Reporting of suspicious transactions under new rules | In Principle

Go to content
Subscribe to newsletter
In principle newsletter subscription form

Reporting of suspicious transactions under new rules

One of the fundamental duties of obliged entities under anti–money laundering regulations is to report suspicious transactions to the authorities. The current AML Act in Poland provides for three separate procedures in this regard, with differing grounds, addressees of notifications, and legal consequences for the obliged entity and for the transactions or assets. This multi-track model will change radically from 10 July 2027, when the EU’s AMLR begins to apply. In this article we examine selected changes step by step.

Current status

The Polish AML Act (Act on Combating Money Laundering and Financing of Terrorism of 1 March 2018) provides three main procedures for reporting suspicious transactions:

  • Notification to the General Inspector of Financial Information (GIIF) of circumstances indicating suspicion of money laundering or financing of terrorism (ML/FT), under the procedure laid down in AML Act Art. 74 (suspicious activity report—SAR)
  • Notification to GIIF of a reasonable suspicion that a given transaction or given assets may be connected to ML/FT, under the procedure laid down in AML Act Art. 86 (suspicious transaction report—STR)
  • Notification to the prosecutor under the procedure laid down in AML Act Art. 89 of a reasonable suspicion that assets that are the subject of a transaction or held in an account derive from a criminal offence, or other ML/FT not constituting an offence, or from a fiscal criminal offence, or are connected with an offence other than an ML/FT offence or fiscal offence.

The functioning of three separate reporting procedures generates significant difficulties in practice. An obliged entity that identifies a suspicious transaction must first assess which of these three procedures is applicable—no trivial choice, as it translates into different legal consequences, particularly involving the duty to refrain from carrying out the transaction or to block the account, as well as releasing the obliged entity of liability for carrying out its statutory duties. An added complication is the lack of a standardised form for submitting notifications: the expected content of the notification arises partially out of the AML Act and partially out of positions and communiqués issued by GIIF, which requires obliged entities to monitor the regulator’s practices and expectations. This means that with every notice, the obliged entity must essentially draft the notification from scratch, filling in the wording based on fragmented sources—and for all of this the obliged entity may have, for example, barely two business days in the case of an SAR. With such short deadlines, combined with the need to draw up the form and scope of the notice afresh in each case, this can greatly hinder the whole process in complex fact patterns, and requires efficient coordination within the obliged entity.

AMLR—one harmonised reporting track

The AMLR (Regulation (EU) 2024/1624 of the European Parliament and of the Council of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing) replaces the existing multi-track reporting model with a single harmonised procedure for notification of the Financial Intelligence Unit (FIU, which in Poland is GIIF). Under Art. 69 AMLR, an obliged entity must report to the FIU where the obliged entity knows, suspects or has reasonable grounds to suspect that funds or activities, regardless of the amount involved:

  • Are the proceeds of criminal activity or
  • Are related to terrorist financing or criminal activity.

On this basis, obliged entities are required to report all suspicious transactions that proceed from criminal activity, or are related to criminal activity or terrorist financing, regardless of the value. They must also report attempts at such transactions (even if ultimately the transaction is not carried out) and suspicions arising from the inability to conduct customer due diligence (know-your-customer or KYC procedures) with respect to the client (which is in line with the current rule under AML Act Art. 41(2)).

Predicate offences

To assess the scope of the duty under Art. 69(1)(a) AMLR, it is essential to know what constitutes “criminal activity.” Under Art. 2(1)(3) AMLR, this term means:

  • Criminal activity as defined in Art. 2(1) of Directive (EU) 2018/1673, i.e. a catalogue of predicate offences including such items as participation in organised crime or racketeering, terrorism, human trafficking, corruption, tax crimes, cybercrime, or environmental crimes
  • Fraud affecting the European Union’s financial interests as defined in Art. 3(2) of Directive (EU) 2017/1371
  • Passive and active corruption as defined in Art. 4(2) of that directive
  • Misappropriation as defined in Art. 4(3) of that directive.

Thus the term “criminal activity” has a standalone definition within the AMLR itself, and does not necessarily cover every punishable offence defined in the criminal law of a given member state.

This definition gives rise to fundamental doubts in interpretation: how the understanding of “criminal activity” is affected by national law, and whether an obliged entity must determine what specific type of predicate offence has occurred. As the catalogue of “criminal activity” under the AMLR may not fully overlap with the catalogue of crimes defined in the national law of the various member states, it may be considered whether an obliged entity will be required to determine on its own which specific offence is involved—and thus whether the given behaviour falls within the catalogue of predicate offences under the AMLR.

