AML Procedure – what is it and who must implement it?

September 23, 2026

An AML procedure is one of the fundamental elements of the anti-money laundering and counter-terrorist financing framework within an obliged institution. It defines how an organisation fulfils its obligations under the AML Act – from risk assessment and customer verification, through ongoing monitoring of business relationships, to reporting to the General Inspector of Financial Information (GIIF).

However, it should not be treated solely as a document prepared for the purpose of an inspection. A properly designed procedure should primarily answer practical questions: who performs specific activities, when particular actions should be taken, what information must be collected, and how to proceed in situations involving increased risk.

The law also requires the procedure to take into account the nature, type and scale of the organisation’s activities. This means that a document prepared for a small accounting firm will look different from the procedure used by a bank, payment institution or company serving customers from multiple countries. The procedure must also be subject to ongoing review and, where necessary, updated.

Example:

A company has an AML procedure that was prepared several years ago using a generic template. The document requires certain customer checks to be performed, but it does not specify who is responsible for carrying them out, which criteria should be used to assess risk, or when a case should be escalated to the person responsible for AML.

Formally, the procedure exists. In practice, however, employees make decisions based on their own experience, and the approach taken depends on the individual handling the customer. This may result in inconsistent application of AML obligations and make it difficult to demonstrate during an inspection that the adopted rules actually work.

What is an AML procedure?

An AML procedure is an internal set of rules defining how an obliged institution prevents money laundering and terrorist financing. The obligation to introduce such a procedure is based on Article 50 of the Polish AML Act. Under this provision, obliged institutions must introduce an internal AML/CFT procedure describing how specific obligations are fulfilled, taking into account the specific nature of the organisation’s activities.

An AML procedure should not be confused with the entire AML framework. The framework also includes, among other things, the institution-wide risk assessment, customer due diligence measures, the KYC process, customer and transaction monitoring, training, reporting to GIIF and the allocation of responsibilities within the organisation. The procedure should define how these processes are to be carried out. In other words, the AML procedure acts as an operational instruction manual for the organisation in the area of anti-money laundering and counter-terrorist financing.

If you would like to understand the broader framework, we explain it in our article “AML – what is it and how does it work?”.

Who must have an AML procedure?

The obligation to introduce an internal AML procedure applies to obliged institutions, i.e. entities specified in Article 2 of the Polish AML Act. These are not limited to banks and large financial institutions. The list is much broader and includes, among others, certain:

  • banks and financial institutions,
  • payment institutions,
  • investment firms,
  • entities operating in the insurance sector,
  • entities providing certain accounting or tax services,
  • legal professionals – within the scope specified in the Act,
  • real estate agents – within the scope covered by the Act,
  • currency exchange businesses and other entities carrying out activities specified in the legislation.

The complete list of obliged institutions is set out in Article 2(1) of the Act. For certain types of business, the status also depends on the nature of the activities performed or on meeting additional statutory conditions. Therefore, operating in a particular industry does not always automatically determine the AML obligations of a specific entity.

Does a small company also need an AML procedure?

Yes – if it qualifies as an obliged institution. The Act does not make the obligation to have an AML procedure dependent on whether a company employs a few people, several dozen employees or several thousand. The scale of the business does, however, affect the procedure itself. Article 50 requires it to take into account the nature, type and scale of the activities carried out.

In a small organisation, several functions may be performed by the same person and the processes may be relatively simple. In a larger institution, responsibilities may need to be divided between several teams, with multi-level approvals, transaction monitoring systems and more complex control mechanisms. The procedure should reflect this reality.

What should an AML procedure include?

The scope of the procedure is not arbitrary. Article 50 of the Polish AML Act specifies the areas that must be regulated. However, this does not mean that it is sufficient to copy individual provisions of the Act into an internal document. The procedure should explain how a particular obligation is actually performed within the organisation.

1. Rules for identifying and managing AML risk

The procedure should define the actions taken by the organisation to mitigate the risk of money laundering and terrorist financing and to manage risks that have already been identified. In practice, this means that the procedure should be linked to the institution-wide risk assessment. Different risks may arise in a company serving only domestic businesses with simple ownership structures compared with an organisation offering remote onboarding to customers from multiple jurisdictions. The procedure should take these differences into account.

