[codicts-css-switcher id=”346″]

Global Law Experts Logo
how to implement a corporate criminal compliance programme in Spain 2026

How to Implement a Corporate Criminal Compliance Programme in Spain in 2026: Step‑by‑step

By Global Law Experts
– posted 11 hours ago

Understanding how to implement a corporate criminal compliance programme in Spain in 2026 is now a practical necessity for any legal person operating in the country. Spain’s Código Penal (Penal Code) holds companies directly liable for offences committed on their behalf or for their benefit, and an effective compliance programme is the principal statutory mechanism to mitigate, or even exclude, that liability. This guide walks compliance officers, general counsels, in‑house legal teams and business owners through each procedural step, from board approval to external effectiveness testing. It reflects the 2026 enforcement landscape, including heightened prosecutorial scrutiny, NIS2 cybersecurity obligations and renewed AML supervisory guidance from SEPBLAC and the Banco de España.

Overview of the Process and Who It Applies To

A corporate criminal compliance programme in Spain is a documented system of governance, risk controls, reporting channels, training and monitoring designed to prevent, detect and respond to criminal conduct attributable to the organisation. Its legal objective is defined by the Código Penal: where an effective programme exists and the entity can demonstrate it was genuinely operative before the offence, courts may reduce or fully exclude corporate criminal liability.

The compliance programme requirements in Spain apply to all legal persons, sociedad anónima, sociedad limitada, foundations, associations and branches of foreign entities, regardless of size. In practice, the compliance programme is most urgent for medium and large companies, entities in sectors regulated by the CNMC, organisations within the scope of Directive (EU) 2022/2555 (NIS2) and financial institutions subject to AML oversight by SEPBLAC and the Banco de España.

The programme must be a living system, not a static document. Industry observers expect that programmes which cannot demonstrate periodic testing, updated risk maps and genuine board oversight will receive no credit from prosecutors or courts. The 2026 enforcement environment places particular weight on documented effectiveness, meaning evidence that the programme actually works, not merely that it was written down.

Eligibility and Prerequisites for a Compliance Programme in Spain

Every entity incorporated or operating in Spain through a legal person is exposed to corporate criminal liability under the Código Penal. However, certain triggers should accelerate your timeline. These include high‑risk commercial activities (public procurement, regulated financial services, international trade), operations involving personal data at scale, exposure to bribery or corruption risk, and designation as an essential or important entity under NIS2.

Before the programme design begins, several organisational prerequisites must be in place. First, the board of directors (or equivalent governing body) must formally authorise the programme and allocate a dedicated budget. Second, an accountable owner must be appointed, typically the General Counsel, Chief Risk Officer or a dedicated Chief Compliance Officer. Third, a core project team should be assembled, drawing on legal, human resources, IT and finance functions. For groups with multi‑jurisdictional operations, the scope must clearly define which Spanish legal entities and business lines are covered.

External specialist counsel is advisable where the company lacks in‑house criminal law expertise, where the risk mapping involves complex regulatory sectors, or where the organisation is already under investigation. GDPR considerations arise from the outset: any processing of personal data for compliance purposes, employee monitoring, whistleblowing reports, third‑party screening, must be assessed against the requirements of the Agencia Española de Protección de Datos (AEPD). Mapping your data access points and preparing an organisational chart at the start of the project will save significant time later. Browse the Compliance practice area directory for qualified specialists.

Step‑by‑Step Procedure to Implement a Corporate Criminal Compliance Programme in Spain (2026)

How do you set up a compliance programme in Spain? The process follows seven sequential steps, each producing specific deliverables that prosecutors and regulators will expect to see if the programme is ever tested. The table below summarises the steps, responsible parties and typical durations before the detailed walkthrough.

Step Who does it Typical duration
Scoping & governance set‑up (board resolution, appoint owner) Board / General Counsel / CRO 1–4 weeks
Criminal risk mapping (process mapping, interviews) Internal legal + external counsel / risk consultants 4–8 weeks
Design controls & policies (policy drafting) Legal + HR + IT + external counsel 4–8 weeks
Whistleblowing channel & reporting Legal + IT + HR 2–6 weeks
Role‑based training rollout HR / Compliance team 4–12 weeks (staged rollout)
Monitoring & testing (internal testing) Internal audit / Compliance Ongoing, periodic cycles (quarterly/annual)
External audit / effectiveness testing External auditor / forensic firm 1–4 weeks per audit; annual/biannual cadence

Step 1, Scoping and Governance Set‑Up (Weeks 0–4)

The programme begins with a formal board resolution authorising its creation, scope and budget. This resolution is one of the most important pieces of evidence prosecutors will request, it demonstrates that the governing body took the initiative and that the programme has institutional backing rather than being a retroactive defensive measure.

During this phase, the board appoints an accountable programme owner (the GC, CRO or a dedicated CCO) and forms a project steering group with representatives from legal, HR, IT and finance. The steering group defines the assessment perimeter: which legal entities, geographies and business lines fall within scope. For groups operating across multiple Spanish entities or internationally, each entity’s exposure must be assessed individually.

