Skip to content

Regular AML reporting to the CNB

Who, what, and when must be sent

Regular AML reporting to the Czech National Bank is not one universal annual filing but a set of ongoing duties that depend on the type of regulated business and its activities. Firms need an up-to-date risk assessment, effective internal controls and reliable reporting processes, while suspicious transactions are reported separately. This article explains what must be reported, which authority receives it and how to stay ready for an inspection.

Professional discussing AML reporting requirements for the Czech National Bank.

Key takeaways

AML compliance in the Czech Republic is subject to dual supervision, which increases its complexity and associated risks. The Czech National Bank (CNB) focuses on prudential and statistical reporting for financial institutions, while the Financial Analytical Office (FAO) supervises the reporting of suspicious transactions (STRs) in the non-financial sector. Failure to comply with these obligations may result in financial penalties and reputational damage.
The CNB supervises the financial market and requires regular reporting through the SDAT system. Its authority extends to credit institutions, payment institutions, electronic money institutions, and investment firms and funds. For data collection, it utilizes the standardized electronic tool SDAT.
The FAO focuses on the non-financial sector and collects information on suspicious transactions. The FAO's supervision applies, for example, to real estate brokers, accountants, and tax advisors. Its primary role is the central collection and analysis of information on suspicious transactions (STRs).
The deadlines for AML reporting to the CNB vary depending on the type of institution. Financial services intermediaries must submit annual reports by 31 March of the following year. Large-scale payment institutions are additionally required to submit quarterly reports on payment transactions and semi-annual reports on fraud.
ARROWS law firm

Initial Analysis and Problem Definition

The problem with fulfilling these obligations lies not only in possible financial penalties but also in the huge reputational risk that can threaten the trust of banks and business partners. It is essential to realize that there is dual supervision in the Czech legal environment.

The CNB primarily monitors prudential and statistical reporting, which affects financial stability, while the Financial Analytical Unit (FAU) focuses on the reporting and investigation of Suspicious Transaction Reports (STRs). Effective compliance therefore requires a coordinated strategy for both authorities, and the Prague-based lawyers at ARROWS routinely handle this complex synergy. 

AML Reporting: CNB vs. FAU – Who Audits and Reports You?

For the correct setup of internal processes, a clear definition of the supervisory authorities' competencies is crucial, as obliged entities are often subject to the supervision of both. The scope of your obligations depends on whether you are supervised by the CNB, the FAU, or both.

Definition of Supervisory Authorities' Powers

The Czech National Bank (CNB) has supervisory authority over the financial market, which includes credit institutions, payment institutions, electronic money institutions, and investment companies and funds.

The CNB requires regular, statistical, and prudential reports that provide information on the financial situation, scope of activities, and internal AML/CFT culture. In contrast, the Financial Analytical Unit (FAU) supervises the non-financial sector (e.g., real estate agents, accountants, and tax advisors) and centrally collects and analyzes information on Suspicious Transactions.  

If a company has difficulties with data accuracy for the CNB, it is highly likely that it also has flawed internal controls, making it a risk factor for the FAU as well. Ensuring comprehensive compliance requires linking regulatory reporting (CNB) and internal processes (FAU).

The Role of the CNB in Reporting and How SDAT Works

The CNB uses a standardized electronic tool, SDAT (Data Collection System), to obtain data. Most obligations apply to financial institutions, which must report frequently. For example, financial services intermediaries submit annual reports by March 31 of the following year, which include information on their financial situation, operating results, and compliance with AML/CFT requirements.

Payment institutions (large-scale) also have an obligation of quarterly reporting on payment transactions and semi-annual fraud reporting. Correct and timely submission of reports via the SDAT system is essential to meet your information obligation to the Czech National Bank. 

DO YOU NEED LEGAL HELP?

Get in touch — we're happy to help.

ARROWS law firm

Practical Case: Alternative Funds (Minifunds under the ZISIF)

One of the most common sources of regulatory problems concerns alternative investment funds (so-called minifunds) under Section 15 of the Act on Investment Companies and Investment Funds (ZISIF). These entities are obliged to report the status of managed assets at the end of the calendar year (e.g., as of December 31) with the deadline for submitting reports usually by January 31 of the following year. The funds use the SDAT system to submit specific reports, such as ROFOS 36 and ROFOS 37.  

Owners of small or newly established funds often make a serious mistake. Reporting is mandatory for all alternative funds, including those with no assets or investors under management.

