The typical course of events is fairly repetitive: first, a signal appears (an audit, inspection, notification, conflict within the company, data incident or contractor claim), then documents and correspondence are secured, followed by actions by the authorities (summonses, searches, questioning, seizure of items and account freezes). At the same time, reputational risk and the risk of operational paralysis increase. The good news is that most of these risks can be significantly reduced by approaching the matter as a process and establishing a clear division of roles.

1) Identify areas where criminal risk is real (not theoretical)

In Poland, criminal liability in business often materialises not in “major fraud” cases, but in matters that begin as a commercial dispute, shareholder conflict, tax audit or compliance incident. During the first 30–60 days after starting operations, it is worth mapping the risks and linking them to specific company processes.

  • Economic criminal law: allegations concerning fraud, abuse of trust, document forgery, unlawful obtaining of information and acting to the detriment of a company.
  • Fiscal criminal proceedings: risks connected with settlements, documentation, invoice circulation, due diligence and discrepancies between the factual situation and the documents.
  • Data and cyber incidents: a criminal aspect may arise alongside the regulatory one (e.g. in cases of unauthorised access, leaks, loss of media or sabotage).
  • Internal disputes: a conflict within the management board or between shareholders often ends with notifications to the prosecutor’s office “to secure one’s position” in a civil dispute.
  • Reputational risk: even the “checking” stage by the authorities can trigger reactions from banks, insurers, partners and customers.

Under UK/US standards, many issues “remain” within the civil-law regime, while criminal proceedings are initiated in narrower categories and follow different dynamics. In Poland, it is worth assuming that a dispute over money, documents or control of assets can quickly move to the prosecutor’s office, changing the rules of the game.

2) Establish rules for the circulation of documents and decisions (this is the fuel for proceedings)

In practice, criminal and fiscal criminal proceedings are “proceedings about documents”: contracts, annexes, minutes, resolutions, email and messenger correspondence, files on drives, system data, as well as notes and calendars. The first operational decision should be to implement minimum but enforceable standards for documenting decisions.

  1. Single source of truth: where contracts, annexes, powers of attorney, minutes and project correspondence are stored.
  2. Versioning and approvals: who approves key provisions, who approves final versions and how the “why this way” (business rationale) is documented.
  3. Communication policy: rules for using messengers and private email for company matters, including archiving issues.
  4. Data retention: actual data storage and deletion periods, consistent with litigation and inspection risks.
  5. Permissions and access: who has access to which data, including financial and HR repositories.

This is not “corporate bureaucracy”. It is a mechanism that limits the risk of allegations that decisions were merely formal, undocumented, made without due diligence or in a conflict of interest.

3) Define the liability boundaries of managers and signatories (D&O in practice)

In many international groups, broad delegation of signing authority and powers is standard, often based on practice rather than current documents. In Poland, this is a frequent flashpoint in economic criminal cases: who was authorised, who actually made the decision, who had a duty of supervision and who “could have prevented it”.

  • Power-of-attorney matrix: clearly specify who may sign contracts, incur obligations, initiate payments and submit statements to authorities, and within which limits.
  • Escalation paths: when a matter must go to the management board, headquarters, compliance or a lawyer.
  • Conflicts of interest: simple procedures for recusing oneself from decisions and documenting that the conflict was identified.
  • D&O insurance: merely having a policy is not enough if the decision-making process and documents do not meet the required standard.

If the management board and key managers are to have genuine confidence to act, they need not only insurance but also a practical evidentiary system: documents showing due diligence and a logical decision-making process.

4) Prepare a plan for an inspection, search and seizure (the first 24 hours)

One of the biggest differences between an “academic” and a business approach is that a company should know what to do before a problem arises. In Poland, actions by the authorities can be dynamic, and improvisation during the first hours generates costs and risks for months.

The minimum response plan should include:

  • List of people: who receives the authorities, who contacts the lawyer, who is responsible for IT and data security, and who communicates with headquarters.
  • Rules of conduct: how to respond to requests to surrender documents, how to document the course of activities and how to maintain consistency of information.
  • Protection of data and secrets: how to identify sensitive data, trade secrets, personal data and information covered by confidentiality obligations.
  • Crisis communication: simple rules specifying who may say what to employees, partners, the media and banks.

In practice, companies benefit from a “one-pager” for reception and on-duty managers: a few steps, contact numbers, a rule against taking hasty action and the rapid involvement of defence counsel. This limits the risk of accidental errors that are difficult to undo later.

5) Internal reports and “whistleblowing”: set it up so that it does not generate proceedings

Internal reporting mechanisms make sense only when a company can quickly assess the credibility of a report, secure the material and take proportionate action. Otherwise, the risk increases that the report will become a source of parallel notifications to the authorities, employment disputes and allegations of obstructing clarification of the matter.

  1. Triage: who assesses the report within 24–72 hours and what the criteria are for “urgent vs. standard”.
  2. Evidence-first: before broad communication begins, data must be secured and the critical documents identified.
  3. Separation of roles: HR, compliance and the lawyer should not always handle the same thread, especially when criminal risk arises.
  4. Protection of individuals: rules against discriminating against whistleblowers and limiting “retaliatory” personnel moves without analysing the risks.

In an international model, it is often assumed that an internal investigation “closes” the matter. In Poland, one must reckon with the fact that some categories of cases may require a parallel strategy: employment-related, regulatory and criminal.

