Compliance Officer Outsourcing for Regulated Businesses
I take on the compliance workload: procedures, appointments, training, inspection readiness and contact with the regulator. MiCA, payment services, AML, DORA, the AI Act. Three ways to work together: a one-off review, an implementation with an end date, or ongoing counsel on a monthly retainer.
Direct counsel from the attorney handling your matter – not an account manager.
The short answer
Compliance officer outsourcing means handing the compliance workload to an external lawyer: drafting and updating procedures, putting appointments in order, training the team, preparing for inspections and handling correspondence with the regulator. It does not cover holding the functions the law requires you to assign within your own organisation – under Polish AML rules, a board member and a senior manager (articles 7 and 8). I work in three formats: a one-off review ending in a memo, an implementation with a set end date, and ongoing counsel on a monthly retainer.
Compliance officer outsourcing – what it actually means
I take on the work, not the post.
I build and maintain compliance inside your business: procedures, appointments, training, contact with the regulator. I go deep enough into the organisation to know it from the inside, and I stay.
What I do not take on are the functions the law requires you to assign to someone within your own organisation. Appointing the board member and the senior manager responsible for AML (articles 7 and 8 of the Polish AML Act, and their equivalents across the EU) is yours to do – as are operational decisions on live matters.
My job is to make sure those people are properly appointed, working from current procedures, and backed by a lawyer who knows their business. That is the difference between advising from the outside and actually running compliance.
02
When to consider this
>You have the licence and now everything has to work. During the application, documents were enough. From the day of authorisation, the regulator looks at whether the business actually runs that way.
>You are growing faster than your procedures. New product, new market, new people – and the policies are still last year's.
>Your compliance person has left. The knowledge went with them, and hiring for that role takes months.
>An inspection has been announced, or a request for information has arrived. You need someone to establish the facts and prepare the response before you answer on your own.
>You are entering a new EU market. Passporting (article 65 MiCA, article 28 PSD2) is not a formality – it means a new supervisor and new expectations of your procedures.
You do not need a compliance team to start. You only need to know that the current setup will not survive the first inspection.
03
Three ways to work together
01
Review
The starting point when it is not yet clear where the gaps are, or how serious.
I start with your organisation. Who is responsible for what, and whether the people holding statutory functions were appointed correctly. I establish where board responsibility ends and the operational level begins.
Next come the documents: procedures, policies, contracts with providers and related entities. I also talk to the teams that work with those procedures every day.
Then I check how it works in practice – whether the documents describe what actually happens. This is where problems usually surface. An inspection spots the gap quickly; your team rarely sees it from the inside.
You get
a memo listing the gaps by risk and urgency, with specific recommendations, plus a working session on the findings and the order of work.
The Review fee is credited against Implementation.
02
Implementation
For when you know what needs fixing and want it closed by a set date.
I draft and revise your procedures and policies – not templates, but documents built around how your business actually runs. I put the appointments in order: resolutions, powers of attorney, defined lines of responsibility. I review contracts with providers and related entities against outsourcing requirements.
Then I hand it over to the team. I train the people who will use these procedures and walk through the first live runs of the process. A document nobody knows how to apply does not work – not in the business, and not in an inspection.
You get
the full documentation in place, a trained team, and written confirmation that the recommendations from the Review have been implemented and are being applied.
Implementation has a defined scope and end date. The fee is fixed, not hourly.
03
Ongoing counsel
For when the procedures are in place and you need someone making sure they stay that way.
I am available as matters arise: assessing new products and new markets before they go live, preparing your team for inspections, and helping with correspondence to the regulator. I update the documentation when the rules change or your business model does – usually the second moves faster than the first.
Once a quarter I check whether the procedures still match what the business actually does. It is the same test as in the Review, run regularly and before someone external runs it for you.
I do not hold functions that require formal appointment within your organisation, and I do not make operational decisions for you. My role is to make sure the people who do have solid ground to stand on.
You get
direct access to me, a quarterly review, and responses to day-to-day matters without pricing each one separately.
Scope and the monthly fee are set at the outset, sized to your organisation.
04
What I do, and what I do not
I do
>Draft and update procedures, policies and registers
>Put appointments in order: resolutions, powers of attorney, lines of responsibility
>Review new products and business models before they go live
>Prepare the business for inspections and handle correspondence with the regulator
>Verify that procedures are applied in practice
I do not
>Hold functions that require formal appointment within your organisation (articles 7 and 8 of the Polish AML Act and equivalents)
>Sign filings and reports submitted by your company
>Review transaction alerts or decide on client relationships
>Replace a full-time hire or an internal audit function
What I learn about your business stays with your business. As an attorney-at-law I am bound by professional secrecy – indefinitely, and enforceable through professional liability. It is a statutory duty of the profession, not a clause in a contract. Consultants and advisory firms are not held to that standard.