Failure to report this zero status is an administrative offense for the regulator, for which it can impose a sanction. For managers under Section 15(1) of the ZISIF, a new report, DOFOS15, is also being prepared from 2025, which relates to reporting the total number of investors and is submitted by June 30 of the following year.  

Real Consequences of Neglecting Reporting

Although the maximum fines that can be imposed for violations of AML/CFT regulations in the Czech Republic reach enormous amounts, for example, up to CZK 150,000,000 under the ZISIF or CZK 130,000,000 or 10% of net annual turnover in general AML cases, in practice, for minor administrative failures, fines in the order of tens of thousands of crowns are usually imposed. Nevertheless, even these lower fines are significant.

Furthermore, it is necessary to emphasize the risk of the entity being deleted from the CNB's list in case of long-term neglect of duties and non-communication, which leads to a de facto ban on activities. The experience of the ARROWS law firm in handling reporting obligations with the CNB has helped dozens of entities minimize these risks.  

Regulatory Reporting to the CNB (SDAT, ZISIF, and Others)

Regulatory reporting is a fundamental obligation, the neglect of which has direct and often very high penalties.

Risks and Penalties for Non-Reporting to CNB/SDAT

How ARROWS Helps (consultation@arws.cz)

A fine of up to CZK 150,000,000 under the ZISIF for omitting or late reporting of the status of managed assets.

Accurate preparation and timely submission of all regulatory reports (ROFOS 36, 37, DOFOS15) via the SDAT system. Contact consultation@arws.cz.

Deletion of the obliged entity from the CNB list, leading to a de facto ban on activities and loss of investments.

Legal consultation and representation in proceedings before the CNB, securing your license and business continuity. Write to consultation@arws.cz.

Failure to report zero asset status for investment funds, a common mistake for entities in their initial phase.

Review and implementation of reporting processes, including situations with zero assets, which the Prague-based lawyers at ARROWS routinely handle. Ask at consultation@arws.cz.

Penalties of up to CZK 130,000,000 or 10% of annual turnover for general AML/CFT offenses.

Legal audit and setup of complete AML documentation to protect against maximum penalties. consultation@arws.cz.

ARROWS law firm

Internal Compliance: The System of Internal Policies (SIP) as a Safety Net

The foundation for correct and timely fulfillment of reporting obligations to the CNB is flawless internal documentation and functional processes. Without them, reporting cannot be reliable. These internal processes are key to general AML/CFT compliance and are primarily supervised by the FAU, but their failure indirectly affects the CNB's assessment.

The SIP is not a paper document, but a living system

The System of Internal Policies (SIP) is a key document that describes in detail how your company identifies, manages, and mitigates the risks of money laundering. Supervisory authorities, including the CNB and FAU, consistently identify a common shortcoming: the purchase of generic, poorly adapted AML regulations that do not correspond to the client's actual processes. These systems exist only on paper, while practice differs.

A properly configured SIP must be developed in accordance with Section 21 of the AML Act and must always be appropriate to the specific activities of the Obliged Person.  

The Obliged Person is also required to notify the FAU of the written SIP, and it is necessary to comply with the submission requirements under the Administrative Procedure Code (e.g., electronic signature). Failure to send it with an electronic signature is considered a breach of duty. The Prague-based lawyers at ARROWS prepare internal policies that are tailored to the client's business and fully meet the demands of supervision.

Our specialists will help you

JUDr. Jakub Dohnal, Ph.D., LL.M.

JUDr. Jakub Dohnal, Ph.D., LL.M.

advokát, řídící partner

dohnal@arws.cz
Mgr. Jáchym Petřík

Mgr. Jáchym Petřík

advokát, partner

petrik@arws.cz
ARROWS law firm

Key Elements of the SIP that Supervisory Authorities Check

Supervisory authorities focus intensively on whether internal processes are truly functional and whether the company has sufficient human and technological capacity for them.

1. Risk Assessment: A necessary part of the SIP is the Risk Assessment. The Obliged Person must apply the comply or explain principle and sufficiently justify the chosen risk categories assigned to individual types of clients, products, or services. It is critical that money laundering risks cannot be confused with other risks, such as the risk of loan default.  

2. Governance: Regulations require that a member of the board of directors be designated in each institution as responsible for the AML area, and that this person has sufficient expertise and interest in the effective functioning of the processes. Ensuring sufficient expertise at the highest level is a key priority of CNB supervision.  

