• PL
  • EN
  • Proud Member of Alliott Global Alliance — Chambers Top Ranked Global 2023

    Legal compliance audit

    We check whether your company meets the rules that actually bind it — before a regulator, investor or auditor does. You get a conformity matrix, a list of gaps and a dated plan to close them.

    Home Services Legal Compliance Audit

    Compliance has stopped being a formality — it is now a dense web of binding rules with hard deadlines: GDPR, NIS2, AML, whistleblowing, KSeF, the AI Act, ESG. Each imposes concrete duties, and some carry real penalties and board accountability.

    A legal compliance audit checks whether your company meets exactly the rules that bind it — not "the law in general", but a named regime you are obliged to meet. We start with a requirements map and finish with a dated remediation roadmap: what, by when, and who.

    That is what sets a compliance audit apart from a preventive business legal health check, which you run on your own initiative, without a specific obligation.

    Legal position: August 2026. This material is for information only and is not legal advice.

    What we audit

    Scope and method

    When a compliance audit is required

    We tell you whether an audit is legally required or simply sensible. Many regimes impose substantive duties without mandating an external audit, but some — such as the security audit under NIS2 for essential entities — do. Other triggers include a regulator's inquiry, an investor's or counterparty's requirement tied to a named regime, an incident, or a rule entering into force.

    How we run the audit — from a requirements map to remediation

    We start with a requirements map: the named regime, the trigger, the entity, its role, the effective date and the evidence set. Then we build a requirement-by-requirement conformity matrix, classify the gaps by risk, and give you a dated remediation roadmap — not a general report, but a "what, by when, who" list.

    Data and digital obligations

    Data protection (GDPR)

    We audit GDPR compliance where there is a real trigger: a supervisory-authority inquiry, a breach, a high-risk DPIA, a transfer outside the EEA, or an investor/contract requirement. We check the lawful bases, processor agreements, records, data-subject rights and security — and flag the gaps that will bite first.

    Cybersecurity — NIS2 / the National Cybersecurity System Act

    We establish whether you are an essential or important entity (by Annexes I/II and size) and guide you through the deadlines: the NIS2-implementing act has been in force since 3 April 2026, registration is due by 3 October 2026, substantive duties by 3 April 2027, and the first statutory security audit (essential entities) by 3 April 2028. We check ICT risk management, incident reporting (24 h / 72 h) and board accountability.

    The AI Act and AI systems

    We map what applies to you and when: prohibited practices and the AI-literacy duty already apply, rules for general-purpose AI (GPAI) since August 2025, most other rules from 2 August 2026, and high-risk system obligations phasing in later (the exact date depends on the system category). The Polish Act on AI systems enters into force on 11 August 2026, with supervisory provisions from 28 October 2026.

    DORA — digital operational resilience

    For financial entities: DORA has applied since 17 January 2025. We audit ICT risk management, resilience testing, the register of third-party arrangements and incident reporting. We note that only designated critical third-party ICT providers fall under direct EU oversight — not every technology supplier.

    Finance and market integrity

    AML — anti-money-laundering

    For obliged institutions we audit the procedures: risk assessment, KYC, transaction monitoring and reporting. We verify filings and updates in the Central Register of Beneficial Owners (CRBR) — which in Poland, as of August 2026, remains public and freely accessible — and readiness for reporting via the SIGIIF system. The EU AML package is already adopted and AMLA is operating — full direct supervision comes later; we show what to prepare now.

    Sanctions and export controls

    We audit sanctions screening (EU and national lists), counterparty and source-of-funds checks. Separately we examine export controls and dual-use goods (Regulation 2021/821 and the Polish strategic-goods trade law) — a regime technology and manufacturing companies often overlook.

    Competition, State aid and the FSR

    Three distinct regimes we keep apart: antitrust compliance (prohibited agreements, abuse of dominance), State aid beneficiary compliance, and the FSR — the control of foreign subsidies, with notification duties in transactions and public procurement. We establish which one actually applies to you.

    KSeF and tax compliance

    Mandatory e-invoicing through the National e-Invoicing System (KSeF) phases in: the duty to receive invoices from 1 February 2026, and to issue them from 1 February 2026 for the largest taxpayers and 1 April 2026 for the rest, with a deferral for the smallest. We audit process and integration readiness; wider tax compliance we run within the scope you agree.

    People, products and ESG

    Whistleblower protection

    The Whistleblower Protection Act (of 14 June 2024, in force since 25 September 2024) requires a reporting channel for entities employing at least 50 persons performing paid work (counted on 1 January and 1 July); some entities (including financial and AML) are covered regardless of headcount. We audit the channel, the procedure and the register — because "paper" compliance does not protect.

    ESG/CSRD and product compliance (GPSR)

    We check the real scope of reporting duties: the CSRD-narrowing directive ultimately covers entities exceeding both 1,000 employees and EUR 450m turnover, and Poland applies a deadline postponement and an optional exemption for part of the first wave — we do not present CSRD as an obligation for everyone. For product and e-commerce businesses we audit GPSR (product safety — Reg. 2023/988; the Polish supervisory act applies from 3 January 2026).

    Who it is for

    • Essential and important entities (NIS2) — readiness for the statutory audit and the 2026–2028 deadlines.
    • Obliged institutions (AML) — procedures, CRBR, SIGIIF.
    • Companies processing sensitive or large-scale data — a GDPR audit before an inquiry or after a breach.
    • Product, e-commerce and export businesses — GPSR, export controls, sanctions.
    • Companies before a transaction or financing — compliance as an investor or lender condition.

    Frequently asked questions

    How is a compliance audit different from a business legal health check?

