Contractor verification: the white list, VIES, and the one check that carries legal weight
Every accounting office in Poland verifies contractors. Almost all of them do it on the wrong day — and file proof from the wrong day too.
From the inside the routine looks solid. A cost invoice arrives, the accountant opens the Ministry of Finance register, pastes the NIP, confirms the supplier is an active VAT payer, saves a screenshot into the client folder, books the document. Diligent, documented, done.
Except the rules don't care about the day you booked the invoice. They care about the day the transfer was ordered. In a normal month those are two different days, sometimes two and a half weeks apart.
The date the law actually uses
Three things travel together for any single transaction of PLN 15,000 or more gross paid to a business contractor:
- the payment has to go to an account listed in the register of VAT taxpayers on the day the transfer is ordered,
- if it doesn't, that payment stops being a tax-deductible cost for the part sent to the off-list account,
- and you pick up joint liability for the VAT the supplier doesn't pay.
Put a number on it, because the abstraction hides how expensive this gets. A PLN 61,500 gross invoice is 50,000 net plus 11,500 VAT. Paid to an account outside the register, it costs roughly 9,500 zł in additional tax at the 19% rate — 4,500 for a small taxpayer on 9% — plus exposure of up to 11,500 zł of somebody else's VAT. Around 21,000 zł of risk on one transfer, out of a single field nobody re-read on the day the money moved.
There is an escape hatch, and the detail matters: a ZAW-NR notification filed with the tax office within seven days of ordering the transfer removes both consequences. Since the 2020 amendment, one notification per bank account is enough — not one per transaction. The catch is that seven days is short, and the clock starts on a day nobody marked in a calendar, because at that point nobody knew anything was wrong.
That is the real shape of the problem. Not "we do not check contractors." We check them on the eighth, and the money leaves on the twenty-sixth.
What sits in the registers, and what does not
Two public sources do the mechanical work.
The VAT white list (Wykaz podatników VAT) publishes a full flat file once a day and also answers per-NIP queries. That distinction matters more than it looks. Single lookups are built for a human checking one contractor. The daily file is built for exactly what an office needs: sweeping a few thousand NIPs at once, comparing today against yesterday, reporting only the differences. The register also serves historical states, and that is what turns a check into evidence — you can show what the register said on a given date, not what it says today.
VIES validates EU VAT numbers and returns a confirmation number when you query with your own VAT number. That confirmation number, not a screenshot, is the thing worth storing. Two quirks bite in practice. Several member states don't return the company name or address, so you get a yes/no and nothing to reconcile against the invoice. And the service depends on each national system being up, so "not available" means try again later, not invalid.
Neither register tells you whether a transaction is real. That gap is the whole reason the Ministry's due diligence methodology exists, and it is where the human stays.
Three moments, not one
Rebuild the process around when things actually get verified and it splits cleanly.
At booking. Is this contractor an active VAT payer, does the EU number check out, is the bank account on the invoice the one we know for them? This catches typos, a supplier who has quietly switched banks, and an invoice that should never have arrived in the first place. Cheap, useful, no legal weight of its own.
On payment day. The register state for that account on that date. This is the one with money attached — and the one most often missing, because payment happens in a different system, usually with a different person, sometimes in a different week.
Three years later. An inspection asks what you knew and when. A screenshot in a folder, filename typed by hand, is weak evidence. A timestamped snapshot of the register response, tied to the invoice and the transfer, is strong. Collected automatically, the two cost the same. Collected by hand, they are nowhere near each other.
Most offices run the first, skip the second, and end up presenting the third in a form they would rather not show anyone.
What this looks like on a portfolio of forty clients
Take the numbers I use across these posts: forty clients, around sixty documents each, roughly 2,400 documents a month.
Assume about one in ten purchase invoices crosses the 15,000 zł threshold. That leaves around 240 payments a month that genuinely need a payment-day check. Done properly by hand — open the register, paste the NIP, paste the account number, save the response, attach it to the document — call it 90 seconds each. About six hours a month.
Six hours. I am not going to inflate that, and nobody buys software over six hours.
So the reason to automate this is a different one, and I would rather say it plainly: being 99% diligent here is worth close to nothing on the 1% that slips through. The value is not the six hours. It is that one missed transfer costs more than a whole year of checking, and manual processes fail exactly where volume meets deadline pressure — which is the window between the 15th and the 25th, when nobody has time to paste account numbers into a government website.
Then there is one check that automation does not speed up so much as make possible at all. That same portfolio has, say, 3,200 unique active contractors. Nobody re-verifies 3,200 NIPs by hand. Ever. From the daily flat file it is a single pass: today's statuses against yesterday's, output only what changed. A supplier struck off the register. A taxpayer moved from active to exempt. An account that quietly dropped out of the listing. No accounting team can do that manually, at any headcount. It is not a faster version of an existing task — it is a task nobody was doing.
What an agent does, concretely
Wired into documents arriving from KSeF and the ERP, it comes down to a short list:
- daily sweep of every active contractor in the portfolio against the register file, reporting only status changes
- at booking: VAT status, VIES for EU numbers, the invoice account against the register and against the account history for that supplier
- flagging every document above the threshold so it enters the payment queue already marked
- re-checking on the day the payment is prepared, and blocking release when the account is not listed
- a seven-day ZAW-NR countdown that starts the moment a payment goes out to an off-list account, notification pre-filled, deadline visible
- storing each check as a timestamped snapshot tied to the document, exportable as a package for an inspection
All of it in draft-and-alert mode — the same rule that governs every other agent I build for accounting offices: the software prepares and warns, a named person decides. In an enova365 or Optima setup the checks land as attributes and attachments on the document, not in a separate tool somebody has to remember to open.
What must stay with a person
Deciding to pay anyway, with a ZAW-NR, because the supplier has a legitimate reason for the account. Judging whether a transaction is genuine when the registry is clean but the price sits 30% below market. Handling the client who insists on paying an off-list account. Signing the notification. Deciding that a contractor is one you no longer work with.
An agent sold as "handling compliance" without a person on those five is being sold to you dishonestly.
When not to build this
If your practice sends fewer than about twenty transfers a month over the threshold, do not commission anything. The maths does not work and it will not start working. Use a checklist and a chat bot — KsięgoAI does this per NIP for 39 zł per 30 checks, stores the due diligence proof, and needs no integration project. For most single companies and small practices, that is the honest answer.
The threshold where a built agent makes sense is the one I worked through in what an accounting AI agent costs: document volume, not enthusiasm. Verification rarely justifies a project on its own. It is what you add once an intake or reconciliation agent is already running — at which point the marginal cost is small and the risk drops immediately.
One number to measure before you decide anything: take last month's payments over 15,000 zł and check how many have a register snapshot from the payment date. Not the booking date. If the honest answer is "almost none", you have found the gap — and you now know whether closing it is worth six hours a month or one bad transfer.
Want to know how this would attach to your ERP and how much of your portfolio it would actually cover? Get in touch — scoping is free and takes half an hour. If you are earlier than that, here is how I score whether a practice is ready for any of this: the AI readiness audit.
Let’s talk about your project
Free 30-minute consultation. We’ll figure out if and how I can help.



