SteersBiuro Rachunkowe
← Back to home page

Counteracting money laundering (AML)

The accounting office is an obliged institution within the meaning of the Act on Counteracting Money Laundering and Terrorist Financing. We explain what this means in practice for clients and partners.

Last updated: 08.09.2026

1. Why this document exists

This is information for the office's clients and partners — it is not the text of our internal AML procedure. We describe what questions and documents to expect at the start of cooperation and during it, and why we cannot dispense with them.

The internal procedure, the risk assessment and the documentation of its application are confidential. We disclose them only to authorities entitled to them under the law.

3. Internal procedure and organisation

  • The office has an implemented internal procedure for an obliged institution, covering the rules for applying financial security measures, risk assessment, retaining documentation and reporting.
  • A member of senior management has been designated as responsible for fulfilling the statutory obligations, together with an employee responsible for the day-to-day application of the procedure and contact with GIIF.
  • We review the procedure at least once a year and each time after a material change in the law or in the office's business profile.
  • A restricted-access rule applies: AML documentation is available only to people who need it to perform their duties.

4. Risk assessment

We prepare and update the office's risk assessment and assess the risk of every business relationship. The assessment determines the scope and frequency of the financial security measures applied.

  • The type of client and its ownership structure, including the presence of foreign entities and multi-tier structures.
  • The geographical area of operation and links to high-risk third countries.
  • The type of products and services offered and their distribution channel, including the share of cash turnover — significant in the HoReCa sector.
  • The value and nature of transactions, unusual settlement patterns, transactions without economic justification.
  • The result of the assessment translates into standard, simplified or enhanced measures; we inform a client about the application of enhanced measures during onboarding.

5. Financial security measures

We apply financial security measures before entering into a business relationship, and then throughout the cooperation — periodically, and always when circumstances change or doubts arise about the data we hold.

  • Identification of the client and verification of its identity based on documents and data from public registers.
  • Identification and verification of the beneficial owner, establishing the ownership and control structure, including comparison with the entry in the Central Register of Beneficial Owners (CRBR) and clarifying any discrepancies.
  • Establishing whether the client, the beneficial owner or the person representing it is a politically exposed person (PEP), a family member of such a person, or a person known to be a close associate — based on a statement made under pain of criminal liability.
  • Assessing the purpose and intended nature of the business relationship.
  • Ongoing monitoring of the business relationship, including examining transactions for consistency with our knowledge of the client and its business profile, and establishing the source of wealth where the risk level requires it.
  • Checking the client and related persons against sanctions lists — EU, national, and those arising from the act on special measures to counteract support for aggression against Ukraine.

6. Documents at onboarding

At the start of cooperation we ask for a full set of information allowing us to fulfil our statutory obligations. The scope depends on the legal form and the risk assessment; below is a typical set.

  • The entity's registration data: name, legal form, registered address, NIP, REGON, KRS number or CEIDG entry.
  • An identity document of the people representing the entity, and a power of attorney if the agreement is signed by an attorney.
  • Information about the ownership structure and beneficial owners: first and last name, citizenship, country of residence, PESEL number or date of birth, the size and nature of their share or entitlements.
  • A PEP-status statement for the client, the beneficial owner and the people representing them.
  • Information about the scope and scale of the business, its main markets, forms of settlement and the share of cash.
  • For foreign entities — registration documents from the country of their registered office, together with a translation where needed.
  • An update of the above data with every material change, in particular a change of partners, management or business profile.

7. When we cannot apply security measures

If we are unable to apply financial security measures — for example we do not receive data on the beneficial owner, or the information provided raises reasonable doubts — the Act requires us not to enter into the business relationship, not to carry out the transaction, or to terminate a relationship already entered into.

In that case we also consider whether there are grounds to report the matter to the General Inspector of Financial Information. This is not a judgment on the client's reliability — it is a statutory obligation we cannot depart from.

8. Reporting to GIIF and the prohibition on disclosure

  • We pass on to the General Inspector of Financial Information information about circumstances that may indicate a suspicion of money laundering or terrorist financing, as well as about transactions subject to a reporting obligation.
  • We submit a notification of suspicion without delay, and in the cases indicated in the Act we suspend the transaction or block the account on the terms set out in the law.
  • A statutory prohibition on disclosure (tipping-off) applies: we do not inform the client or third parties that information has been passed to GIIF, that an analysis is underway, or about proceedings in the matter.
  • Passing on information in accordance with the Act does not constitute a breach of professional secrecy or of any confidentiality obligation arising from a contract.

9. Retention of documentation

We retain documents and information obtained as a result of applying financial security measures, together with evidence confirming transactions carried out, for 5 years, counted from the first day of the year following the year in which the business relationship with the client ended or an occasional transaction was carried out.

The General Inspector of Financial Information may demand that this period be extended by a further 5 years. After the period expires, we delete the documentation, unless its further retention is required by other provisions.

10. Training and internal control

  • Employees and associates performing duties related to counteracting money laundering take part in training programmes, repeated periodically and after material changes in the law.
  • We conduct documented internal control of how the procedure is applied and draw conclusions from it that update the procedure and the risk assessment.
  • Before admitting anyone to AML duties, we verify their professional preparation and lack of a criminal record to the extent permitted by law.

11. Reporting breaches (whistleblowers)

In accordance with Art. 53 of the Act on Counteracting Money Laundering and Terrorist Financing, the office has an internal procedure for anonymously reporting actual or potential breaches of anti-money-laundering and counter-terrorist-financing law.

  • Reports can be submitted by employees, associates and other people performing work for the office, regardless of the basis of their engagement.
  • A report can be submitted anonymously, using the channel indicated in the procedure; the procedure sets out how reports are received, verified and followed up.
  • The reporting person is protected — a report made in good faith cannot be grounds for retaliatory action, discrimination or other unfair treatment.
  • The data of the reporting person and of the person the report concerns are protected in accordance with the Act and personal data protection law.
  • Independently of the internal channel, breaches can be reported directly to the General Inspector of Financial Information.

12. Protection of data collected in connection with AML

We process personal data collected to fulfil our statutory obligations on the basis of Art. 6(1)(c) GDPR, solely for the purposes of counteracting money laundering and terrorist financing — we do not use it for other purposes, in particular marketing.

We fulfil the information obligation towards people whose data we collect for this purpose in accordance with the Act; the right of access to data and other entitlements may be subject to restrictions arising from AML law, including the prohibition on disclosure. The remaining rules are described in the Privacy policy.

13. Cooperation with the client

We ask that AML questions be treated as a standard part of the service. Complete data from the outset shortens onboarding, and keeping it up to date helps avoid settlements being held up during the year.

Direct any questions about the scope of required documents to your accountant or to the office's email address.

Counteracting money laundering (AML) — Steers