    A compliance audit checks you against a SPECIFIC binding rule (GDPR, NIS2, AML…), while a health check is a broad, preventive "own-initiative" review. Here the starting point is a named regime and a trigger — a regulator, an investor, a contract or an incident.

    If you want a general X-ray of the company with no specific obligation in play, the right service is the business legal health check. Here we focus on proving compliance with what actually binds you.

    When is a compliance audit legally required, and when just sensible?

    Most rules impose substantive duties without mandating an external audit — but there are exceptions, like the statutory security audit under NIS2 for essential entities. We draw that line at the outset.

    More often an audit is "sensible": forced by an inquiry, an investor's requirement, a contract or an approaching effective date. We tell you plainly which situation you are in.

    Does NIS2 apply to me and what are my deadlines?

    If you operate in a sector under Annexes I/II and exceed the size thresholds, you are probably an essential or important entity. The NIS2-implementing act has been in force since 3 April 2026.

    The next deadlines are registration by 3 October 2026, substantive duties by 3 April 2027, and the first statutory audit (essential entities) by 3 April 2028. We establish your classification and timetable.

    Who must have a whistleblower channel?

    Entities employing at least 50 persons performing paid work (counted on 1 January and 1 July) — and some sectors, including financial and AML, regardless of headcount. The Act has applied since 25 September 2024.

    The channel alone is not enough: we audit the procedure, the register, the deadlines and the reporter's protection, because "paper" compliance protects against neither a penalty nor a leak.

    What are the penalties for GDPR non-compliance?

    Administrative fines (in the most serious cases up to EUR 20m or 4% of worldwide turnover), individuals' claims and real reputational risk — most often all at once. The scale depends on the breach and your cooperation with the authority.

    An audit before an inquiry or right after a breach limits your exposure: we identify the gaps, prioritise, and give you a remediation plan to show the authority.

    Am I subject to CSRD?

    The ultimate scope after the narrowing covers entities exceeding both 1,000 employees and EUR 450m turnover — not every company. On top of that, Poland applies a deadline postponement and an optional exemption for part of the first wave.

    We check your status against the current transposition and tell you whether you report mandatorily, voluntarily, or not yet at all.

    What is the AI Act and when does it apply to me?

    AI Act obligations phase in over several years, and which of them bind you — and from when — depends on your role and the type of AI system you use. Prohibited practices and the AI-literacy duty already apply; GPAI rules since August 2025; most other rules from 2 August 2026; high-risk system obligations phase in later (the date depends on the system category).

    The Polish Act on AI systems enters into force on 11 August 2026, with supervisory provisions from 28 October 2026. We establish which obligations and deadlines are yours.

    KSeF — from when must I issue e-invoices?

    Receiving invoices via KSeF is mandatory from 1 February 2026, and issuing them from 1 February 2026 for the largest taxpayers and 1 April 2026 for the rest, with a deferral for the smallest. The date turns on your turnover.

    We audit the readiness of your processes, integration and authorisations, and flag what to close before your cut-off date.

    What is the CRBR and is it public?

    The CRBR is the Central Register of Beneficial Owners — in Poland, as of August 2026, it remains public and freely accessible. The duty to file and update it applies to, among others, companies.

    We check the entry's accuracy and currency — an error in the ownership structure can block financing, a transaction or a banking relationship.

    What do I get at the end of the audit?

    A requirement-by-requirement conformity matrix, a gap classification by risk, and a dated remediation roadmap — not a general report. You see exactly what is compliant, what is not, how serious it is, and by when it must be fixed.

    It is a document you can show the board, an investor or a regulator — and one that actually drives the work after the audit.

    Does the audit include implementing the recommendations?

    Yes, if you want it — the audit is stage one, remediation is stage two. We can run the implementation: procedures, contracts, the whistleblower channel, registers, integrations.

    We agree the scope of remediation after the audit, once you know the gaps and priorities. We do not sell a fix blind, before the diagnosis.

    One-off audit or recurring?

    Some regimes impose a statutory cycle (e.g. NIS2), while others call for a repeat only on licence renewal, a material change in the law, an incident or a regulator's direction. We do not propose "monitoring just in case".

    We set a realistic cycle for your regimes — where the law or a contract requires it.

    Do you only audit large companies?

    No — we match the scope to your size and to the regimes that actually bind you. A small company with one critical duty (say AML or NIS2) gets a narrow, targeted audit; a large one gets a full matrix across many regimes.

    We always start from a requirements map, so we do not audit what does not apply to you.

    Our experts

    The team that will run your compliance audit — from a requirements map, through the conformity matrix, to a dated remediation roadmap.

    Michał Wołoszański

    Michał Wołoszański

    Founder & Managing Partner,
    INSEAD Global Executive MBA, Attorney-at-law

    Michał oversees the firm's key transactions — from deal structure and negotiation to risk and contracts.

    Contact MichałClick the card for the full profile ›
    Łukasz Kudela

    Łukasz Kudela

    Senior Associate, Attorney-at-law,
    Cryptocurrency Project Manager

    Łukasz combines company law, competition and AML compliance — reviewing structure, transaction clearances and the target's regulatory risks.

    Contact ŁukaszClick the card for the full profile ›
    Kinga Miller

    Kinga Miller

    Partner, Advocate,
    Approved Compliance Expert, Approved ESG Officer

    Kinga reviews the target's regulatory and litigation risks — those that really affect price and the contract.

    Contact KingaClick the card for the full profile ›
    Karolina Dębiec

    Karolina Dębiec

    Lawyer,
    Key Projects Coordinator

    Karolina runs the corporate review and company law — title to shares, ownership governance and the target's structure.

    Contact KarolinaClick the card for the full profile ›

    Let's check your compliance

    Tell us which regime applies to you or what is driving the audit (an inquiry, an investor, a deadline) — we will map the scope and the next step.

    Contact us