[codicts-css-switcher id=”346″]

Global Law Experts Logo
how to implement a corporate criminal compliance programme in Spain 2026

How to Implement a Corporate Criminal Compliance Programme in Spain, Step‑by‑step (2026 Update)

By Global Law Experts
– posted 11 hours ago

Understanding how to implement a corporate criminal compliance programme in Spain in 2026 is now a front‑of‑mind priority for compliance officers, general counsel and business owners operating through Spanish legal entities. Under Article 31 bis of the Código Penal, legal persons face criminal liability for a catalogue of offences committed on their behalf, but a properly designed, documented and tested compliance programme can mitigate or even fully exempt the entity from that liability. Heightened enforcement expectations from the Fiscalía General del Estado, the operational arrival of NIS2 cybersecurity obligations and reinforced AML supervision by SEPBLAC and the Banco de España have all raised the evidentiary bar for what prosecutors and regulators regard as “effective.

” This guide walks through every procedural step, the documents needed for a compliance programme, costs and the 2026‑specific changes that affect the timeline to implement a compliance programme in Spain.

Overview of the Process and Who It Applies To

A corporate criminal compliance programme, known in Spanish practice as a modelo de organización y gestión, is an integrated set of policies, controls, governance structures and monitoring mechanisms designed to prevent, detect and respond to criminal conduct attributable to the company. Its principal legal objective is to satisfy the mitigation and exemption conditions set out in Article 31 bis of the Código Penal, as amended by Ley Orgánica 1/2015.

The corporate criminal liability regime applies to all legal persons incorporated or operating in Spain, sociedades anónimas, sociedades limitadas, branches of foreign companies and, with certain exceptions, public‑sector entities engaged in commercial activity. While the law draws no explicit size threshold, the practical reality is that prosecutors and courts assess proportionality: a multinational with 5,000 employees in Spain is expected to maintain a substantially more granular programme than a 20‑person start‑up. Industry observers expect that, following the 2024–2026 cycle of heightened scrutiny, even smaller entities will find it difficult to argue that a light‑touch approach suffices.

Certain sectors face additional, overlapping compliance programme requirements. Financial institutions, payment service providers and insurance companies fall under SEPBLAC AML/CTF supervision. Entities designated as essential or important under Spain’s transposition of the NIS2 Directive (Directive (EU) 2022/2555) must demonstrate cybersecurity risk‑management measures and incident‑reporting capabilities. Companies processing personal data, particularly those operating whistleblowing channels, must align with AEPD guidance on data protection impact assessments and retention.

The critical point is that a compliance programme in Spain is not a one‑off policy exercise. It must be a living system: risk‑mapped, resourced, tested, updated and, above all, documented so that each element can be evidenced to a prosecutor, judge or regulator at any point.

Eligibility and Compliance Programme Requirements

Before drafting a single policy, the organisation must confirm its perimeter and prerequisites. Failing to scope correctly is one of the most common reasons programmes are later found to be ineffective.

Scoping the perimeter

The programme must cover every Spanish legal entity through which the group operates. For multinational groups, this means identifying each sociedad, branch or joint venture with a Spanish nexus. The scoping exercise should also capture business lines, geographic territories served from Spain and any regulated activities (AML‑obliged services, critical‑infrastructure operations under NIS2, public procurement participation).

  • Legal entities. List all Spanish‑incorporated entities and registered branches of foreign companies.
  • Regulated activities. Flag entities subject to SEPBLAC, Banco de España, CNMV or NIS2 supervision.
  • Third‑party exposure. Identify agents, distributors and subcontractors whose conduct may be attributed to the company.
  • Data processing. Map personal‑data flows that will be generated by the compliance programme itself (e.g., whistleblowing reports, investigation files).

Governance decision, Board approval and resource allocation

Under the Penal Code framework, the programme must be adopted and supervised by the governing body. This means a formal Board resolution (or equivalent corporate organ decision) that authorises the programme, allocates budget and appoints a compliance lead with sufficient autonomy and access. Without a documented governance mandate, every subsequent step lacks the foundational authority that prosecutors examine first.

The compliance programme requirements under Article 31 bis include, at a minimum: identification of risk activities; establishment of protocols and decision‑making processes; management of financial resources to prevent offences; an obligation to report possible risks and non‑compliance through an appropriate channel; establishment of a disciplinary system; and periodic verification and updating of the model. These elements, often grouped as seven core pillars, form the structural blueprint for the step‑by‑step procedure that follows.

