An outline is a starting point. Completed policies must describe actual services, statutory methods and operational decisions. Each chapter should tell staff when to act, what to verify, where to save evidence and whom to contact.
Translate requirements into operations
Section 21(5) specifies written-policy content: relevant suspicious indicators, identification including PEPs and sanctions, due diligence, risk management, records and disclosure, reporting workflows and organisational rules. Guideline 11’s annex provides a non-financial outline. Adapt it to applicability, activities and actual work allocation.
Specify identification methods and conditions. If no statutory remote method is implemented, do not claim an ordinary questionnaire satisfies it. Link risk factors to measures. Define storage, access, export and retention. A generic software handles it statement does not explain who decided or on what evidence.
Set decision points and cover
Describe onboarding, incomplete evidence, sanctions alerts, PEP status, owner changes, discrepancies and possible suspicion. Each branch needs a responsible role, reachable contacts and continuation conditions. Separate commercial acceptance from statutory response. Do not disclose suspicion details to clients or in shared exports.
Address staff absence, software outages and unavailable lists. A process relying on one person and password can fail during leave. Set alternatives and permission limits. Providers and other workers need rules matching their work; a contractual claim of legal knowledge is not an operational procedure.
Test implementation with a model case
After approval, walk a synthetic case from initial data to retention and possible escalation. Check that procedures match application fields and roles. Repair gaps and train staff on the new version. Update for law, products, client risk and observed defects. Adopting or submitting a template is not itself legal approval of its content.
Maintain one operative version
Each approved version should show its applicability date, approving role and material changes. Retain older versions as historical evidence while clearly providing workers the current one. When an escalation contact changes, update the application, training and cover. When identification methods change, update their conditions and evidence requirements. Separate documents must not give contradictory instructions for the same case.
Include failures in the test case: an unavailable source, client refusal to cooperate or absent approver. Check that workers recognise their authority limits and can escalate securely. If the procedure requires a statutory action the tool does not perform, describe the manual follow-up. A template is not ready merely because it contains every heading; it is ready when material decisions match actual roles, methods and evidence.
Practical steps
- Assess applicability and use a current outline.
- Add methods, roles and evidence.
- Set escalation, cover and outage handling.
- Approve and test a model case.
Illustrative scenario
An office changes screening providers and updates sources, alert resolution, exports and alternatives, then informs staff.
When the situation differs
Policies describe biometric identification the firm does not implement and call the result verified identity.
What to document
- Approved policies linked to risks.
- Roles and evidence of staff familiarisation.
- Model walkthrough result.
Common pitfalls
- Merely changing the business name in a template.
- Paper controls without operational capability.
Frequently asked questions
Is an FAÚ template a completed policy?
It supports structure. Content must fit your statutory branch, risks and actual practice.
Put this guidance into practice
Choose a record for the step you are working on. Adapt it to your profession and actual case.
Complete client information online
Where to go next
- Risk assessment and internal policies: what your business needs — Applicability, written form and exceptions for risk assessment and internal policies.
- Building an obliged entity’s risk assessment — A practical map of clients, products, channels and geography with measures matching actual activities.
Sources and legal references
- Zákon č. 253/2008 Sb., znění od 11. 1. 2026 ↗
§ 16–17a, § 18–24, § 26–27, § 38–39; použitelnost podle § 2 · accessed 2026-10-04 - FAÚ: MP č. 11 – Hodnocení rizik a SVZ ↗
působnost, obsah, aktualizace, příloha 1; nefinanční sektor · accessed 2026-10-04
Editorial work and source checks are not independent legal approval of your particular process. Compare the conditions and exceptions with your own circumstances.