2. Customer and relationship risk assessment

Another important element is defining how the risks associated with a specific customer, business relationship or occasional transaction are identified and assessed. The procedure should answer questions such as:

  • which factors are taken into account when assessing risk,
  • who performs the assessment,
  • how the risk level is determined,
  • when the assessment must be repeated,
  • which events trigger an update of the customer’s risk profile.

Relevant factors may include the customer’s industry, ownership structure, geographic exposure, products used, the nature of the relationship and expected transaction activity. Risk assessment should therefore not be limited to selecting a “low / medium / high” field during onboarding. It should be based on information obtained about the customer and should influence how the relationship is subsequently managed.

3. Application of customer due diligence measures

The AML procedure should define the rules for applying customer due diligence measures. This primarily includes:

  • identifying the customer,
  • verifying the customer’s identity,
  • identifying and verifying the beneficial owner,
  • where appropriate, understanding the ownership and control structure,
  • assessing the purpose and intended nature of the business relationship,
  • ongoing monitoring of the relationship.

This is where the KYC process plays a particularly important role. However, the procedure should go beyond a general statement that “the employee identifies the customer”. It should make it possible to determine, among other things, what information is collected, which sources may be used for verification, how discrepancies should be handled and what should be done if the required customer due diligence measures cannot be applied.

You can read more about the customer identification and verification process in our article “KYC – what is it and how does it work?”.

4. Documentation, record-keeping and reporting to GIIF

An AML framework is based not only on performing specific activities, but also on being able to demonstrate that they were actually performed. The procedure should therefore define how activities are documented and how information is stored. In practice, it is useful to specify clearly:

  • which documents and information are collected,
  • where they are stored,
  • who has access to them,
  • who is responsible for maintaining proper documentation,
  • how analyses and decisions are documented.

The procedure should also describe how reporting obligations towards GIIF are fulfilled, including the internal process for escalating a case to the person responsible for assessing it. A first-line employee should not have to work out, only after a suspicious situation arises, who should receive the case and what information needs to be provided.

5. Training and reporting breaches

Persons performing AML-related duties should have knowledge appropriate to their responsibilities. The procedure should therefore define how knowledge concerning anti-money laundering and counter-terrorist financing is disseminated within the organisation. This is not limited to completing a single training session after an employee joins the company. The scope of knowledge should correspond to the employee’s role, and training should take into account changes in legislation, processes and risks. The Act also provides separate requirements concerning the internal reporting of actual or potential breaches of AML regulations. These processes should be consistent with one another, but the internal AML procedure should not be confused with the procedure for anonymous reporting of breaches.

6. Internal control and compliance oversight

The procedure should define the rules for internal control or oversight of compliance with AML regulations and with the rules laid down in the procedure itself. This is important because merely defining rules does not show whether they are being applied correctly. Controls may, for example, include checking:

  • whether KYC documentation is complete,
  • whether risk assessments are correct,
  • whether customer data is updated on time,
  • whether required checks have been carried out correctly,
  • how decisions are documented,
  • whether escalation rules are followed.

The scope of the controls should be appropriate to the organisation and its risk profile.

7. Beneficial ownership discrepancies and the CRBR

The AML procedure should also address how to deal with discrepancies between beneficial ownership information established by the obliged institution and information recorded in the Central Register of Beneficial Owners (CRBR). The Act requires such discrepancies to be recorded and steps to be taken to clarify their causes. Comparing information against the CRBR therefore does not complete the beneficial ownership identification process. The procedure should specify, among other things, who performs the analysis, how the result is documented and what happens if a discrepancy is confirmed.

8. Difficulties in identifying the beneficial owner

The Act also requires the procedure to include rules for documenting difficulties encountered when verifying the beneficial owner, as well as steps taken in cases where the identification process results in a natural person holding a senior management position being identified as the beneficial owner. In practice, this is particularly important in the case of more complex ownership structures or where information concerning control over the customer is not readily available. The procedure should therefore specify not only the final outcome, but also how the process leading to that outcome is documented.