Does national criminal law influence the assessment of what constitutes “criminal activity” under the AMLR, and if so, whose law?

To illustrate this issue it is worth considering an example—by necessity, a marginal and purely hypothetical one. Assume that a Polish obliged entity (a bank) suspects that funds entering a customer’s account derive from an act committed abroad which in the country where it was committed constitutes a crime but in Poland would not be punishable (purely by way of example, suppose that the funds are the profit from a publication critical of the authorities of a foreign country, which is punishable by the law there but is a matter of indifference under the criminal law of Poland). The question arises which jurisdiction’s criminal law should be considered by the obliged entity when evaluating whether there is a reporting obligation in this instance.

An analogous question arises in dealings between EU member states, as differences undoubtedly exist between their systems of criminal law. If a given act is a crime in one member state, but not in another, whose regulations should the obliged entity consider when assessing whether it has a reporting obligation? The criminal law of the state where the obliged entity is established? The criminal law of the place where the act from which the funds derive was committed? Or perhaps the abstract, standalone definitions of predicate offences drawn from the AMLR and the directives cross-referenced in the AMLR?

Recognising that an obliged entity must take into account the criminal law of the place where the act was committed would lead to absurdity, as with every transaction with at least a cross-border dimension the obliged entity would have to analyse the criminal law of jurisdictions all over the world, which in practice would be futile. On the other hand, relying solely on the standalone definition of “criminal activity” in the AMLR also does not appear to be the correct solution—and it seems to me that this was not the intention of EU lawmakers. This definition is abstract and cross-references catalogues of predicate offences set forth in directives, particularly Directive (EU) 2018/1673, which only sets a standard for minimal harmonisation. Member states could have adopted a broader definition of predicate offences in their own national law. Poland provides an example of this, as the predicate offence for the crime of money laundering may be any punishable act, not solely the categories of acts indicated in Art. 2(1) of Directive (EU) 2018/1673. Thus if an obliged entity were to rely solely on the definition in the AMLR, it would lead in such instances to a situation where there would be no reporting obligation when the national definition of criminal activity goes beyond the framework of the directives—and such a restriction on the reporting obligation was probably not intended by the EU lawmakers. This understanding is indicated by recital 6 of the AMLR preamble, which states: “Harmonisation in the relevant area of criminal law enables a strong and coherent approach at Union level to the prevention of and fight against money laundering and its predicate offences, including corruption. At the same time, such an approach ensures that Member States that have adopted a broader approach to the definition of criminal activities which constitute predicate offences for money laundering can continue to apply such an approach.”

For these reasons, the only sensible path appears to be to recognise that an obliged entity should evaluate whether a given act qualifies as “criminal activity” within the meaning of the AMLR, from the perspective of its own national criminal law. Thus in practice the same transaction might be reported by one obliged entity (because in its jurisdiction the act constitutes a predicate offence for the crime of money laundering), but not reported by another obliged entity participating in the same transaction but acting in another member state (because there the same act is not a predicate offence for the crime of money laundering)—and in that case both of the obliged entities could be acting properly.

Is an obliged entity required to determine exactly what type of predicate offence has occurred?

In practice it is hard to expect that an obliged entity will always have the instruments, knowledge and qualifications at its disposal needed to conduct such a criminal-law classification. The obliged entity is not a law enforcement authority—it does not admit evidence, has no access to investigatory materials, and often is not familiar with the full state of facts underlying a given transaction, but is only aware of fragmentary facts arising from the information it has about the customer. To require prior to filing of a report that the AML compliance officer (the employee appointed to ensure compliance with AML/CFT regulations) determine, with the precision expected of law enforcement authorities, the specific type of predicate offence involved (e.g. tax fraud, corruption, or environmental crime), would be disproportionate and in many cases not feasible.

It also seems that this was not the legislative intent, as indicated in recital 138 to the AMLR, which stresses that obliged entities should not be discouraged from making reports even if they are not in a position to identify precisely the underlying offence. (“Where the underlying predicate offence is not known or apparent to the obliged entity, the role of identifying and reporting suspicious transactions is fulfilled more efficiently by focusing on detecting suspicions and submitting reports promptly. In those cases, the predicate offence need not be specified by the obliged entity when reporting a suspicious transaction to the FIU, if it is not known to them.”) This is confirmed indirectly in the safe harbour provision of Art. 72 AMLR, protecting persons disclosing information to the FIU in good faith, and clearly indicating that this protection also applies to situations where the obliged entities “were not precisely aware of the underlying criminal activity and regardless of whether illegal activity actually occurred.” The drafters thus seem to have assumed that in practice, the criminal-law classification of the offence underlying the suspicious funds rests with the authorities conducting the subsequent proceedings, and not with the obliged entity.

