[codicts-css-switcher id=”346″]

Global Law Experts Logo
financial reporting obligations spain

Spain's 2026 Financial Reporting & Tax Information Obligations, Criminal Compliance Risks and a Corporate Checklist

By Global Law Experts
– posted 2 hours ago

Executive Summary & Key Actions

Spain’s financial reporting obligations have undergone their most significant overhaul in a decade. Royal Decree 253/2025, published in the Boletín Oficial del Estado (BOE) on 1 April 2025, introduced sweeping changes to the scope, frequency, and granularity of tax information that financial institutions, payment service providers, and certain non-financial corporates must submit to the Agencia Tributaria (AEAT). In a subsequent analysis dated 26 November 2025, the AEAT confirmed the removal of the €3,000 minimum threshold for card-payment reporting, meaning virtually every card transaction processed in Spain now falls within scope.

These reporting obligations 2026 took effect on 1 January 2026, and the consequences of non-compliance extend well beyond administrative fines: inaccurate, incomplete, or late filings can trigger referrals to the Fiscalía and expose both companies and their directors to corporate criminal liability under the Spanish Código Penal.

For general counsel, CFOs, and compliance officers, the window for reactive implementation has closed. The priority now is to verify that systems, controls, and escalation protocols are operating correctly, and to remediate any gaps before they crystallise into enforcement risk. The five immediate actions every affected organisation should take are:

  • Confirm scope. Map every reporting obligation triggered by Royal Decree 253/2025 against your entity type, transaction volumes, and data sources.
  • Validate data feeds. Verify that automated exports from card acquirers, payment processors, and lending systems match the AEAT’s required XML schema and reporting cadence.
  • Run a reconciliation. Cross-check your first 2026 filings against underlying transaction records to identify discrepancies before the AEAT does.
  • Review your compliance programme. Ensure your corporate criminal-risk prevention model (modelo de prevención de delitos) explicitly covers tax-reporting obligations and assigns clear ownership.
  • Establish an escalation protocol. Define the red flags, discrepancy thresholds, system failures, suspicious patterns, that require immediate involvement of external counsel.

Background & Legal Framework for Financial Reporting Obligations in Spain

Understanding the 2026 changes requires a working knowledge of the institutional and legal architecture that governs financial compliance in Spain. Three pillars support the reporting ecosystem: the AEAT as the primary tax authority, the BOE as the vehicle for legislative publication, and the Registro Mercantil (Commercial Register) as the repository for corporate filings. Overlaying these domestic structures are the EU’s Directive on Administrative Cooperation (DAC) framework and the OECD’s Common Reporting Standard (CRS), both of which drive Spain’s progressive expansion of automatic exchange and reporting obligations.

Spain’s Reporting Architecture, AEAT, BOE, and Commercial Register

The AEAT administers and enforces tax reporting obligations Spain through a combination of Royal Decrees, Ministerial Orders, and interpretative analyses. Royal Decrees are published in the BOE and carry the force of law. The AEAT supplements these with technical guidance, such as the 26 November 2025 analysis on financial information obligations, that clarifies how reporting entities should interpret their duties in practice. The Commercial Register, governed by the Ley de Sociedades de Capital and the Reglamento del Registro Mercantil, requires companies to file annual accounts (cuentas anuales) within one month of their approval by the general meeting. For companies closing their financial year on 31 December, this typically means filing by the end of July.

Filing Annual Accounts, Who, When, and Where

All Spanish sociedades de capital (including sociedades limitadas and sociedades anónimas) must file annual accounts with the Commercial Register. The filing comprises the balance sheet, profit-and-loss account, statement of changes in equity, cash-flow statement (where required), and the directors’ report. Failure to file within the statutory deadline results in administrative sanctions imposed by the Register and, for persistent non-filers, potential closure of the company’s registered page, effectively paralysing corporate transactions.

Accounting Standards in Spain, PGC vs IFRS

Spain does not follow US GAAP. Statutory individual-entity accounts must be prepared under the Plan General de Contabilidad (PGC), Spain’s national accounting framework, which is substantially aligned with IFRS but contains specific local adaptations. Listed groups are required to prepare consolidated financial statements under full EU-adopted IFRS. Non-listed groups may elect to apply IFRS for consolidation purposes. Understanding which framework applies is essential when assessing whether reported data meets the AEAT’s expectations, since discrepancies between PGC and IFRS treatments can create reconciliation challenges in tax reporting.

