• PL
  • EN
  • Proud Member of Alliott Global Alliance — Chambers Top Ranked Global 2023

    Business Legal Health Check

    We review your whole company for legal risk before it turns into a fine, a lost dispute or a blocked deal — preventively, internally and under statutory professional secrecy.

    Home Services Business Legal Health Check

    A business legal health check is a cross-cutting review of your whole company — contracts, ownership structure, corporate governance, employment, data, intellectual property and solvency — that shows where legal risk is ticking before it turns into a fine, a lost dispute or a blocked deal.

    You run it for yourself, preventively — not for a specific transaction and not for the other side. That is what sets it apart from legal due diligence, which the other side of a transaction — a buyer, investor or lender — runs on your company for a given deal. The whole engagement is covered by statutory professional secrecy (that of an advocate and an attorney-at-law), so even the uncomfortable findings stay between you and us.

    2025 and 2026 brought an unusual wave of change: KSeF e-invoicing became mandatory, the AI Act entered its enforceable phase, NIS2 arrived in Polish law, and the data-protection authority moved from warnings to record fines. Documents from two years ago rarely match the current law — we check that before an authority or a counterparty does.

    What we check

    Obligations that have just come into force

    KSeF — e-invoicing that already applies

    Since February and April 2026, invoices in scope are as a rule issued through the National e-Invoicing System (KSeF); in online mode the issue date is the date they are sent to the system, while offline modes follow separate rules. We check whether your contracts, document flow and KSeF permissions are ready — before administrative penalties of up to 100% of the invoice VAT start in 2027.

    Whistleblowing — a procedure whose absence is already penalised

    If 50 or more people work for your company (or, under anti-money-laundering duties, any number), you must have a working internal reporting procedure and a ban on retaliation against whistleblowers. We check whether your procedure actually works or just sits in a binder — the duty has applied since September 2024.

    AI and data protection

    The AI Act — count where you actually use AI

    The EU Artificial Intelligence Act already prohibits some AI uses and requires staff competence (AI literacy) and — depending on your role and the system — specific transparency duties, such as telling people they are interacting with AI. We inventory the AI tools across your company — in recruitment, customer service, marketing — and map your duties before the high-risk regimes come in.

    GDPR after years of leniency

    The Polish data-protection authority has moved from reprimands to fines in the tens of millions of złoty. We verify your legal bases, data-processing agreements, breach procedure (72 hours) and marketing consents, so a gap does not surface at an inspection.

    Cybersecurity and corporate governance

    NIS2 — are you an essential or important entity?

    The amendment to the Act on the National Cybersecurity System (the KSC Act) has applied since April 2026 and covers far more companies, with the deadline to self-identify and register on the list falling on 3 October 2026. We establish whether you are in scope and what the board — which is personally accountable for this — must put in place.

    Corporate governance — who can actually sign for the company

    The most common silent defect is an expired board mandate — after the 2022 Commercial Companies Code amendment, terms of office are counted differently than many old articles of association assume. We check mandates, representation rules, commercial proxy and the validity of resolutions, so your contracts are not signed by someone without authority.

    Group structure and contract portfolio

    Company groups and intra-group transactions

    In holding structures the risk sits in the contracts between companies, personal links across their boards and the absence of a shareholders' agreement. We tidy up group membership, the documentation of related-party transactions and the rules on binding instructions, so neither the tax authority nor a shareholder can challenge them later.

    Contract portfolio — where the clause-bombs are ticking

    Automatic renewals, a counterparty's unilateral right to terminate, uncapped contractual penalties, no indexation clause in multi-year contracts and change-of-control clauses can cost more than many a dispute. We review your key contracts and point out what to renegotiate before a clause goes off.

    Team and intellectual property

    Employment law — B2B, work-life balance and PPK

    Bogus self-employment (a B2B or mandate contract instead of an employment one) is one of today's costliest risks — reclassification means back-dated social-security contributions, leave and interest. We check the reality of the working relationship, and along the way the work-life balance package, remote work, sobriety checks and PPK auto-enrolment (the next one in 2027).

    Intellectual property — whether it is really yours

    Code, designs and content from B2B contractors are yours only if there is a written contract naming the fields of exploitation — without it the transfer of rights is void and the work stays with its author. We check IP contracts, trademarks and domains before you run into an investor, a buyer or a former collaborator.

