AML/KYC

AML/KYC and ISO 37001 – How to Implement a Compliance System That Truly Protects Management

AML/KYC and ISO 37001—How to Implement a Compliance System That Truly Protects Management

Implementing AML/KYC in a Polish company is no longer a one-time project, but rather an ongoing process that, between 2025 and 2028, will undergo the most significant legal changes since the 2018 Anti-Money Laundering Act took effect. Added to this is ISO 37001 certification—voluntary but increasingly required in tenders and B2B relationships—concerning the management of anti-corruption measures within a company. Companies that fail to update their procedures by 2027—when the new AML regulation takes direct effect throughout the EU—will be operating under an outdated legal framework, with a real risk of sanctions and personal liability for board members.

Why is this issue back on the agenda of corporate boards now?

The EU AML/CFT package, adopted by the European Parliament and published in the Official Journal of the EU in June 2024, introduces three new legal acts: the AML Regulation, the AML Directive (known as AMLD6), and a regulation establishing a new European supervisory authority — the Anti-Money Laundering and Counter-Terrorist Financing Authority (AMLA). The AML Regulation will take effect directly in all Member States in the second half of 2027, and the AMLA will begin direct supervision of high-risk groups as of January 1, 2028. The years 2025–2027 therefore represent a window of opportunity to review and adapt procedures—not to wait until the regulations take effect.

Importantly, Poland’s 2018 AML Act—which has been the central piece of legislation in this area to date—will lose its current status. The EU regulation will take effect directly, without the need for transposition, which means that some national procedures will have to be based on the EU regulation rather than on the Polish Act. For obligated institutions, this represents a change in the source of law, not merely another amendment.

What, in practice, changes for the obligated institutions?

The new regulations harmonize several areas across the European Union that, until now, each country had regulated slightly differently:

  • Customer due diligence measures —harmonized KYC procedures, including uniform rules for identifying the beneficial owner and verifying data in central registers.
  • List of regulated entities —expanded compared to the current legal framework, covering, among others, part of the cryptoasset market and—with a longer transition period—professional soccer clubs and soccer agents.
  • Cash payment limits – an EU-wide cap on large cash transactions for goods and services.
  • AMLA Technical Standards – By July 26, 2026, the Authority is to develop regulatory technical standards regarding the scope of information necessary to conduct customer due diligence, and further guidelines (including those concerning the assessment of the risk profile of obligated entities) are already under consultation.

For the company, this means specific tasks for the coming months: updating the customer-product-channel-jurisdiction risk matrix, reviewing AML policies in light of new definitions and thresholds, and scheduling regular training sessions—including for those responsible for identifying customers who hold politically exposed positions or equivalent roles.

Where does ISO 37001 fit into all of this?

ISO 37001 is an international standard for anti-bribery management systems—distinct from AML regulations, but functionally closely linked to them. In Poland and in most countries around the world, its implementation is not a legal requirement—the global exception is Peru, where certification is sometimes required in public tenders. Nevertheless, on the Polish market, an increasing number of entities treat ISO 37001 as an industry standard, particularly in the construction, energy, and pharmaceutical sectors, as well as in dealings with state-owned companies and international institutions (UN agencies, the EBRD, and the World Bank), where certification is often a formal requirement for qualification in a tender.

The standard is based on a high-level structure (HLS), which allows it to integrate with other management systems (e.g., ISO 9001, ISO 27001, ISO 27000), and its implementation—depending on the size and maturity of the organization’s processes—typically takes between three and several months, followed by an independent certification audit. It is crucial that the ACMS (Anti-Corruption Management System) documentation not be created merely “for the sake of having it,” but that it actually change the way purchasing decisions are made, suppliers are managed, and gifts and conflicts of interest are handled.

