attorney-at-law · Poznań Bar Association · ex-in-house in a regulated financial institution
Legal counsel for
European
fintech.
Licensing and regulatory advice in crypto (MiCA), payments and AI Act governance – directly from an attorney with in-house experience who built compliance and licensing from inside a regulated financial institution, not just advised from outside.
my services
End-to-end counsel for EU crypto & digital finance
From MiCA and token offerings to payments, DORA and AI – one named lawyer accountable for every mandate.
- Custody & client-asset safeguarding policy (Art. 70)
- Programme of operations & business plan
- Supervisory dialogue & response packs (KNF, CySEC, EU NCAs)
- Governance, fit-and-proper file & board composition (Art. 68)
- Capital & prudential requirements (Art. 67)
- Cross-border passporting (Art. 65)
Built from inside a regulated EU crypto exchange – not advised from the outside.
- Token classification & legal opinions (financial-instrument analysis)
- White paper drafting & competent-authority notification (Art. 6, 8)
- Marketing communications review (Art. 7)
- Offer-to-public exemptions & thresholds (Art. 4(2))
- ART/EMT issuer authorisation & reserve disclosures (Title III/IV)
- Admission to trading & listing support (Art. 5)
- Exchange, brokerage & trading-platform model design (Art. 76–78)
- Custodial vs non-custodial wallet structuring (Art. 75)
- Crypto-earn, yield & staking – MiCA scope & classification analysis
- Stablecoin (EMT) product & reserve model (Title IV)
- Token economics & on-chain incentive-mechanism structuring
- PSD2–MiCA boundary for payment-adjacent products (Art. 70(4))
- Travel Rule: CASP-to-CASP & self-hosted-wallet controls (FATF R.16 · TFR)
- AML/CFT internal procedure & risk-based controls
- Risk assessment & customer due diligence (CDD/EDD)
- Sanctions screening & PEP procedures
- GIIF reporting procedures & AMLCO role design
- AMLA transition & AMLR/AMLD6 supervisory readiness
- SPI / MIP registration (Polish Payment Services Act)
- Full Payment Institution (PI / KIP) authorisation
- E-Money Institution (EMI) authorisation (EMD2)
- Safeguarding accounts & client-funds protection
- Agent registration & outsourcing arrangements
- PSD3 / PSR transition & EMI re-authorisation advisory
- DORA gap analysis & implementation roadmap
- ICT risk management framework (Ch. II)
- ICT incident classification & reporting (Ch. III)
- Resilience testing programme & TLPT (Ch. IV)
- ICT third-party risk & critical-provider register (Ch. V)
- ICT contractual requirements (Art. 30)
- AI system risk classification (prohibited / high-risk / limited / minimal)
- Provider conformity assessment & technical documentation (high-risk)
- GPAI model obligations – transparency & copyright (Art. 53)
- Deployer obligations & fundamental-rights impact assessment (Art. 26–27)
- Transparency & AI-generated-content disclosure (Art. 50)
- AI literacy & internal governance programme (Art. 4)
- Day-to-day regulatory queries & legal opinions
- Ongoing regulator dialogue & supervisory correspondence (KNF, CySEC, EU NCAs)
- Incident & breach notification support (DORA / MiCA)
- Board & management reporting packs
- Regulatory-change monitoring & gap analysis
- Licence variation, scope changes & regulatory notifications
cross-border
One lead counsel, backed by local network
One lead counsel owns your entire EU regulatory matter – from the first call to the regulator's decision. Strategy, drafting and the regulator relationship stay in one pair of hands throughout. This is possible because MiCA is one rulebook for the whole Union: authorisation before a single national regulator (Art. 63 MiCA) and a licence that passports across the entire EU (Art. 65 MiCA) – you don't need a separate firm in every country. I bring in local specialists only where the law requires it, and I select, brief and supervise them myself. You manage no one but me.
One point of accountability
Strategy, structure and the regulator relationship sit with one accountable attorney, end to end – from the first call to the final decision. Not a rotating team, not a referral and a goodbye.
Local where it's truly needed
I help you obtain authorisation in your chosen EU jurisdiction. Where national rules or the regulator's practice require a filing in a language other than English, adaptation of the application to national law, or local bar admission – I draw on vetted local firms, proven on live mandates. Scoped, briefed and supervised by your lead counsel. You never manage local counsel – that is the point of the model.
about
Direct counsel. No account managers.
At SWITALSKI.LAW your matter is handled by the attorney whose name is on the door – never an account manager, never an anonymous queue. I counsel founders building inside EU fintech regulation: crypto, payments, AI and adjacent technology.
My background runs through both sides of the table. I started at a larger business law firm, working on payment institution licensing proceedings before the KNF. Then I moved in-house to a licensed EU crypto exchange – designing its compliance frameworks and running its licensing proceedings from the inside. Today I lead CASP licensing under MiCA, including proceedings before CySEC. In Hungary I prepared a CASP application alongside local counsel – ultimately not filed, after the legislator introduced terms that made the route unworkable.
Day to day I draw on specialists in compliance, tax and IT, assembled per mandate – but strategy, drafting and the regulator relationship stay with one attorney throughout.
how i work
From first call to long-term compliance
Discovery call
A 30-minute call mapping your product, target jurisdictions and the regulatory perimeter that actually applies – MiCA, PSD2, AI Act, DORA, GDPR.
Scoping & engagement
A fixed-fee licensing roadmap with milestones, a written opinion on the regulatory path, and an engagement letter signed before any clock starts.
Filing & dialogue
The application pack is prepared and supervisory dialogue runs with the competent authority – KNF, CySEC or another national regulator – until a decision is issued. Timelines are regulator-dependent.
From licence to operations
Once the decision is issued, work shifts to operations: implementing licence conditions, first reporting cycles and – where needed – a transition to retainer-based counsel.
Discovery call
Current setup, obligations and pain points – where compliance stands today and what the regulator expects next.
Compliance gap review
A structured review of existing frameworks against current obligations – MiCA, AML, DORA – closing with a prioritised action list.
Onboarding
Retainer scope, reporting lines and agreed response times, fixed in the engagement letter before the retainer starts.
Ongoing counsel
Incident reporting, AML/KYC, DORA testing, AI Act conformity, contract review, regulator interactions, board reporting.
Discovery call
The project, its timeline and the regulatory questions it raises – token issuance, structuring, agreements.
Modular proposal
Scope split into modules, each priced before work starts. You approve what runs and what waits.
Delivery
Drafting and structuring delivered against agreed milestones, with review points along the way.
Handover
Documentation, internal guidelines and a clean close – with support available when the project evolves.
ready when you are
Tell me what you're building.
I'll reply within 1 business day with how I'd approach it and a fee proposal – in English or Polish.
Your data is used solely to respond to your message. Controller: Mateusz Świtalski Kancelaria Radcy Prawnego, Małachowskiego 8/P1, Poznań, info@switalski.law. Full details and your rights – Privacy Policy.
Direct counsel – no account managers, no anonymous queue. · Confidential · EN / PL