    Solvency and litigation exposure

    Solvency and the board's personal liability

    A bankruptcy petition must be filed within 30 days of the grounds arising — missing that deadline can lead to personal liability of the board members for the company's debts, subject to the conditions and exculpation defences set out in the statutes. We build early warning and a record of board decisions that protects the people, not just the company, if a dispute comes.

    Limitation and disputes — don't give money away by the calendar

    Claims connected with business activity generally become time-barred after 3 years — a missed deadline hands your counterparty a defence. We map limitation periods, the state of disputed matters and the quality of your standard terms, because a single error in the general terms repeats across hundreds of contracts.

    ESG and the tax interface

    ESG and CSRD after the Omnibus package — what really applies to you

    Sustainability-reporting thresholds have risen sharply and the obligation for 2025–2026 has disappeared for most companies — but larger clients can still demand ESG data by contract. We establish whether you report at all, and protect you from greenwashing and from over-reporting just in case.

    The legal-tax interface — the white list and split payment

    A payment on a transaction worth over PLN 15,000 to an account outside the VAT white list can strip a tax-deductible cost and trigger joint liability for your counterparty's VAT. We verify payment procedures, mandatory split payment and due-diligence documentation — from the legal side, not tax advice.

    For whom

    • Limited liability companies and joint-stock companies — that want to know where the risk really sits before it surfaces.
    • Capital groups and holdings — with intra-group transactions and several corporate bodies to keep in order.
    • Companies before an investor, a round or a sale — to pass someone else's due diligence faster and reduce the grounds for price adjustments.
    • Companies after a major change in the law — KSeF, the AI Act, NIS2 — whose documents need updating.
    • Boards protecting themselves from personal liability — for solvency, representation and regulatory duties.

    Why WLAW

    We don't audit a single regime — we look across the board: corporate governance, contracts, employment, data, intellectual property, solvency and regulatory duties at once, because risk rarely sits where you expect it. The whole engagement is covered by statutory professional secrecy, so we can call things by their name. We track legal change for you and, instead of an academic treatise, give you a decision-ready report — a list of risks ranked by weight, with a concrete recommendation and legal basis for each point.

    How we work

    1

    Scope and quote

    we agree the scope in a short conversation and give a fixed price and timeline up front.

    2

    Gathering documents

    we point to a concise list of materials you already have — contracts, resolutions, registers.

    3

    Cross-cutting analysis

    we review every area at once and look for risks that don't show up on the balance sheet.

    4

    Report by priority

    you get a list of risks ranked by weight, with a recommendation for each point.

    5

    Discussion and remedy

    we discuss the report with the board and, if you wish, lead the remedy of the top items.

    Legal landscape

    Recent months have reshaped companies' obligations sharply. We track them for you:

    • KSeF — e-invoicing is mandatory from 1 February 2026 (large firms) and 1 April 2026 (most others); the smallest taxpayers only from 1 January 2027; administrative penalties from 2027.
    • Whistleblowing — the internal reporting procedure and the ban on retaliation have applied since 25 September 2024.
    • The AI Act — the prohibitions and the AI-literacy duty have applied since 2025, and the transparency duties since 2 August 2026.
    • NIS2 — the amendment to the Act on the National Cybersecurity System (the KSC Act) has applied since 3 April 2026; the deadline to self-identify and register on the list falls on 3 October 2026.
    • ESG / CSRD — the Omnibus package reversed direction: thresholds rose and the reporting duty for 2025–2026 disappeared for most companies.
    • Bogus B2B — reclassifying a B2B contract as employment (the Labour Code's employment-relationship test) is a real, costly risk.

    Legal position: August 2026.

    Frequently asked questions

    How long does it take and how much does it cost?

    The scope and price depend on the size of the company and the number of areas reviewed, so we start with a short scoping conversation and give a fixed price and timeline up front. We don't start work until you know what you'll get and when.

    We run the health check in a few stages — gathering documents, analysis, report, discussion — so you have a clear schedule and a predictable cost from the outset, with no open-ended hourly meter.

    How does this differ from a financial audit?

    A financial audit examines whether the financial statements fairly reflect the numbers; a legal health check examines whether the company's contracts, structure and procedures hide legal risks that the balance sheet does not show. They are two different views of the same company.

    An accountant or auditor will tell you how much you owe. We show which contract, resolution or missing procedure could suddenly increase those liabilities — an uncapped contractual penalty, say, or an expired board mandate.

    What exactly do we get at the end?

    You get a written report with a list of risks ranked by weight — what to extinguish immediately, what to plan for — with a concrete recommendation and legal basis for each point. We then discuss it with the board in person.

