Our Expert in Spain
No results available
Understanding how to implement a corporate criminal compliance programme in Spain in 2026 is now a front‑of‑mind priority for compliance officers, general counsel and business owners operating through Spanish legal entities. Under Article 31 bis of the Código Penal, legal persons face criminal liability for a catalogue of offences committed on their behalf, but a properly designed, documented and tested compliance programme can mitigate or even fully exempt the entity from that liability. Heightened enforcement expectations from the Fiscalía General del Estado, the operational arrival of NIS2 cybersecurity obligations and reinforced AML supervision by SEPBLAC and the Banco de España have all raised the evidentiary bar for what prosecutors and regulators regard as “effective.
” This guide walks through every procedural step, the documents needed for a compliance programme, costs and the 2026‑specific changes that affect the timeline to implement a compliance programme in Spain.
A corporate criminal compliance programme, known in Spanish practice as a modelo de organización y gestión, is an integrated set of policies, controls, governance structures and monitoring mechanisms designed to prevent, detect and respond to criminal conduct attributable to the company. Its principal legal objective is to satisfy the mitigation and exemption conditions set out in Article 31 bis of the Código Penal, as amended by Ley Orgánica 1/2015.
The corporate criminal liability regime applies to all legal persons incorporated or operating in Spain, sociedades anónimas, sociedades limitadas, branches of foreign companies and, with certain exceptions, public‑sector entities engaged in commercial activity. While the law draws no explicit size threshold, the practical reality is that prosecutors and courts assess proportionality: a multinational with 5,000 employees in Spain is expected to maintain a substantially more granular programme than a 20‑person start‑up. Industry observers expect that, following the 2024–2026 cycle of heightened scrutiny, even smaller entities will find it difficult to argue that a light‑touch approach suffices.
Certain sectors face additional, overlapping compliance programme requirements. Financial institutions, payment service providers and insurance companies fall under SEPBLAC AML/CTF supervision. Entities designated as essential or important under Spain’s transposition of the NIS2 Directive (Directive (EU) 2022/2555) must demonstrate cybersecurity risk‑management measures and incident‑reporting capabilities. Companies processing personal data, particularly those operating whistleblowing channels, must align with AEPD guidance on data protection impact assessments and retention.
The critical point is that a compliance programme in Spain is not a one‑off policy exercise. It must be a living system: risk‑mapped, resourced, tested, updated and, above all, documented so that each element can be evidenced to a prosecutor, judge or regulator at any point.
Before drafting a single policy, the organisation must confirm its perimeter and prerequisites. Failing to scope correctly is one of the most common reasons programmes are later found to be ineffective.
The programme must cover every Spanish legal entity through which the group operates. For multinational groups, this means identifying each sociedad, branch or joint venture with a Spanish nexus. The scoping exercise should also capture business lines, geographic territories served from Spain and any regulated activities (AML‑obliged services, critical‑infrastructure operations under NIS2, public procurement participation).
Under the Penal Code framework, the programme must be adopted and supervised by the governing body. This means a formal Board resolution (or equivalent corporate organ decision) that authorises the programme, allocates budget and appoints a compliance lead with sufficient autonomy and access. Without a documented governance mandate, every subsequent step lacks the foundational authority that prosecutors examine first.
The compliance programme requirements under Article 31 bis include, at a minimum: identification of risk activities; establishment of protocols and decision‑making processes; management of financial resources to prevent offences; an obligation to report possible risks and non‑compliance through an appropriate channel; establishment of a disciplinary system; and periodic verification and updating of the model. These elements, often grouped as seven core pillars, form the structural blueprint for the step‑by‑step procedure that follows.
The following nine‑step sequence covers the complete project lifecycle. Each step identifies who is responsible, the typical duration and the evidence to keep, because in Spanish criminal proceedings, the burden of proving programme effectiveness falls on the company.
| Step | Who does it | Typical duration |
|---|---|---|
| 1. Board scoping & mandate | Board / GC / CEO | 1–2 weeks |
| 2. Criminal risk mapping | Compliance + external experts | 2–6 weeks |
| 3. Design controls & policies | Compliance / HR / IT / GC | 4–6 weeks |
| 4. Governance & appointments | Board / HR / GC | 2–4 weeks |
| 5. Whistleblowing channel | Compliance / IT / HR | 2–4 weeks |
| 6. Training roll‑out | Compliance / HR | 2–6 weeks (staged) |
| 7. Monitoring & internal testing | Internal audit / Compliance | Ongoing; first cycle 3 months |
| 8. External assurance & review | External auditor / Compliance | 1–3 months per review |
| 9. Incident response & reporting | Legal / Compliance / IT | Immediate / as required |
The Board or governing body defines the programme’s objectives, territorial and entity perimeter and acceptance criteria. It formally resolves to adopt the compliance programme, appoints a compliance lead and approves an initial budget allocation. The resolution should reference Article 31 bis of the Código Penal explicitly to anchor the programme in the statutory framework.
