Reporting of suspicious transactions: Who, how and when
The EU’s Anti–Money Laundering Regulation changes the rules for reporting of suspicious transactions. In place of the three reporting channels now familiar to Polish obliged entities, with varying reporting deadlines, the AMLR introduces a single, unified track for reporting suspicions, with a duty to act promptly. The AMLR also requires obliged entities to refrain from carrying out reported transactions. Meanwhile, the AMLA, a new EU-level authority, is working to develop standard reporting forms, which should make it easier for obliged entities to perform their tasks.
Reporting deadline and the duty to refrain from carrying out transactions
One of the challenges of the current model for reporting suspicious transactions is the multiplicity of reporting channels, which are also linked with short reporting deadlines (for example, in the case of a suspicious activity report (SAR) the deadline is two days from confirming a suspicion). Another difficulty is the lack of a standardised reporting form. We write about this in the article “Reporting of suspicious transactions under new rules.” The AMLR (Regulation (EU) 2024/1624 of the European Parliament and of the Council of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing) takes a new approach to these issues.
Art. 69(1) AMLR requires obliged entities to cooperate fully with the Financial Intelligence Unit (FIU), which in Poland is the General Inspector of Financial Information (GIIF), by “promptly” reporting to the FIU. This means that the AMLR does not set a rigid deadline for reporting, calculated in a fixed number of business days. Instead of setting a specific number of days, the AMLR employs a general clause requiring obliged entities to act promptly, but does not impose a single time limit applicable to all cases. Obliged entities are already familiar with a similar approach currently provided for in the Polish AML Act in the procedure for filing suspicious transaction reports (STRs).
But the AMLR does impose a hard deadline, counted in days, for another activity. Under the third paragraph of Art. 69(1), “obliged entities shall reply to requests for information by the FIU within 5 working days. In justified and urgent cases, FIUs may shorten that deadline, including to less than 24 hours.” And, as an exception, “the FIU may extend the deadline for a response beyond the 5 working days where it considers it justified and provided that the extension does not undermine the FIU’s analysis.” Thus, these deadlines do not apply to the decision to file a report in the first place, but to the stage following the filing of a report, if the FIU seeks additional information from the obliged entity.
Reporting suspicions to the FIU is just one side of the coin when it comes to the reporting obligation under the AMLR. Art. 71 introduces the further duty to refrain from carrying out the suspicious transaction. Under Art. 71(1), “Obliged entities shall refrain from carrying out transactions which they know or suspect to be related to proceeds of criminal activity or to terrorist financing until they have submitted a report…, and have complied with any further specific instructions from the FIU or other competent authority….” Art. 71(1) goes on to state: “Obliged entities may carry out the transaction concerned after having assessed the risks of proceeding with the transaction if they have not received instructions to the contrary from the FIU within 3 working days of submitting the report.”
The AMLR does not provide for any automatic mechanism in this respect. The passage of three days without a response from the FIU does not automatically mean that the transaction can proceed, nor does it mean that the obliged entity must still refrain from carrying it out. Instead, the obliged entity must make its own assessment of the risk associated with carrying out the transaction, and take its own decision on whether to execute the transaction or continue to refrain from doing so. The FIU’s silence after three working days only opens the way for the obliged entity to act, but without releasing it from responsibility for that decision or shifting the burden of risk assessment to the FIU. In practice this means it is necessary to develop an internal procedure for taking this decision when there is no response from the FIU, with clearly assigned decision-making responsibility, as well as documentation of the risk assessment made by the obliged entity.
Art. 71(2) AMLR provides an exception from the duty to refrain from carrying out the transaction until a report is filed with the FIU. Namely, in all instances where “it is not possible for an obliged entity to refrain from carrying out a transaction,” or where “refraining would be likely to frustrate efforts to pursue the beneficiaries of a suspected transaction,” the obliged entity must instead “inform the FIU immediately after carrying out the transaction.”
Thus, the decision to apply this exception, or to continue to hold back the transaction, will require the obliged entity to make a case-by-case assessment, and in particular to map the legal, regulatory and business risks associated with each option under consideration.
Uniform reporting formats
A further element of the reform which may have a noticeable impact on the everyday work of AML compliance divisions at obliged entities is the consolidation of the reporting form itself. Art. 69(3) AMLR requires the AMLA (Authority for Anti–Money Laundering and Countering the Financing of Terrorism) to develop implementing technical standards (ITS) specifying the format to be used for reporting suspicions, and submit them to the European Commission for adoption. In July 2026 the AMLA published a draft of the ITS, along with an interpretative note and annexes, and opened public consultations, which run through 20 September 2026.
For Polish obliged entities, this is a change of fundamental practical importance. Currently, neither the AML Act nor any executive regulations issued under the act provide for any standardised reporting form. The content of an SAR or STR must be constructed based on the AML Act and various positions and communiqués from GIIF, and the obliged entity must do this from scratch with each report. The AMLR turns this situation around. According to the draft, the AMLA is seeking to establish uniform, comprehensive formats for reporting suspicions, while ensuring a high level of convergence between the member states. A clear standard form, which Polish obliged entities now lack, will appear in a common form for the entire EU.
