Our Expert in Spain
No results available
To prove compliance programme spain effectiveness in criminal proceedings, an organisation must move beyond having a policy on paper and demonstrate, through documented, dated and independently verifiable evidence, that its prevention model was designed, implemented and operating at the moment the alleged offence occurred. In 2026, with intensified criminal enforcement against companies and closer prosecutorial scrutiny of corporate governance, the difference between mitigation, exemption and full corporate liability increasingly turns on the quality of the evidence a company can put before a Spanish court. This guide sets out the statutory framework, the forensic evidence checklist that prosecutors and courts value, audit and documentation methods that withstand challenge, and the timing strategies that maximise mitigation.
It is written for compliance officers, general counsel and directors who need practical, court-facing answers rather than abstract theory.
Who this is for: compliance officers, general counsel, directors and external counsel preparing for investigations or seeking mitigation or exemption in Spanish criminal proceedings. Focus: practical evidence, audit design, documentation and mitigation tactics.
Corporate criminal liability in Spain (responsabilidad penal de las personas jurídicas) is set out in the Código Penal (Ley Orgánica 10/1995), the consolidated criminal code published by the Boletín Oficial del Estado. The regime was introduced into Spanish law by Organic Law 5/2010 and substantially reformed by Organic Law 1/2015, which added the provisions on organisation and management models (Article 31 bis and related articles). The framework establishes that legal persons can be held criminally responsible for certain offences committed for their benefit by their representatives, directors, or by employees who were inadequately supervised.
Understanding these provisions is the foundation for any effort to prove compliance programme spain adequacy, because the statute itself defines the conditions under which a company can avoid or reduce liability.
Article 31 bis of the Código Penal contemplates two broad routes to corporate liability: offences committed by senior figures (legal representatives and those with authority to take decisions or exercise control) acting for the company’s benefit, and offences committed by persons subject to their authority because those with authority seriously breached their duties of supervision, monitoring and control. The distinction matters enormously for defence strategy. Where a subordinate commits the offence, the central question becomes whether the company had implemented and enforced adequate supervision and control measures, precisely the terrain on which a well-documented prevention model does its work.
Where senior management is implicated directly, the evidentiary burden is heavier, and the company must show that the individuals fraudulently circumvented an otherwise effective model.
The statute permits exemption from liability where the company, before the offence was committed, adopted and effectively implemented an organisation and management model (a modelo de prevención de delitos) suited to preventing offences of the type committed. The elements set out in Article 31 bis typically include: identification of the activities where the relevant offences may be committed; establishment of protocols and procedures for decision-making; management of the financial resources needed to prevent the offences; an obligation to report possible risks and breaches to the supervisory body; a disciplinary system that adequately sanctions non-compliance; and periodic verification and, where appropriate, modification of the model.
For the model to support exemption, an autonomous supervisory body with sufficient powers of initiative and control must have been entrusted with monitoring its operation, and the offenders must have committed the offence by fraudulently evading the model rather than because the model failed.
Where these conditions are only partially met, the model may still operate as a mitigating factor rather than a full exemption. This is why the concept of modelo de prevención de delitos pruebas, the evidence proving the prevention model, sits at the heart of every corporate defence. The court does not accept the mere existence of a document; it examines whether the model lived and breathed within the organisation.
Spanish Supreme Court (Tribunal Supremo) jurisprudence, accessible through the search facilities of the Consejo General del Poder Judicial, has progressively clarified how courts assess prevention models. Landmark rulings of the Sala de lo Penal from 2016 onward established that a model must be genuine and operational, not cosmetic, and addressed the role of corporate “culture of compliance. ” The consistent theme is substance over form. Courts have signalled that an independent, properly documented internal investigation and external audit evidence can support mitigation where they are contemporaneous and credible.
The Fiscalía General del Estado has published prosecutorial guidance (notably Circular 1/2016 on corporate criminal liability) addressing how prosecutors should evaluate corporate compliance, cooperation and remediation, guidance that in-house teams should treat as a practical checklist of what will be scrutinised. Prosecutor guidance on compliance in Spain repeatedly emphasises the substance of implementation over formal adoption.