Knowledge, suspicion, and reasonable grounds for suspicion

The duty to report to the FIU materialises when the entity knows, suspects, or has reasonable grounds to suspect that a transaction is connected with criminal activity. But the AMLR does not define these three notions.

The most straightforward instance would be where the facts are so clear that there can be said to be knowledge. But in practice this is rare, because obliged entities don’t conduct criminal investigations and don’t have the tools at their disposal to determine the facts beyond a reasonable doubt.

Much more often suspicion will come into play—the moment when the information on hand provides a basis to question the legality of the source of the funds or the purpose of the transaction, although no one could say so with certainty.

The third basis under Art. 69(1)(a) AMLR, reasonable grounds for suspicion, is an objective measure for how the obliged entity has acted on the information in its possession. From a risk management perspective, this is the most demanding test, because reasonable grounds may exist even when an actual suspicion has not yet formed. In this instance, it is sufficient that the available information—looked at objectively and at arm’s length—should have given rise to a suspicion. For example, if the system did not generate a transaction alert at all because it was improperly calibrated, but the objective information available to the obliged entity should have caused it to form a suspicion, then the obliged entity may be exposed to a charge of infringing its reporting obligations. The same situation would occur if a transaction alert was generated, but nonetheless the AML compliance officer did not form a suspicion even though they should have, based on the information in their possession. In both cases, explaining that there was no subjective belief that irregularities had occurred may not be a defence for the obliged entity if the warning signals were, objectively, evident in the available data.

How is the obliged entity supposed to know whether funds or activities are suspicious?

The answer to this question is found in Art. 69(2) AMLR, which states that “obliged entities shall assess transactions or activities carried out by their customers on the basis of and against any relevant fact and information known to them or which they are in possession of.” In practice this means that a single atypical transfer, viewed on its own and without the broader context, will generally not suffice to find that there was knowledge or suspicion within the meaning of the AMLR.

The assessment should thus be holistic, not based on a single data point. It is only the juxtaposition of specific elements—the identity of the customer and its representatives, the size and manner of conducting the transaction, the action plan followed, potential links between individual transactions, and the actual origin and destination of the funds—that will enable a determination that the situation rises to the threshold warranting filing of a report.

In practice, significant conclusions may be drawn from comparing the customer’s current behaviour with the earlier findings made during the KYC process, such as the customer’s stated business profile, anticipated transaction volume, or source of assets. So long as the customer continues to behave consistently with the findings made at the onboarding stage, it is hard to say that anything is suspicious. The problem arises when these two pictures—the declared and the actual—begin to diverge. Thus, proper performance of the duty under Art. 69 AMLR requires the skill of combining information from different stages of the customer relationship, rather than assessing individual events in isolation.

Further support in this assessment is to be provided by guidelines issued by the AMLA (Authority for Anti–Money Laundering and Countering the Financing of Terrorism). Under Art. 69(5) AMLR, the AMLA has until 10 July 2027 to issue “guidelines on indicators of suspicious activity or behaviours,” which are to be periodically updated. These guidelines are intended to consolidate and clarify the specific criteria for the assessment referred to in Art. 69(2) AMLR, helping obliged entities apply in practice the tests for knowledge, suspicion, or reasonable grounds for suspicion.

Summary

The AMLR brings order to the existing fragmented system for reporting suspicious transactions, and introduces a single procedure for reporting to Financial Intelligence Units, harmonised across the EU, which—at least at the systemic level—should facilitate the actions of obliged entities, as well as FIUs’ comparison and exchange of information. But this doesn’t mean that the new regime is free of doubts in interpretation, and some of those doubts may have far-reaching consequences.

By 10 July 2027, obliged entities in Poland need to replace the current channels for reporting suspicious activity or transactions (SAR, STR, and notification of prosecutors) with one track for reporting to the General Inspector of Financial Information under Art. 69(1)(a) AMLR, as well as verifying, and when necessary adjusting, the procedures for identifying and analysing suspicions. The earlier these procedures are reviewed, the less risk there is that gaps or doubts will not be revealed until reports are already being filed with GIIF under the AMLR regime.

We discuss the details of reports (deadline, format, the person filing the report and the person’s responsibility) in the article “Reporting of suspicious transactions: Who, how and when.”

Joanna Werner, attorney-at-law, Banking & Project Finance practice, New Technologies practice, Wardyński & Partners