• PL
  • EN
  • Proud Member of Alliott Global Alliance — Chambers Top Ranked Global 2023
    Expert Anti Money Laundering (AML) Legal Services

    AML and Sanctions Legal Services

    We guide companies through AML obligations and international sanctions — from assessing whether you are an obliged institution, through procedures and counterparty screening, to GIIF reporting and defence in proceedings.

    Home Services AML and Sanctions Legal Services

    We advise companies for which one missed AML signal or one unchecked counterparty is not a formality but a real risk of a fine and a lost bank account. We serve banks, payment institutions, investment firms, accounting offices, law firms, real-estate agents, crypto companies and exporters — everyone the law calls an obliged institution or exposes to sanctions risk.

    We don't leave you alone with the statute. We translate complex regulation into plain language, build procedures you can actually implement, and pick up the phone when you must decide fast: report the transaction or not, onboard the counterparty or freeze the payment.

    We track the law where it moves fastest: the EU AML package and AMLA, sanctions against Russia and Belarus, the criminalisation of sanctions breaches, and AML in crypto — MiCA, the CASP licence and the travel rule. We tell you what actually affects your business this year.

    What we do

    Foundation — obligation and risk

    Obliged-institution status assessment

    We start with a question many firms answer wrongly: are you an obliged institution at all? We test your business model against the AML Act's catalogue and tell you plainly which duties apply — before an inspection does it for us.

    Risk assessment and internal policies (Art. 27 and Art. 50)

    We prepare your institutional risk assessment and an internal AML procedure fitted to your structure, clients and sector — not an off-the-shelf template. The document sets out concrete steps, who owns what, and how to act when a red flag lights up.

    Due diligence and beneficial ownership

    KYC and customer due diligence (CDD/EDD)

    We build your know-your-customer process and the application of financial-security measures: standard (CDD — customer due diligence) and enhanced for higher-risk clients (EDD — enhanced due diligence). We set it so it protects the firm without paralysing sales.

    Beneficial owner (UBO) and CRBR

    We establish who really controls your client or your company — the ultimate beneficial owner (UBO) — generally a person above 25% of shares or votes, or who otherwise exercises control. We file the data to the Central Register of Beneficial Owners (CRBR) and keep in mind the trap that's easy to miss: the CRBR entry alone is not enough — you must verify it yourself.

    Monitoring, reporting and payments

    Transaction monitoring and GIIF reporting (SAR/STR)

    We set your rules for monitoring transactions and deciding what to report to GIIF (the General Inspector of Financial Information) and when — from above-threshold reports for defined transaction categories over EUR 15,000 to suspicious-transaction reports (SAR/STR), which apply regardless of amount. We train the team to spot signals and document the decision to report — or not.

    Payments, correspondent banking and cash limits

    We advise payment institutions and high-volume businesses: correspondent relationships, cross-border payments, high geographic risk and the incoming EU cash limits. We design the process so compliance does not clog the flow of money.

    International sanctions

    Sanctions screening — EU, UN, OFAC

    We check counterparties, owners and transactions against sanctions lists: the EU Consolidated List, UN lists and the US OFAC lists. We examine ownership structure, because sanctions also reach controlled entities — in the US (OFAC) generally from aggregate ownership of 50% or more, and in the EU from ownership above 50% or, separately, from control — so a company can be caught without a majority stake.

    Sanctions advisory, freezing and authorisations (derogations)

    We advise what to do when a counterparty or funds fall under sanctions: freezing assets, the ban on making funds available, reporting to the competent authority and — where the law allows — applying for an authorisation to release funds (a derogation). We walk you through the decision step by step, before a costly mistake.

    Crypto and new regulation

    AML in crypto — MiCA, the CASP licence and the travel rule

    We guide crypto-asset firms through the MiCA regime: the move from the VASP register to the CASP (crypto-asset service provider) licence, AML duties and the travel rule — the requirement that originator and beneficiary data travel with every transfer, with no de-minimis threshold.

    Readiness for the EU AML package and AMLA

    We prepare the firm for the incoming single AML rulebook: the AMLR regulation and the new EU supervisor AMLA, seated in Frankfurt. We run a gap analysis and an adaptation plan, so the change doesn't catch you on the home straight.

    Audit, training and proceedings

    AML audits and training

    We check whether your procedures, documents and due-diligence measures actually work — the audit ends with a report on your level of compliance and a list of recommendations. We train the board, the AML Officer and staff, because the best procedure fails if the team doesn't know when to trigger it.

    Proceedings, inspections and penalties

    We represent you in inspections and proceedings — before GIIF, the Head of the National Revenue Administration (KAS) and the courts. We defend in AML administrative-penalty cases (reaching millions of euro) and in sanctions-breach cases, and help fix compliance before a penalty becomes final.

