Regular AML reporting to the CNB
Who, what, and when must be sent
Regular AML reporting to the Czech National Bank is not one universal annual filing but a set of ongoing duties that depend on the type of regulated business and its activities. Firms need an up-to-date risk assessment, effective internal controls and reliable reporting processes, while suspicious transactions are reported separately. This article explains what must be reported, which authority receives it and how to stay ready for an inspection.

Key takeaways
Initial Analysis and Problem Definition
The problem with fulfilling these obligations lies not only in possible financial penalties but also in the huge reputational risk that can threaten the trust of banks and business partners. It is essential to realize that there is dual supervision in the Czech legal environment.
The CNB primarily monitors prudential and statistical reporting, which affects financial stability, while the Financial Analytical Unit (FAU) focuses on the reporting and investigation of Suspicious Transaction Reports (STRs). Effective compliance therefore requires a coordinated strategy for both authorities, and the Prague-based lawyers at ARROWS routinely handle this complex synergy.
AML Reporting: CNB vs. FAU – Who Audits and Reports You?
For the correct setup of internal processes, a clear definition of the supervisory authorities' competencies is crucial, as obliged entities are often subject to the supervision of both. The scope of your obligations depends on whether you are supervised by the CNB, the FAU, or both.
Definition of Supervisory Authorities' Powers
The Czech National Bank (CNB) has supervisory authority over the financial market, which includes credit institutions, payment institutions, electronic money institutions, and investment companies and funds.
The CNB requires regular, statistical, and prudential reports that provide information on the financial situation, scope of activities, and internal AML/CFT culture. In contrast, the Financial Analytical Unit (FAU) supervises the non-financial sector (e.g., real estate agents, accountants, and tax advisors) and centrally collects and analyzes information on Suspicious Transactions.
If a company has difficulties with data accuracy for the CNB, it is highly likely that it also has flawed internal controls, making it a risk factor for the FAU as well. Ensuring comprehensive compliance requires linking regulatory reporting (CNB) and internal processes (FAU).
The Role of the CNB in Reporting and How SDAT Works
The CNB uses a standardized electronic tool, SDAT (Data Collection System), to obtain data. Most obligations apply to financial institutions, which must report frequently. For example, financial services intermediaries submit annual reports by March 31 of the following year, which include information on their financial situation, operating results, and compliance with AML/CFT requirements.
Payment institutions (large-scale) also have an obligation of quarterly reporting on payment transactions and semi-annual fraud reporting. Correct and timely submission of reports via the SDAT system is essential to meet your information obligation to the Czech National Bank.
Practical Case: Alternative Funds (Minifunds under the ZISIF)
One of the most common sources of regulatory problems concerns alternative investment funds (so-called minifunds) under Section 15 of the Act on Investment Companies and Investment Funds (ZISIF). These entities are obliged to report the status of managed assets at the end of the calendar year (e.g., as of December 31) with the deadline for submitting reports usually by January 31 of the following year. The funds use the SDAT system to submit specific reports, such as ROFOS 36 and ROFOS 37.
Owners of small or newly established funds often make a serious mistake. Reporting is mandatory for all alternative funds, including those with no assets or investors under management.
Failure to report this zero status is an administrative offense for the regulator, for which it can impose a sanction. For managers under Section 15(1) of the ZISIF, a new report, DOFOS15, is also being prepared from 2025, which relates to reporting the total number of investors and is submitted by June 30 of the following year.
Real Consequences of Neglecting Reporting
Although the maximum fines that can be imposed for violations of AML/CFT regulations in the Czech Republic reach enormous amounts, for example, up to CZK 150,000,000 under the ZISIF or CZK 130,000,000 or 10% of net annual turnover in general AML cases, in practice, for minor administrative failures, fines in the order of tens of thousands of crowns are usually imposed. Nevertheless, even these lower fines are significant.
Furthermore, it is necessary to emphasize the risk of the entity being deleted from the CNB's list in case of long-term neglect of duties and non-communication, which leads to a de facto ban on activities. The experience of the ARROWS law firm in handling reporting obligations with the CNB has helped dozens of entities minimize these risks.
Regulatory Reporting to the CNB (SDAT, ZISIF, and Others)
Regulatory reporting is a fundamental obligation, the neglect of which has direct and often very high penalties.
