PKO Bank Polski, supported by its subsidiary PKO Finat, runs Kropka, a nationwide lottery where users collect points (Kropki), including for cashless payments confirmed with a receipt. Across the lottery there are almost 130,000 prizes to be won, worth over 3.5M PLN, across six seasons.
Fizen provides the open banking verification layer in Kropka. Our role is AIS (Account Information Service): with the user's consent and under PSD2, we confirm that the transaction behind an added receipt was genuinely paid from their bank account. This keeps points tied to real activity and makes the lottery fair and resistant to abuse.
The scale speaks for itself. According to PKO's figures, more than 100,000 receipts were verified in July 2026 alone, over 3,000 per day on average, and users have collected more than 1.37M Kropki since launch. Verification happens automatically, with no manual proof of payment and without sharing banking credentials with Fizen. The user controls the consent and can revoke it at any time.
How the verification works
Verification is based on the Account Information Service (AIS) under PSD2. The user grants consent once and authenticates at their own bank (SCA), and Fizen connects to the account through the bank's API. Banking credentials are never shared with Fizen or stored anywhere.
After a receipt is added, Fizen checks the account's transaction history for a matching, actually settled payment. Only a confirmed transaction results in points. A receipt photo with no corresponding payment from the account is not enough.
In practice this means:
- a single Fizen integration covers many banks, so the mechanism works regardless of where the user banks,
- verification is automatic and happens in near real time,
- consent is scoped and time-limited (up to 180 days under PSD2 and the PSR) and revocable at any time,
- Fizen reads only the data needed to confirm the transaction, following the data minimisation principle.
Working on a project by Poland's largest bank confirms that Fizen's infrastructure meets the security and compliance requirements of the most demanding financial institutions.