Evidence to keep: Signed Board resolution or written mandate (PDF with electronic signatures); project brief document; formal record of compliance‑lead appointment. Store permanently, minimum 10 years.
Conduct a structured criminal risk assessment aligned to the Penal Code offence catalogue. This means mapping each business process to the specific offences that could arise, including fraud, bribery and corruption, money laundering, computer crimes, environmental offences, offences against workers’ rights and data‑protection breaches. For entities in NIS2 scope, include cyber‑intrusion and critical‑infrastructure disruption scenarios.
The output is a prioritised risk register scoring likelihood and impact, with a control‑gap analysis for each high‑risk area. Prosecutors and the Fiscalía General del Estado evaluate whether the risk map is comprehensive, proportionate and periodically updated, a static, generic matrix will not suffice.
Evidence to keep: Risk map document with methodology disclosure; process flowcharts; risk register with scoring and control gaps; interview logs and data‑source records; GC or compliance officer sign‑off. Retain for a minimum of 7–10 years in versioned format.
Draft the policy suite and operational protocols that address each risk identified in Step 2. At a minimum, the suite should include a code of conduct, an anti‑bribery and corruption policy, an AML/KYC policy (for obliged entities), procurement and third‑party controls, IT and cybersecurity controls (mapped to NIS2 where applicable) and a whistleblowing policy compliant with Spain’s transposition of the EU Whistleblower Directive.
Each policy must include version control, approval authority, distribution records and a review schedule. Decision trees and escalation protocols translate high‑level policies into day‑to‑day operational guidance, these are what prosecutors look at to determine whether the programme was genuinely embedded.
Evidence to keep: All policy documents with version history; Board or committee approval records; distribution and acknowledgement logs. Retain current versions plus historical versions for at least 7 years.
Formally appoint the compliance officer or compliance committee. The Penal Code requires the body with supervisory powers over the programme to have autonomous initiative and control powers. Define clear reporting lines (the compliance officer should report directly to the Board or a designated Board committee), a committee charter and a disciplinary regime for non‑compliance.
Evidence to keep: Compliance officer appointment letter and job description; compliance committee charter and minutes of inaugural meeting; delegation matrix showing authority limits. Retain throughout the officer’s tenure and for 7 years thereafter.
Implement a secure, confidential reporting channel that allows employees and third parties to report potential criminal conduct and compliance breaches. The channel must offer the option of anonymous reporting and comply with AEPD guidance on processing whistleblower personal data, including a data protection impact assessment. Appoint a designated receiver, define handling timescales and establish an internal investigation protocol.
Evidence to keep: Whistleblowing policy (signed); channel provider contract and technical specifications; AEPD data protection impact assessment; anonymised case logs and handling SLA records. Retain per AEPD retention guidance and internal rules.
Roll out mandatory training segmented by risk level. Board members and senior management receive governance‑focused sessions. High‑risk teams (procurement, finance, sales, IT) receive deep‑dive training on the specific Penal Code compliance steps relevant to their functions. All employees receive code‑of‑conduct induction and annual refresher training. For NIS2‑scope entities, add cybersecurity awareness modules.
Evidence to keep: Training attendance logs; online LMS completion records and assessment scores; employee attestation forms (electronic signatures accepted). Retain for 5–7 years.
Design a monitoring framework with quantified KPIs, for example, number of whistleblowing reports received and resolved, percentage of high‑risk staff trained, completion rate of third‑party due diligence and number of control exceptions identified. Conduct periodic controls testing: transaction sampling, process walk‑throughs, scenario simulations and, for cyber controls, red‑team exercises. Document every test, its findings and any corrective action taken.
Evidence to keep: Test reports with methodology and sample details; remediation logs signed off by control owners; KPI dashboards reported to the Board; follow‑up evidence of corrective action completion. Retain 5–7 years.
Commission an external independent review or audit of the programme’s effectiveness. The likely practical effect of recent prosecutorial guidance is that companies seeking full exemption from corporate criminal liability in Spain will need to demonstrate that the programme has been validated by an independent third party, not merely self‑assessed. Update the programme based on findings, close remediation items and present a summary to the Board.
Evidence to keep: External audit report and management letter; Board summary and minutes evidencing discussion of findings; corrective action completion certificates. Retain permanently.
Establish an incident‑handling workflow that includes immediate evidence preservation, legal privilege management, internal escalation and, where legally required, timely reporting to authorities. AML‑obliged entities must report suspicious transactions to SEPBLAC without delay. NIS2 essential and important entities must notify the competent authority of significant incidents within the timeframes set by Spain’s national transposition. Criminal complaints must be filed promptly where the company identifies offending conduct.
Evidence to keep: Incident logs; evidence chain‑of‑custody records; copies of notifications sent to SEPBLAC, the NIS2 competent authority or law enforcement. Retain per statutory requirements and legal hold obligations.
