Skip to content Skip to footer

AML is “sailing” into broader waters. Do you know who is responsible for it today?

Table of Contents

  1. The bank is no longer the sole gatekeeper
  2. A procedure is no longer a “shelf-ware alibi”
  3. “Should you have known?”
  4. A company’s problem can quickly become a board member’s problem
  5. AML is becoming an element of enterprise management
  6. The new boundary of liability
  7. AML is entering new sectors today. But above all, it is entering boardrooms.

For years, anti-money laundering (AML) was primarily associated with banks, financial institutions, beneficial owner forms, and a million questions about where the client got their money from. It was a world of procedures, transaction alerts, and specialists locked away in compliance departments. That world is now definitively coming to an end.

AML is increasingly ceasing to be the exclusive domain of the financial sector. Meanwhile, its core requirements are making their way into law firms, tech companies, accounting offices, estate agencies, crypto market operators, luxury goods traders, and even professional sports. The EU AML package further expands the catalogue of obliged entities to include, among others, a significant portion of the crypto sector, luxury goods dealers, as well as professional football clubs and agents.

At the same time, the European Anti-Money Laundering Authority (AMLA) has been established to strengthen and harmonise supervision across the entire system. However, this is not just about adding more industries to the legislation. Much more important is the shift in how liability is perceived.

The bank is no longer the sole gatekeeper

The AML system is based on the premise that it is not only the state that is supposed to “hunt down” criminals. Private entities standing between the client and the transaction are also expected to assist.

A bank sees the flow of money. An accountant knows the settlement structure. An estate agent sees who is buying the apartment. An advisor helps structure a transaction. A law firm may be involved in setting up a company, acquiring a business, or managing a client’s assets. In the eyes of the European legislator, each of these entities is a gatekeeper to the legitimate economy.

In Poland, advocates, attorneys-at-law, foreign lawyers, and tax advisors are already obliged entities when they provide assistance concerning, inter alia, the buying and selling of real estate or enterprises, managing assets, opening accounts, making contributions, and creating or managing companies. This does not mean that every piece of legal advice is subject to AML. It does mean, however, that a law firm participating in certain transactions can no longer assume that the issue of the origin of funds is solely the bank’s problem.

The same applies to entrepreneurs. Not every entrepreneur is directly an obliged entity. However, almost anyone can encounter AML as a bank client, a participant in a transaction, an entity disclosing its ultimate beneficial owner, or a contractor whose ownership structure, funding source, or payment routing starts to raise questions.

AML is therefore spilling beyond the formal statutory catalogue. It enters ordinary business operations through the back door, via banks, contractors, audits, financing, and corporate group requirements. The only limitation here is the “processing capacity” of the supervisory authorities.

A procedure is no longer a “shelf-ware alibi”

Even a few years ago, many organisations treated compliance quite simply: we write a voluminous procedure that is essentially unreadable, conduct some generic training, collect signatures, and place the document in a suitably thick binder or a beautifully named folder on a shared drive.

The binder had one fundamental advantage: it looked professional, and the drive was backed up.

The problem is that regulators are increasingly less likely to ask merely whether a procedure existed. They ask whether it was tailored to the actual business model, whether it identified specific risks, whether it was updated, and whether anyone checked if it was working.

In the current approach, risk assessment cannot be reduced to labelling a client as “low”, “normal”, or “high”. The risk category must influence the scope and intensity of the actions actually taken. A change in product, distribution channel, geographical area, client structure, or political situation may require an immediate update of the assessment. The authority also expects the documentation to allow for the verification of the effectiveness of the measures applied, and for the risk assessment to be approved by responsible persons at the management level.

In other words, a procedure sitting on a server proves at most that someone knew how to write or outsource writing. It does not prove that the organisation knows how to manage risk.

“Should you have known?”

This is where the most dangerous shift occurs.

Liability is increasingly not based solely on the question of whether someone actually knew about the suspicious nature of a transaction. The question of whether you should have noticed it under a properly organised system is becoming ever more crucial.

Did the client’s profile match the nature of the transaction? Was the source of funds credible? Did the ownership structure make commercial sense? Was the sudden change in payment routing explained? Did the intermediary have a genuine business justification? Did anyone connect several seemingly neutral pieces of information?

This is no longer a classic document check. It is an obligation to draw conclusions.

The regulator does not expect clairvoyance. However, they do expect the organisation to know its own business well enough to spot anomalies. And when something is missed, a very uncomfortable question will arise: was it a failure of the employee, the procedure, the IT system, or perhaps the management board that approved an operational model without adequate safeguards? This is precisely where the boundary between compliance and personal liability blurs.

A company’s problem can quickly become a board member’s problem

The Polish AML Act does not leave this solely in the realm of best practices.

In an obliged entity where a management board operates, a person responsible for the implementation of AML duties must be designated from among its members. This is not an honorary function or a mere footnote in an organisational resolution. The Act allows for financial penalties to be imposed on persons responsible for fulfilling AML obligations. It also provides for the possibility of a temporary ban on holding managerial positions. In specific cases, breaches of reporting obligations may even lead to criminal liability.

Naturally, a board member is not expected to personally analyse every transaction. However, they are expected to ensure that there is an efficient system, adequate resources, a clear division of responsibilities, and a realistic escalation path.

Therefore, it is not enough to say, “We have an AML officer for that”.

The board may delegate the execution of tasks. It cannot delegate the entire problem and then pretend that AML reports were just an exotic, graphically pleasing addition to the board meeting materials.

Situations where the compliance unit has been signalling staff shortages, inefficient tools, backlogs in client reviews, or data quality issues for months, while the management merely notes the information and calmly moves on to the sales agenda, become particularly risky.

Such a meeting minute may one day turn out to be more interesting than many a procedure.

AML is becoming an element of enterprise management

The biggest mistake today is treating AML as an isolated regulatory island. Money laundering risk is intertwined with sanctions risk, corruption, tax, reputational, cyber risks, and the criminal liability of management.

A new product, expansion into a foreign market, a company acquisition, a venture into digital assets, serving clients from high-risk countries, or a change in the payment model are not purely business decisions. They should also trigger questions about AML implications.

Therefore, a properly functioning system cannot be built once and for all. It must respond to changes in the company’s operations. If the business has changed but the risk assessment remains the same, it usually does not mean the risk has been stable. It means nobody has looked at the document.

The new boundary of liability

AML is no longer just about fighting a suitcase of cash brought into a bank by a man in dark glasses looking like someone from a B-movie gangster film. Today’s risk hides in multi-level ownership structures, cross-border payments, digital assets, seemingly legitimate investments, brokerage agreements, and transactions, each of which looks perfectly innocent on its own.

Consequently, the expectations towards those responsible for the organisation are also changing. It is not enough not to know. You also have to demonstrate that the organisation did everything that could reasonably be expected of it to find out. And this is exactly where the comfortable world of compliance understood as a set of documents ends. What begins is accountability for decisions, omissions, lack of resources, and risks that nobody wanted to see.

AML is entering new sectors today. But above all, it is entering boardrooms.

AML is entering new sectors today. But above all, it is entering boardrooms, and it is there that the decision is made as to whether the company truly understands its risks or merely possesses a document covering them. If you are not sure which side your organisation stands on, we will help you find out before the regulator asks.

Translate »