3. Training and Competence: According to Section 23 of the AML Act, employees must be trained at least once every 12 calendar months. The training must focus on practical scenarios, especially on identifying signs of Suspicious Transactions and on the correct identification and due diligence of the client.  

Legal Tips for Internal Policies

1. Does the board of directors have to approve the SIP, even if we are a small LLC?

Yes, responsibility for AML/CFT must be ensured at the highest management level, and a member of the statutory body must be designated as responsible for fulfilling the obligations. We will help you define responsibility and with documentation, contact consultation@arws.cz.

2. What is the real penalty for a missing SIP?

The absence of or an outdated System of Internal Policies is subject to a fine of up to CZK 1,000,000. We will prepare internal policies for you that will stand up to an audit. Ensure your compliance at consultation@arws.cz.  

ARROWS law firm

The Role of ARROWS in Setting Up the SIP and Control Measures

The ARROWS law firm understands that supervision focuses on the culture of compliance – that is, on the functionality and explainability of processes. We have extensive experience with the implementation of AML/CFT in large corporations and financial institutions, which is confirmed by our practice of preparing internal policies and documentation for 150 joint-stock companies and 250 LLCs.  

For our clients, we ensure the preparation of internal policies that include a tailored risk assessment and the preparation of documentation for supervisory authorities. A key element is also regular, practical AML training for employees. If your company does not have a system of internal policies in place, the Prague-based lawyers at ARROWS will create a tailored system of internal policies, risk assessment, and client due diligence procedures for your company, which will protect you from a fine of up to CZK 1,000,000.

International Dimension: How New EU Regulation is Changing the Game

For commercial companies and corporations with an international presence, as well as for investors and managers, AML compliance is much more complex. International standards require Enhanced Due Diligence (EDD) for transactions involving high-risk jurisdictions or Politically Exposed Persons (PEPs).  

Challenges of Group AML Function and Cross-Border Risks

Supervisory authorities consider it a priority that group compliance is strong enough to ensure the quality implementation of preventive measures across the individual institutions in the group.

At the same time, this governance must take into account local aspects and leave appropriate responsibility and flexibility in each country. If a client refuses to provide the necessary cooperation for identification, the obliged person is required not to carry out such a transaction and to report it as a suspicious transaction under Section 15 of the AML Act.  

If you are dealing with legal services and transactions outside the Czech Republic, the EU-based legal team at ARROWS International will help you set up compliance in local jurisdictions. The ARROWS law firm provides these international services thanks to the ARROWS International network, built over ten years, and deals with issues with an international element (Query requirement) on a practically daily basis.

Impact of the European AML Package (AMLR and AMLD6)

The European Union has carried out the most extensive reform in the fight against money laundering, resulting in the so-called AML Package of 2024. A key change is the transition from directives (requiring implementation into national law) to a directly applicable Regulation on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (AMLR). This change will ensure faster and stricter harmonization of rules across the EU.  

The new regulations will expand the range of obliged persons, for example, to include entities providing services related to virtual assets. Although the regulation's effective date is set for a later time, proactive companies that start preparing for these harmonized standards now will gain a competitive advantage through future-proof compliance.  Procedural Shortcomings and Internal Compliance

Procedural shortcomings in the System of Internal Policies are a frequent cause of fines imposed by the FAU and indirectly threaten reporting to the CNB.

Risks and Penalties for SIP/Process Shortcomings

How ARROWS Helps (consultation@arws.cz)

A fine of up to CZK 1,000,000 for an absent or outdated SIP that does not reflect business reality.

Preparation of tailored internal policies and Risk Assessment that will pass scrutiny by both the FAU and the CNB. Contact consultation@arws.cz.

Discrepancy between "paper" rules and actual practice (e.g., insufficient Enhanced Due Diligence EDD).

Legal audit of processes, review of risk settings, and ensuring the comply or explain principle for critical transactions. Write to consultation@arws.cz.

Ineffective employee training, leading to failure to detect Suspicious Transaction Reports (STRs).

Regular, practical AML training for employees, focused on typologies of suspicious transactions in your sector. Ask at consultation@arws.cz.

Failure to notify the FAU of the appointment of a contact person in the new, mandatory electronic format from February 1, 2025.

Quick handling of this administrative duty, including submission in the specified data structure via data box. consultation@arws.cz.