Key 2026 Reporting Changes: Who, What, and When

Royal Decree 253/2025 and the AEAT’s accompanying guidance represent a structural shift in tax reporting obligations Spain must accommodate. The changes affect both the categories of data that must be reported and the entities that must report them. The most immediately impactful reforms are outlined below.

Removal of the €3,000 card-payment threshold. The AEAT’s analysis of 26 November 2025 confirmed that the previous de minimis threshold, which exempted card transactions below €3,000 from itemised reporting, has been eliminated. From 1 January 2026, all card-payment transactions, regardless of value, must be reported to the AEAT by acquirers and payment processors. Industry observers expect this change alone to multiply the volume of reportable data by an order of magnitude for many institutions.

Expanded reporting categories. The decree broadens the scope of reportable financial information to include open accounts, lending activity, cash movements, collections, card payments, and cross-border payment flows. Financial institutions and PSPs must now report on categories that were previously either voluntary or subject to higher materiality thresholds.

Increased reporting frequency. For certain categories, particularly those affecting PSPs and foreign payment providers operating in Spain, the AEAT has moved from annual or quarterly reporting to a monthly cadence. This compressed timeline demands near-real-time data extraction and validation capabilities.

Cross-border alignment. Spain’s reforms also implement elements of the EU’s DAC framework and reflect the OECD’s push for automatic exchange of financial account information under the CRS. The likely practical effect is that data reported to the AEAT will be shared with tax authorities in other EU member states and CRS-participating jurisdictions under existing exchange agreements.

Date Source (BOE / AEAT) Practical Effect
1 April 2025 BOE, Royal Decree 253/2025 New reporting obligations published; defines expanded categories, entity scope, and transitional provisions.
26 November 2025 AEAT, Interpretative analysis Confirms removal of €3,000 card-payment threshold; provides technical guidance on data elements and XML schemas.
1 January 2026 BOE / AEAT (effective date) Majority of new reporting obligations 2026 take effect; monthly reporting cycle begins for designated entities.

Reporting Obligations by Sector & Entity Type

The scope of Spain’s 2026 reporting changes varies significantly depending on entity type, activity, and transaction volume. The following comparison table summarises the main obligations and the compliance actions each category of organisation should prioritise.

Entity Type Main Reporting Obligation(s) (2026) Key Compliance Actions
Banks / deposit takers Expanded periodic reporting of card payments, account openings, and cash activity; monthly cadence in some cases. Map data feeds, update reporting scripts, reconcile card acquirer files to AEAT submissions.
Payment Service Providers (PSPs) / Fintechs Detailed reporting on open accounts, collections, card payments, lending transactions, monthly from 1 January 2026 for many. Confirm reporting XML schema, implement automated exports, establish record retention policy.
Lenders (incl. marketplace lenders) Reporting of lending flows and outstanding balances if covered by Royal Decree 253/2025. Update loan origination systems to tag AEAT reporting fields; ensure AML/KYC data is linked.
Non-financial corporates Reporting triggers when acting as payees/processors for large volumes or cross-border flows, obligations depend on volume and sector. Identify reporting triggers, maintain invoicing controls, coordinate with payment service providers.
Small & medium enterprises Generally exempt from expanded financial-intermediary reporting, but standard tax filing and invoicing obligations remain; may be indirectly affected as data subjects. Verify whether any PSP/acquirer reporting triggers apply; maintain compliant invoicing practices.

PSPs & Fintechs, Data Elements, Frequency, and Sample Forms

PSPs face the steepest compliance curve. The AEAT expects monthly submissions containing granular transaction-level data: payer/payee identification, IBAN or equivalent account references, transaction amounts, dates, and categorisation codes aligned with the AEAT’s published XML schema. Fintechs that operate cross-border must also comply with DAC7 platform-reporting requirements where they facilitate payments for sellers or service providers. Early indications suggest that the AEAT’s automated validation systems will reject files that fail schema checks, triggering penalty exposure from the first month of non-compliant submission.