Step‑by‑Step Procedure to Implement a Corporate Criminal Compliance Programme in Spain

The following nine‑step sequence covers the complete project lifecycle. Each step identifies who is responsible, the typical duration and the evidence to keep, because in Spanish criminal proceedings, the burden of proving programme effectiveness falls on the company.

Step Who does it Typical duration
1. Board scoping & mandate Board / GC / CEO 1–2 weeks
2. Criminal risk mapping Compliance + external experts 2–6 weeks
3. Design controls & policies Compliance / HR / IT / GC 4–6 weeks
4. Governance & appointments Board / HR / GC 2–4 weeks
5. Whistleblowing channel Compliance / IT / HR 2–4 weeks
6. Training roll‑out Compliance / HR 2–6 weeks (staged)
7. Monitoring & internal testing Internal audit / Compliance Ongoing; first cycle 3 months
8. External assurance & review External auditor / Compliance 1–3 months per review
9. Incident response & reporting Legal / Compliance / IT Immediate / as required

Step 1: Board Scoping and Mandate (Weeks 0–2)

The Board or governing body defines the programme’s objectives, territorial and entity perimeter and acceptance criteria. It formally resolves to adopt the compliance programme, appoints a compliance lead and approves an initial budget allocation. The resolution should reference Article 31 bis of the Código Penal explicitly to anchor the programme in the statutory framework.

Evidence to keep: Signed Board resolution or written mandate (PDF with electronic signatures); project brief document; formal record of compliance‑lead appointment. Store permanently, minimum 10 years.

Step 2: Criminal Risk Mapping and Assessment (Weeks 2–6)

Conduct a structured criminal risk assessment aligned to the Penal Code offence catalogue. This means mapping each business process to the specific offences that could arise, including fraud, bribery and corruption, money laundering, computer crimes, environmental offences, offences against workers’ rights and data‑protection breaches. For entities in NIS2 scope, include cyber‑intrusion and critical‑infrastructure disruption scenarios.

The output is a prioritised risk register scoring likelihood and impact, with a control‑gap analysis for each high‑risk area. Prosecutors and the Fiscalía General del Estado evaluate whether the risk map is comprehensive, proportionate and periodically updated, a static, generic matrix will not suffice.

Evidence to keep: Risk map document with methodology disclosure; process flowcharts; risk register with scoring and control gaps; interview logs and data‑source records; GC or compliance officer sign‑off. Retain for a minimum of 7–10 years in versioned format.

Step 3: Design Controls and Policies (Weeks 4–10)

Draft the policy suite and operational protocols that address each risk identified in Step 2. At a minimum, the suite should include a code of conduct, an anti‑bribery and corruption policy, an AML/KYC policy (for obliged entities), procurement and third‑party controls, IT and cybersecurity controls (mapped to NIS2 where applicable) and a whistleblowing policy compliant with Spain’s transposition of the EU Whistleblower Directive.

Each policy must include version control, approval authority, distribution records and a review schedule. Decision trees and escalation protocols translate high‑level policies into day‑to‑day operational guidance, these are what prosecutors look at to determine whether the programme was genuinely embedded.

Evidence to keep: All policy documents with version history; Board or committee approval records; distribution and acknowledgement logs. Retain current versions plus historical versions for at least 7 years.

Step 4: Governance, Roles and Delegated Powers (Weeks 4–8)

Formally appoint the compliance officer or compliance committee. The Penal Code requires the body with supervisory powers over the programme to have autonomous initiative and control powers. Define clear reporting lines (the compliance officer should report directly to the Board or a designated Board committee), a committee charter and a disciplinary regime for non‑compliance.

Evidence to keep: Compliance officer appointment letter and job description; compliance committee charter and minutes of inaugural meeting; delegation matrix showing authority limits. Retain throughout the officer’s tenure and for 7 years thereafter.

Step 5: Whistleblowing Channel and Internal Reporting (Weeks 6–10)

Implement a secure, confidential reporting channel that allows employees and third parties to report potential criminal conduct and compliance breaches. The channel must offer the option of anonymous reporting and comply with AEPD guidance on processing whistleblower personal data, including a data protection impact assessment. Appoint a designated receiver, define handling timescales and establish an internal investigation protocol.

Evidence to keep: Whistleblowing policy (signed); channel provider contract and technical specifications; AEPD data protection impact assessment; anonymised case logs and handling SLA records. Retain per AEPD retention guidance and internal rules.