What should an AML procedure describe in practice?

AreaWhat the procedure should define
Risk assessmentwho assesses customer risk, when it is assessed and according to which criteria
KYCwhich data is collected and how it is verified
Beneficial ownerhow the ownership and control structure is identified and documented
Monitoringwhich events require the customer to be reassessed
Escalationto whom a case should be escalated and in which situations
GIIFwho is responsible for the analysis and fulfilment of reporting obligations
Documentationwhere and how the results of AML activities are stored
Trainingwho should receive training and to what extent
Controlwho verifies whether the procedure is actually being followed
CRBRhow discrepancies concerning beneficial ownership should be handled

This list does not replace the statutory requirements. It does, however, illustrate the important difference between a procedure that merely repeats the wording of the law and a document that genuinely enables employees to perform their duties.

How to prepare and implement an AML procedure in practice

Preparing an AML procedure should begin not with writing the document, but with understanding how the organisation actually operates.

1. Assess the risks associated with the business

The starting point should be an assessment of money laundering and terrorist financing risks relating to the institution’s activities. This should take into account, among other things, the types of customers, markets served, products and services offered, delivery channels and the nature of transactions. Only on this basis can appropriate control mechanisms be determined.

2. Map AML processes

The next step is to identify where AML obligations arise within the organisation. This may include:

  • onboarding a new customer,
  • identification and verification,
  • identification of the beneficial owner,
  • PEP and sanctions screening,
  • risk assessment,
  • monitoring,
  • KYC refresh,
  • analysis of unusual activity,
  • escalation of alerts,
  • reporting.

This allows the procedure to be aligned with the actual process flow rather than forcing operations to fit an abstract document.

3. Assign responsibilities

One of the common problems in AML documentation is the use of phrases such as “the institution shall perform”, “it should be checked” or “an analysis shall be carried out”. Such wording does not explain who is actually responsible for performing the activity. The procedure should clearly define roles: who performs the check, who makes the decision, who may approve an exception and to whom an issue should be escalated.

In larger organisations, the AML Officer plays a particularly important role as the person responsible for ensuring compliance with specific AML obligations. We discuss this role in more detail in our article “Who is an AML Officer and what do they do?”.

4. Define how activities should be documented

In AML, the outcome itself is not the only thing that matters. The organisation should also be able to reconstruct the decision-making process later. If an employee decides that an alert does not require further action, the organisation should be able to explain the basis for that decision. If a customer is assigned a particular risk category, it should be possible to determine which factors influenced the assessment. The procedure should therefore define a minimum documentation standard for individual AML activities.

5. Train the people responsible for implementing the procedure

Even a well-designed document will not be effective if the people expected to use it do not know how to interpret its provisions. Training should relate to the employee’s actual responsibilities. A person performing basic onboarding will require a different level of knowledge from a specialist analysing unusual transactions or a person responsible for decisions concerning regulatory reports.

6. Verify whether the procedure actually works

The final step should not be saving a PDF file in an internal folder. Once implemented, the organisation should verify whether the process is actually being performed in accordance with the document. If employees carry out an additional check that is not described in the procedure, the document may need to be updated. If the procedure requires an activity that the organisation is technically unable to perform, the process design itself may be flawed. The procedure should describe a real and operationally feasible model of how the organisation works.

Who approves the AML procedure?

An AML procedure should not be introduced solely on the basis of a decision made by the person who prepared it. Under Article 50(3) of the Polish AML Act, an internal procedure or an update to that procedure must be approved by senior management before it is implemented. The Polish Financial Supervision Authority also points out that it should be possible to determine who approved the document and when, in accordance with the organisation’s internal rules.

This does not mean that senior management must prepare the entire documentation themselves. The draft may be prepared by the AML Officer, the compliance department, lawyers or external specialists. What matters is that the document is properly approved before implementation.

How often should an AML procedure be updated?

The Act does not establish a universal rule requiring every AML procedure to be updated, for example, exactly once a year. It does, however, require the procedure to be reviewed on an ongoing basis and updated where necessary. This means that the organisation should respond to changes affecting the content of the procedure.