6) Disputes with contractors: filter them through criminal risk from the outset

A common scenario on the Polish market looks like this: a dispute over payment or quality of performance turns into an allegation of “fraud” or “acting to the detriment”. For a foreign company, this can be surprising because the usual intention is to strengthen its negotiating position, not to seek a conviction. The side effects are nevertheless real: questioning, seizures, freezes, reputational damage and uncertainty among banks.

Initial decisions that limit this risk:

  • Evidentiary standard: acceptance reports, a complaints process, and documentation of arrangements and changes in scope.
  • Clear payment rules: schedules, milestones, conditions for withholding payment, interest and security measures.
  • Dispute escalation mechanism: business-level negotiations, then mediation/ADR, and only thereafter hard-fought litigation.
  • Communication control: avoiding wording that may be taken out of context as an “admission” or an unsupported promise.

If a dispute begins to take the form of “blackmail involving a notification”, it is worth developing an evidentiary and communication strategy immediately rather than reacting solely emotionally or on an ad hoc basis.

7) Minimum implementation package: what to have ready within 2–4 weeks

There is no need to start with an extensive compliance programme. A set of documents and processes that work in reality and are known to the people involved is enough. Below is a package that often offers the best ratio of cost to reduction of criminal risk.

  1. Powers and authorisations matrix (signatures, payments, obligations and contact with authorities).
  2. Contract and decision circulation policy (repository, approvals, versioning and justifications).
  3. Procedure for responding to an inspection and search (roles, contacts, rules of conduct and IT).
  4. Basic training for the management board and key operational personnel (what is permitted, what not to do and how not to escalate risks).
  5. Internal incident investigation procedure (triage, data preservation and decisions on further steps).

If you work with a partner who understands cross-border realities, it is easier to establish a standard comparable to the UK/US standard but operationally adapted to the practice of Polish authorities. In such projects, support from a team such as law firm poland, operating within the law firm Kopeć & Zaborowski Adwokaci i Radcowie Prawni, is often crucial; it combines an international perspective with local dispute and defence practice.

The most common mistakes when entering the PL market (from a criminal-risk perspective)

  • No process “owners”: everyone is “doing something”, but no one is responsible for the completeness of documents and decisions.
  • Communication through private channels: key arrangements in messengers without archiving or context.
  • Overly broad authorisations or outdated authorisations: a mismatch between the paperwork and reality.
  • Ignoring “minor” signals: a conflict with a contractor, a signal from an employee, an unusual inspection or a request for documents.
  • Ad hoc action during the first inspection: nervously handing over documents without recording the process, unnecessary conversations and IT chaos.
  • Lack of a consistent narrative: different people say different things, which later reappears in minutes and testimony.

If the matter is urgent or concerns cross-border risks (regulatory, tax or litigation-related), it is worth consulting a team that combines Polish-market practice with international experience.

FAQ

1) Do management board members in Poland genuinely risk criminal liability for business decisions?

Yes, especially when there is an allegation of acting to the detriment of the company, abuse of trust, document forgery or a fiscal criminal aspect. The key question is whether due diligence, the business rationale for the decision and the proper decision-making process can be demonstrated.

2) What should you do when a contractor threatens to “report you to the prosecutor’s office” in a payment dispute?

Do not escalate emotionally. Secure the documents, organise the timeline of events, harmonise communications and prepare an evidentiary strategy. It is often also sensible to pursue a parallel negotiation or ADR path, but without concessions that could look like an admission of guilt.

3) How should a company prepare for a search or the seizure of documents?

The best approach is to have a short procedure and designated roles: a lawyer’s contact details, an IT person and a person responsible for contract and document repositories. The key elements are documenting the course of activities, controlling the flow of information and protecting sensitive data.

4) Can an internal investigation be harmful?

It can be if conducted chaotically: without securing data, separating roles, unnecessary internal communication or hasty personnel decisions. A well-planned investigation usually reduces risks and enables prompt operational decisions.

5) Is “paper compliance” enough?

No. In practice, what matters is whether people know the procedures, whether they work in real situations and whether the company can demonstrate consistent application of the standards (document circulation, approvals, training and incident response).

6) What are the first signs that a matter may move onto a criminal track?

Threats of notification, demands to provide documents “immediately”, shareholder conflicts, sudden inspections, unusual questions from authorities about decision-makers and attempts to shift responsibility onto specific individuals. IT or data incidents may also be signs when unauthorised access is involved.

7) What is most important during the first 24–72 hours of a crisis?

Secure data and documents, establish a single version of the facts based on the evidence, designate contact persons and engage professional legal assistance. At the same time, it is worth limiting internal communication to the necessary minimum.

Bibliography (real sources only)

  • Act of 6 June 1997 – Criminal Code (Journal of Laws 1997 No. 88, item 553, as amended).
  • Act of 6 June 1997 – Code of Criminal Procedure (Journal of Laws 1997 No. 89, item 555, as amended).
  • Act of 10 September 1999 – Fiscal Penal Code (Journal of Laws 1999 No. 83, item 930, as amended).
  • Act of 29 August 1997 – Banking Law (Journal of Laws 1997 No. 140, item 939, as amended).
  • Act of 10 May 2018 on the Protection of Personal Data (Journal of Laws 2018, item 1000, as amended).
  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).
  • The Republic of Poland’s website – Internet System of Legal Acts (ISAP): https://isap.sejm.gov.pl/