Step 6: Training and Communication (Weeks 8–14)

Roll out mandatory training segmented by risk level. Board members and senior management receive governance‑focused sessions. High‑risk teams (procurement, finance, sales, IT) receive deep‑dive training on the specific Penal Code compliance steps relevant to their functions. All employees receive code‑of‑conduct induction and annual refresher training. For NIS2‑scope entities, add cybersecurity awareness modules.

Evidence to keep: Training attendance logs; online LMS completion records and assessment scores; employee attestation forms (electronic signatures accepted). Retain for 5–7 years.

Step 7: Monitoring, Internal Audit and Continuous Testing (Month 3 Onwards)

Design a monitoring framework with quantified KPIs, for example, number of whistleblowing reports received and resolved, percentage of high‑risk staff trained, completion rate of third‑party due diligence and number of control exceptions identified. Conduct periodic controls testing: transaction sampling, process walk‑throughs, scenario simulations and, for cyber controls, red‑team exercises. Document every test, its findings and any corrective action taken.

Evidence to keep: Test reports with methodology and sample details; remediation logs signed off by control owners; KPI dashboards reported to the Board; follow‑up evidence of corrective action completion. Retain 5–7 years.

Step 8: External Assurance and Periodic Review (Months 6–12)

Commission an external independent review or audit of the programme’s effectiveness. The likely practical effect of recent prosecutorial guidance is that companies seeking full exemption from corporate criminal liability in Spain will need to demonstrate that the programme has been validated by an independent third party, not merely self‑assessed. Update the programme based on findings, close remediation items and present a summary to the Board.

Evidence to keep: External audit report and management letter; Board summary and minutes evidencing discussion of findings; corrective action completion certificates. Retain permanently.

Step 9: Incident Response and Reporting to Authorities (As Required)

Establish an incident‑handling workflow that includes immediate evidence preservation, legal privilege management, internal escalation and, where legally required, timely reporting to authorities. AML‑obliged entities must report suspicious transactions to SEPBLAC without delay. NIS2 essential and important entities must notify the competent authority of significant incidents within the timeframes set by Spain’s national transposition. Criminal complaints must be filed promptly where the company identifies offending conduct.

Evidence to keep: Incident logs; evidence chain‑of‑custody records; copies of notifications sent to SEPBLAC, the NIS2 competent authority or law enforcement. Retain per statutory requirements and legal hold obligations.

Required Documents and Compliance Programme Checklist

Prosecutors evaluating whether a compliance programme is effective focus heavily on documentary evidence. The following table lists the core documents needed for a compliance programme in Spain, together with format, issuing authority and recommended retention periods. Maintaining this evidence in a centralised, version‑controlled repository, whether on‑premise or in an encrypted cloud environment, is essential for demonstrating the programme’s integrity over time.

Document Notes (issuer, format, retention)
Board resolution / mandate for compliance programme Issued by Board/CEO; signed PDF; keep permanently (minimum 10 years)
Criminal risk map & risk register Produced by compliance team or consultant; editable + archived PDF; retain 7–10 years in versioned format
Compliance policies suite (code of conduct, AML, anti‑bribery, procurement, IT security, whistleblowing) Issued by GC/Compliance; versioned signed PDF; retain current + all historical versions (7 years minimum)
Compliance officer appointment & job description Signed appointment letter; HR file; retain for employment lifecycle + 7 years
Whistleblowing policy & channel logs Policy (signed), channel provider contract, anonymised case logs, DPIA; retain per AEPD guidance
Training records & attestations Attendance logs, LMS exports, employee attestations; keep 5–7 years
Controls testing & internal audit reports Test results, remediation logs; signed by Internal Audit / Compliance; keep 5–7 years
External audit / independent review reports External auditor report and management responses; keep permanently with remediation evidence
Incident management records & chain of custody Incident reports, evidence preservation records, authority notifications (SEPBLAC, NIS2); retain per statutory requirements
Procurement due diligence & third‑party risk files KYC/KYB documents, anti‑bribery screening, contracts; retain 7–10 years
Financial controls documentation Payment approvals, segregation of duties flowcharts, reconciliation reports; keep 7 years
Register of delegations & powers Signed delegation matrix; keep current + historical versions
Records of disciplinary actions HR records demonstrating consistent enforcement of disciplinary regime; retain per labour law requirements

Maintaining this evidence trail is not optional. The documents and tests that prove a compliance programme is effective for criminal‑liability mitigation are precisely the items that a court will request if the company is charged. A programme that exists on paper but cannot produce contemporaneous records of risk mapping, testing and remediation will almost certainly fail the effectiveness assessment.

