The CNB decisions demonstrate that supervision of a currency exchange office goes well beyond the exchange-rate list displayed at the premises. The regulator also examines pre-contract information, customer receipts, transaction records, customer identification, examination of the source of funds and cooperation with the supervisory authority.
This article summarises four decisions supplied for analysis that were issued or finally confirmed in 2024. Some of the underlying conduct took place between 2021 and 2023.
1. Overview of the fines
CZK 400,000 for multiple operational and AML failures
The highest fine concerned an extensive combination of breaches of the Czech Currency Exchange Act and the Czech AML Act.
The CNB found that currency exchange activities had been carried out at three business locations whose placement had not been notified at least three business days before operations commenced. Mandatory information was also missing from exchange-rate lists.
The inspections further identified:
10 cases in which no transaction receipt was issued,
9 cases in which the transaction was not entered in the operator’s records,
7 cases in which the required pre-contract information was not provided for a transaction exceeding EUR 1,000,
7 cases in which the customer was not identified,
2 cases in which no receipt confirming withdrawal from the exchange contract was issued,
2 cases in which the source of funds was not examined.
The CZK 400,000 fine therefore resulted from repeated deficiencies across several business locations rather than from a single administrative error.
CZK 350,000 for failures identified during test transactions
The second-highest fine concerned deficiencies identified during test transactions. In four cases, the operator failed to provide the required pre-contract information and failed to identify the customer even though the transaction exceeded EUR 1,000.
No transaction receipt was issued in four cases, and no receipt confirming withdrawal from the exchange contract was issued in one case.
In one inspected transaction, an intended exchange of EUR 1,200 was divided into two transactions of EUR 600. The CNB treated this as an attempt to avoid the customer-identification requirement.
The CNB Bank Board subsequently upheld the CZK 350,000 fine. It emphasised that a legal entity cannot avoid liability merely by stating that its employees had received training. The operator must actively require compliance, supervise its employees and document the controls and measures implemented.
CZK 50,000 for failure to submit the AMLIFE01 report
In another case, the operator failed to submit the AMLIFE01 – Anti Money Laundering – Basic report by the applicable deadline, despite receiving two subsequent reminders from the CNB.
When determining the penalty, the CNB also considered the operator’s repeated failure to cooperate and previous regulatory sanctions. A fine of CZK 50,000 was imposed.
CZK 15,000 for an incorrect and uncorrected report
The final decision also concerned the AMLIFE01 report. The original filing contained serious errors and was rejected by the SDAT reporting system. The operator did not correct the errors and did not respond to two reminders.
The report was submitted only after administrative offence proceedings had commenced. The CNB treated this as a mitigating circumstance and reduced the original penalty from CZK 30,000 to CZK 15,000.
The argument that the operator was no longer actively carrying out currency exchange business was unsuccessful. As long as an entity remains registered as a currency exchange operator and continues to hold its authorisation, the relevant reporting and supervisory obligations remain in force.
2. Which failures occurred repeatedly?
The decisions reveal four principal areas of compliance risk.
Customer documents and information
The CNB repeatedly penalised failures to issue transaction receipts, provide pre-contract information and include the mandatory details in the exchange-rate list.
These obligations must be fulfilled for each individual transaction. Pre-contract information cannot be replaced by an oral explanation or an amount displayed only on a calculator.
Customer identification and AML controls
A significant breach involved the failure to identify customers in transactions exceeding EUR 1,000. Dividing one intended exchange into several smaller transactions does not necessarily remove the identification requirement where the transactions are connected in substance.
In one case, the CNB also identified a failure to examine the source of the funds involved.
Record-keeping and regulatory reporting
A currency exchange operator must not only serve customers correctly but must also maintain demonstrable transaction records and provide the CNB with the information it requests.
Two of the analysed penalties concerned exclusively the failure to submit, or correctly submit, the AMLIFE01 report. A report rejected by the SDAT system because of serious errors cannot be treated as properly submitted unless the errors are subsequently corrected.
Internal supervision of employees
Employee training alone may not be sufficient. The operator should also implement control mechanisms, regularly review the conduct of staff and retain evidence showing that compliance is actively required and monitored.
3. Practical lessons from the decisions
A currency exchange operator should regularly review:
the accuracy of information registered for all business locations,
the content and visibility of the exchange-rate list,
the provision of pre-contract information,
the automatic issuance of customer receipts,
the recording of all completed transactions,
customer identification and the assessment of linked transactions,
examination of the source of funds where required,
the company data box and requests received from the CNB,
the status of reports submitted through the SDAT system,
employees’ practical compliance with internal procedures.
Conclusion
The decisions show that the highest fines generally arise where deficiencies in customer documentation, AML procedures and transaction records occur repeatedly and in combination.
However, a missed data-box message, an uncorrected regulatory report or outdated information about business premises can also lead to enforcement proceedings.