Key deliverables at this stage are the signed board resolution (retained permanently), a project plan with milestones and a preliminary stakeholder register identifying process owners across the business.

Step 2, Criminal Risk Mapping (Weeks 1–8)

Criminal risk mapping is the analytical core of the programme. The objective is to map every relevant business process against the Código Penal’s catalogue of offences for which legal persons can be held liable. These offences span fraud, bribery, money laundering, offences against workers’ rights, environmental crimes, data‑protection infringements, market abuse, tax offences and, increasingly relevant in 2026, cyber‑intrusions affecting critical services.

The method combines structured interviews with process owners, document review (contracts, financial flows, procurement procedures), transactional sampling and preliminary control testing. Each risk is rated by likelihood and impact, and a control gap register is produced showing where existing controls are absent or insufficient.

The deliverable is a documented risk map, version‑dated and signed by the programme owner. It must include the evidence base (interview logs, data sources reviewed) so that an independent auditor or prosecutor can verify that the assessment was thorough and genuine. This is the document that prosecutors will scrutinise most closely, a generic template with no company‑specific analysis carries no evidentiary weight.

Step 3, Design Controls and Policies (Weeks 4–12)

With the risk map complete, the programme moves to designing the controls and policies that will prevent, detect or respond to each identified risk. The essential parts of an effective compliance programme at this stage include a code of conduct, an anti‑bribery and anti‑corruption policy, an AML/KYC linkage policy (where the entity handles financial flows), a whistleblowing policy, IT and cybersecurity controls (mandatory for NIS2‑scope entities), and sector‑specific policies where relevant.

Each policy must be mapped back to the risk register, creating a governance matrix that shows which control addresses which risk. Key performance indicators should be defined for each control, for example, percentage of high‑risk transactions screened, average time to close a whistleblowing report, or training completion rates among board members.

The deliverables are the governance matrix, each written policy in final form, and the KPI definitions. All policies require formal board endorsement (or endorsement by the delegate body authorised in the board resolution). Policies that exist on paper but were never formally approved or communicated to employees will be treated as ineffective by prosecutors.

Step 4, Implement Reporting and Whistleblowing Channels (Weeks 6–14)

Spain’s whistleblowing regime requires organisations to deploy a secure, accessible internal reporting channel. The channel must guarantee confidentiality (and where possible, anonymity), be accessible to employees, contractors and third parties, and operate in compliance with GDPR, specifically the AEPD’s guidance on data protection impact assessments for whistleblowing systems.

During this phase, the compliance team configures the channel (typically a SaaS platform), establishes an internal reporting flow (triage, investigation, resolution, closure), and aligns the disciplinary policy with applicable labour law. The deliverables are the published whistleblowing policy, channel configuration documentation, a completed privacy impact assessment filed with the AEPD, and a data retention schedule.

Step 5, Training and Communications (Weeks 8–20)

Training transforms written policies into operational behaviour. The programme must include a role‑based training plan distinguishing between board members, senior management, high‑risk operational teams and general staff. For entities within NIS2 scope, specific cybersecurity awareness training is mandatory and must be documented.

Training is delivered in staged rollouts, senior leadership first, followed by high‑risk teams and then the broader workforce. Each session must generate verifiable evidence: attendance registers, training materials distributed, and assessment scores. An LMS (learning management system) is the most efficient way to produce these records at scale. The training plan should be refreshed annually and updated whenever a material change in risk profile or regulation occurs.

Step 6, Monitoring, Testing and Internal Audit (Weeks 12–Ongoing)

A compliance programme that is never tested cannot demonstrate effectiveness. What evidence do prosecutors look for to mitigate corporate liability? Above all, they look for documented proof that the controls described in the programme were periodically tested and, where weaknesses were found, that remediation was carried out.

Monitoring activities include periodic controls testing (walkthroughs, re‑performance of key controls), transaction sampling (screening a random sample of high‑risk transactions against the control framework), and process walkthroughs with department heads. Internal audit should conduct at least one full cycle before the first external review. Every test must generate a written report showing the scope, methodology, findings and remediation actions.

Deliverables include test reports, a remediation plan with assigned owners and deadlines, and evidence that corrective actions were closed. Where a control failure is material, the compliance officer must escalate to the board and document the escalation, the board’s response and the timeline for remediation.

Step 7, Continuous Improvement and External Assurance (Ongoing)

The final step converts the compliance programme from a one‑off project into a continuous management cycle. An annual review of the risk map, policies and controls should be presented to the board, together with KPI data showing programme performance over the preceding period. The risk register must be updated to reflect new offences, regulatory changes and operational developments.

External assurance, an independent audit conducted by a qualified external firm, is the strongest evidence of programme effectiveness. Industry observers expect Spanish prosecutors to give significant weight to programmes backed by at least one external effectiveness audit within the first 12–24 months and repeated on a regular cadence thereafter. The external auditor’s report, engagement letter and any remediation evidence should be retained as part of the programme’s evidence pack. This pack, comprising the risk map, board minutes, audit reports, training records and disciplinary records, is the combined body of evidence the entity would present to a court or prosecutor if its liability were ever challenged.