Banks & Deposit Takers, Scope and Information Flows

Traditional banks already report under CRS and existing AEAT informative returns (modelos). The 2026 changes expand the data envelope: banks must now include additional card-payment data without the former €3,000 floor, report on new account categories, and align cash-activity reporting with enhanced anti-money-laundering data flows. The operational challenge lies in integrating legacy core-banking system exports with the AEAT’s updated file specifications.

Non-Financial Companies, When Reporting Is Triggered

Most non-financial corporates are not directly subject to the expanded intermediary-reporting obligations. However, companies that process payments on behalf of third parties, operate marketplace platforms, or handle significant cross-border cash flows may trigger reporting thresholds under Royal Decree 253/2025. Additionally, all companies remain subject to standard tax reporting obligations Spain enforces through periodic modelo filings, withholding-tax returns, and invoicing requirements, including the forthcoming e-invoicing mandates.

Criminal Compliance Risks & Corporate Criminal Liability in Spain

The most consequential, and most frequently underestimated, dimension of the 2026 reporting changes is the criminal exposure they can create. Spain’s corporate criminal liability regime, introduced through Organic Law 5/2010 and significantly expanded by Organic Law 1/2015, allows the prosecution of legal entities for offences committed on their behalf or for their benefit by directors, officers, or employees. Tax fraud, falsification of accounts, and money laundering are all within scope.

Typical Enforcement Pathway, AEAT Admin Audit to Criminal Investigation

The escalation from administrative non-compliance to criminal investigation follows a well-established path in Spain. The AEAT conducts routine and risk-based audits of informative returns. When an audit uncovers discrepancies that suggest deliberate underreporting, falsification, or concealment, the AEAT refers the matter to the Fiscalía (public prosecutor’s office). The Fiscalía then determines whether there is sufficient evidence to open a criminal investigation. Under the Código Penal, tax fraud (delito fiscal) arises where the amount defrauded exceeds the applicable statutory threshold and involves wilful conduct or gross negligence amounting to recklessness.

For compliance officers, the critical insight is that inaccurate reporting, even if unintentional, can trigger an AEAT audit, and the audit trail (or lack thereof) determines whether the matter stays administrative or becomes criminal. Organisations without robust controls and documented processes face elevated risk of the latter.

Penalties & Sanctions for Tax Non-Compliance

The penalty framework operates on two levels:

  • Administrative sanctions. The General Tax Law (Ley General Tributaria) empowers the AEAT to impose fixed and proportional fines for late, incomplete, or inaccurate informative returns. Penalties escalate for repeat offenders and for obstructing the AEAT’s verification procedures.
  • Criminal sanctions. The Código Penal provides for imprisonment for individuals convicted of tax fraud and falsification of documents. Corporate entities may face fines calculated as multiples of the amount defrauded, judicial dissolution, suspension of activities, or disqualification from public contracts. Directors and officers face personal criminal liability where they authorised, directed, or failed to prevent the offending conduct despite having the means and duty to do so.

A well-designed and effectively implemented compliance programme (modelo de prevención de delitos) serves as a potential defence or mitigating factor in criminal proceedings. The Supreme Court has confirmed that an adequate compliance programme can exempt or reduce corporate criminal liability, but only where the programme is genuinely operational, regularly updated, and properly supervised by a compliance officer or body with real independence and resources.

Practical Corporate Tax Compliance Checklist & Remediation Steps

The following checklist is designed for GCs, CFOs, and heads of compliance at organisations subject to Spain’s 2026 financial reporting obligations. Each step identifies the action, its rationale, and the function that should own it.

1. Governance & Ownership

Assign a named senior owner (typically the CFO or Chief Compliance Officer) with board-level accountability for AEAT reporting compliance. Establish a cross-functional reporting committee comprising Legal, Finance, IT, and Internal Audit. Document terms of reference and meeting frequency (minimum quarterly, monthly during implementation). This governance structure is a prerequisite for any credible modelo de prevención de delitos. Owner: Board / CEO.

2. Immediate Triage & Gap Analysis

Conduct a comprehensive mapping exercise that identifies every data source, data flow, and existing report relevant to the 2026 obligations. Compare current output against the AEAT’s published requirements, including the updated XML schemas and the expanded categories introduced by Royal Decree 253/2025. Document every gap, assign remediation owners, and set deadlines. Owner: Finance & IT (jointly).

