Our Expert in Spain
No results available
Compliance due diligence Spain has become one of the highest-stakes workstreams in any Spanish M&A transaction as 2026 opens, driven by intensifying corporate criminal enforcement, tightened anti-money-laundering scrutiny and the now-mature whistleblowing regime. Buyers face the risk of inheriting undisclosed criminal or regulatory liabilities that survive completion; sellers face aggressive information demands, indemnity caps and escrow holdbacks unless they arrive at the table with remediation evidence in hand. This is fundamentally a decision article: it tells corporate teams, general counsel and private-equity principals exactly who should run which checks, which contractual protections to insist on, and how to draft negotiation-ready wording.
If you are buying, work from the buyer checklist and push for broad reps, indemnities and escrow; if you are selling, work from the seller checklist and remediate before you market. The pages that follow give you the side-by-side grid, the priority risk map and the sample clauses to act on both positions.
Compliance due diligence in a Spanish M&A deal is the structured investigation of a target’s exposure to criminal, regulatory and reputational liability, conducted before signing so that the parties can allocate that risk through price, contract terms and post-closing obligations. Unlike financial or tax diligence, its focus is whether the target’s conduct, controls and culture create hidden liabilities, bribery, money laundering, fraud, sanctions breaches, data-protection failures or a missing whistleblowing channel, that a buyer could inherit. Effective M&A compliance Spain review is not a box-ticking exercise; it converts findings into leverage at the negotiating table.
Three pillars define the legal backdrop. First, Spain’s Código Penal establishes criminal liability for legal persons, a regime materially developed by the 2010 introduction of Article 31 bis and reinforced by the 2015 reform (Ley Orgánica 1/2015), exposing companies to fines, activity bans and other penalties for offences committed for their benefit, and giving credit for effective crime-prevention programmes (Source: BOE, Código Penal). Second, Ley 10/2010 of 28 April imposes anti-money-laundering obligations, including customer due diligence, beneficial-ownership identification and suspicious-transaction reporting on regulated entities (Source: BOE, Ley 10/2010).
Third, the whistleblowing framework, Directive (EU) 2019/1937, transposed into Spanish law by Ley 2/2023 of 20 February, requires internal reporting channels for whistleblowers, reshaping how targets must handle internal reports and how buyers may lawfully access them (Source: BOE, Ley 2/2023). Together these establish why compliance due diligence Spain must be run rigorously and early. For a deeper statutory treatment, see Spanish corporate criminal compliance 2026 (GLE article).
The two sides pursue mirror-image goals. A buyer conducts compliance due diligence Spain to identify undisclosed liabilities, quantify their financial and criminal exposure, and secure contractual remedies, reps, indemnities, escrow and, where needed, walk-away rights. A seller conducts its own compliance review to reduce deal friction: to remediate material problems before marketing, to narrow the scope of what must be disclosed, and to demonstrate that credible controls already exist so that buyer demands for holdbacks and long survival periods can be resisted. Both share a common analytical spine, risk identification, remediation and contractual allocation of risk, but they optimise for opposite outcomes.
The table below is the operational centrepiece of this guide. Use it to allocate tasks by role, to confirm what to request or prepare at each deal stage, and to identify red flags that should trigger escalation. When any red flag surfaces, unexplained payments, missing KYC files, refused investigation reports, stop and bring in specialist compliance counsel and, where appropriate, a forensic accountant before proceeding. Do not treat the grid as advisory; treat it as a decision map for your side of the deal.
