AML Obligations of a Virtual Office Operator
A virtual office has become one of the most common ways for startups, freelancers and foreign companies to register a business in Poland quickly and at low cost. Behind that convenience sits a strict legal regime. Under the Polish Act on counteracting money laundering and terrorist financing (the AML Act), the operator of such an office is not an ordinary entrepreneur. It becomes an obliged institution and must meet the full set of anti-money-laundering requirements.
This article explains the legal basis, the mandatory registers, day-to-day duties, practical examples and the consequences of neglect.

Why a virtual office falls under the AML Act
The AML Act protects the financial system against money laundering and terrorist financing. Its catalogue of obliged institutions is closed but broad. It covers not only banks and currency exchange offices, but also entities providing “services to companies or trusts”.
The key rule is Article 2(1)(16) of the AML Act, which lists as obliged institutions businesses whose activity consists of providing services to companies or trusts, including:
- providing a registered office, a registration address or a correspondence address
- handling correspondence
- other related administrative services
This is exactly what a virtual office does. It does not matter whether this is your main activity or a sideline to coworking or accounting services. If a client pays you for “registered address plus letter scanning”, you are an obliged institution.
Mandatory register of activity for companies or trusts
The first obligation is to register before starting or continuing the activity. The register is kept by the Director of the Tax Administration Chamber in Katowice, acting for the Minister of Finance (Articles 129a to 129l of the AML Act). Registration is filed electronically through ePUAP, together with a statement that you meet the conditions and proof of the PLN 616 registration fee. In 2026 the register and its conditions remain in force.
Identification form to the GIIF
In addition to the Katowice register, you must file an identification form with the General Inspector of Financial Information (GIIF) under Article 77 of the AML Act. It is submitted electronically through the GIIF IT system. This is not a public register, but it is how the GIIF knows who is subject to supervision.

Full catalogue of AML duties
Once registered, you are a fully fledged obliged institution. The main obligations under the AML Act include:
- Risk assessment and internal procedures: prepare a written risk assessment, implement and keep an internal AML/CFT procedure up to date, and appoint a person responsible for AML.
- Financial security measures (customer due diligence): identify and verify the customer and the beneficial owner, check the CRBR (Central Register of Beneficial Owners), apply enhanced measures for high-risk countries, PEPs and transactions above thresholds, and monitor the relationship over time.
- Reporting to the GIIF: report suspicious transactions with no amount threshold, report certain transactions above EUR 15,000, and keep documentation for five years.
- Training and internal audit: train staff at least once a year and review procedures periodically.
- Cooperation with authorities: provide documents on request to the GIIF, the National Revenue Administration, the Police and the Internal Security Agency.
Practical examples
A client from Dubai wants a Warsaw address and correspondence handling. Risk is high (third country), so you must verify identity, establish the beneficial owner, apply enhanced measures and monitor whether dozens of companies suddenly register at the address.
A quick Polish limited company pays a monthly fee for an address. Risk is low to medium, so standard due diligence and an annual review usually suffice.
Suspicious correspondence such as parcels containing cash or documents from sanctioned countries calls for immediate suspension of the service and a report to the GIIF within 24 hours.
Penalties for neglect
Running the activity without registration carries a fine of up to PLN 100,000. Missing AML procedures or inadequate due diligence can lead to administrative penalties from the GIIF of up to PLN 1,000,000 or more for repeat breaches. Failing to report a suspicious transaction can trigger criminal liability. In 2026 the GIIF and the National Revenue Administration have tightened controls specifically on virtual offices, which are treated as high risk.
What to do now
Check whether you are in the Katowice register. File the identification form with the GIIF if you have not. Implement a proven AML procedure, and train regularly, bearing in mind that the EU AML Regulation 2024/1624 will phase in from 2027. The cost of a professional AML implementation is a fraction of the penalty you may face.
For screening customers and beneficial owners against sanctions and PEP data, a tool such as Hyperflow keeps the checks current and auditable.
UK perspective
In the United Kingdom the framework is analogous but the institutions differ. The UK financial intelligence unit is the UK Financial Intelligence Unit within the National Crime Agency (NCA), and suspicious activity reports are filed to the NCA. Supervision is split between the Financial Conduct Authority, HMRC and OPBAS for professional bodies. The underlying obligations, being risk assessment, customer due diligence and reporting, mirror the Polish requirements described above.