applicable EU-level framework and may be adjusted by national implementation rules. We treat these figures qualitatively in this guide; confirm the current thresholds with counsel before building your compliance architecture.
Sanctions Screening and Transaction Monitoring: What Polish Regulators Examine
Sanctions compliance and ongoing transaction monitoring sit alongside KYC as the two pillars the GIIF and KNF examine most closely when they review a crypto firm's AML program. Polish obliged entities must screen all customers and counterparties against EU restrictive-measures lists (the EU sanctions regime applies directly in Poland) as well as United Nations consolidated lists. For businesses with US-dollar settlement rails or US-connected investors, OFAC screening is a practical necessity even though it is not formally a Polish-law obligation.
Transaction monitoring must be risk-based and documented. The GIIF does not prescribe a specific alert-generation tool, but supervisory guidance makes clear that a manual spreadsheet process is inadequate for any exchange or custody operation above minimal volumes. Operators we advise typically deploy a recognised on-chain analytics tool to flag wallet addresses associated with sanctioned entities, darknet markets, mixers and high-risk exchanges, and integrate those alerts into their case-management workflow.
A firm's internal risk appetite statement, its transaction-monitoring threshold rationale, and the documented outcomes of prior alert reviews are the three documents a GIIF examiner asks for first. Producing credible records on all three in a short timeframe — which is usually what the regulator allows — is only possible if the process was built and documented in advance.
Cross-Border Interaction: KYC, Banking and Tax in Poland
The tension between a solid KYC program and access to banking is sharper in Poland than in some Western European markets. Polish banks remain cautious toward crypto businesses, even those with clean regulatory status. In our experience, a business that can present its full compliance architecture — CDD policy, transaction-monitoring rationale, AML risk assessment, MLRO appointment and, ideally, a draft or confirmed regulatory status — is materially better placed to open and retain a PLN account than one that arrives with a Cayman registration and a verbal description of its controls.
The tax interaction is also worth mapping at the outset. Poland taxes crypto gains under its personal and corporate income tax regimes, and the reporting obligations that sit on a Polish-incorporated entity differ from those applicable to a foreign entity with Polish-resident clients. These obligations affect the data a business must collect at onboarding — for instance, Polish tax-residence status of the customer and the nature of the transaction (exchange, staking, lending) — making KYC and tax reporting architectures interdependent from day one.
For a business sitting between an EU licensing hub and the Polish market, the legal question turns on where each function is performed. If the Polish entity executes the customer onboarding, it carries the full Polish AML obligation; if the EU CASP entity onboards and the Polish entity merely introduces, the analysis differs. Structuring that boundary correctly before go-live is substantially cheaper than restructuring it after the first supervisory inquiry.
A Recent Onboarding Matter: Structuring Before Launch
In a recent onboarding engagement, a payments and exchange operator expanding from a Central European holding structure into the Polish market asked us to map its KYC architecture against Polish AML Act requirements. The operator's existing compliance program had been built for its home jurisdiction's lighter-touch VASP registration; it did not address GIIF-standard EDD triggers, PEP screening rationale or Travel Rule data fields. We identified three structural gaps in the CDD policy, rewrote the internal risk-assessment methodology to reflect the Polish regulatory standard, and advised on the MLRO appointment and reporting-line structure. The operator launched its Polish-market onboarding flow without a remediation notice from the GIIF. The engagement ran over a period of several weeks prior to go-live.
Internal Governance: MLRO, Records and Reporting Obligations
Every Polish obliged entity in the virtual-asset sector must appoint a designated compliance officer — functionally equivalent to the Money Laundering Reporting Officer (MLRO) model used in UK and common-law jurisdictions. The MLRO carries personal responsibility for the adequacy of the AML program, for filing suspicious activity reports (SARs) with the GIIF, and for ensuring that staff training is documented and current.
The MLRO need not be a licensed lawyer, but the role requires genuine senior authority within the business. A compliance function that sits below the CFO or COO and lacks the ability to pause onboarding or freeze a transaction pending investigation is unlikely to satisfy the GIIF's governance expectations. We have seen enforcement actions in analogous EU jurisdictions that turned specifically on whether the MLRO had the actual authority the governance chart claimed.
Record retention is a statutory obligation: CDD records, transaction records and internal investigation files must be held for a minimum period set by the AML Act (the exact period is set by legislation; confirm the current requirement with counsel). The records must be accessible to the GIIF on demand within a short response window — in practice, days rather than weeks.
CTA #2 — For the Operator Who Has Already Hit a Problem
If a prior application to a Polish or EU regulator stalled, or if a banking partner issued a termination notice citing compliance concerns, a structured second review of the AML program can surface the specific gap and map the route back. To discuss your situation, message us via t.me/oboluslaw.