| Topic / Task | Buyer (what buyer should do) | Seller (what seller should do) |
|---|---|---|
| Primary objective | Identify undisclosed compliance liabilities, quantify risk, secure contractual remedies | Reduce deal friction, limit disclosure scope, demonstrate remediation to reduce buyer demands |
| Timing | Pre-LOI: high-level risk screen; Pre-SPA (DD window): deep dives; Post-closing: integration | Pre-market: remediate material issues; Pre-SPA: prepare disclosure schedule & supporting docs; Post-closing: limited remediation & cooperative obligations |
| Scope (core areas) | Corporate criminal liability, AML/KYC, anti-bribery, sanctions, data protection (whistleblowing channels), environmental compliance where relevant | Same coverage, focus on internal controls, policies, training records, incident logs and remediation evidence |
| Team | Compliance lawyer (Spain), forensic accounting, local counsel in target jurisdictions, external investigators when red flags | Seller counsel + compliance lead; external consultants only for remediation and to produce certificates |
| Documents to request / provide | Policies & controls, internal audit reports, investigation reports, sanctions-screening logs, third-party due diligence, whistleblowing reports, training records, intermediary contracts, AML KYC files (where permitted) | Up-to-date compliance manuals, evidence of implementation, internal investigation reports (with privilege strategy), remediation plans, certifications, no-claim letters where appropriate |
| Enhanced checks triggers | High-risk sectors/geographies, history of investigations, government contracts, complex agent networks, significant cash flows | If past incidents identified: prepare redacted investigation reports, mitigation evidence and propose escrow or insurance |
| Red flags | Unexplained payments, deficient KYC records, non-existent policies, suspicious whistleblower allegations, related-party transactions | Incomplete documentation, refusal to disclose investigation documents, inconsistent statements, missing training records |
| Typical buyer protections | Specific compliance reps & warranties, indemnities, escrow, purchase-price holdback, conditional closing (remediation/cure), termination for material compliance breach | Narrower reps, extensive disclosure schedule, baskets/loss thresholds, shorter survival for compliance reps, liability caps, carve-outs for disclosed matters |
| Evidence standard | Contractual: materiality qualifiers, knowledge definitions, diligence to prove breach | Push for known-item disclosure, knowledge thresholds (actual/constructive), and de-minimis thresholds |
| Remedies preferred | Indemnity for losses, step-in rights, mandatory remediation, escrow, termination for fraud | Limitation of liability, knowledge qualifiers, short survival, indemnity caps, insurance procurement |
| Data and privacy constraints | Respect data protection: follow AEPD guidance on whistleblowing & employee data, use redaction & lawyers’-eyes-only protocols | Use privilege advice, redact personal data; propose bespoke data rooms with restricted access |
| Post-closing obligations | Integration plan, remediation schedule with KPIs, seller reporting where remediation ongoing | Cooperation covenant, limited remediation obligations, defined timelines and cost allocation |
| Typical negotiation battlegrounds | Scope of reps, survival periods, caps, escrow amounts, knowledge qualifiers | Disclosure granularity, survival, constructive-knowledge definition, insurance/escrow limits |
As a buyer, scope your review around the target’s criminal, AML, anti-bribery, sanctions and data-protection exposure, then widen or deepen depending on sector and geography. Your document request should cover the full control environment: compliance manuals and policies, internal audit and investigation reports, sanctions-screening logs, third-party due-diligence files, whistleblowing reports (subject to the privacy constraints below), training records, and contracts with agents, distributors and intermediaries. Where local rules permit, request AML KYC files for material counterparties.
Enhanced checks are not discretionary in certain fact patterns. Escalate to a deeper compliance due diligence Spain review whenever you encounter high-risk sectors or jurisdictions, any history of regulatory investigation, significant public-sector contracts, complex networks of sales agents, or unusually large cash flows. In those cases, assemble the right team early, a Spanish compliance lawyer, a forensic accountant, local counsel in each relevant jurisdiction and, where red flags appear, external investigators. Speed matters; the DD window is finite and forensic testing takes time.
Treat the following as red flags demanding immediate action: unexplained or round-sum payments, deficient or missing KYC records, policies that exist on paper but are not implemented, credible whistleblower allegations, and related-party transactions lacking commercial rationale. When any of these appear, do not simply note them in a report. Pause the workstream, brief the deal principals, and translate the finding into a specific contractual ask, a targeted indemnity, an escrow uplift, a condition to closing requiring remediation, or in serious cases a walk-away right for fraud. The purpose of buyer-side compliance due diligence Spain is not merely to describe risk but to price and contractualise it.
As a seller, your best defence is preparation. Begin pre-sale readiness well before marketing: run an internal compliance review, remediate material issues, refresh policies and capture evidence of implementation and training. A target that arrives at diligence with a functioning whistleblowing channel, current AML procedures and documented board oversight gives the buyer far less to hold back on. Seller disclosure schedule compliance is the core discipline here, a well-constructed, granular disclosure schedule converts unknown risk into disclosed, carved-out matters that fall outside the reps.
Best practice on the disclosure schedule is to be specific and comprehensive: disclose against each rep with dated references to underlying documents, and use redacted investigation reports and independent-auditor certifications to substantiate that historic issues have been addressed. Manage privilege carefully, take advice on how to present internal investigation findings without waiving legal privilege, and consider producing a summary certificate rather than the full privileged file.
The central seller question is how to limit post-completion criminal liability for historic breaches. Several levers work in combination. Remediate before completion and document it. Disclose known incidents fully, so they become carved-out matters. Where residual exposure remains, propose an escrow or warranty-and-indemnity insurance rather than an open-ended indemnity. Negotiate hard on the mechanics: seek knowledge qualifiers (actual rather than constructive), de-minimis and basket thresholds, a liability cap, and short survival periods for compliance reps. Understand, however, that fraud carve-outs typically survive all of these limitations, no disclosure or cap will shield a seller from liability for concealment, and criminal liability of the legal person itself cannot be transferred away by contract.