ARROWS law firm

Conclusion and Direct Call for Cooperation

AML reporting and overall compliance are dynamic areas, influenced not only by Czech laws but also by upcoming European regulations. It is crucial that legal obligations cannot be fulfilled retroactively. A quick and precise response to identified shortcomings is therefore key to reducing potential fines. Companies need a partner who is well-versed in both the specific data requirements of the CNB (SDAT) and the FAU's demands on internal systems (SIP).  

Our Prague-based law firm routinely handles complex AML issues for corporations and financial institutions and has extensive experience with supervisory authorities. Thanks to this practice, we can offer clients fast and effective solutions. Thanks to our extensive network and experience with clients (including 150 joint-stock companies, 250 LLCs, and 51 municipalities/regions), we can also effectively connect clients.

DO YOU NEED LEGAL HELP?

Get in touch — we're happy to help.

ARROWS law firm

Specific Offer of ARROWS Services

We don't just limit ourselves to consultations. We offer a complete portfolio of services that protect your business:

  1. Preparation of Policies: Preparation of a tailored SIP, Risk Assessment, and detailed preparation of documentation for supervisory authorities.

  2. Preparation for the CNB: Correct completion of regular reports for the CNB (SDAT, ROFOS, DOFOS) and ensuring timely submission.

  3. Legal Consultation and Compliance Audit: Ensuring group AML compliance through the ARROWS International network for international transactions.

  4. Representation: Active representation before the CNB and FAU in the event of administrative proceedings, with the aim of reducing fines and protecting the company's reputation.

Don't let regulatory reporting, whether it concerns SDAT reports for the CNB or the implementation of internal processes, jeopardize your business – contact us for a fast and effective solution at consultation@arws.cz. We are ready to support you.

FAQ – Most Common Legal Questions about AML Reporting to the CNB

1. What is the main difference between AML reporting for the CNB and for the FAU?

A: The CNB requires regular statistical and prudential reports (e.g., via SDAT) concerning stability and data on managed assets, financial situation, and scope of activities. The FAU primarily focuses on reporting Suspicious Transactions (STRs) that indicate potential criminal activity and checks the functionality of your System of Internal Policies. Contact consultation@arws.cz to be sure you are fulfilling your obligations to both authorities.

2. Does the regular reporting obligation to the CNB also apply to the non-financial sector?

A: The CNB primarily supervises financial institutions, investment companies, and intermediaries. Non-financial sector entities (e.g., accountants, real estate agents) primarily report to the FAU. However, all must comply with basic AML obligations (SIP, client identification), which also affects their cooperation with financial institutions. If you need to assess whether you are an obliged person, use a legal consultation at consultation@arws.cz.

3. What happens if, as an alternative fund, I don't submit the ROFOS reports on time?

A: You face a fine of up to CZK 150 million under the ZISIF and, in extreme cases, even deletion from the list of entities performing asset management. Although fines in practice may be in the tens of thousands, even late submission or incorrect data can lead to penalties. For a quick solution to reporting backlogs, contact ARROWS at consultation@arws.cz.

4. We are an international group. How should we ensure group AML compliance?

A: Group governance must be strong enough for uniform implementation of prevention (group compliance), but it must take local specifics into account. ARROWS will help you set up an effective group AML function through the ARROWS International network, which deals with cross-border issues daily. We will prepare a detailed strategy for your international reach at consultation@arws.cz.

5. What are the most common mistakes that the CNB/FAU uncover during an SIP inspection?

A: Most often, it is a discrepancy between written policies and actual practice, the absence of specific procedures for the given business, and insufficient, outdated employee training (which must take place at least once a year). Avoid unnecessary fines and have your SIP reviewed. Contact us at consultation@arws.cz.

6. How will the new EU AML Package (AMLR) affect us?

A: The 2024 AML Package introduces a directly applicable regulation (AMLR) that harmonizes rules across the EU and tightens requirements for the System of Internal Policies, Risk Assessment, and new entities (e.g., virtual asset service providers). Ensure timely adaptation to the new EU legislation, write to us at consultation@arws.cz.

DO YOU HAVE MORE QUESTIONS? GET IN TOUCH

ARROWS law firm

About the author

Mgr. Jáchym Petřík
Mgr. Jáchym Petřík

Associate, partner

Jáchym Petřík, as one of the partners and attorneys at ARROWS, focuses primarily on providing services to technology startups and clients operating in the financial markets, investment companies and persons seeking to secure investment projects both legally and in terms of securing financing.

Disclaimer:

The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.