3. Controls & Reconciliations

Implement automated end-to-end reconciliation procedures that match source-system data (card acquirer files, payment processor exports, lending-system extracts) to the data submitted to the AEAT. Reconciliations should run at or before every filing cycle, monthly for entities on the new monthly cadence. Tolerance thresholds should be defined: any variance exceeding the agreed threshold triggers a formal investigation and a hold on filing until the variance is explained. Financial compliance Spain demands require these controls to be documented and testable. Owner: Finance (with IT support).

4. Evidence Preservation & Internal Audit

Adopt a records-retention policy that preserves all data, working papers, reconciliation reports, and correspondence related to AEAT filings for a minimum of six years, aligned with the statutory limitation period for tax obligations in Spain. Implement tamper-proof storage (hashing, immutable logs) for XML submissions and their underlying datasets. Schedule internal audit reviews of reporting processes at least twice per year, with findings reported to the compliance committee. Owner: Internal Audit & IT.

5. Data Protection & Transfers

Reconcile AEAT reporting requirements with GDPR obligations. Reporting to the AEAT constitutes a legal obligation under Article 6(1)(c) GDPR, providing a lawful basis for processing personal data included in informative returns. However, organisations should conduct a Data Protection Impact Assessment (DPIA) where the volume or sensitivity of data is significant, ensure data minimisation principles are applied (report only what the AEAT requires), and document the legal basis and retention justification in the organisation’s Records of Processing Activities. Owner: Legal / Data Protection Officer.

6. Remediation Playbook for Discovered Errors

If historic or current misreporting is discovered, the compliance team should follow a structured remediation protocol:

  1. Quantify the error. Determine the scope, period, and financial impact of the discrepancy.
  2. Assess intent. Evaluate whether the error resulted from system failure, human error, or conduct that could be characterised as deliberate concealment.
  3. Consider voluntary disclosure. The AEAT’s voluntary disclosure regime offers reduced penalties for taxpayers who self-correct before an audit notification. Voluntary disclosure is generally advisable for inadvertent errors.
  4. Involve external counsel. Where the error exceeds materiality thresholds, involves potential intentionality, or could trigger criminal referral, engage external counsel and forensic accountants before making any disclosure.
  5. Document the response. Maintain a complete paper trail of the remediation process, including the decision-making rationale. This documentation may be critical evidence of good faith and effective compliance.

Owner: Legal / Compliance (with external counsel where required).

Implementation Timeline & Internal Controls

Organisations that have not yet completed their implementation should adopt a compressed 90/60/30-day plan structured around three phases: assessment (days 1–30), build and test (days 31–60), and go-live validation (days 61–90). For entities already filing under the 2026 regime, the plan functions as a health check to identify and close residual gaps.

Control Frequency Owner Evidence
Source-to-submission reconciliation Monthly (or per filing cycle) Finance Reconciliation report with variance analysis
XML schema validation (pre-submission) Every filing IT Automated validation log; error/exception report
Compliance committee review Quarterly CCO / GC Meeting minutes; action tracker
Internal audit of reporting process Semi-annually Internal Audit Audit report with findings and remediation plan
Records-retention compliance check Annually IT / Legal Retention log; sample retrieval test

Suggested IT Changes & Data Feeds

IT departments should prioritise three workstreams: first, establishing automated data exports from card acquirers and payment processors in the AEAT’s specified format; second, integrating e-invoicing systems with reporting workflows to eliminate manual re-keying; and third, building pre-submission validation scripts that check each file against the AEAT’s published XML schema before upload. Where legacy systems cannot produce compliant outputs, middleware solutions or managed-service providers may be required.

Internal Audit Schedule for 2026

Internal audit should conduct its first comprehensive review of 2026 reporting processes no later than the end of Q2 2026, covering the first five months of filings. A follow-up review in Q4 2026 should assess whether controls are operating effectively and whether any systemic issues identified in the first review have been remediated. Audit findings should be reported directly to the compliance committee and, where material, to the board. These scheduled reviews are a core component of demonstrating financial compliance Spain regulators and prosecutors expect.