The single most valuable output of this guide is a forensic evidence checklist. When you set out to prove compliance programme spain effectiveness, you are effectively assembling a dossier that answers one question in the mind of the prosecutor and the judge: “Was this model real, was it appropriate to the risk, and was it working?” The categories below map to the statutory elements and to established prosecutorial expectations. Each category should be capable of production with dates, authors and evidence of dissemination.
Board and committee minutes are among the most persuasive pieces of evidence because they show the tone from the top and the objective discussion of risk. Minutes should demonstrate that the board considered the company’s criminal-risk exposure, approved the prevention model, allocated resources, and received periodic reports from the supervisory body. Dated, signed minutes with attendance lists and references to specific agenda items carry real weight. Generic minutes that merely record “compliance matters noted” are of little value. Governance guidance from the Comisión Nacional del Mercado de Valores, including its good governance code for listed companies, reinforces the expectation that boards exercise active oversight of internal control and risk-management frameworks.
A documented, methodologically sound risk assessment is the spine of any defensible model. Prosecutors expect to see that the company identified the offences to which its activities exposed it, assessed the likelihood and impact of each, and calibrated controls accordingly. The risk map should be dated, show the methodology used, name those responsible, and evidence periodic review and updating. A model built on a stale risk assessment, one that ignored a business line where the offence actually occurred, is a common point of failure.
Policies, codes of conduct and procedures constitute the evidence of compliance in Spain that shows how the company translated risk into rules. What matters is not only their existence but their communication: evidence that policies were distributed, acknowledged, and made accessible in the working language of employees. Retain acknowledgement receipts, intranet publication logs and version histories. A policy nobody read is a weak defence.
Training closes the loop between policy and behaviour. Courts look for tailored, role-specific training rather than a single generic session. Keep attendance registers, course content, dates, completion certificates and assessment results. Where high-risk functions received enhanced training, document it. This category frequently determines whether a court accepts that the model reached the individuals whose conduct is in question.
Ongoing compliance testing and monitoring is what separates a live model from a dormant one. This includes control testing, transaction reviews, whistleblowing channel activity, KPI dashboards and periodic reporting to the supervisory body. Note that Spain’s Law 2/2023 on the protection of persons who report regulatory and anti-corruption breaches requires many organisations to maintain an internal reporting channel and information system with defined procedures and safeguards; activity from this channel is a relevant source of monitoring evidence. Retain logs showing what was tested, when, by whom, what was found, and what followed. Evidence that monitoring detected issues and prompted action is powerful, it demonstrates the model performing its intended function.
A company that identifies concerns and investigates them credibly demonstrates a functioning model. Maintain investigation files with scope, methodology, findings and remediation. Where the company acted on findings, disciplining individuals, tightening controls, recovering losses, this evidence supports both effectiveness and good faith.
Many corporate offences arise through intermediaries, agents and suppliers. Prosecutors examine whether the company conducted proportionate due diligence on third parties, embedded compliance clauses in contracts, and monitored ongoing relationships. Retain due diligence records, screening results, contractual compliance provisions and evidence of periodic re-assessment.
Across all these categories, two threshold tests recur: sufficiency (is there enough contemporaneous documentation to establish the fact?) and credibility (is the evidence independent, dated and free from any suggestion of after-the-fact creation?). A dossier that satisfies both is the strongest way to prove compliance programme spain effectiveness before a court.
Compliance audits in Spain are one of the most persuasive evidentiary tools available, provided they are designed to survive scrutiny. An audit that is scoped narrowly, conducted without independence, or filed away without follow-up can undermine rather than support a defence. The goal is audit-grade evidence: findings a prosecutor cannot easily dismiss as self-serving.
Internal audits demonstrate that the company polices itself and are valuable for showing continuous monitoring. External audits carry additional weight precisely because they are independent. In practice, the two are complementary: internal functions run frequent, targeted testing, while external reviewers provide periodic validation and challenge. When preparing to prove compliance programme spain adequacy, a combination of both, with clear reporting lines to the supervisory body, is the strongest position. The OECD Good Practice Guidance on Internal Controls, Ethics and Compliance identifies periodic review and independent assessment as recognised indicators of programme effectiveness that courts and prosecutors treat as persuasive.
