Our Expert in Spain
No results available
Spain’s financial reporting obligations have undergone their most significant overhaul in a decade. Royal Decree 253/2025, published in the Boletín Oficial del Estado (BOE) on 1 April 2025, introduced sweeping changes to the scope, frequency, and granularity of tax information that financial institutions, payment service providers, and certain non-financial corporates must submit to the Agencia Tributaria (AEAT). In a subsequent analysis dated 26 November 2025, the AEAT confirmed the removal of the €3,000 minimum threshold for card-payment reporting, meaning virtually every card transaction processed in Spain now falls within scope.
These reporting obligations 2026 took effect on 1 January 2026, and the consequences of non-compliance extend well beyond administrative fines: inaccurate, incomplete, or late filings can trigger referrals to the Fiscalía and expose both companies and their directors to corporate criminal liability under the Spanish Código Penal.
For general counsel, CFOs, and compliance officers, the window for reactive implementation has closed. The priority now is to verify that systems, controls, and escalation protocols are operating correctly, and to remediate any gaps before they crystallise into enforcement risk. The five immediate actions every affected organisation should take are:
Understanding the 2026 changes requires a working knowledge of the institutional and legal architecture that governs financial compliance in Spain. Three pillars support the reporting ecosystem: the AEAT as the primary tax authority, the BOE as the vehicle for legislative publication, and the Registro Mercantil (Commercial Register) as the repository for corporate filings. Overlaying these domestic structures are the EU’s Directive on Administrative Cooperation (DAC) framework and the OECD’s Common Reporting Standard (CRS), both of which drive Spain’s progressive expansion of automatic exchange and reporting obligations.
The AEAT administers and enforces tax reporting obligations Spain through a combination of Royal Decrees, Ministerial Orders, and interpretative analyses. Royal Decrees are published in the BOE and carry the force of law. The AEAT supplements these with technical guidance, such as the 26 November 2025 analysis on financial information obligations, that clarifies how reporting entities should interpret their duties in practice. The Commercial Register, governed by the Ley de Sociedades de Capital and the Reglamento del Registro Mercantil, requires companies to file annual accounts (cuentas anuales) within one month of their approval by the general meeting. For companies closing their financial year on 31 December, this typically means filing by the end of July.
All Spanish sociedades de capital (including sociedades limitadas and sociedades anónimas) must file annual accounts with the Commercial Register. The filing comprises the balance sheet, profit-and-loss account, statement of changes in equity, cash-flow statement (where required), and the directors’ report. Failure to file within the statutory deadline results in administrative sanctions imposed by the Register and, for persistent non-filers, potential closure of the company’s registered page, effectively paralysing corporate transactions.
Spain does not follow US GAAP. Statutory individual-entity accounts must be prepared under the Plan General de Contabilidad (PGC), Spain’s national accounting framework, which is substantially aligned with IFRS but contains specific local adaptations. Listed groups are required to prepare consolidated financial statements under full EU-adopted IFRS. Non-listed groups may elect to apply IFRS for consolidation purposes. Understanding which framework applies is essential when assessing whether reported data meets the AEAT’s expectations, since discrepancies between PGC and IFRS treatments can create reconciliation challenges in tax reporting.
Royal Decree 253/2025 and the AEAT’s accompanying guidance represent a structural shift in tax reporting obligations Spain must accommodate. The changes affect both the categories of data that must be reported and the entities that must report them. The most immediately impactful reforms are outlined below.
Removal of the €3,000 card-payment threshold. The AEAT’s analysis of 26 November 2025 confirmed that the previous de minimis threshold, which exempted card transactions below €3,000 from itemised reporting, has been eliminated. From 1 January 2026, all card-payment transactions, regardless of value, must be reported to the AEAT by acquirers and payment processors. Industry observers expect this change alone to multiply the volume of reportable data by an order of magnitude for many institutions.
Expanded reporting categories. The decree broadens the scope of reportable financial information to include open accounts, lending activity, cash movements, collections, card payments, and cross-border payment flows. Financial institutions and PSPs must now report on categories that were previously either voluntary or subject to higher materiality thresholds.
Increased reporting frequency. For certain categories, particularly those affecting PSPs and foreign payment providers operating in Spain, the AEAT has moved from annual or quarterly reporting to a monthly cadence. This compressed timeline demands near-real-time data extraction and validation capabilities.