It should be clarified what this uniformity will involve, because according to the AMLA “format” is a broader notion than just the appearance of the form. It also covers the content of the report, i.e. the required “data points,” as well as the structure of the report. In this respect, the AMLA does not impose one technical language or one file format for all member states, only requiring (apart from specific instances) the use of a machine-readable electronic format. Thus national reporting systems (in Poland, SI*GIIF) will retain certain discretion in implementation, but the substantive content of the report should be framed in the same categories of data common across the EU.
The second major assumption behind the draft is that there will not be one universal form identical for all obliged entities. The draft ITS differentiate the scope of required information depending on the type of reporting entity and the type of reported suspicion, providing appropriate templates with data fields relevant to the given sector. In practice this means that a credit institution or other financial institution reporting a suspicious transaction will complete a different version of the form than, say, a provider of accounting services or an operator of gambling services.
The catalogue of data fields is designed flexibly, not as a rigid list shared by all users. Some fields may be “mandatory” (indeed, some of them may be technically required for filing the report), “mandatory if available,” “optional” depending on the responses given in other fields, or required only at the request of the national Financial Intelligence Unit (in Poland, GIIF). This structure is designed to reconcile two aims: on one hand, complete comparability of reports between member states; on the other, avoiding situations where an entity would have to complete fields for data that it never gathers in its operations.
The draft also calls for implementation in phases, not immediate replacement of all current national solutions. During the first phase, lasting for two years after publication of the standards, FIUs will test and evaluate the completeness and accuracy of the proposed data fields, as well as analysing any gaps between the data points already applied nationally and those indicated in the annexes. Then the AMLA will coordinate a collective decision-making process to adapt the annexes if necessary, and finalise the harmonised templates. The second phase will involve technical implementation of the adopted formats into the FIUs’ and obliged entities’ reporting systems. Thus institutions operating in Poland will have time to prepare for the changes, but it is worth monitoring the results of the consultations now, particularly with respect to which data fields will be deemed technically mandatory for a given type of activity, because this will drive the scope of information that will have to be gathered and held in readiness for use when a report must be filed.
Person responsible for submitting reports
The AMLR specifies who within an obliged entity will actually file the report with the FIU. Under Art. 69(6) AMLR, the person responsible for filing reports to the FIU is the AML compliance officer, appointed under Art. 11(2) to be responsible for the policies, procedures and controls in the day-to-day operation of the obliged entity’s AML/CFT requirements. Within the obliged entity, the AML compliance officer is the formal addressee of the obligation to file reports with the FIU for the member state where the reporting entity is established.
The AMLR provides a certain degree of flexibility for obliged entities operating in a group structure. First, where justified by the size of the obliged entity and the low risk of its activities, an obliged entity that is part of a group may appoint as its AML compliance officer an individual who performs that function in another group entity. In that case, the AML compliance officer from the group but outside the structure of the specific obliged entity will file reports to the FIU on behalf of the obliged entity. This option does not appear to be limited jurisdictionally; in other words, a group entity may appoint as its AML compliance officer a person who performs this function in another group entity, regardless of where the other entity is established. Second, group entities that cannot use this option (e.g. due to their size or their level of risk) will still be able to exploit intra-group synergies in preparing and filing reports with the FIU. Namely, despite the general ban on outsourcing the filing of reports with FIUs, Art. 18(3)(e) AMLR carves out an exception for obliged entities operating within a group. But this exception applies only when the reporting is outsourced to an entity which is also an obliged entity, which belongs to the same group, and which also is established in the same member state as the obliged entity.
Safe harbour—a few words on liability
The AMLR introduces a “safe harbour” rule protecting obliged entities filing reports in good faith. Under Art. 72 AMLR, “Disclosure of information to the FIU in good faith by an obliged entity or by an employee or director of such an obliged entity … shall not constitute a breach of any restriction on disclosure of information imposed by contract or by any legislative, regulatory or administrative provision, and shall not involve the obliged entity or its directors or employees in liability of any kind even in circumstances where they were not precisely aware of the underlying criminal activity and regardless of whether illegal activity actually occurred.”
For Polish obliged entities, this provision is something of a novelty. Until now, the scope of protection against liability has depended on which of the three reporting channels applies in the given case. When filing an SAR under AML Act Art. 74, the AML Act does not provide for any release from liability in connection with filing the report. The situation is different for STRs filed under AML Act Art. 86 or notifications to the prosecutor under AML Act Art. 89. Under both of the latter channels, which are automatically linked with need to block the transaction or freeze the assets, a broad release from liability applies under AML Act Art. 91, which provides that performance by an obliged entity of the duties referred to in Art. 86 or 89 of the act shall not result in disciplinary, civil, criminal or other liability provided under separate regulations.
The scope of protection of the safe harbour in Art. 72 AMLR should be considered against this background. Art. 72 expressly refers only to disclosure of information to the FIU, i.e. the actual filing of a report under Art. 69–70 AMLR. However, the AMLR is silent on any release from liability for refraining from carrying out a transaction under Art. 71 AMLR—and in practice this is the type of decision that generates the biggest risk and potential liability for the obliged entity, particularly to a customer who may dispute the justification for refusing to execute its transaction. Under current Polish law, AML Act Art. 91 expressly covers the entirety of actions taken in performance of duties under AML Act Art. 86 or 89. By contrast, the literal wording of Art. 72 AMLR does not provide the same certainty with respect to actions taken under Art. 71 AMLR.
Joanna Werner, attorney-at-law, Banking & Project Finance practice, New Technologies practice, Wardyński & Partners