Audit conclusions are only as strong as their methodology. Document the sampling approach, the population from which samples were drawn, the rationale for sample size, and the tests applied. Where an audit claims that controls operated effectively across thousands of transactions, a defensible sampling method makes that claim credible. Ad hoc, unexplained sampling invites challenge. Record the evidence gathered for each test so findings can be reconstructed later.
An audit that identifies weaknesses and triggers timely remediation is more persuasive than a clean report. Courts understand that no programme is perfect; what they reward is a functioning cycle of detection and correction. Every finding should be logged with a severity rating, a named owner, a deadline and evidence of closure. This remediation trail is itself evidence of an effective model.
Once an offence is suspected, forensic auditors can gather and preserve evidence to investigative standards, critical for both establishing facts and demonstrating cooperation. Engaging forensic specialists early, ideally under the direction of counsel, helps protect the integrity of findings and supports arguments for mitigation based on prompt, credible internal response.
Even the best compliance activity is worthless in court if the underlying documentation cannot be shown to be authentic and contemporaneous. Compliance documentation in Spain must therefore be managed with the same rigour a litigator would expect of any evidentiary record. This section addresses how to keep evidence admissible and persuasive.
Adopt a retention policy that preserves compliance records for the periods relevant to potential criminal exposure, taking into account the limitation periods applicable to the relevant offences, and ensure metadata, creation dates, authors, version histories, is preserved intact. Metadata is often what converts a document from “asserted” to “proven.” Avoid practices that strip or overwrite metadata, and ensure that policy versioning demonstrates the model’s evolution over time.
Where digital records may become evidence, maintain a documented chain of custody: who collected the data, when, how it was stored, and who accessed it. Secure storage, timestamping and access logs protect against allegations of tampering. E-discovery readiness, being able to locate, preserve and produce relevant records quickly, also signals a mature compliance function and supports cooperation with authorities.
Distinguishing privileged from non-privileged records is essential. In Spain, professional secrecy (secreto profesional) protects communications with external lawyers, and mishandling such material can expose sensitive analysis. Guidance from the Consejo General de la Abogacía Española on professional conduct and professional secrecy, together with the General Statute of the Legal Profession, should inform how internal investigations are structured and how counsel is involved. Equally, companies must respect employee privacy and data protection rights when collecting and processing personal data during monitoring and investigations, balancing evidentiary needs against obligations under the EU General Data Protection Regulation and Spain’s Organic Law 3/2018 on data protection and digital rights, as supervised by the Agencia Española de Protección de Datos.
Third-party compliance certification in Spain is frequently offered up as proof of a functioning programme, but its value must be understood realistically. Certifications can help, yet they are rarely decisive on their own.
Certifications such as ISO 37001 (anti-bribery management systems) and ISO 37301 (compliance management systems), or conformity with the Spanish standard UNE 19601 on criminal compliance management systems, demonstrate that a company’s control framework has been assessed against a recognised standard. This is genuinely useful evidence of design quality, it shows an external body examined the architecture of the programme. However, as the OECD guidance underscores, standards certification attests principally to the design of controls at a point in time, not to their operational effectiveness at the moment an offence occurred. That distinction is the crux of how courts treat certifications.
Every certification and attestation has a defined scope, and the scope frequently does not cover the specific process or business unit where an offence arose. When presenting a certificate, be candid about its scope and supplement it with operational evidence, audit reports, testing logs and remediation records, that shows the certified controls actually worked in practice. Presenting a certificate as a talisman, without operational corroboration, invites a prosecutor to expose the gap between design and operation.
Used correctly, certifications form one strand of a broader mitigation argument. They corroborate that the company invested in a serious, externally validated framework. The persuasive package pairs the certificate with the underlying audit reports, the follow-up actions taken on any nonconformities, and evidence of continuous monitoring. This combination is far more effective than either the certificate or the internal evidence alone.
Timing can be as important as substance. The decisions a company takes in the hours and days after discovering a potential offence significantly influence the mitigation available in later proceedings.
