[codicts-css-switcher id=”346″]

Global Law Experts Logo
prove compliance programme spain

How to Prove Your Corporate Criminal Compliance Programme Works in Spain (2026)

By Global Law Experts
– posted 2 hours ago

To prove compliance programme spain effectiveness in criminal proceedings, an organisation must move beyond having a policy on paper and demonstrate, through documented, dated and independently verifiable evidence, that its prevention model was designed, implemented and operating at the moment the alleged offence occurred. In 2026, with intensified criminal enforcement against companies and closer prosecutorial scrutiny of corporate governance, the difference between mitigation, exemption and full corporate liability increasingly turns on the quality of the evidence a company can put before a Spanish court. This guide sets out the statutory framework, the forensic evidence checklist that prosecutors and courts value, audit and documentation methods that withstand challenge, and the timing strategies that maximise mitigation.

It is written for compliance officers, general counsel and directors who need practical, court-facing answers rather than abstract theory.

Who this is for: compliance officers, general counsel, directors and external counsel preparing for investigations or seeking mitigation or exemption in Spanish criminal proceedings. Focus: practical evidence, audit design, documentation and mitigation tactics.

Legal Framework: What Counts as a Defence or Exemption Under Spanish Law

Corporate criminal liability in Spain (responsabilidad penal de las personas jurídicas) is set out in the Código Penal (Ley Orgánica 10/1995), the consolidated criminal code published by the Boletín Oficial del Estado. The regime was introduced into Spanish law by Organic Law 5/2010 and substantially reformed by Organic Law 1/2015, which added the provisions on organisation and management models (Article 31 bis and related articles). The framework establishes that legal persons can be held criminally responsible for certain offences committed for their benefit by their representatives, directors, or by employees who were inadequately supervised.

Understanding these provisions is the foundation for any effort to prove compliance programme spain adequacy, because the statute itself defines the conditions under which a company can avoid or reduce liability.

Statutory Elements of Corporate Liability

Article 31 bis of the Código Penal contemplates two broad routes to corporate liability: offences committed by senior figures (legal representatives and those with authority to take decisions or exercise control) acting for the company’s benefit, and offences committed by persons subject to their authority because those with authority seriously breached their duties of supervision, monitoring and control. The distinction matters enormously for defence strategy. Where a subordinate commits the offence, the central question becomes whether the company had implemented and enforced adequate supervision and control measures, precisely the terrain on which a well-documented prevention model does its work.

Where senior management is implicated directly, the evidentiary burden is heavier, and the company must show that the individuals fraudulently circumvented an otherwise effective model.

Legislated Mitigation and Exemption Criteria (Modelo de Prevención de Delitos)

The statute permits exemption from liability where the company, before the offence was committed, adopted and effectively implemented an organisation and management model (a modelo de prevención de delitos) suited to preventing offences of the type committed. The elements set out in Article 31 bis typically include: identification of the activities where the relevant offences may be committed; establishment of protocols and procedures for decision-making; management of the financial resources needed to prevent the offences; an obligation to report possible risks and breaches to the supervisory body; a disciplinary system that adequately sanctions non-compliance; and periodic verification and, where appropriate, modification of the model.

For the model to support exemption, an autonomous supervisory body with sufficient powers of initiative and control must have been entrusted with monitoring its operation, and the offenders must have committed the offence by fraudulently evading the model rather than because the model failed.

Where these conditions are only partially met, the model may still operate as a mitigating factor rather than a full exemption. This is why the concept of modelo de prevención de delitos pruebas, the evidence proving the prevention model, sits at the heart of every corporate defence. The court does not accept the mere existence of a document; it examines whether the model lived and breathed within the organisation.

Key Jurisprudence Shaping Evidentiary Expectations

Spanish Supreme Court (Tribunal Supremo) jurisprudence, accessible through the search facilities of the Consejo General del Poder Judicial, has progressively clarified how courts assess prevention models. Landmark rulings of the Sala de lo Penal from 2016 onward established that a model must be genuine and operational, not cosmetic, and addressed the role of corporate “culture of compliance. ” The consistent theme is substance over form. Courts have signalled that an independent, properly documented internal investigation and external audit evidence can support mitigation where they are contemporaneous and credible.

The Fiscalía General del Estado has published prosecutorial guidance (notably Circular 1/2016 on corporate criminal liability) addressing how prosecutors should evaluate corporate compliance, cooperation and remediation, guidance that in-house teams should treat as a practical checklist of what will be scrutinised. Prosecutor guidance on compliance in Spain repeatedly emphasises the substance of implementation over formal adoption.