Honest, evidenced disclosure remains the most reliable protection, and it is the foundation of any credible seller-side compliance due diligence Spain strategy.
Not every compliance issue is deal-critical. Prioritise the risks that carry criminal exposure, regulatory sanction or the potential to unwind the transaction. The four categories below deserve the first tranche of any compliance due diligence Spain review.
The single most important risk is corporate criminal liability Spain. Under Article 31 bis of the Código Penal, legal persons can be held criminally liable for a defined list of offences committed for their benefit by directors, employees or those under their control, with the 2015 reform clarifying the conditions under which an effective compliance programme can exempt or mitigate liability (Source: BOE, Código Penal). The offences most relevant to M&A are bribery and corruption, fraud, tax and financial crimes, and money laundering. A conviction can bring fines, disqualification from public subsidies and contracts and other penalties that attach to the company itself, and therefore remain with it in a share deal.
Crucially, an adequately designed and effectively implemented crime-prevention programme (modelo de organización y gestión) can mitigate or exclude liability, which is why buyers scrutinise whether the target’s programme is genuine rather than cosmetic. The Fiscalía General del Estado has issued guidance on how prosecutors assess the genuineness of compliance programmes and cooperation (Source: Fiscalía General del Estado). For buyers, the presence, or absence, of a credible programme is both a risk indicator and a negotiation lever.
AML due diligence Spain focuses on whether the target, if an obliged entity under Ley 10/2010, meets its obligations: customer due diligence, identification of beneficial owners, enhanced measures for higher-risk relationships and reporting of suspicious transactions to the SEPBLAC (the Spanish financial intelligence unit) (Source: BOE, Ley 10/2010). Enhanced due diligence is triggered by high-risk jurisdictions, politically exposed persons, complex ownership structures and certain higher-risk transactions. Layer sanctions screening over this, and align your approach with EU-level standards on anti-money-laundering and counter-terrorist financing (Source: European Commission, AML/CFT). Weak KYC files or a history of unreported suspicious activity are among the most serious red flags a buyer can find.
Whistleblowing channel M&A issues cut two ways. First, confirm the target operates a compliant internal reporting channel as required under Ley 2/2023, which transposes Directive (EU) 2019/1937 (Source: BOE, Ley 2/2023); its absence is a compliance gap and, for many entities, a legal breach. Second, respect the privacy limits on accessing whistleblower reports. AEPD guidance restricts the sharing of whistleblower data and emphasises data minimisation, redaction of personal data and restricted-access protocols when such material enters a data room (Source: AEPD). A buyer cannot simply demand raw whistleblower files; access must be structured lawfully.
Sales agents, distributors and customs brokers are recurring vectors of bribery and sanctions exposure. Scrutinise commission structures, success fees, offshore payment routes and any intermediary operating in a high-risk market without documented due diligence. An agent network that lacks contractual anti-corruption terms and vetting records is a priority red flag.
Sequencing matters. Run compliance due diligence Spain in three phases aligned to the deal timeline, so that early findings shape the letter of intent and deep findings shape the SPA and price.
Before the letter of intent, run a fast, low-cost screen: open-source and corporate-registry checks, sanctions and PEP screening of the target and its principals, and adverse-media searches. The goal is to surface deal-breakers early and to calibrate the depth of the diligence to come. A clean screen supports a leaner process; hits justify a wider scope and budget.
Inside the DD window, move to substantive work. Issue a detailed document request covering policies, audit and investigation reports, KYC files, intermediary contracts and training records. Build an interview plan for compliance, finance and commercial leads. Undertake sample testing of transactions and a forensic review of any suspicious payments identified in screening. Establish data-room protocols before anything sensitive is uploaded, restricted access, redaction of personal data, and lawyers’-eyes-only handling for privileged or whistleblower material, consistent with AEPD guidance. This is where enhanced checks belong: a buyer should carry out enhanced AML, anti-corruption and whistleblowing review whenever screening or sector risk warrants it, and always before signing rather than after. Findings feed directly into reps, indemnities and price.
After completion, convert diligence findings into a monitoring plan. Define KPIs for open remediation items, set a reporting cadence to the buyer’s board, and tie escrow releases to remediation milestones where the SPA provides for it. Documented board-level oversight and prompt remediation can be relevant factors should any historic issue surface post-closing and attract scrutiny from a regulator or the Fiscalía.