Reasons for an update may include:

  • changes in legislation,
  • changes to the business model,
  • introduction of a new product or service,
  • expansion into new markets,
  • introduction of new customer categories,
  • changes to the onboarding process,
  • implementation of a new KYC tool or monitoring system,
  • changes in the allocation of responsibilities,
  • findings from an inspection or audit,
  • identified deficiencies,
  • changes to the institution-wide risk assessment.

Example:

A company previously verified all customers exclusively during face-to-face meetings. It then introduces a fully remote onboarding process. If the AML procedure still describes only document checks performed by an employee during an in-person meeting, it no longer reflects the actual process. A change in the onboarding model should therefore result in an assessment of the new risks and an appropriate update of the AML documentation.

The most common mistakes in AML procedures

One of the most common mistakes is treating the procedure as a document that an organisation simply needs to “have”. The mere existence of a file does not mean that the obligation has been properly fulfilled. In practice, common problems include:

  1. Using a generic template without adapting it to the company. The document describes products, customers, processes or risks that do not exist in the organisation.
  2. No link to the risk assessment. The procedure applies the same approach to every customer without taking the identified risk into account.
  3. Unclear allocation of responsibilities. It is clear what should theoretically be done, but not who is responsible for carrying out the activity or making the decision.
  4. No escalation rules. An employee identifies an unusual situation, but the procedure does not explain what should happen next.
  5. A mismatch between the document and actual practice. The procedure describes one process while employees have been carrying out the activity differently for months.
  6. Failure to cover all required areas. The document may omit, for example, internal controls, CRBR-related rules or the method of documenting certain activities relating to beneficial ownership.
  7. Failure to update the procedure. The company has changed its business model, organisational structure or customer servicing model, but the procedure still describes the situation from several years ago.

These are not merely theoretical issues. Published information concerning administrative penalties has included cases where the internal procedure did not cover all statutorily required rules or contained solutions that were not adapted to the nature, type and scale of the institution’s activities.

What are the consequences of not having an AML procedure?

Introducing an internal procedure is an obligation arising directly from the Act. Article 147 of the Polish AML Act identifies failure to introduce the procedure referred to in Article 50 as an infringement subject to an administrative penalty. The range of possible penalties is broader than a financial penalty alone.

The Act provides for, among other things:

  • publication of information about the obliged institution and the identified infringement,
  • an order to cease certain activities,
  • in certain cases, withdrawal of a licence or authorisation, or removal from a register,
  • a temporary ban on performing managerial functions imposed on the person responsible for the infringement,
  • a financial penalty.

In practice, the risk is not limited to a complete absence of the document. Supervisory authorities have also identified deficiencies involving incomplete rules of conduct or procedures that were not properly adapted to the activities of a specific institution. An AML procedure should therefore not be treated merely as a formal document prepared before an inspection.

Can preparation of an AML procedure be outsourced?

Yes. An organisation may use external specialists to support the analysis of its processes, preparation of documentation and subsequent updates. External support may include, among other things:

  • analysis of the business model and existing AML processes,
  • identification of gaps in the documentation,
  • preparation or updating of the procedure,
  • design of KYC and risk assessment rules,
  • preparation of escalation workflows,
  • support in assigning responsibilities,
  • preparing the organisation for the practical implementation of new rules.

However, outsourcing the preparation of documentation does not transfer the statutory obligations of the obliged institution to the external provider. The procedure must reflect the organisation’s actual processes, be properly approved and then genuinely applied. For this reason, preparing a good AML procedure should start with understanding the company’s business rather than simply inserting the company name into a ready-made template.

Do you need support in preparing or updating your AML procedure?

We can analyse how AML obligations are currently implemented within your organisation, identify gaps and prepare or update the procedure so that it reflects your actual business model. We can also support you with the ongoing implementation of AML processes, including KYC, PEP and sanctions screening, risk assessment, monitoring and customer data updates. Tell us briefly about your organisation and your current operating model. We will tailor the scope of support to your needs.

Contact us

office@amloutsourcing.pl