Skip to content
SWITALSKI.LAW – home
EN PL

services / ongoing counsel

Compliance Officer Outsourcing for Regulated Businesses

I take on the compliance workload: procedures, appointments, training, inspection readiness and contact with the regulator. MiCA, payment services, AML, DORA, the AI Act. Three ways to work together: a one-off review, an implementation with an end date, or ongoing counsel on a monthly retainer.

The short answer I take on the compliance workload, not a post that requires formal appointment inside your business. Three formats: review, implementation, ongoing counsel.

Direct counsel from the attorney handling your matter – not an account manager.

The short answer

Compliance officer outsourcing means handing the compliance workload to an external lawyer: drafting and updating procedures, putting appointments in order, training the team, preparing for inspections and handling correspondence with the regulator. It does not cover holding the functions the law requires you to assign within your own organisation – under Polish AML rules, a board member and a senior manager (articles 7 and 8). I work in three formats: a one-off review ending in a memo, an implementation with a set end date, and ongoing counsel on a monthly retainer.

Compliance officer outsourcing – what it actually means

I take on the work, not the post.

I build and maintain compliance inside your business: procedures, appointments, training, contact with the regulator. I go deep enough into the organisation to know it from the inside, and I stay.

What I do not take on are the functions the law requires you to assign to someone within your own organisation. Appointing the board member and the senior manager responsible for AML (articles 7 and 8 of the Polish AML Act, and their equivalents across the EU) is yours to do – as are operational decisions on live matters.

My job is to make sure those people are properly appointed, working from current procedures, and backed by a lawyer who knows their business. That is the difference between advising from the outside and actually running compliance.

When to consider this

  • You have the licence and now everything has to work. During the application, documents were enough. From the day of authorisation, the regulator looks at whether the business actually runs that way.
  • You are growing faster than your procedures. New product, new market, new people – and the policies are still last year's.
  • Your compliance person has left. The knowledge went with them, and hiring for that role takes months.
  • An inspection has been announced, or a request for information has arrived. You need someone to establish the facts and prepare the response before you answer on your own.
  • You are entering a new EU market. Passporting (article 65 MiCA, article 28 PSD2) is not a formality – it means a new supervisor and new expectations of your procedures.

You do not need a compliance team to start. You only need to know that the current setup will not survive the first inspection.

Three ways to work together

Review

The starting point when it is not yet clear where the gaps are, or how serious.

I start with your organisation. Who is responsible for what, and whether the people holding statutory functions were appointed correctly. I establish where board responsibility ends and the operational level begins.

Next come the documents: procedures, policies, contracts with providers and related entities. I also talk to the teams that work with those procedures every day.

Then I check how it works in practice – whether the documents describe what actually happens. This is where problems usually surface. An inspection spots the gap quickly; your team rarely sees it from the inside.

You get

a memo listing the gaps by risk and urgency, with specific recommendations, plus a working session on the findings and the order of work.

The Review fee is credited against Implementation.

Implementation

For when you know what needs fixing and want it closed by a set date.

I draft and revise your procedures and policies – not templates, but documents built around how your business actually runs. I put the appointments in order: resolutions, powers of attorney, defined lines of responsibility. I review contracts with providers and related entities against outsourcing requirements.

Then I hand it over to the team. I train the people who will use these procedures and walk through the first live runs of the process. A document nobody knows how to apply does not work – not in the business, and not in an inspection.

You get

the full documentation in place, a trained team, and written confirmation that the recommendations from the Review have been implemented and are being applied.

Implementation has a defined scope and end date. The fee is fixed, not hourly.

Ongoing counsel

For when the procedures are in place and you need someone making sure they stay that way.

I am available as matters arise: assessing new products and new markets before they go live, preparing your team for inspections, and helping with correspondence to the regulator. I update the documentation when the rules change or your business model does – usually the second moves faster than the first.

Once a quarter I check whether the procedures still match what the business actually does. It is the same test as in the Review, run regularly and before someone external runs it for you.

I do not hold functions that require formal appointment within your organisation, and I do not make operational decisions for you. My role is to make sure the people who do have solid ground to stand on.

You get

direct access to me, a quarterly review, and responses to day-to-day matters without pricing each one separately.

Scope and the monthly fee are set at the outset, sized to your organisation.

What I do, and what I do not

I do

  • Draft and update procedures, policies and registers
  • Put appointments in order: resolutions, powers of attorney, lines of responsibility
  • Review new products and business models before they go live
  • Check provider contracts against outsourcing requirements (article 73 MiCA, article 30 DORA)
  • Train the team and the board
  • Prepare the business for inspections and handle correspondence with the regulator
  • Verify that procedures are applied in practice

I do not

  • Hold functions that require formal appointment within your organisation (articles 7 and 8 of the Polish AML Act and equivalents)
  • Sign filings and reports submitted by your company
  • Review transaction alerts or decide on client relationships
  • Replace a full-time hire or an internal audit function

What I learn about your business stays with your business. As an attorney-at-law I am bound by professional secrecy – indefinitely, and enforceable through professional liability. It is a statutory duty of the profession, not a clause in a contract. Consultants and advisory firms are not held to that standard.

