evidoria

← Back to browse

Good practice Imported

STIR — Poland's AI system for real-time VAT carousel-fraud detection

Poland · Warsaw · See the Poland profile · See the Warsaw profile

Evidence: Observational / pre–post Top 66% 53/100 · Ask Evidence Copilot about this practice

Poland's STIR applies ML to daily bank transactions of 4 million entities to detect VAT carousel fraud in near-real-time; STIR-attributable state savings ≈€133 million in 2019. Transparency concerns: opaque algorithm, account freezes without prior notice, documented by AlgorithmW

11000000+
Daily transactions analysed (2019)
~4000000
Entities covered (2019)
584 PLN million (≈€133M)
STIR-attributable state savings (2019)
537
Accounts frozen (2019)
67 PLN million (≈€15M)
Blocked assets (2019)
79 %
Administrative complaints dismissed (through 2019)
6.6B → 1.7B EUR
Poland VAT gap (2017-2021)
STIR — Poland's AI system for real-time VAT carousel-fraud detection

Details

Maturity
Established
Promoter
Krajowa Administracja Skarbowa (Poland National Revenue Administration)
Period
2018–present
Keywords
VAT fraud detection, machine learning, banking transaction analysis, carousel fraud, tax compliance

Context

STIR (System Teleinformatyczny Izby Rozliczeniowej) was enacted by law in 2017 and operationalised under Poland's National Revenue Administration (KAS) from April 2018. Built and operated by the National Clearing House (KIR), it mandates all Polish banks to transmit daily transaction data to a centralised platform.

Objectives

Detect VAT carousel fraud in near-real time by scoring taxpayer risk from banking transaction patterns, enabling the tax authority to freeze suspect accounts before fraudulent VAT refunds or losses occur.

Activities

Machine learning algorithms assign a risk coefficient to each taxpaying entity from the daily bank transaction feed; suspicious-entity reports are reviewed by KAS and can trigger bank account freezes — without prior notice to the account holder — for up to 3 months. From July 2019, banks have also been required to share IP-address data for all account-holders.

Results

By 2019 STIR was analysing over 11 million transactions daily, covering nearly 4 million entities and 5.5 million associated individuals. In 2019, 537 accounts across 113 entities were frozen; blocked assets exceeded PLN 67 million (≈€15 million); KAS estimated STIR-attributable state savings at PLN 584 million (≈€133 million). The broader VAT reform package — STIR plus the split-payment mechanism and mandatory e-invoicing (KSeF) — reduced Poland's overall VAT gap from an estimated €6.6 billion in 2017 to €1.7 billion in 2021 per CASE think-tank data, though the post-2021 gap has partially widened again.

Conclusions

Governance and transparency concerns are significant and independently documented: the scoring algorithm is classified, and through 2019, 52 administrative complaints were filed at Warsaw courts, of which 41 (79%) were dismissed. A June 2020 Poznań court ruling found that insufficient justification for initial 72-hour blocks invalidated subsequent extensions — the first significant judicial pushback. Mass IP-address collection, introduced without public consultation, has been criticised by the Polish Commissioner for Human Rights and the Panoptykon NGO, and AlgorithmWatch classified STIR as a cautionary case of opaque algorithmic enforcement in its Automating Society Report 2020.

Implementation

Indicative cost
High (€500k–€5M) — No public unit cost disclosed; the system requires mandatory daily data integration across the entire Polish banking sector plus a dedicated KAS review/enforcement function — a large national administrative-IT build, estimated high cost band.
Time to results
Long (> 3 years) — Legislated 2017, operational under KAS since April 2018, and continuously running through at least the years covered by the sources reviewed — an established, long-running system.
Staffing & skills
National Clearing House (KIR) — builds and operates the platform, National Revenue Administration (KAS) — reviews suspicious-entity reports and executes freezes, All Polish banks — mandated daily transaction reporting

Conditions for success

  • Legal mandate (2017 law) compelling universal bank participation
  • Centralised ML risk-scoring platform ingesting daily nationwide transaction data
  • Enforcement power (account freeze) tied directly to detection

Common failure modes

  • Opaque, classified scoring algorithm undermines due process and challengeability
  • Freezes without prior notice trigger legal and human-rights pushback (a 2020 court ruling found insufficient justification for freeze extensions)
  • Mass IP-data collection introduced without public consultation drew criticism from the Human Rights Commissioner and NGOs — a governance/legitimacy risk even where fiscal metrics are positive

Where it fits

Governance type
national tax administration with a centralised bank-data mandate
Scale
national (all Polish banks, ~4M entities)
Income level
high-income (EU/Poland)

Commonly funded by

National / regional programmes Digital Europe Programme

Indicative funding routes for practices of this type — always check each programme's current calls and eligibility rules.

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Attachments

Similar practices you may find useful