    It is a decision document, not an academic treatise. Each item says plainly what to do and how urgent it is, so the board can make a decision rather than wade through legal reasoning.

    How often should this be repeated?

    As a rule once a year as a periodic review, and additionally on any event that changes the risk: before a sale or an investor coming in, on a reorganisation, after a major change in the law, and on entering new markets.

    The law and your contract portfolio change constantly — and 2025–2026 brought unusually many changes — so a one-off review quickly goes out of date. A regular review keeps the risk picture current.

    Is this covered by privilege?

    Yes — working with the firm is covered by statutory professional secrecy (that of an advocate and an attorney-at-law), so the findings, including the uncomfortable ones, stay between you and us.

    That is an important difference from audits run by parties without that privilege. It lets us name the risks plainly, without the worry that the report will turn against you.

    Will you dig around the company and get in the way of work?

    No — we work mainly on documents you already have (contracts, resolutions, terms, registers), and keep conversations to a few key people.

    We point to a concise list of the materials we need, to take as much off your team as possible. The health check is meant to lift risk off you, not add work.

    You'll find problems — what then?

    We don't leave you with an unmanageable list — the report is ordered by priority and feasibility, and each risk comes with a recommendation and a proposed next step.

    We separate plainly what you can do yourselves from what is worth outsourcing. We can also lead the remedy of the most important points — but the decision and the pace are yours.

    How does this differ from transactional due diligence?

    Due diligence is done for a specific transaction — a buyer, an investor, a lender or a seller (vendor DD) can commission it; a legal health check you do for yourself, preventively, with no transaction in play, to find and fix risks before someone finds them for you.

    A company that regularly checks its own health passes someone else's due diligence far faster and reduces the grounds for price adjustments or extra contractual protections. They are two sides of the same coin — the same review, at a different moment and in your own interest.

    Our company is small — isn't this overkill?

    On the contrary — in a smaller company a single error (no IP contract with a contractor, an expired mandate, bogus B2B) can decide the whole business, because there is no legal department to catch it.

    We scale the health check to the size of the company: a smaller firm means a narrower scope and a lower cost, but the same critical points. The aim is to stop a small gap growing into a problem that halts the whole business.

    Which risks are the hottest right now?

    The freshest and most often neglected are KSeF (already in force), the whistleblowing procedure, the AI inventory under the AI Act, NIS2 duties (deadline 3 October 2026) and bogus B2B.

    These are areas where the law changed in the last 12–24 months, so documents from two years ago may be out of date. We tend to start there, because that is where the risk is most real.

    Do you handle tax as well?

    We examine the legal-structural interface with tax — the VAT white list, split payment, related-party documentation, the consistency of contracts — but we do not replace a tax adviser or an accounting office.

    Where needed, we point out what to consult on the tax side. The aim is that the legal structure does not generate risks that only hit at settlement.

    How will we know it was worth it?

    The measure is a list of concrete risks removed before they became a cost — a fine, a lost dispute, a lost tax deduction or a blocked transaction.

    The report shows plainly where the company was exposed and how far we reduced that exposure. We don't promise specific savings in złoty — we promise less risk that could catch you off guard.

    Our experts

    The team that will review your company and order its risks — compliance, data, company law and solvency.

    Michał Wołoszański

    Michał Wołoszański

    Founder & Managing Partner,
    INSEAD Global Executive MBA, Attorney-at-law

    Michał oversees the firm's key matters — from strategy and structure to regulatory risk and disputes.

    Contact MichałClick the card for the full profile ›
    Marta Solarska-Kaleńczuk

    Marta Solarska-Kaleńczuk

    Partner, Chief Operating Officer,
    Data Protection Officer

    Marta leads data protection and new technologies — GDPR, documentation and the compliance of company processes.

    Contact MartaClick the card for the full profile ›
    Kinga Miller

    Kinga Miller

    Partner, Advocate,
    Approved Compliance Expert, Approved ESG Officer

    Kinga runs compliance and ESG — conformity audits, procedures and a company's regulatory risk.

    Contact KingaClick the card for the full profile ›
    Łukasz Kudela

    Łukasz Kudela

    Senior Associate, Attorney-at-law,
    Cryptocurrency Project Manager

    Łukasz combines company law, competition and AML compliance — ordering structure and regulatory risk.

    Contact ŁukaszClick the card for the full profile ›

    See where the risk is ticking — before someone else does

    Tell us how large the company is and what worries you — we'll define the scope of the check and give a fixed quote.

    Book a legal health check