Timeline and Key Deadlines for Implementing a Compliance Programme in Spain

The timeline to implement a compliance programme depends on the organisation’s size, sector complexity and existing control maturity. A realistic end‑to‑end implementation for a mid‑sized Spanish company typically spans 9–18 months from Board mandate to first external review. The following phased approach reflects industry practice.

Phase Activities Timeframe
Phase A, Foundation Board mandate, compliance officer appointment, criminal risk mapping, core policies drafted, whistleblowing channel operational 0–3 months
Phase B, Rollout Full policy publication, staged training, controls implementation, first internal testing cycle, initial KPI reporting to Board 3–9 months
Phase C, Assurance External independent effectiveness review, full remediation close‑out, annual Board effectiveness report, continuous monitoring established 9–18 months

Certain external deadlines may compress this timeline. NIS2 essential and important entities must already be capable of notifying significant incidents to the competent authority. SEPBLAC‑obliged entities must maintain ongoing AML reporting readiness, including the ability to file suspicious transaction reports without delay. AEPD enforcement of whistleblowing data‑protection requirements is active; any entity operating a reporting channel must have a compliant data protection impact assessment in place now.

Organisations facing imminent regulatory review, M&A due diligence or a known investigation should consider fast‑tracking Phase A to 4–6 weeks and commissioning an external assurance review in parallel with Phase B.

Compliance Programme Costs in Spain

Budgeting for a compliance programme involves both internal resource allocation and external professional fees. The table below provides indicative cost ranges for a mid‑sized Spanish company. Actual amounts vary significantly with company size, sector complexity, number of entities and level of existing control maturity.

Item Indicative range Notes
External criminal risk mapping (consultant / counsel) €3,000 – €20,000 Depends on company size and number of business lines; VAT applies
Whistleblowing platform setup & annual licence €1,000 – €15,000 per year Varies by provider, language options and anonymity features
External independent effectiveness review / audit €5,000 – €40,000 Scope‑dependent; higher for complex or multi‑entity programmes
Training (LMS platform, content development, translation) €2,000 – €25,000 Per‑user licensing and NIS2 cyber modules may add cost
Legal advisory for regulatory notifications €1,500 – €10,000 per matter Ad hoc; depends on severity and regulator involved
Internal compliance officer (FTE, fully loaded) €50,000 – €120,000 per year Includes salary, employer social security contributions and benefits

Professional service fees are generally subject to Spanish VAT at the standard rate. Internal salary costs are employment expenses deductible against corporate income tax. Companies should budget for ongoing annual costs, platform licences, periodic training refreshers and the external review cycle, in addition to the initial implementation investment.

What Changes in 2026: Implementing a Corporate Criminal Compliance Programme Under New Expectations

Several regulatory and enforcement developments in the 2024–2026 cycle directly affect the Penal Code compliance steps that companies must follow. The practical impact is that programmes designed before these shifts may no longer meet the effectiveness standard.

  • Heightened prosecutorial focus on documented effectiveness. Guidance from the Fiscalía General del Estado increasingly emphasises that prosecutors should examine not just whether a programme exists on paper, but whether it has been tested, updated and enforced. Early indications suggest that companies unable to produce external audit reports and contemporaneous remediation records face a significantly weaker defence.
  • NIS2 operational obligations. Spain’s transposition of Directive (EU) 2022/2555 requires essential and important entities to implement cybersecurity risk‑management measures and incident‑notification processes. For compliance programmes, this means integrating cyber‑risk controls, IT‑incident logs and NIS2 notification evidence into the overall compliance evidence pack.
  • Strengthened AML/CTF supervision. SEPBLAC and the Banco de España have reinforced expectations around KYC/KYB documentation, suspicious transaction monitoring and the integration of AML controls into broader compliance frameworks. Entities that treat AML compliance as a separate silo, disconnected from their criminal compliance programme, risk a gap that prosecutors can exploit.
  • AEPD enforcement on whistleblowing data. The AEPD continues to enforce data‑protection obligations specific to internal reporting channels, including mandatory data protection impact assessments, proportionate retention periods and data‑minimisation principles. Programmes that collect excessive personal data or retain reports indefinitely are exposed to both regulatory sanctions and evidentiary challenges.