Prosecutors evaluating whether a compliance programme is effective focus heavily on documentary evidence. The following table lists the core documents needed for a compliance programme in Spain, together with format, issuing authority and recommended retention periods. Maintaining this evidence in a centralised, version‑controlled repository, whether on‑premise or in an encrypted cloud environment, is essential for demonstrating the programme’s integrity over time.
| Document | Notes (issuer, format, retention) |
|---|---|
| Board resolution / mandate for compliance programme | Issued by Board/CEO; signed PDF; keep permanently (minimum 10 years) |
| Criminal risk map & risk register | Produced by compliance team or consultant; editable + archived PDF; retain 7–10 years in versioned format |
| Compliance policies suite (code of conduct, AML, anti‑bribery, procurement, IT security, whistleblowing) | Issued by GC/Compliance; versioned signed PDF; retain current + all historical versions (7 years minimum) |
| Compliance officer appointment & job description | Signed appointment letter; HR file; retain for employment lifecycle + 7 years |
| Whistleblowing policy & channel logs | Policy (signed), channel provider contract, anonymised case logs, DPIA; retain per AEPD guidance |
| Training records & attestations | Attendance logs, LMS exports, employee attestations; keep 5–7 years |
| Controls testing & internal audit reports | Test results, remediation logs; signed by Internal Audit / Compliance; keep 5–7 years |
| External audit / independent review reports | External auditor report and management responses; keep permanently with remediation evidence |
| Incident management records & chain of custody | Incident reports, evidence preservation records, authority notifications (SEPBLAC, NIS2); retain per statutory requirements |
| Procurement due diligence & third‑party risk files | KYC/KYB documents, anti‑bribery screening, contracts; retain 7–10 years |
| Financial controls documentation | Payment approvals, segregation of duties flowcharts, reconciliation reports; keep 7 years |
| Register of delegations & powers | Signed delegation matrix; keep current + historical versions |
| Records of disciplinary actions | HR records demonstrating consistent enforcement of disciplinary regime; retain per labour law requirements |
Maintaining this evidence trail is not optional. The documents and tests that prove a compliance programme is effective for criminal‑liability mitigation are precisely the items that a court will request if the company is charged. A programme that exists on paper but cannot produce contemporaneous records of risk mapping, testing and remediation will almost certainly fail the effectiveness assessment.
The timeline to implement a compliance programme depends on the organisation’s size, sector complexity and existing control maturity. A realistic end‑to‑end implementation for a mid‑sized Spanish company typically spans 9–18 months from Board mandate to first external review. The following phased approach reflects industry practice.
| Phase | Activities | Timeframe |
|---|---|---|
| Phase A, Foundation | Board mandate, compliance officer appointment, criminal risk mapping, core policies drafted, whistleblowing channel operational | 0–3 months |
| Phase B, Rollout | Full policy publication, staged training, controls implementation, first internal testing cycle, initial KPI reporting to Board | 3–9 months |
| Phase C, Assurance | External independent effectiveness review, full remediation close‑out, annual Board effectiveness report, continuous monitoring established | 9–18 months |
Certain external deadlines may compress this timeline. NIS2 essential and important entities must already be capable of notifying significant incidents to the competent authority. SEPBLAC‑obliged entities must maintain ongoing AML reporting readiness, including the ability to file suspicious transaction reports without delay. AEPD enforcement of whistleblowing data‑protection requirements is active; any entity operating a reporting channel must have a compliant data protection impact assessment in place now.
Organisations facing imminent regulatory review, M&A due diligence or a known investigation should consider fast‑tracking Phase A to 4–6 weeks and commissioning an external assurance review in parallel with Phase B.
Budgeting for a compliance programme involves both internal resource allocation and external professional fees. The table below provides indicative cost ranges for a mid‑sized Spanish company. Actual amounts vary significantly with company size, sector complexity, number of entities and level of existing control maturity.
| Item | Indicative range | Notes |
|---|---|---|
| External criminal risk mapping (consultant / counsel) | €3,000 – €20,000 | Depends on company size and number of business lines; VAT applies |
| Whistleblowing platform setup & annual licence | €1,000 – €15,000 per year | Varies by provider, language options and anonymity features |
| External independent effectiveness review / audit | €5,000 – €40,000 | Scope‑dependent; higher for complex or multi‑entity programmes |
| Training (LMS platform, content development, translation) | €2,000 – €25,000 | Per‑user licensing and NIS2 cyber modules may add cost |
| Legal advisory for regulatory notifications | €1,500 – €10,000 per matter | Ad hoc; depends on severity and regulator involved |
| Internal compliance officer (FTE, fully loaded) | €50,000 – €120,000 per year | Includes salary, employer social security contributions and benefits |
Professional service fees are generally subject to Spanish VAT at the standard rate. Internal salary costs are employment expenses deductible against corporate income tax. Companies should budget for ongoing annual costs, platform licences, periodic training refreshers and the external review cycle, in addition to the initial implementation investment.
Several regulatory and enforcement developments in the 2024–2026 cycle directly affect the Penal Code compliance steps that companies must follow. The practical impact is that programmes designed before these shifts may no longer meet the effectiveness standard.
The 2026 update checklist for existing programmes is straightforward:
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 5 hours ago
No results available
Find the right Legal Expert for your business
Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message