What Prosecutors and Courts Actually Look For, An Evidence Checklist

The single most valuable output of this guide is a forensic evidence checklist. When you set out to prove compliance programme spain effectiveness, you are effectively assembling a dossier that answers one question in the mind of the prosecutor and the judge: “Was this model real, was it appropriate to the risk, and was it working?” The categories below map to the statutory elements and to established prosecutorial expectations. Each category should be capable of production with dates, authors and evidence of dissemination.

Governance and Board Minutes

Board and committee minutes are among the most persuasive pieces of evidence because they show the tone from the top and the objective discussion of risk. Minutes should demonstrate that the board considered the company’s criminal-risk exposure, approved the prevention model, allocated resources, and received periodic reports from the supervisory body. Dated, signed minutes with attendance lists and references to specific agenda items carry real weight. Generic minutes that merely record “compliance matters noted” are of little value. Governance guidance from the Comisión Nacional del Mercado de Valores, including its good governance code for listed companies, reinforces the expectation that boards exercise active oversight of internal control and risk-management frameworks.

Risk Assessments and the Risk Map (MRA)

A documented, methodologically sound risk assessment is the spine of any defensible model. Prosecutors expect to see that the company identified the offences to which its activities exposed it, assessed the likelihood and impact of each, and calibrated controls accordingly. The risk map should be dated, show the methodology used, name those responsible, and evidence periodic review and updating. A model built on a stale risk assessment, one that ignored a business line where the offence actually occurred, is a common point of failure.

Written Policies and Communications

Policies, codes of conduct and procedures constitute the evidence of compliance in Spain that shows how the company translated risk into rules. What matters is not only their existence but their communication: evidence that policies were distributed, acknowledged, and made accessible in the working language of employees. Retain acknowledgement receipts, intranet publication logs and version histories. A policy nobody read is a weak defence.

Training and Attendance Records

Training closes the loop between policy and behaviour. Courts look for tailored, role-specific training rather than a single generic session. Keep attendance registers, course content, dates, completion certificates and assessment results. Where high-risk functions received enhanced training, document it. This category frequently determines whether a court accepts that the model reached the individuals whose conduct is in question.

Monitoring, Testing and KPIs

Ongoing compliance testing and monitoring is what separates a live model from a dormant one. This includes control testing, transaction reviews, whistleblowing channel activity, KPI dashboards and periodic reporting to the supervisory body. Note that Spain’s Law 2/2023 on the protection of persons who report regulatory and anti-corruption breaches requires many organisations to maintain an internal reporting channel and information system with defined procedures and safeguards; activity from this channel is a relevant source of monitoring evidence. Retain logs showing what was tested, when, by whom, what was found, and what followed. Evidence that monitoring detected issues and prompted action is powerful, it demonstrates the model performing its intended function.

Investigations and Remedial Actions

A company that identifies concerns and investigates them credibly demonstrates a functioning model. Maintain investigation files with scope, methodology, findings and remediation. Where the company acted on findings, disciplining individuals, tightening controls, recovering losses, this evidence supports both effectiveness and good faith.

Third-Party Due Diligence Files

Many corporate offences arise through intermediaries, agents and suppliers. Prosecutors examine whether the company conducted proportionate due diligence on third parties, embedded compliance clauses in contracts, and monitored ongoing relationships. Retain due diligence records, screening results, contractual compliance provisions and evidence of periodic re-assessment.

Across all these categories, two threshold tests recur: sufficiency (is there enough contemporaneous documentation to establish the fact?) and credibility (is the evidence independent, dated and free from any suggestion of after-the-fact creation?). A dossier that satisfies both is the strongest way to prove compliance programme spain effectiveness before a court.

Designing Compliance Audits and Testing That Stand Up in Court

Compliance audits in Spain are one of the most persuasive evidentiary tools available, provided they are designed to survive scrutiny. An audit that is scoped narrowly, conducted without independence, or filed away without follow-up can undermine rather than support a defence. The goal is audit-grade evidence: findings a prosecutor cannot easily dismiss as self-serving.