Confession of the offence to the authorities before knowing that judicial proceedings are directed against the company, and cooperation with the investigation by providing new and decisive evidence, are recognised as mitigating circumstances under Article 31 quater of the Código Penal. Self-reporting is not, however, a guarantee of exemption. The value of self-reporting depends on its timing, its completeness and the credibility of the accompanying evidence. Premature disclosure without a factual foundation, or partial disclosure that later proves incomplete, can backfire. The decision should be taken with counsel, weighing the strength of the internal investigation, the likelihood of external discovery, and the remediation already underway.
Remediation that demonstrates the model working carries the greatest weight. Design remediation with measurable outcomes: specific control enhancements, disciplinary measures, recovery of losses, retraining, and independent verification that the fix is effective. Reparation or reduction of the harm before trial is itself a recognised mitigating circumstance. Each remediation action should be logged with a responsible owner, a deadline and evidence of completion. A remediation log that shows prompt, thorough and verified corrective action is one of the strongest mitigation tools available.
When the company reaches the point of arguing for reduced corporate criminal liability, the remediation record and the demonstrable improvements to the prevention model become central. Establishing measures before trial to prevent and detect future offences is expressly recognised as a mitigating circumstance under Article 31 quater. This behaviour shows that the company took responsibility, corrected the failure, and reduced the risk of recurrence, precisely the conduct the statutory mitigation provisions are designed to reward. Corporate criminal liability mitigation in Spain rewards demonstrable, verified corrective action far more than promises of future compliance.
The table below compares common categories of evidence used to prove compliance programme spain effectiveness, their typical weaknesses, and how to strengthen each. Use it as a triage tool when assembling a defence dossier.
| Evidence type | Persuasive weight | Typical weaknesses | How to strengthen |
|---|---|---|---|
| Board minutes | High | Generic entries; no evidence of objective risk discussion or decisions | Use dated, signed minutes with attendance lists and specific references to risk items and resource decisions |
| External ISO/UNE certification | Medium | Shows control design but not operation; scope may exclude the relevant unit | Pair with audit reports, testing logs and evidence of follow-up actions demonstrating operation |
| Internal investigation report | High (if independent and documented) | Conducted in-house without safeguards; perceived as self-serving | Involve an external reviewer, apply forensic standards, and preserve underlying evidence |
| Risk assessment / risk map | High | Stale; failed to cover the business line where the offence occurred | Show methodology, dates, ownership and periodic updating reflecting the actual risk |
| Training and attendance records | Medium to High | Generic sessions; no proof the relevant employees attended | Provide role-specific training records, completion certificates and assessment results |
| Monitoring and testing logs | High | No evidence of follow-up when issues detected | Log findings, owners, deadlines and closure to show the model detecting and correcting |
As a rule of thumb, “good” evidence is contemporaneous, dated, independently verifiable and shows a control functioning; “weak” evidence is undated, generic, created after the fact, or asserts effectiveness without operational proof.
When an offence is suspected, structured action in the first days and weeks preserves evidence and builds the mitigation case. The following timeline gives in-house teams a defensible sequence to prove compliance programme spain readiness and protect the company’s position.
Engage external forensic counsel when the suspected conduct involves senior management, significant financial exposure, cross-border elements, or a realistic prospect of prosecution. External specialists strengthen the independence and credibility of the investigation and audit evidence, which is exactly what a court weighs when deciding whether the company’s response supports mitigation.
To prove compliance programme spain effectiveness in 2026 is, fundamentally, an evidentiary exercise: it is not enough to have a model, you must be able to show, through dated, verifiable, contemporaneous records, that the model was appropriate to the risk, genuinely implemented, actively monitored, and capable of detecting and correcting problems. The statutory framework in the Código Penal, the criteria applied by the Fiscalía General del Estado, and the jurisprudence of the Tribunal Supremo all point in the same direction: substance over form.
Companies that build a disciplined evidence base, governance records, current risk assessments, training and monitoring logs, credible audits, and a demonstrable remediation cycle, place themselves in the strongest position to secure mitigation or exemption if a prosecution ever arises. For a deeper foundation, see the Spanish Corporate Criminal Compliance (2026) overview, and use the evidence checklist and internal audit methodology resources to operationalise the guidance above. Preparing this evidence before an investigation begins, rather than scrambling after, is the single most reliable way to prove compliance programme spain readiness when it matters most.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.
posted 10 minutes ago
posted 19 minutes ago
posted 52 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message