Self-Assessment: Is Your KYC Program Poland-Ready?
Before an operator accepts its first Polish-resident client, the following elements should each be in place and documented:
- A written AML risk assessment that covers the specific products, customer segments and geographies the business operates — not a generic template.
- A CDD policy that distinguishes standard, simplified and enhanced procedures and specifies the triggers for each.
- A PEP screening process that uses a recognised commercial database and documents senior-management sign-off for PEP relationships.
- An MLRO formally appointed, with a documented reporting line and clear authority to pause onboarding or escalate to the GIIF.
- A transaction-monitoring ruleset calibrated to the business's product type, with documented alert-review records from a test or pre-launch period.
- Travel Rule data-collection fields built into the transfer-initiation flow, with a counterpart VASP onboarding questionnaire ready for B2B transfer relationships.
- Sanctions screening integrated into the onboarding flow and into the ongoing monitoring cycle, covering EU, UN and — where relevant — OFAC lists.
- A SAR process with clear internal escalation steps and a confirmed GIIF reporting channel.
A business that can produce a current, coherent version of each of these elements is in a fundamentally different regulatory position from one that cannot. The gap between the two is not primarily a technology gap; it is a governance and documentation gap.
Decision Matrix: Which Operator Profile Needs What?
Not every business faces the same priority order. The relevant variables are entity domicile, activity type and customer-base geography.
Profile A — EU-incorporated CASP (CASP authorisation held in Lithuania, Malta or Poland) passporting into Poland: The CASP-level AML program satisfies the baseline Polish obligation for regulated activities, but the operator must still apply Polish AML Act requirements for the Polish customer book. Priority: Travel Rule architecture, Polish-language SAR process, and a documented MLRO with authority over the Polish operational team.
Profile B — Non-EU entity (e.g. BVI, Cayman, UAE) with Polish-resident users: The operator is an obliged entity under the AML Act by virtue of activity alone. Priority: GIIF registration analysis, full CDD program build, and an assessment of whether the operating model requires a Polish legal presence to regularise the regulatory position. The risk of operating without addressing this is not theoretical — enforcement has followed similar fact patterns in other EU member states.
Profile C — Polish-incorporated start-up building toward CASP authorisation: Priority is to build the AML program in parallel with the CASP application file, not sequentially. KNF will review the AML governance as part of the authorisation assessment. A strong program submitted at the first application materially reduces back-and-forth review time.
In each profile, the interaction between the KYC architecture and the banking relationship is a live variable, not a downstream consideration. Banking due diligence by Polish correspondent banks effectively audits the compliance program before the regulator does.
Related at OBOLUS
- AML, KYC and Travel Rule practice overview – full-scope compliance advisory for digital-asset businesses across jurisdictions
- Sanctions screening for crypto: practical lessons for boards – board-level analysis of OFAC, EU and UN screening obligations
- Tax treatment of tokens for early-stage founders – how token classification affects reporting obligations at incorporation
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a virtual asset service provider (VASP) to collect and transmit identifying information about both the originator and the beneficiary of a virtual-asset transfer. The specific data fields include name, account identifier and, for transfers above applicable thresholds, address and identity-document reference. The obligation applies to transfers between institutional counterparties. Where the receiving entity is unhosted or operates outside a compliant jurisdiction, the sending VASP must apply additional risk-based measures before executing the transfer. Thresholds vary by jurisdiction and should be confirmed against current legislation.
Who must act as MLRO for a crypto firm?
A Polish-regulated crypto business must appoint a designated compliance officer — functionally the MLRO — who carries personal responsibility for the adequacy of the AML program, for filing suspicious-activity reports with the GIIF, and for staff training. The individual need not hold a legal qualification, but must have genuine senior authority within the business, including the practical power to pause onboarding or escalate a transaction for review. A nominal appointment without that authority is unlikely to satisfy regulatory scrutiny and has been a basis for enforcement action in comparable EU regimes.
How do regulators audit crypto AML programs?
The GIIF and KNF typically begin an audit of a crypto firm's AML program by requesting the written risk assessment, the CDD policy and a sample of recent alert-review records. Examiners look for consistency between the written program and the actual operational evidence — discrepancies between documented procedures and what the records show in practice are a primary finding. Remote document reviews are common; on-site examinations follow where initial findings suggest material deficiencies. Maintaining clean, dated and accessible records is therefore not a compliance formality but an operational necessity.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance architecture that sits around them. Digital assets are the whole of our practice. We map the licence, KYC and compliance stack across operating, custody and payment layers before a client commits, and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when it matters most. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst — specialising in AML/KYC program design and VASP regulatory compliance across EU and Central European jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.