Internal Versus External Audits, Role and Weight

Internal audits demonstrate that the company polices itself and are valuable for showing continuous monitoring. External audits carry additional weight precisely because they are independent. In practice, the two are complementary: internal functions run frequent, targeted testing, while external reviewers provide periodic validation and challenge. When preparing to prove compliance programme spain adequacy, a combination of both, with clear reporting lines to the supervisory body, is the strongest position. The OECD Good Practice Guidance on Internal Controls, Ethics and Compliance identifies periodic review and independent assessment as recognised indicators of programme effectiveness that courts and prosecutors treat as persuasive.

Sampling, Testing and Statistical Validity

Audit conclusions are only as strong as their methodology. Document the sampling approach, the population from which samples were drawn, the rationale for sample size, and the tests applied. Where an audit claims that controls operated effectively across thousands of transactions, a defensible sampling method makes that claim credible. Ad hoc, unexplained sampling invites challenge. Record the evidence gathered for each test so findings can be reconstructed later.

Documenting Findings and Remediation

An audit that identifies weaknesses and triggers timely remediation is more persuasive than a clean report. Courts understand that no programme is perfect; what they reward is a functioning cycle of detection and correction. Every finding should be logged with a severity rating, a named owner, a deadline and evidence of closure. This remediation trail is itself evidence of an effective model.

Using Forensic Auditors in Investigations

Once an offence is suspected, forensic auditors can gather and preserve evidence to investigative standards, critical for both establishing facts and demonstrating cooperation. Engaging forensic specialists early, ideally under the direction of counsel, helps protect the integrity of findings and supports arguments for mitigation based on prompt, credible internal response.

Documentation, Logs and Chain of Custody, Making Evidence Admissible and Persuasive

Even the best compliance activity is worthless in court if the underlying documentation cannot be shown to be authentic and contemporaneous. Compliance documentation in Spain must therefore be managed with the same rigour a litigator would expect of any evidentiary record. This section addresses how to keep evidence admissible and persuasive.

Document Retention and Metadata

Adopt a retention policy that preserves compliance records for the periods relevant to potential criminal exposure, taking into account the limitation periods applicable to the relevant offences, and ensure metadata, creation dates, authors, version histories, is preserved intact. Metadata is often what converts a document from “asserted” to “proven.” Avoid practices that strip or overwrite metadata, and ensure that policy versioning demonstrates the model’s evolution over time.

Chain of Custody for Digital Evidence

Where digital records may become evidence, maintain a documented chain of custody: who collected the data, when, how it was stored, and who accessed it. Secure storage, timestamping and access logs protect against allegations of tampering. E-discovery readiness, being able to locate, preserve and produce relevant records quickly, also signals a mature compliance function and supports cooperation with authorities.

Handling Privileged Materials During Investigations

Distinguishing privileged from non-privileged records is essential. In Spain, professional secrecy (secreto profesional) protects communications with external lawyers, and mishandling such material can expose sensitive analysis. Guidance from the Consejo General de la Abogacía Española on professional conduct and professional secrecy, together with the General Statute of the Legal Profession, should inform how internal investigations are structured and how counsel is involved. Equally, companies must respect employee privacy and data protection rights when collecting and processing personal data during monitoring and investigations, balancing evidentiary needs against obligations under the EU General Data Protection Regulation and Spain’s Organic Law 3/2018 on data protection and digital rights, as supervised by the Agencia Española de Protección de Datos.

Third-Party Certification and External Attestations, Benefits and Limitations

Third-party compliance certification in Spain is frequently offered up as proof of a functioning programme, but its value must be understood realistically. Certifications can help, yet they are rarely decisive on their own.

ISO and Anti-Bribery Certifications

Certifications such as ISO 37001 (anti-bribery management systems) and ISO 37301 (compliance management systems), or conformity with the Spanish standard UNE 19601 on criminal compliance management systems, demonstrate that a company’s control framework has been assessed against a recognised standard. This is genuinely useful evidence of design quality, it shows an external body examined the architecture of the programme. However, as the OECD guidance underscores, standards certification attests principally to the design of controls at a point in time, not to their operational effectiveness at the moment an offence occurred. That distinction is the crux of how courts treat certifications.

Independent Attestations and Scope Limitations

Every certification and attestation has a defined scope, and the scope frequently does not cover the specific process or business unit where an offence arose. When presenting a certificate, be candid about its scope and supplement it with operational evidence, audit reports, testing logs and remediation records, that shows the certified controls actually worked in practice. Presenting a certificate as a talisman, without operational corroboration, invites a prosecutor to expose the gap between design and operation.