Risks and Penalties for Non-Reporting to CNB/SDAT | How ARROWS Helps (consultation@arws.cz) |
A fine of up to CZK 150,000,000 under the ZISIF for omitting or late reporting of the status of managed assets. | Accurate preparation and timely submission of all regulatory reports (ROFOS 36, 37, DOFOS15) via the SDAT system. Contact consultation@arws.cz. |
Deletion of the obliged entity from the CNB list, leading to a de facto ban on activities and loss of investments. | Legal consultation and representation in proceedings before the CNB, securing your license and business continuity. Write to consultation@arws.cz. |
Failure to report zero asset status for investment funds, a common mistake for entities in their initial phase. | Review and implementation of reporting processes, including situations with zero assets, which the Prague-based lawyers at ARROWS routinely handle. Ask at consultation@arws.cz. |
Penalties of up to CZK 130,000,000 or 10% of annual turnover for general AML/CFT offenses. | Legal audit and setup of complete AML documentation to protect against maximum penalties. consultation@arws.cz. |
Internal Compliance: The System of Internal Policies (SIP) as a Safety Net
The foundation for correct and timely fulfillment of reporting obligations to the CNB is flawless internal documentation and functional processes. Without them, reporting cannot be reliable. These internal processes are key to general AML/CFT compliance and are primarily supervised by the FAU, but their failure indirectly affects the CNB's assessment.
The SIP is not a paper document, but a living system
The System of Internal Policies (SIP) is a key document that describes in detail how your company identifies, manages, and mitigates the risks of money laundering. Supervisory authorities, including the CNB and FAU, consistently identify a common shortcoming: the purchase of generic, poorly adapted AML regulations that do not correspond to the client's actual processes. These systems exist only on paper, while practice differs.
A properly configured SIP must be developed in accordance with Section 21 of the AML Act and must always be appropriate to the specific activities of the Obliged Person.
The Obliged Person is also required to notify the FAU of the written SIP, and it is necessary to comply with the submission requirements under the Administrative Procedure Code (e.g., electronic signature). Failure to send it with an electronic signature is considered a breach of duty. The Prague-based lawyers at ARROWS prepare internal policies that are tailored to the client's business and fully meet the demands of supervision.
Key Elements of the SIP that Supervisory Authorities Check
Supervisory authorities focus intensively on whether internal processes are truly functional and whether the company has sufficient human and technological capacity for them.
1. Risk Assessment: A necessary part of the SIP is the Risk Assessment. The Obliged Person must apply the comply or explain principle and sufficiently justify the chosen risk categories assigned to individual types of clients, products, or services. It is critical that money laundering risks cannot be confused with other risks, such as the risk of loan default.
2. Governance: Regulations require that a member of the board of directors be designated in each institution as responsible for the AML area, and that this person has sufficient expertise and interest in the effective functioning of the processes. Ensuring sufficient expertise at the highest level is a key priority of CNB supervision.
3. Training and Competence: According to Section 23 of the AML Act, employees must be trained at least once every 12 calendar months. The training must focus on practical scenarios, especially on identifying signs of Suspicious Transactions and on the correct identification and due diligence of the client.
The Role of ARROWS in Setting Up the SIP and Control Measures
The ARROWS law firm understands that supervision focuses on the culture of compliance – that is, on the functionality and explainability of processes. We have extensive experience with the implementation of AML/CFT in large corporations and financial institutions, which is confirmed by our practice of preparing internal policies and documentation for 150 joint-stock companies and 250 LLCs.
For our clients, we ensure the preparation of internal policies that include a tailored risk assessment and the preparation of documentation for supervisory authorities. A key element is also regular, practical AML training for employees. If your company does not have a system of internal policies in place, the Prague-based lawyers at ARROWS will create a tailored system of internal policies, risk assessment, and client due diligence procedures for your company, which will protect you from a fine of up to CZK 1,000,000.
International Dimension: How New EU Regulation is Changing the Game
For commercial companies and corporations with an international presence, as well as for investors and managers, AML compliance is much more complex. International standards require Enhanced Due Diligence (EDD) for transactions involving high-risk jurisdictions or Politically Exposed Persons (PEPs).
Challenges of Group AML Function and Cross-Border Risks
Supervisory authorities consider it a priority that group compliance is strong enough to ensure the quality implementation of preventive measures across the individual institutions in the group.