The regimes I work in

Compliance does not run separately for each regulation. Inside one business, the same procedures have to satisfy several regimes at once – and that is usually harder than any of them taken alone.

Most of my work is under MiCA: CASP licensing, token classification, white papers, passporting. This is the core of the practice and where the experience runs deepest – licensing proceedings I have run, not advice given from a distance.

The second area is payment services: payment and e-money institutions, small payment institutions, safeguarding, proceedings before KNF (the Polish financial supervisor).

Alongside that, AML and the Travel Rule – in practice the most common source of inspection findings, whatever the sector. DORA – ICT risk management, the register of provider contracts, resilience testing; I have run an implementation of this with a client. And the AI Act, where the clients are mainly deployers: businesses that buy and use AI rather than build it. Role classification, obligations towards the provider, human oversight, information duties – a different set of requirements from the ones usually discussed in the context of model developers.

These are all EU regulations. They apply the same way in Warsaw, Tallinn and Nicosia – what differs is the procedure before the regulator, not the substance of the requirements.

Who does the work

Mateusz Świtalski
Mateusz Świtalski attorney-at-law (radca prawny), PZ-5181, Poznań Bar Association

Before advising from the outside, I ran compliance and licensing from within, in-house at a regulated financial institution. I know both sides: how a procedure reads on paper, and what the day looks like when someone has to make a decision under it.

Read full bio
  • CASP licensing proceedings under MiCA
  • Proceedings before KNF on payment institution matters
  • A DORA implementation delivered with a client – ICT risk management, provider contract register
  • AML and the Travel Rule – procedures, training, inspection readiness

I handle the matter myself. No account manager, no anonymous inbox, no juniors learning on your matter. As the team grows, the principle stays the same.

How we start

  1. A call – 30 minutes, no charge. You tell me what your business does, where you are in the process, and what is keeping you up. I tell you what follows from that and the range this kind of work falls into. You leave with a sense of the cost, even if you decide not to work together.
  2. Scope and engagement letter. You get a written proposal: what I do, by when, for how much. No hourly rates on Review and Implementation – you know the figure up front.
  3. Start. We agree one point of contact on your side and a schedule. First conversations with your teams usually within two weeks of signing.

You do not have to start with the Review. If you already know what needs doing, we go straight to Implementation.

How I bill

Review and Implementation – fixed fee. Set after our call, once I know the size of your organisation and how many regimes are in play. I do not bill by the hour and I do not add hours after the fact. The Review fee is credited against Implementation.

Ongoing counsel – monthly retainer. Scope is agreed at the outset and written into the engagement letter. Day-to-day matters sit inside the retainer, without pricing each one separately. Larger projects outside the agreed scope – a licence application, entry into a new market – are quoted separately, always before the work starts.

I give you the range on the first call. Before you spend time reading a proposal, you know whether you are in the right bracket.

Frequently asked questions

No. The law requires these functions to be held by people inside your organisation – under Polish AML rules, a board member and a senior manager (articles 7 and 8). I take on the work: procedures, appointments, training, contact with the regulator. The post stays on your side.

An employee is available every day, but is one person with one profile. Ongoing counsel gives you a lawyer who works across several regimes at once and has seen how they land in other businesses. Many organisations do both – an employee for daily operations, me for decisions and documentation.

Yes. MiCA, PSD2, DORA and the AI Act are EU law and apply uniformly across the Union. In Poland I represent clients directly. Elsewhere in the EU I run the project as lead counsel and work with a local firm where an opinion on national law is required.

It depends on scope. Delegating operational functions can trigger outsourcing requirements – article 73 MiCA for CASPs, article 30 DORA for ICT providers. I structure the engagement to meet those requirements and tell you what belongs in your register of contractual arrangements.

We start with the Review and test whether they match how the business actually runs. Documents are often correct but written for a different business model or a different regime. I do not rewrite everything – I fix what needs fixing.

When regulatory questions come up monthly rather than annually. New products, new markets, changes in the team, correspondence with the regulator. If you have one thing to close, a Review or an Implementation is enough.

As an attorney-at-law I am bound by professional secrecy – indefinitely, by statute, enforceable through professional liability. I will sign an NDA on request, but the duty exists regardless of any contract.

In Poland, yes, in full. Elsewhere in the EU I prepare the position and handle correspondence as lead counsel, and where local admission is required I bring in the firm I work with in that jurisdiction.

ongoing compliance counsel

Tell me what isn't working.

A new licence and procedures that haven't caught up. An inspection announced. Your compliance person gone. Or simply the question of whether what you have would survive the first inspection. Describe it in a few sentences – I'll reply within one business day, in English or Polish.

    Your data is used solely to respond to your message. Controller: Mateusz Świtalski Kancelaria Radcy Prawnego, Małachowskiego 8/P1, Poznań, info@switalski.law. Full details and your rights – Privacy Policy.

    1 business day
    Reply time
    Fixed fee
    Where possible
    NDA on request
    Standard wording

    Direct counsel – no account managers, no anonymous queue. · Confidential · EN / PL