Using Certifications in Mitigation Arguments

Used correctly, certifications form one strand of a broader mitigation argument. They corroborate that the company invested in a serious, externally validated framework. The persuasive package pairs the certificate with the underlying audit reports, the follow-up actions taken on any nonconformities, and evidence of continuous monitoring. This combination is far more effective than either the certificate or the internal evidence alone.

Self-Reporting, Remediation and Timing Strategies to Maximise Mitigation

Timing can be as important as substance. The decisions a company takes in the hours and days after discovering a potential offence significantly influence the mitigation available in later proceedings.

Self-Reporting Best Practice

Confession of the offence to the authorities before knowing that judicial proceedings are directed against the company, and cooperation with the investigation by providing new and decisive evidence, are recognised as mitigating circumstances under Article 31 quater of the Código Penal. Self-reporting is not, however, a guarantee of exemption. The value of self-reporting depends on its timing, its completeness and the credibility of the accompanying evidence. Premature disclosure without a factual foundation, or partial disclosure that later proves incomplete, can backfire. The decision should be taken with counsel, weighing the strength of the internal investigation, the likelihood of external discovery, and the remediation already underway.

Designing Remediation with Measurable Outcomes

Remediation that demonstrates the model working carries the greatest weight. Design remediation with measurable outcomes: specific control enhancements, disciplinary measures, recovery of losses, retraining, and independent verification that the fix is effective. Reparation or reduction of the harm before trial is itself a recognised mitigating circumstance. Each remediation action should be logged with a responsible owner, a deadline and evidence of completion. A remediation log that shows prompt, thorough and verified corrective action is one of the strongest mitigation tools available.

Using Remediation to Support Sentencing and Mitigation Arguments

When the company reaches the point of arguing for reduced corporate criminal liability, the remediation record and the demonstrable improvements to the prevention model become central. Establishing measures before trial to prevent and detect future offences is expressly recognised as a mitigating circumstance under Article 31 quater. This behaviour shows that the company took responsibility, corrected the failure, and reduced the risk of recurrence, precisely the conduct the statutory mitigation provisions are designed to reward. Corporate criminal liability mitigation in Spain rewards demonstrable, verified corrective action far more than promises of future compliance.

Comparison Table, Evidence Types and Persuasive Weight in Spanish Proceedings

The table below compares common categories of evidence used to prove compliance programme spain effectiveness, their typical weaknesses, and how to strengthen each. Use it as a triage tool when assembling a defence dossier.

Evidence type Persuasive weight Typical weaknesses How to strengthen
Board minutes High Generic entries; no evidence of objective risk discussion or decisions Use dated, signed minutes with attendance lists and specific references to risk items and resource decisions
External ISO/UNE certification Medium Shows control design but not operation; scope may exclude the relevant unit Pair with audit reports, testing logs and evidence of follow-up actions demonstrating operation
Internal investigation report High (if independent and documented) Conducted in-house without safeguards; perceived as self-serving Involve an external reviewer, apply forensic standards, and preserve underlying evidence
Risk assessment / risk map High Stale; failed to cover the business line where the offence occurred Show methodology, dates, ownership and periodic updating reflecting the actual risk
Training and attendance records Medium to High Generic sessions; no proof the relevant employees attended Provide role-specific training records, completion certificates and assessment results
Monitoring and testing logs High No evidence of follow-up when issues detected Log findings, owners, deadlines and closure to show the model detecting and correcting

As a rule of thumb, “good” evidence is contemporaneous, dated, independently verifiable and shows a control functioning; “weak” evidence is undated, generic, created after the fact, or asserts effectiveness without operational proof.

Practical Steps and a 90-Day Timeline to Prove Compliance Programme Spain Readiness

When an offence is suspected, structured action in the first days and weeks preserves evidence and builds the mitigation case. The following timeline gives in-house teams a defensible sequence to prove compliance programme spain readiness and protect the company’s position.

Immediate Preservation Actions (24–72 Hours)

  • Preserve systems and data. Suspend routine deletion, issue a legal hold, and secure relevant email, transaction and access-log data.
  • Secure third-party records. Preserve contracts, due diligence files and communications with implicated intermediaries.
  • Notify counsel. Engage internal and, where appropriate, external counsel to direct the response and protect professional secrecy.
  • Begin a scoped internal review. Define a narrow, protected scope to establish the facts before deciding on wider action.