At the same time, this governance must take into account local aspects and leave appropriate responsibility and flexibility in each country. If a client refuses to provide the necessary cooperation for identification, the obliged person is required not to carry out such a transaction and to report it as a suspicious transaction under Section 15 of the AML Act.
If you are dealing with legal services and transactions outside the Czech Republic, the EU-based legal team at ARROWS International will help you set up compliance in local jurisdictions. The ARROWS law firm provides these international services thanks to the ARROWS International network, built over ten years, and deals with issues with an international element (Query requirement) on a practically daily basis.
Impact of the European AML Package (AMLR and AMLD6)
The European Union has carried out the most extensive reform in the fight against money laundering, resulting in the so-called AML Package of 2024. A key change is the transition from directives (requiring implementation into national law) to a directly applicable Regulation on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (AMLR). This change will ensure faster and stricter harmonization of rules across the EU.
The new regulations will expand the range of obliged persons, for example, to include entities providing services related to virtual assets. Although the regulation's effective date is set for a later time, proactive companies that start preparing for these harmonized standards now will gain a competitive advantage through future-proof compliance. Procedural Shortcomings and Internal Compliance
Procedural shortcomings in the System of Internal Policies are a frequent cause of fines imposed by the FAU and indirectly threaten reporting to the CNB.
Risks and Penalties for SIP/Process Shortcomings | How ARROWS Helps (consultation@arws.cz) |
A fine of up to CZK 1,000,000 for an absent or outdated SIP that does not reflect business reality. | Preparation of tailored internal policies and Risk Assessment that will pass scrutiny by both the FAU and the CNB. Contact consultation@arws.cz. |
Discrepancy between "paper" rules and actual practice (e.g., insufficient Enhanced Due Diligence EDD). | Legal audit of processes, review of risk settings, and ensuring the comply or explain principle for critical transactions. Write to consultation@arws.cz. |
Ineffective employee training, leading to failure to detect Suspicious Transaction Reports (STRs). | Regular, practical AML training for employees, focused on typologies of suspicious transactions in your sector. Ask at consultation@arws.cz. |
Failure to notify the FAU of the appointment of a contact person in the new, mandatory electronic format from February 1, 2025. | Quick handling of this administrative duty, including submission in the specified data structure via data box. consultation@arws.cz. |
Conclusion and Direct Call for Cooperation
AML reporting and overall compliance are dynamic areas, influenced not only by Czech laws but also by upcoming European regulations. It is crucial that legal obligations cannot be fulfilled retroactively. A quick and precise response to identified shortcomings is therefore key to reducing potential fines. Companies need a partner who is well-versed in both the specific data requirements of the CNB (SDAT) and the FAU's demands on internal systems (SIP).
Our Prague-based law firm routinely handles complex AML issues for corporations and financial institutions and has extensive experience with supervisory authorities. Thanks to this practice, we can offer clients fast and effective solutions. Thanks to our extensive network and experience with clients (including 150 joint-stock companies, 250 LLCs, and 51 municipalities/regions), we can also effectively connect clients.
Specific Offer of ARROWS Services
We don't just limit ourselves to consultations. We offer a complete portfolio of services that protect your business:
Preparation of Policies: Preparation of a tailored SIP, Risk Assessment, and detailed preparation of documentation for supervisory authorities.
Preparation for the CNB: Correct completion of regular reports for the CNB (SDAT, ROFOS, DOFOS) and ensuring timely submission.
Legal Consultation and Compliance Audit: Ensuring group AML compliance through the ARROWS International network for international transactions.
Representation: Active representation before the CNB and FAU in the event of administrative proceedings, with the aim of reducing fines and protecting the company's reputation.
Don't let regulatory reporting, whether it concerns SDAT reports for the CNB or the implementation of internal processes, jeopardize your business – contact us for a fast and effective solution at consultation@arws.cz. We are ready to support you.
About the author
Read also:
- How to prepare for administrative proceedings at the CNB: Legal and documentation minimum
- Compliance audits: How to conduct an internal audit before the authorities arrive
- Holding Structures and Beneficial Ownership in the Czech Republic: Compliance Checklist
- Operating Without a Licence in the Czech Republic: Legal Consequences Explained
- GDPR inspections in practice: how investigations by the Office for Personal Data Protection are conducted
Disclaimer:
The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.

