Recently, I wrote about an AML audit in Poland that concluded without any findings. Since then, I have also represented another Polish virtual asset service provider in an AML audit. It also concluded with a favourable outcome.
The audit concerned BTCBIT Sp. z o.o., where I have served as AML Officer since January 2023. I also represented the Company throughout the audit as its attorney-at-law.
I decided to write about this audit because it differed in several inportant respects from the one described previously. I also believe that this is a good opportunity to further discuss how AML audits in Poland are conducted in practice.
The audited company: BTCBIT Sp. z o.o.
The audit concerned BTCBIT Sp. z o.o., a Polish virtual asset service provider incorporated in early 2018. My involvement with the Company began in 2020. Initially, I provided ad hoc AML advisory services. In 2021, I conducted an external AML audit of the Company’s AML framework.
In 2022, I joined the Company as its attorney-at-law. Since January 2023, I have also served as its AML Officer.
During the audit period, the Company’s core business was the exchange between virtual currencies and fiat currencies. These services were provided primarily through the BTCBIT.net online platform. The Company served several thousand clients during the audit period. It also maintained a dedicated multi-person AML team responsible for the day-to-day implementation of its AML framework.
Scope of the AML audit
The audit covered the period from 1 January 2023 to 31 December 2024.
The audit focused on the Company’s compliance with the Polish AML Act and the implementation of its AML/CFT framework during the audited period.
The audit was conducted by the Małopolski Urząd Skarbowy w Krakowie (Małopolska Tax Office in Kraków). This may seem unusual to readers unfamiliar with the Polish AML supervision system. Under the Polish AML Act, AML inspections are not conducted exclusively by a single AML regulator. The Act provides for supervisory and inspection powers to be exercised by different authorities, including authorities of the National Revenue Administration. In the case of BTCBIT, the competent authority conducting the audit was the Małopolska Tax Office in Kraków.
The authority requested the following documents and information:
- the risk assessment referred to in Article 27 of the Polish AML Act;
- a list of clients for the audited period, including the AML/CFT risk level assigned to each client, the financial security measures applied, any enhanced financial security measures applied, and any specific restrictive measures applied;
- the internal AML/CFT procedure referred to in Article 50 of the Polish AML Act;
- evidence confirming the participation of persons performing AML/CFT duties in training programmes;
- the internal procedure for anonymous reporting of actual or potential AML/CFT violations;
- identification of the person responsible for ensuring the Company’s compliance with the Polish AML Act;
- information on whether the Company verified clients against the sanctions lists referred to in Article 118 of the AML Act;
- information on whether the Company had submitted notifications to the General Inspector of Financial Information concerning suspected money laundering or terrorist financing, or transactions or assets suspected of being connected with money laundering or terrorist financing; and
- information identifying the banks maintaining the Company’s bank accounts.
The authority therefore requested both AML documentation and specific elaboration on how the Company performed its AML obligations in practice.
The audit in practice
In response to the authority’s request described above, I submitted a written response on behalf of the Company. Rather than simply providing the requested documents, the response also explained how the Company’s AML framework operated in practice.
One of the areas that required more detailed explanation was the Company’s risk-based approach. The Company had maintained general risk assessments throughout the audited period. In June 2024, it also introduced a dedicated Customer Risk Assessment Methodology. The methodology translated the principles set out in the general risk assessment into a structured scoring model based on geographical, customer and activity-related risk.
This was relevant because the authority did not only receive a customer list with assigned risk levels. It also needed to understand how those risk levels translated into the financial security measures applied to customers. The Company explained the distinction between standard and enhanced measures and how they depended on the customer’s risk classification. The authority subsequently confirmed that the measures applied were adequate to the assigned risk level.
Another area that required explanation was the structure of the Company’s AML documentation. The framework did not consist of a single document. It consisted of a main AML procedure supported by a number of operational procedures covering areas such as onboarding, customer risk assessment, sanctions, ongoing due diligence, reporting, whistleblowing and transaction monitoring. We explained how these documents operated together as one AML framework and how the individual requirements of Article 50 of the Polish AML Act were reflected in the documentation.
The Company’s AML training also required some explanation. I provided information not only on the training attended by members of the AML function, but also on the internal AML training conducted within the Company. In particular, I conducted two internal training modules in my capacity as the Company’s AML Officer, covering the Polish AML/CFT system and the specific AML/CFT obligations applicable to Polish VASPs and CASPs. This allowed the Company to demonstrate that the training provided was appropriately tailored to the functions performed by the employees.
The reporting function provided another practical element. The Company maintained an internal register of notifications submitted to GIIF and the Prosecution Office during the audited period. We also provided records from the GIIF system confirming the submission and status of those notifications.
The language of the documentation
There was also an issue that I expected to become relevant during the audit. The Company’s AML documentation was maintained exclusively in English. Based on my previous experience with AML audits, I expected that the authority might require us to provide Polish translations of all submitted documents.
This did not happen.
The authority did not require the Company to translate its AML documentation into Polish. I consider this worth mentioning because it made the audit considerably more straightforward. I also believe that the approach taken by the officer conducting the audit deserves particular recognition.
No further requests for documents or explanations
There was another aspect of the audit that I found unusual.
After receiving the Company’s response, including the explanations and supporting documentation, the authority did not issue a further request for additional documents or explanations. In other words, one substantive response from the Company was sufficient to complete this part of the audit.
This is not something I would take for granted in an AML audit. Further requests and follow-up questions are often part of the process. In this case, there were none.
In my view, this may indicate two things. First, the documentation provided to the authority was sufficiently complete and consistent. Second, the explanation of how the Company’s AML framework operated in practice was clear enough for the authority to understand the framework without requiring another round of clarification.
As a consequence, the overall timeline was also relatively short. The audit was conducted between 17 March 2026 and 7 July 2026. In my experience, AML audits of this type often take at least a year to complete.
The audit ultimately concluded without any findings. The final protocol expressly states that no irregularities were identified within the scope of the audit.