Diligence findings are only as valuable as the contract that captures them. The sample wording below illustrates typical positions; adapt each to the specific transaction and take advice before use.
Reps and warranties compliance drafting turns on scope, knowledge qualifiers and materiality. Buyers want a broad, unqualified rep; sellers want it narrowed by knowledge and materiality. A buyer-favourable broad rep might read:
“The Company and each of its subsidiaries has at all times conducted its business in compliance in all material respects with all applicable anti-bribery, anti-corruption, anti-money-laundering, sanctions, data-protection and whistleblowing laws, and no director, officer or employee has engaged in any conduct that would give rise to criminal liability of a legal person under the Código Penal.”
A seller-favourable, knowledge-qualified alternative narrows exposure:
“So far as the Seller is actually aware, the Company has complied in all material respects with applicable anti-corruption and anti-money-laundering laws, and the Seller has received no written notice of any investigation, charge or proceeding alleging non-compliance.”
Negotiation lever: buyers should resist a bare “actual awareness” standard and press for a defined constructive-knowledge concept and a materiality scrape on the indemnity, while sellers push for actual knowledge and a materiality qualifier on the rep itself.
Where diligence reveals a specific or contingent exposure, a targeted indemnity is preferable to reliance on general warranties. A specific compliance indemnity might provide:
“The Seller shall indemnify the Buyer on a euro-for-euro basis against all losses, fines, penalties and reasonable costs arising from any breach of anti-corruption or anti-money-laundering law occurring on or before Completion, without regard to any disclosure, basket or de-minimis threshold, and such indemnity shall not be subject to the general cap on liability.”
Link the indemnity to an escrow or purchase-price holdback sized to the assessed exposure, and carve fraud and criminal penalties out of any cap. Sellers will counter with a cap, a survival limit and, increasingly, warranty-and-indemnity insurance to move risk off their balance sheet. Escrow sizing for compliance claims varies by deal, set it against the specific risk quantified in diligence rather than a fixed percentage.
Disclosure is the seller’s shield. Present investigation reports in redacted form, disclose against each rep with dated document references, and consider independent-auditor certifications to evidence remediation without waiving privilege over the underlying file. Buyers should insist that disclosure be fair and specific, general or “deemed” disclosure of an entire data room should be resisted, because it dilutes the value of the reps.
Where remediation continues after closing, a cooperation and cost-allocation clause keeps the parties aligned:
“For a period of [12] months following Completion, the Seller shall, at the Buyer’s reasonable request, provide such information and assistance as is necessary to complete the remediation items set out in Schedule [X]. The cost of remediating matters arising from facts existing before Completion shall be borne by the Seller up to the amount held in the Escrow Account; costs of ongoing compliance thereafter shall be borne by the Buyer.”
Compliance integration post-merger determines whether the risks priced in diligence are actually contained. Adopt a quick-start 90-day plan: in the first 30 days, extend the acquirer’s code of conduct, whistleblowing channel and sanctions-screening to the target and close any immediate control gaps. By day 60, complete the prioritised remediation items identified in diligence, deficient KYC files, missing training, intermediary contracts lacking anti-corruption terms. By day 90, embed KPIs, assign compliance ownership and establish a reporting line to the acquirer’s board. Where remediation is escrow-linked, tie releases to documented completion of milestones. Maintain a clear record of remediation, as it evidences good faith should any Spanish regulator or the Fiscalía examine legacy conduct.
Choose the buyer checklist when:
Choose the seller checklist when:
Retain specialist compliance counsel the moment any criminal-liability red flag, cross-border AML exposure or contested disclosure arises, the cost of advice is trivial against the cost of an inherited conviction or an unwound deal.
Compliance due diligence Spain in 2026 is where deals are won, lost or repriced. The decision is straightforward once you know your role: buyers should run the enhanced-checks workflow, quantify exposure and lock in broad reps, targeted indemnities and escrow; sellers should remediate early, disclose specifically and negotiate knowledge qualifiers, caps and short survival, remembering that fraud carve-outs survive everything and that criminal liability attaching to the company cannot be contracted away. Prioritise corporate criminal liability, AML, sanctions and whistleblowing, respect AEPD limits on employee data, and convert every diligence finding into contract wording. For bespoke drafting and deal-specific strategy on compliance due diligence Spain, consult a specialist.
Read the profile of Jordi Sot Ball-llosera, lawyer profile (GLE) for tailored counsel.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.
posted 4 minutes ago
posted 11 minutes ago
posted 19 minutes ago
posted 39 minutes ago
posted 57 minutes ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message