30/60/90 Day Tactical Plan

  1. By day 30: assemble the response team, complete a gap analysis against the statutory model elements, and confirm document preservation is comprehensive.
  2. By day 60: run targeted compliance audits on the affected area, complete the fact-finding investigation, and begin a documented remediation log with owners and deadlines.
  3. By day 90: finalise remediation with verification, prepare the evidence dossier mapped to the checklist, and take an informed decision, with counsel, on self-reporting and cooperation.

When to Engage External Forensic Counsel

Engage external forensic counsel when the suspected conduct involves senior management, significant financial exposure, cross-border elements, or a realistic prospect of prosecution. External specialists strengthen the independence and credibility of the investigation and audit evidence, which is exactly what a court weighs when deciding whether the company’s response supports mitigation.

Conclusion

To prove compliance programme spain effectiveness in 2026 is, fundamentally, an evidentiary exercise: it is not enough to have a model, you must be able to show, through dated, verifiable, contemporaneous records, that the model was appropriate to the risk, genuinely implemented, actively monitored, and capable of detecting and correcting problems. The statutory framework in the Código Penal, the criteria applied by the Fiscalía General del Estado, and the jurisprudence of the Tribunal Supremo all point in the same direction: substance over form.

Companies that build a disciplined evidence base, governance records, current risk assessments, training and monitoring logs, credible audits, and a demonstrable remediation cycle, place themselves in the strongest position to secure mitigation or exemption if a prosecution ever arises. For a deeper foundation, see the Spanish Corporate Criminal Compliance (2026) overview, and use the evidence checklist and internal audit methodology resources to operationalise the guidance above. Preparing this evidence before an investigation begins, rather than scrambling after, is the single most reliable way to prove compliance programme spain readiness when it matters most.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.

Sources

  1. Código Penal (Ley Orgánica 10/1995, consolidated text), Boletín Oficial del Estado
  2. Boletín Oficial del Estado (BOE)
  3. Fiscalía General del Estado
  4. Consejo General del Poder Judicial / Tribunal Supremo
  5. Ministerio de Justicia (Spain)
  6. OECD, Good Practice Guidance on Internal Controls, Ethics and Compliance
  7. Consejo General de la Abogacía Española
  8. Comisión Nacional del Mercado de Valores (CNMV)
  9. Agencia Española de Protección de Datos (AEPD)

FAQs

How can a company prove its compliance programme is effective in Spain?
Produce the prevention model (modelo de prevención de delitos) together with the evidence that it lived: a dated risk assessment, documented and communicated policies, training and attendance records, monitoring and testing logs, audit reports, investigation and remediation files, third-party due diligence, and board oversight through minutes. Emphasise contemporaneous documentation, preserved metadata and independent verification. The statutory basis sits in Article 31 bis of the Código Penal, and prosecutorial expectations are reflected in Fiscalía General del Estado guidance.
They look for a model adopted and effectively implemented before the offence, an autonomous supervisory body with adequate powers, effective monitoring, absence of participation by senior management in an otherwise effective model, and credible remediation. Persuasive evidence includes dated board minutes, a current risk map, monitoring logs showing detection and correction, and independent audit or investigation reports.
Properly executed audits and certifications can help demonstrate programme effectiveness, but they must be demonstrable, within relevant scope, and supported by remediation. Certifications such as ISO 37001 or UNE 19601 show control design rather than operation, so they are rarely decisive alone. Combine them with operational evidence to build a credible mitigation argument.
Maintain testing protocols and sampling records, KPI dashboards, and remediation logs that name responsible persons, set deadlines and evidence follow-up and closure. Preserve dates and metadata so the records are demonstrably contemporaneous. This documentation is central to proving the model detected and corrected issues.
No. Confession and cooperation are recognised mitigating factors under Article 31 quater of the Código Penal when combined with effective remediation and credible evidence, but they do not guarantee exemption. Timing, completeness and the strength of the underlying investigation determine their value, so the decision should be taken with counsel.
Yes, where they show active oversight, documented decisions and responses to identified risks. To be persuasive they must be corroborated by contemporaneous evidence such as risk assessments, reports to the board, and follow-up actions. Generic minutes with no substance carry little weight.
Preserve relevant systems and issue a legal hold, suspend document destruction, notify counsel, secure third-party records, and begin a scoped internal review under professional secrecy. These steps protect evidence integrity and lay the foundation for later mitigation arguments.
us citizen buy house bulgaria
By Global Law Experts

posted 52 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Prove Your Corporate Criminal Compliance Programme Works in Spain (2026)

Send welcome message

Custom Message