When to Involve External Counsel: Red Flags & Escalation

Not every reporting issue warrants external legal advice, but certain red flags should trigger immediate escalation beyond the in-house team. Compliance officers should treat the following as escalation triggers:

  • Unexplained discrepancies exceeding 5% of reported values in any filing period, or any single discrepancy exceeding €100,000.
  • Repeated system failures that result in missed or materially inaccurate filings over two or more consecutive periods.
  • Suspicious transaction patterns, including structured payments, round-trip flows, or transactions with sanctioned-country counterparties, that may indicate fraud or money laundering.
  • Receipt of an AEAT penalty notice or audit notification referencing informative-return deficiencies.
  • Any indication of a criminal referral by the AEAT to the Fiscalía, or contact from law-enforcement authorities.

The escalation flow should move from in-house triage (compliance officer and GC) to external counsel and, where financial quantification is needed, forensic accountants. The decision to make a voluntary disclosure to the AEAT should only be taken after external counsel has assessed the legal exposure and strategic implications. Organisations with operations in multiple jurisdictions should also consider whether reporting failures in Spain trigger notification obligations in other countries under CRS or DAC exchange agreements.

Conclusion

Spain’s 2026 financial reporting obligations mark a turning point for corporate compliance. The combination of broader reporting scope, compressed filing timelines, and the elimination of previously relied-upon thresholds means that reporting failures are now far more likely to be detected, and the consequences far more severe. Organisations that have not yet completed their implementation should treat this as urgent: run the gap analysis, validate the data feeds, and pressure-test the controls. Those already filing should prioritise the reconciliation and internal-audit steps outlined in this tax compliance checklist to ensure that first-year filings withstand scrutiny.

The stakes are no longer limited to administrative fines; with corporate criminal liability firmly embedded in Spain’s enforcement framework, the cost of inaction can include criminal prosecution of the company and its officers. To search for a qualified compliance practitioner with expertise in Spanish financial reporting, use the Global Law Experts lawyer directory. For broader context on Spain’s tax enforcement landscape, see also our guide to Spain’s Pillar Two deadline and compliance requirements.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.

Sources

  1. Agencia Tributaria, Analysis / Update on Financial Reporting Obligations (26 November 2025)
  2. Boletín Oficial del Estado (BOE), Royal Decree 253/2025
  3. BOE, Spanish Criminal Code (Código Penal), Consolidated Text
  4. European Commission, Administrative Cooperation (DAC) Directives & EU Tax Transparency
  5. OECD, Tax: Automatic Exchange & Common Reporting Standard (CRS)

FAQs

What financial and tax reporting obligations change in Spain in 2026?
Royal Decree 253/2025 expanded the scope of information financial institutions and PSPs must report to the AEAT. From 1 January 2026, card-payment reporting no longer carries a €3,000 minimum threshold, new categories of financial data (accounts, lending, cash, cross-border flows) are reportable, and many entities must file monthly rather than quarterly or annually.
Administrative fines under the General Tax Law apply to late or inaccurate filings. Where non-compliance involves deliberate concealment or amounts exceeding statutory thresholds, the AEAT may refer the matter to the Fiscalía for criminal investigation. Corporate criminal liability Spain’s Código Penal provides for can result in fines, activity suspensions, or judicial dissolution for the entity, and imprisonment for responsible individuals.
Companies should map all reportable data sources, implement automated reconciliations between source systems and AEAT submissions, validate XML files before submission, preserve audit trails for a minimum of six years, and schedule internal audits of reporting processes at least twice per year.
Most obligations under Royal Decree 253/2025 took effect on 1 January 2026. PSPs subject to monthly reporting should have begun filing from that date. Transitional provisions may apply to specific categories, entities should confirm their filing calendar directly against the AEAT’s published technical specifications.
Spain uses the Plan General de Contabilidad (PGC) for statutory individual-entity accounts. The PGC is aligned with, but not identical to, IFRS. Listed groups must prepare consolidated accounts under EU-adopted IFRS. Non-listed groups may voluntarily adopt IFRS for consolidation.
Quantify the error’s scope and financial impact. Assess whether the cause was systemic or intentional. Consider voluntary disclosure to the AEAT for reduced penalties, but involve external counsel and forensic accountants first if the amount is material or there is any risk of criminal characterisation.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Spain's 2026 Financial Reporting & Tax Information Obligations, Criminal Compliance Risks and a Corporate Checklist

Send welcome message

Custom Message