Cross-border alignment. Spain’s reforms also implement elements of the EU’s DAC framework and reflect the OECD’s push for automatic exchange of financial account information under the CRS. The likely practical effect is that data reported to the AEAT will be shared with tax authorities in other EU member states and CRS-participating jurisdictions under existing exchange agreements.
| Date | Source (BOE / AEAT) | Practical Effect |
|---|---|---|
| 1 April 2025 | BOE, Royal Decree 253/2025 | New reporting obligations published; defines expanded categories, entity scope, and transitional provisions. |
| 26 November 2025 | AEAT, Interpretative analysis | Confirms removal of €3,000 card-payment threshold; provides technical guidance on data elements and XML schemas. |
| 1 January 2026 | BOE / AEAT (effective date) | Majority of new reporting obligations 2026 take effect; monthly reporting cycle begins for designated entities. |
The scope of Spain’s 2026 reporting changes varies significantly depending on entity type, activity, and transaction volume. The following comparison table summarises the main obligations and the compliance actions each category of organisation should prioritise.
| Entity Type | Main Reporting Obligation(s) (2026) | Key Compliance Actions |
|---|---|---|
| Banks / deposit takers | Expanded periodic reporting of card payments, account openings, and cash activity; monthly cadence in some cases. | Map data feeds, update reporting scripts, reconcile card acquirer files to AEAT submissions. |
| Payment Service Providers (PSPs) / Fintechs | Detailed reporting on open accounts, collections, card payments, lending transactions, monthly from 1 January 2026 for many. | Confirm reporting XML schema, implement automated exports, establish record retention policy. |
| Lenders (incl. marketplace lenders) | Reporting of lending flows and outstanding balances if covered by Royal Decree 253/2025. | Update loan origination systems to tag AEAT reporting fields; ensure AML/KYC data is linked. |
| Non-financial corporates | Reporting triggers when acting as payees/processors for large volumes or cross-border flows, obligations depend on volume and sector. | Identify reporting triggers, maintain invoicing controls, coordinate with payment service providers. |
| Small & medium enterprises | Generally exempt from expanded financial-intermediary reporting, but standard tax filing and invoicing obligations remain; may be indirectly affected as data subjects. | Verify whether any PSP/acquirer reporting triggers apply; maintain compliant invoicing practices. |
PSPs face the steepest compliance curve. The AEAT expects monthly submissions containing granular transaction-level data: payer/payee identification, IBAN or equivalent account references, transaction amounts, dates, and categorisation codes aligned with the AEAT’s published XML schema. Fintechs that operate cross-border must also comply with DAC7 platform-reporting requirements where they facilitate payments for sellers or service providers. Early indications suggest that the AEAT’s automated validation systems will reject files that fail schema checks, triggering penalty exposure from the first month of non-compliant submission.
Traditional banks already report under CRS and existing AEAT informative returns (modelos). The 2026 changes expand the data envelope: banks must now include additional card-payment data without the former €3,000 floor, report on new account categories, and align cash-activity reporting with enhanced anti-money-laundering data flows. The operational challenge lies in integrating legacy core-banking system exports with the AEAT’s updated file specifications.
Most non-financial corporates are not directly subject to the expanded intermediary-reporting obligations. However, companies that process payments on behalf of third parties, operate marketplace platforms, or handle significant cross-border cash flows may trigger reporting thresholds under Royal Decree 253/2025. Additionally, all companies remain subject to standard tax reporting obligations Spain enforces through periodic modelo filings, withholding-tax returns, and invoicing requirements, including the forthcoming e-invoicing mandates.
The most consequential, and most frequently underestimated, dimension of the 2026 reporting changes is the criminal exposure they can create. Spain’s corporate criminal liability regime, introduced through Organic Law 5/2010 and significantly expanded by Organic Law 1/2015, allows the prosecution of legal entities for offences committed on their behalf or for their benefit by directors, officers, or employees. Tax fraud, falsification of accounts, and money laundering are all within scope.
The escalation from administrative non-compliance to criminal investigation follows a well-established path in Spain. The AEAT conducts routine and risk-based audits of informative returns. When an audit uncovers discrepancies that suggest deliberate underreporting, falsification, or concealment, the AEAT refers the matter to the Fiscalía (public prosecutor’s office). The Fiscalía then determines whether there is sufficient evidence to open a criminal investigation. Under the Código Penal, tax fraud (delito fiscal) arises where the amount defrauded exceeds the applicable statutory threshold and involves wilful conduct or gross negligence amounting to recklessness.
For compliance officers, the critical insight is that inaccurate reporting, even if unintentional, can trigger an AEAT audit, and the audit trail (or lack thereof) determines whether the matter stays administrative or becomes criminal. Organisations without robust controls and documented processes face elevated risk of the latter.
The penalty framework operates on two levels:
A well-designed and effectively implemented compliance programme (modelo de prevención de delitos) serves as a potential defence or mitigating factor in criminal proceedings. The Supreme Court has confirmed that an adequate compliance programme can exempt or reduce corporate criminal liability, but only where the programme is genuinely operational, regularly updated, and properly supervised by a compliance officer or body with real independence and resources.
The following checklist is designed for GCs, CFOs, and heads of compliance at organisations subject to Spain’s 2026 financial reporting obligations. Each step identifies the action, its rationale, and the function that should own it.
Assign a named senior owner (typically the CFO or Chief Compliance Officer) with board-level accountability for AEAT reporting compliance. Establish a cross-functional reporting committee comprising Legal, Finance, IT, and Internal Audit. Document terms of reference and meeting frequency (minimum quarterly, monthly during implementation). This governance structure is a prerequisite for any credible modelo de prevención de delitos. Owner: Board / CEO.