    For whom

    • Banks, payment institutions and investment firms — the full AML regime, monitoring, screening, AMLA readiness.
    • Crypto-asset firms (VASP/CASP) — MiCA, the CASP licence, the travel rule, AML procedures.
    • Accounting offices, law firms, notaries, real-estate agents — obliged-institution status, procedures, CRBR.
    • Exporters, importers and trading companies — sanctions screening, counterparty checks, freezing and derogations.
    • Boards and AML Officers — ongoing support, training, defence in proceedings.

    Why WLAW

    We combine two things that rarely go together: an AML practice and a sanctions practice, in one team — alongside our compliance and ESG practice. Kinga Miller runs compliance as an advocate and Approved Compliance Expert, Łukasz Kudela handles AML and crypto-asset firms as an attorney-at-law, and Michał Wołoszański ties it together as Managing Partner.

    You don't get a lecture on the statute — you get a procedure you can implement and a phone we answer when a decision can't wait an hour.

    Legal landscape 2026

    AML and sanctions law is changing faster than ever in 2025–2026. We track it for you:

    • EU AML package — the AMLR regulation applies from 10 July 2027; the AMLA supervisor (Frankfurt) is already operating, with direct supervision of up to 40 selected high-risk cross-border groups from 1 January 2028.
    • EUR 10,000 cash limit — incoming with the AMLR (from 10 July 2027); identification for occasional cash transactions already from EUR 3,000.
    • Polish AML rules — changes from 1 September 2025 (the CRBR is no longer public — access now on AML-Act terms — and beneficial-owner verification is tighter).
    • Sanctions against Russia and Belarus — successive EU packages (the 21st adopted in July 2026, with parallel Belarus measures) and the Polish MSWiA list; fines by the Head of KAS up to PLN 20 million.
    • Criminalisation of sanctions breaches — Directive (EU) 2024/1226 sets EU-wide minimums (up to 5 years for the most serious offences; corporate fines up to EUR 40 million / 5% of turnover, with lower tiers for others) — Poland missed the 20 May 2025 deadline and the implementing act is still in the legislative process (as of August 2026).
    • Crypto — MiCA and the travel rule (in force since 30 December 2024); Poland's CASP act is not yet in force (as of August 2026), so the KNF cannot yet license CASPs and VASPs face wind-down pressure.

    Legal position: August 2026.

    Frequently asked questions

    Is my company an obliged institution?

    An obliged institution is an entity the AML Act names expressly — including a bank, payment institution, investment firm, crypto-asset firm, accounting office, notary, real-estate agent or dealer in luxury goods above a cash threshold. If you are on that list, you have duties: a risk assessment, procedures, KYC and GIIF reporting.

    The problem is that many firms don't realise they fall under it — or wrongly assume they don't. It's the first question we ask, and the first an inspection will ask.

    We test your business model against the Act's catalogue and say plainly whether you are covered and, if so, where to start.

    Which transactions must I report to GIIF, and when?

    You report two things: above-threshold transactions over the equivalent of EUR 15,000, and every suspicious transaction (SAR/STR), regardless of amount. Above-threshold transactions are reported within the statutory deadline; suspicious ones without undue delay, once a reasonable suspicion of money laundering or terrorist financing arises.

    What matters is not the amount alone but the signals: an unusual pattern, an unclear source of funds, haste, structured payments. It's a judgement, not an automation.

    We set the monitoring rules and train the team to document the decision — including a decision not to report, which is also reviewed.

    Who is the beneficial owner and what is the CRBR for?

    The beneficial owner (UBO) is the natural person who really controls a client or a company — generally holding above 25% of shares or votes, or exercising control in another way. UBO data is filed to the Central Register of Beneficial Owners (CRBR).

    There's a trap: as an obliged institution you cannot rely on the CRBR entry alone. You must establish and verify the UBO yourself, because the liability for a mistake is yours, not the register's.

    We establish ownership structure — including for foreign and multi-level companies — and tidy up the CRBR filings.

    What's the difference between CDD and EDD, and when do enhanced measures apply?

    You apply CDD (standard due diligence) to every client; EDD (enhanced) when risk is elevated: a high-risk client, links to a tax haven, a PEP (politically exposed person) or an unusual transaction. EDD means a deeper check of the source of wealth and funds and closer monitoring.

    There's a risk the other way too: over-checking where it isn't needed chokes sales and deters good clients.

    We calibrate the process to real risk — so it protects the firm rather than blocking it at every step.

    What are the penalties for breaching AML rules?

    Administrative fines reach millions of euro — generally up to twice the benefit or up to EUR 1,000,000, and for certain institutions up to EUR 5,000,000 or 10% of annual turnover; in extreme cases criminal liability follows. GIIF imposes the fine, and breaches also engage Art. 299 of the Criminal Code (money laundering).

    The risk is not only money: losing your bank account, licence and reputation can hurt more than the fine itself.

    We defend in proceedings and, more importantly, help fix compliance before an inspection turns to it.