05
The regimes I work in
Compliance does not run separately for each regulation. Inside one business, the same procedures have to satisfy several regimes at once – and that is usually harder than any of them taken alone.
Most of my work is under MiCA: CASP licensing, token classification, white papers, passporting. This is the core of the practice and where the experience runs deepest – licensing proceedings I have run, not advice given from a distance.
The second area is payment services: payment and e-money institutions, small payment institutions, safeguarding, proceedings before KNF (the Polish financial supervisor).
Alongside that, AML and the Travel Rule – in practice the most common source of inspection findings, whatever the sector. DORA – ICT risk management, the register of provider contracts, resilience testing; I have run an implementation of this with a client. And the AI Act, where the clients are mainly deployers: businesses that buy and use AI rather than build it. Role classification, obligations towards the provider, human oversight, information duties – a different set of requirements from the ones usually discussed in the context of model developers.
These are all EU regulations. They apply the same way in Warsaw, Tallinn and Nicosia – what differs is the procedure before the regulator, not the substance of the requirements.
06
Who does the work
Mateusz Świtalskiattorney-at-law (radca prawny), PZ-5181, Poznań Bar Association
Before advising from the outside, I ran compliance and licensing from within, in-house at a regulated financial institution. I know both sides: how a procedure reads on paper, and what the day looks like when someone has to make a decision under it.
>Proceedings before KNF on payment institution matters
>A DORA implementation delivered with a client – ICT risk management, provider contract register
>AML and the Travel Rule – procedures, training, inspection readiness
I handle the matter myself. No account manager, no anonymous inbox, no juniors learning on your matter. As the team grows, the principle stays the same.
07
How we start
01A call – 30 minutes, no charge. You tell me what your business does, where you are in the process, and what is keeping you up. I tell you what follows from that and the range this kind of work falls into. You leave with a sense of the cost, even if you decide not to work together.
02Scope and engagement letter. You get a written proposal: what I do, by when, for how much. No hourly rates on Review and Implementation – you know the figure up front.
03Start. We agree one point of contact on your side and a schedule. First conversations with your teams usually within two weeks of signing.
You do not have to start with the Review. If you already know what needs doing, we go straight to Implementation.
08
How I bill
Review and Implementation – fixed fee. Set after our call, once I know the size of your organisation and how many regimes are in play. I do not bill by the hour and I do not add hours after the fact. The Review fee is credited against Implementation.
Ongoing counsel – monthly retainer. Scope is agreed at the outset and written into the engagement letter. Day-to-day matters sit inside the retainer, without pricing each one separately. Larger projects outside the agreed scope – a licence application, entry into a new market – are quoted separately, always before the work starts.
I give you the range on the first call. Before you spend time reading a proposal, you know whether you are in the right bracket.
09
Frequently asked questions
No. The law requires these functions to be held by people inside your organisation – under Polish AML rules, a board member and a senior manager (articles 7 and 8). I take on the work: procedures, appointments, training, contact with the regulator. The post stays on your side.
An employee is available every day, but is one person with one profile. Ongoing counsel gives you a lawyer who works across several regimes at once and has seen how they land in other businesses. Many organisations do both – an employee for daily operations, me for decisions and documentation.
Yes. MiCA, PSD2, DORA and the AI Act are EU law and apply uniformly across the Union. In Poland I represent clients directly. Elsewhere in the EU I run the project as lead counsel and work with a local firm where an opinion on national law is required.
It depends on scope. Delegating operational functions can trigger outsourcing requirements – article 73 MiCA for CASPs, article 30 DORA for ICT providers. I structure the engagement to meet those requirements and tell you what belongs in your register of contractual arrangements.
We start with the Review and test whether they match how the business actually runs. Documents are often correct but written for a different business model or a different regime. I do not rewrite everything – I fix what needs fixing.
When regulatory questions come up monthly rather than annually. New products, new markets, changes in the team, correspondence with the regulator. If you have one thing to close, a Review or an Implementation is enough.
As an attorney-at-law I am bound by professional secrecy – indefinitely, by statute, enforceable through professional liability. I will sign an NDA on request, but the duty exists regardless of any contract.
In Poland, yes, in full. Elsewhere in the EU I prepare the position and handle correspondence as lead counsel, and where local admission is required I bring in the firm I work with in that jurisdiction.
ongoing compliance counsel
Tell me what isn't working.
A new licence and procedures that haven't caught up. An inspection announced. Your compliance person gone. Or simply the question of whether what you have would survive the first inspection. Describe it in a few sentences – I'll reply within one business day, in English or Polish.
Your data is used solely to respond to your message. Controller: Mateusz Świtalski Kancelaria Radcy Prawnego, Małachowskiego 8/P1, Poznań, info@switalski.law. Full details and your rights – Privacy Policy.
1 business day
Reply time
Fixed fee
Where possible
NDA on request
Standard wording
Direct counsel – no account managers, no anonymous queue. · Confidential · EN / PL
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.