Conduct a comprehensive mapping exercise that identifies every data source, data flow, and existing report relevant to the 2026 obligations. Compare current output against the AEAT’s published requirements, including the updated XML schemas and the expanded categories introduced by Royal Decree 253/2025. Document every gap, assign remediation owners, and set deadlines. Owner: Finance & IT (jointly).
Implement automated end-to-end reconciliation procedures that match source-system data (card acquirer files, payment processor exports, lending-system extracts) to the data submitted to the AEAT. Reconciliations should run at or before every filing cycle, monthly for entities on the new monthly cadence. Tolerance thresholds should be defined: any variance exceeding the agreed threshold triggers a formal investigation and a hold on filing until the variance is explained. Financial compliance Spain demands require these controls to be documented and testable. Owner: Finance (with IT support).
Adopt a records-retention policy that preserves all data, working papers, reconciliation reports, and correspondence related to AEAT filings for a minimum of six years, aligned with the statutory limitation period for tax obligations in Spain. Implement tamper-proof storage (hashing, immutable logs) for XML submissions and their underlying datasets. Schedule internal audit reviews of reporting processes at least twice per year, with findings reported to the compliance committee. Owner: Internal Audit & IT.
Reconcile AEAT reporting requirements with GDPR obligations. Reporting to the AEAT constitutes a legal obligation under Article 6(1)(c) GDPR, providing a lawful basis for processing personal data included in informative returns. However, organisations should conduct a Data Protection Impact Assessment (DPIA) where the volume or sensitivity of data is significant, ensure data minimisation principles are applied (report only what the AEAT requires), and document the legal basis and retention justification in the organisation’s Records of Processing Activities. Owner: Legal / Data Protection Officer.
If historic or current misreporting is discovered, the compliance team should follow a structured remediation protocol:
Owner: Legal / Compliance (with external counsel where required).
Organisations that have not yet completed their implementation should adopt a compressed 90/60/30-day plan structured around three phases: assessment (days 1–30), build and test (days 31–60), and go-live validation (days 61–90). For entities already filing under the 2026 regime, the plan functions as a health check to identify and close residual gaps.
| Control | Frequency | Owner | Evidence |
|---|---|---|---|
| Source-to-submission reconciliation | Monthly (or per filing cycle) | Finance | Reconciliation report with variance analysis |
| XML schema validation (pre-submission) | Every filing | IT | Automated validation log; error/exception report |
| Compliance committee review | Quarterly | CCO / GC | Meeting minutes; action tracker |
| Internal audit of reporting process | Semi-annually | Internal Audit | Audit report with findings and remediation plan |
| Records-retention compliance check | Annually | IT / Legal | Retention log; sample retrieval test |
IT departments should prioritise three workstreams: first, establishing automated data exports from card acquirers and payment processors in the AEAT’s specified format; second, integrating e-invoicing systems with reporting workflows to eliminate manual re-keying; and third, building pre-submission validation scripts that check each file against the AEAT’s published XML schema before upload. Where legacy systems cannot produce compliant outputs, middleware solutions or managed-service providers may be required.
Internal audit should conduct its first comprehensive review of 2026 reporting processes no later than the end of Q2 2026, covering the first five months of filings. A follow-up review in Q4 2026 should assess whether controls are operating effectively and whether any systemic issues identified in the first review have been remediated. Audit findings should be reported directly to the compliance committee and, where material, to the board. These scheduled reviews are a core component of demonstrating financial compliance Spain regulators and prosecutors expect.
Not every reporting issue warrants external legal advice, but certain red flags should trigger immediate escalation beyond the in-house team. Compliance officers should treat the following as escalation triggers:
The escalation flow should move from in-house triage (compliance officer and GC) to external counsel and, where financial quantification is needed, forensic accountants. The decision to make a voluntary disclosure to the AEAT should only be taken after external counsel has assessed the legal exposure and strategic implications. Organisations with operations in multiple jurisdictions should also consider whether reporting failures in Spain trigger notification obligations in other countries under CRS or DAC exchange agreements.
Spain’s 2026 financial reporting obligations mark a turning point for corporate compliance. The combination of broader reporting scope, compressed filing timelines, and the elimination of previously relied-upon thresholds means that reporting failures are now far more likely to be detected, and the consequences far more severe. Organisations that have not yet completed their implementation should treat this as urgent: run the gap analysis, validate the data feeds, and pressure-test the controls. Those already filing should prioritise the reconciliation and internal-audit steps outlined in this tax compliance checklist to ensure that first-year filings withstand scrutiny.
The stakes are no longer limited to administrative fines; with corporate criminal liability firmly embedded in Spain’s enforcement framework, the cost of inaction can include criminal prosecution of the company and its officers. To search for a qualified compliance practitioner with expertise in Spanish financial reporting, use the Global Law Experts lawyer directory. For broader context on Spain’s tax enforcement landscape, see also our guide to Spain’s Pillar Two deadline and compliance requirements.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.
posted 2 minutes ago
posted 15 minutes ago
posted 27 minutes ago
posted 40 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message