    Who is AMLA and what does the EU AML package change?

    AMLA is the new EU anti-money-laundering authority, seated in Frankfurt, which — together with the AMLR regulation — harmonises AML rules across the EU. As a regulation, the AMLR applies directly: the same text binds firms in every Member State, with no national transposition.

    AMLA is already operating; direct supervision of the largest cross-border groups starts on 1 January 2028, and full application of the AMLR on 10 July 2027. This is not a tomorrow problem, but the preparation starts today.

    We run a gap analysis and an adaptation plan so the new rulebook doesn't take you by surprise.

    How do I screen a counterparty for sanctions?

    Screening means checking a counterparty, its owners and transactions against sanctions lists: the EU Consolidated List, UN lists and the US OFAC lists. Checking the name on the invoice is not enough — sanctions also reach entities controlled by listed persons, in the US (OFAC) generally from aggregate ownership of 50% or more, and in the EU from ownership above 50% or, separately, from control — so a company can be caught without a majority stake.

    Lists change often, so a one-off check offers no protection — you need a process and repeated screening.

    We set the verification rules, examine ownership structure and flag when a transaction is better not done.

    What are the penalties for breaching sanctions in Poland?

    A sanctions breach in Poland carries an administrative fine imposed by the Head of KAS — up to PLN 20,000,000 — and at EU level Directive (EU) 2024/1226 introduces criminal liability: up to 5 years' imprisonment, and for companies fines up to EUR 40 million or 5% of worldwide turnover. A breach includes making funds available to a listed person or circumventing a freeze.

    The risk is real: the National Revenue Administration has already imposed a PLN 20 million fine for a sanctions breach.

    We advise how to build a control that catches the risk before it becomes a proceeding.

    A counterparty or funds fell under sanctions — what do I do?

    When a counterparty or funds are subject to sanctions, you generally must freeze the assets, stop making funds available and report the matter to the competent authority — not wait it out and process the payment. Breaching the ban, even unintentionally, creates liability.

    In some situations the law allows you to apply for an authorisation to release funds (a derogation) — e.g. for wages, pre-sanctions contracts or basic costs. That's an exception, not a rule, and it requires an application.

    We walk you through the decision — freeze, report, or apply for an authorisation — and prepare the documents.

    What is the travel rule for crypto?

    The travel rule requires that, with every crypto-asset transfer, the originator's and beneficiary's data travel with the transfer — for crypto transfers with no de-minimis threshold at all. It stems from the EU Transfer of Funds Regulation (Regulation (EU) 2023/1113) and has applied since 30 December 2024.

    For a crypto-asset firm this means concrete infrastructure: collecting, verifying and passing on the parties' data, plus a procedure for incomplete transfers.

    We build the travel-rule compliance process and plug it into the wider AML regime and MiCA.

    Does my crypto firm need a CASP licence?

    If you provide crypto-asset services in the EU, you need a CASP (crypto-asset service provider) licence under the MiCA regime, which has replaced the former VASP register. MiCA provided a transitional period for firms operating before 30 December 2024, but it is already ending — today the key step is establishing your current status.

    A CASP licence is not just a form: it's AML procedures, the travel rule, capital requirements and KNF supervision.

    We guide crypto-asset firms through the licensing process and build the compliance the supervisor expects — not a paper minimum.

    What does an AML audit look like, and how do I prepare for an inspection?

    An AML audit checks whether your risk assessment, procedures, KYC and reporting actually work — it ends with a report on your level of compliance and a list of recommendations. It's the cheapest moment to find a gap: before an inspection, not during one.

    An inspection looks not only at documents but at whether the team knows when to report a transaction and how to document the decision.

    We run the audit, close the gaps and prepare the firm and the AML Officer for the conversation with the authority — calmly, with the paperwork in order.

    Our experts

    A real team runs our AML and sanctions practice — meet the people who will handle your matter.

    Kinga Miller

    Kinga Miller

    Partner, Advocate, Approved Compliance Expert, Approved ESG Officer

    Leads the compliance and AML practice — from risk assessment to defence in proceedings.

    Contact KingaClick the card to see the full profile ›
    Łukasz Kudela

    Łukasz Kudela

    Senior Associate | Attorney-at-Law | Approved AML & Sanctions Officer | Cryptocurrency Project Manager

    Handles AML and crypto-asset firms — MiCA, the CASP licence and the travel rule.

    Contact ŁukaszClick the card to see the full profile ›
    Michał Wołoszański

    Michał Wołoszański

    Managing Partner,
    INSEAD Global Executive MBA, Attorney-at-law

    Ties the AML and sanctions practice together with the client's business perspective.

    Contact MichałClick the card to see the full profile ›

    Let's talk about AML and sanctions

    Facing an inspection, a doubt, or a counterparty that fell under sanctions? Tell us where you are — we'll flag the risks and the next step.

    Contact us