Hands-on experience with a CASP application in Cyprus
Work on a CASP application before CySEC under MiCA – governance, programme of operations, prudential and safeguarding framework, and supervisory dialogue.
about · attorney-at-law in poland
Crypto, fintech & payments lawyer.
“Practitioner experience, not theory.”
I am a Polish attorney-at-law specialising in EU regulations for fintech, including crypto-assets and payments services. I help founders, directors and compliance teams of crypto exchanges, payment institutions, AI deployers and Web3 startups obtain relevant authorisation – CASP under MiCA, PSD2 payment licences – and stay compliant with AMLD6, DORA, the AI Act, the Travel Rule (TFR) and other regulations.
Attorney-at-law (radca prawny) · PZ-5181 · OIRP Poznań
what i do
A boutique practice with a focused service stack.
–
practitioner experience
Selected mandates and roles from a decade of practice.
Work on a CASP application before CySEC under MiCA – governance, programme of operations, prudential and safeguarding framework, and supervisory dialogue.
Upgrading an existing Estonian VASP registration toward CASP authorisation under MiCA – Finantsinspektsioon dialogue and entity restructuring.
Programmes of operations, capital and safeguarding planning, agent registers, outsourcing arrangements – including transitions from SPI to full PI as transaction volumes grew.
Regulated-activity mapping, AML/CFT frameworks aligned with FATF Recommendation 16 (Travel Rule), and TFR readiness for non-EU groups operating into the EU.
Led product and regulatory affairs: token listings, market-surveillance setup, terms and disclosures, regulator engagement, and incident response.
For fintech deployers of AI systems (Articles 26–27 AI Act) and financial entities under DORA (Chapters II–V): risk classification, technical documentation, ICT risk framework, TLPT readiness.
Admitted as attorney-at-law in 2021 (PZ-5181). Experience across private practice, in-house, and partner-level advisory in capital markets, payments and crypto.
frequently asked
Yes. Most of my CASP licensing engagements involve non-EU founders – typically from the UK, Switzerland, the US, the UAE, Hong Kong and Singapore – establishing an EU subsidiary in Poland or another Member State. I handle both the corporate setup and the CASP application end-to-end, in English. Under MiCA, the CASP authorisation is issued in a specific Member State and benefits from passporting across the EU/EEA.
The statutory decision period under Article 63(5) MiCA is 40 working days from confirmation that the application is complete. In practice, the regulator’s requests for clarification reset the clock multiple times. Realistic timeline from filing to authorisation is 6–9 months, assuming a clean application file and prompt responses.
Polish and English. Polish applications must be filed in Polish, but the engagement, drafting, client correspondence and regulator dialogue can be run entirely in English. Documents that must be filed in Polish are translated by sworn translators and reviewed against the English working version.
Yes – most mandates start with an incorporation. The typical vehicle is a sp. z o.o. (Polish limited liability company), structured to satisfy regulatory substance requirements: registered office, board composition, key staff, and articles of association tailored to the licensed activity. I also advise on cross-border holding-company structures.
Both. Licensing projects are typically run on fixed-fee milestones – payable as the work progresses (file preparation, submission, response to regulator, decision). Ongoing compliance is billed on a monthly retainer. Ad-hoc advisory is billed hourly. The engagement letter sets the model before any clock starts.
Yes. I have led 10+ Small Payment Institution and National Payment Institution licences before the KNF, and have structured combined CASP + Payment Institution architectures for fiat on-ramps and embedded-finance products. PSD3 / PSR transition is part of every payments mandate I run in 2026.
Yes. The AI Act (Regulation 2024/1689) applies to deployers as well as providers. For fintechs, the main exposure is around credit scoring, fraud detection, KYC automation and customer-facing chat. I deliver AI Act classification, conformity-assessment readiness, deployer-obligations gap analysis, and the internal AI literacy programme required since 2 February 2026.
For financial entities, DORA Chapter II–V applies in full. The deliverables I produce: ICT risk-management framework, incident classification and reporting workflow, third-party risk register and contractual remediation, TLPT readiness, and the information-sharing arrangements expected by competent authorities.
Email me directly at info@switalski.law with a short paragraph on what you are building and where you would like to be licensed. I reply within one business day, in English or Polish, and we book a free 30-minute call to scope the work.
still have a question?
A boutique firm means a real human reading your message. I reply within one business day, in English or Polish.