AML/KYC and ISO 37001 – Why It’s Worth Implementing Them Together

Both systems address overlapping risks—financial fraud, corruption, and a lack of transparency in dealings with business partners—and, in practice, share the same infrastructure: risk assessment policies, procedures for reporting irregularities, an incident log, due diligence on business partners and staff, and periodic training. A company that builds one system in isolation from the other usually ends up duplicating work or leaving a gap—for example, robust KYC without a mechanism for reporting suspected corruption within the organization, or vice versa.

An additional element linking these two areas is the Whistleblower Protection Act, which has been in effect in Poland since September 25, 2024—the reporting channel that the Act requires organizations to implement is also a key tool for detecting AML and corruption violations at the earliest stage, before they become the subject of an investigation by the GIIF or the prosecutor’s office.

Delphi Consulting Group conducts business intelligence research and OSINT analysis for management teams and investors — using only legal sources.

Schedule a Consultation →

Practical Implementation Steps

  1. Gap analysis – a comparison of current AML/KYC procedures with the requirements of Regulation 2024/1624 and the ISO 37001 standard, including an assessment of the actual risk of sanctions.
  2. Development and implementation of new, previously missing procedures and processes,
  3. Risk Assessment Update – New Customer-Product-Channel-Jurisdiction Matrix, Taking into Account the Expanded List of Obligated Entities.
  4. Verification of actual beneficiaries and business partners —an in-depth analysis that goes beyond a standard credit bureau report, covering ownership structures, sanctions lists, and the reputation of the management board.
  5. Establishment or review of a reporting channel —in accordance with the Whistleblower Protection Act, with clearly defined responsibilities for follow-up actions.
  6. Periodic training —mandatory, documented, and tailored to specific roles (sales department, purchasing department, management).
  7. The decision to pursue ISO 37001 certification —recommended for companies that participate in competitive bidding, collaborate with international entities, or operate in industries with a higher risk of corruption.

FAQ

Does a small business also have to implement AML/KYC? It depends on the nature of its business—the list of institutions subject to the new EU regulation is broader than that in the current law and includes, among others, part of the cryptoasset sector and entities providing custodial services. It’s worth checking this on a case-by-case basis, as incorrect classification could result in the lack of required procedures on the day of an inspection.

Is ISO 37001 certification mandatory in Poland? No. It is an industry standard that is increasingly required by contract by business partners, public institutions, and funding agencies, but it is not directly mandated by Polish law.

When do we actually need to start taking action? The EU timeline spreads implementation over the years 2025–2028, but the AMLA technical standards and reviews of national laws are already being introduced—delaying action until the final year of the transition period means implementing the changes under time pressure, which typically increases costs and the risk of errors.

Delphi Consulting Group supports management teams, owners, and investors in developing and auditing AML/KYC and ISO 37001 systems—from risk assessment to the implementation of audit-ready procedures.

Sources

  1. PwC Poland – New AML/CFT Regulatory Package, pwc.pl
  2. Deloitte Poland – The AML Package: A New Chapter in Combating Money Laundering and Terrorist Financing, deloitte.com
  3. Deloitte Poland – 6th AML Directive Adopted, deloitte.com
  4. IDENTT – AMLA – the new EU AML authority: what this means for companies in Poland, identt.pl
  5. iAML – AML in 2026 – Challenges and Predictions, iaml.com.pl
  6. PARP – AML/CFT Package – Who It Applies To and What Procedures It Establishes, parp.gov.pl
  7. KPMG in Poland – Webinar Materials: New AML Challenges in Organizations, kpmg.com
  8. Bureau Veritas Poland – ISO 37001 Certification, bureauveritas.pl
  9. PQS – ISO 37001 Implementation – An Anti-Corruption System Step by Step, progress-szkolenia.com.pl
  10. QSCert – ISO 37001 Certification – Anti-Corruption System, coe.biz.pl

← All Analyses

Do you have a question about this topic?

Let's discuss
your situation.

The initial consultation is complimentary and entails no obligation.

Schedule a Call →