The 2026 update checklist for existing programmes is straightforward:

  • Schedule or accelerate an external independent effectiveness review.
  • Update the risk map to include NIS2 cyber scenarios and current AML typologies.
  • Ensure the whistleblowing channel has a current, AEPD‑compliant data protection impact assessment.
  • Integrate AML/SEPBLAC evidence files into the centralised compliance document repository.
  • Report programme effectiveness metrics to the Board at least annually, with documented minutes.

Common Pitfalls and How to Avoid Them

  • Token policies with no operational embedding. Policies that exist in a shared drive but have never been communicated, trained on or enforced. Remedy: require signed attestations, conduct announced and unannounced spot‑checks, and document distribution logs.
  • No Board‑level sign‑off on record. A programme launched by the compliance team without a formal Board resolution. Remedy: pass a written Board resolution before any other step; minute it and file it permanently.
  • Risk map copied from a template without tailoring. Generic risk matrices that do not reflect the company’s actual business lines, geographies or sector‑specific exposures. Remedy: conduct interviews, review transaction data and map risks to specific Penal Code offences relevant to the entity.
  • Whistleblowing channel without data‑protection safeguards. Operating a reporting channel without an AEPD‑compliant DPIA or with indefinite data retention. Remedy: complete the DPIA before launching the channel and enforce defined retention and deletion schedules.
  • Failure to test controls. Implementing policies but never verifying whether they work in practice. Remedy: build a testing calendar into the compliance plan from day one; document all test results and remediation actions.
  • No external validation. Relying entirely on internal self‑assessment. Remedy: commission an independent review within the first 12 months and repeat on a 12–24‑month cycle thereafter.
  • Weak third‑party due diligence. Onboarding suppliers, distributors or agents without anti‑bribery or AML screening. Remedy: implement risk‑based KYC/KYB procedures and retain screening records for 7–10 years.
  • Disciplinary regime not applied consistently. Having a disciplinary code on paper but no records of enforcement. Remedy: document every compliance‑related disciplinary decision; inconsistent application undermines the entire programme’s credibility.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.

Sources

  1. Official State Gazette (BOE), Código Penal (Ley Orgánica 10/1995)
  2. Fiscalía General del Estado, Spanish Public Prosecutor
  3. SEPBLAC, Spanish Financial Intelligence Unit
  4. Banco de España
  5. EUR‑Lex, Directive (EU) 2022/2555 (NIS2 Directive)
  6. Agencia Española de Protección de Datos (AEPD)

FAQs

How do you set up a compliance programme in Spain?
Begin with a formal Board resolution authorising the programme and appointing a compliance lead. Conduct a criminal risk mapping exercise aligned to the Penal Code offence catalogue. Then design controls and policies, implement a whistleblowing channel, roll out training, and establish a monitoring and testing cycle. Commission an external effectiveness review within 12 months of launch.
Prosecutors examine the Board mandate, the criminal risk map, versioned policies, training records with attestations, controls testing reports, external audit findings, remediation evidence, whistleblowing channel logs, incident‑response records and disciplinary action files. The programme must be able to produce contemporaneous, dated evidence for each element.
A typical end‑to‑end implementation for a mid‑sized company takes 9–18 months from Board mandate through to the first external review. The foundational phase, mandate, risk map, core policies and whistleblowing channel, can usually be completed within 3 months. Companies facing imminent regulatory scrutiny may compress the foundation phase to 4–6 weeks.
Article 31 bis of the Código Penal requires identification of risk activities, protocols for decision‑making, management of financial resources to prevent offences, an obligation to report through an appropriate channel, a disciplinary system and periodic verification. In practice, this translates into the nine‑step procedure described in this guide, from Board scoping through to incident response.
A group‑level programme can provide the framework, but Spanish legal entities need local adaptation. The risk map must reflect Spanish Penal Code offences, the whistleblowing channel must comply with AEPD requirements, training must address Spain‑specific rules and the Board resolution must come from the Spanish entity’s governing body. A central programme alone, without local tailoring, is unlikely to satisfy the mitigation test.
Late or missed notifications can result in administrative sanctions from the competent supervisory authority and may undermine the programme’s credibility in any subsequent criminal proceeding. The compliance programme should include a documented incident‑response workflow with clear escalation timelines to prevent missed deadlines.
Engaging a specialist compliance lawyer is advisable from the outset, particularly for the Board resolution drafting, risk‑mapping methodology, policy legal review and preparation for the external effectiveness audit. Companies in regulated sectors (AML, NIS2) or those facing an active investigation should treat external legal advice as essential rather than optional.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Implement a Corporate Criminal Compliance Programme in Spain, Step‑by‑step (2026 Update)

Send welcome message

Custom Message