Required Documents for a Criminal Compliance Programme in Spain

What documents and tests prove a compliance programme is effective for criminal liability mitigation? The table below sets out the core documents needed for a compliance programme, together with notes on who issues each document, the recommended format and retention expectations.

Document Notes (who issues it, format, validity)
Board resolution approving compliance programme Issued by the Board; signed minutes (PDF); retain permanently
Criminal risk map / risk register Internal document; versioned PDF/Excel; include evidence of interviews and data sources; review date on header
Code of Conduct & core policies (anti‑bribery, AML, IT security) Drafted by Legal; published to employees; signed acknowledgement forms retained for 5+ years
Whistleblowing policy & channel records Channel provider logs + case file summaries; privacy impact assessment (AEPD) and retention schedule
Third‑party due diligence files (KYC/KYB) Vendor/KYC documents, risk assessment forms, dated evidence of screening
Training attendance & assessment records HR / LMS export CSVs showing completion and assessment scores
Internal testing reports & remediation logs Internal audit/compliance test reports with evidence and closure records
External audit / effectiveness report External auditor report (signed), engagement letter, remediation evidence
Disciplinary records (if any) HR records (redacted if necessary) demonstrating consistent enforcement
Relevant IT logs & incident response reports (NIS2 scope) IT/SIEM exports, incident tickets, forensic reports; retain per NIS2 / regulatory guidance
AML reporting evidence (if applicable) STR filings, AML risk assessments, SEPBLAC correspondence
Data processing / DPIA evidence for whistleblowing AEPD DPIA output and retention compliance records

Every document should be version‑controlled, dated and stored in a secure, auditable repository. The ability to produce this evidence pack rapidly, within days rather than weeks, is itself a strong indicator of programme maturity that prosecutors will note.

Timeline to Implement a Compliance Programme in Spain

How long does it take to implement a compliance programme? Industry observers estimate that a company starting from scratch needs six to twelve months to design, implement and embed a programme that will withstand regulatory or prosecutorial scrutiny. The precise timeline depends on the number of legal entities in scope, the complexity of the business, and whether external counsel or consultants are engaged.

Milestone Timeframe Board reporting
Board resolution & project initiation Month 0 Board minute recorded at approval
Scoping, governance set‑up, initial risk mapping Months 0–2 Progress report to board at month 2
Policy drafting, whistleblowing channel live, senior management training Months 2–4 Policy endorsement at board meeting
Full training rollout, controls implemented, start internal testing Months 4–8 KPI dashboard first presented at month 6
External effectiveness audit & board effectiveness report; remediation closed Months 9–12 Annual effectiveness report to board
Annual review and continuous improvement cycle After month 12 Annual board update; external audit every 12–24 months

Several triggers can compress this timeline. An incoming regulatory inspection, a pending investigation, or an imminent NIS2 compliance deadline may require accelerated delivery. In these circumstances, engaging specialist external counsel from the outset and running workstreams in parallel (risk mapping alongside policy drafting, for instance) can reduce the overall duration to four to six months, though this increases external advisory costs significantly. The key is that no step should be skipped entirely, as an incomplete programme is unlikely to carry weight with prosecutors.

Costs, Fees and Tax Considerations

The costs of implementing a corporate criminal compliance programme in Spain vary substantially by company size, sector and complexity. The table below presents indicative market ranges. All professional services fees are subject to VAT at the applicable Spanish rate. Internal salary costs (such as a newly hired CCO) are treated as employment expenses.

Item Typical amount (estimate) Notes
External criminal risk mapping (consultant + counsel) €5,000 – €40,000 Range depends on company size and number of entities; VAT applies
Policy drafting & legal review €3,000 – €20,000 Modular pricing; smaller firms at the lower end
Whistleblowing channel (SaaS) €2,000 – €15,000 p.a. Depends on provider, languages, anonymity features; VAT applies
Training (LMS + content development) €1,000 – €15,000+ Per course + per‑user licensing; NIS2 cyber modules may add cost
External effectiveness audit / forensic review €6,000 – €50,000 Independent scope, sample size, technical work impacts fee
CCO / compliance officer salary (if hiring) €45,000 – €120,000 p.a. Dependent on market and seniority; payroll taxes apply

For a mid‑sized company with a single Spanish entity and moderate risk profile, the total first‑year external cost (excluding a new CCO hire) typically falls between €20,000 and €80,000. Groups with multiple entities, cross‑border exposure or NIS2 obligations should budget toward the higher end. Ongoing annual costs for monitoring, testing and channel maintenance are generally lower than the initial investment. Consult a qualified lawyer in Spain for a scope‑specific estimate.

What Changes in 2026: Enforcement and Regulatory Impact on Compliance Programmes

The 2026 enforcement environment introduces several procedural changes that directly affect how companies implement a corporate criminal compliance programme in Spain. Compliance officers should integrate these into their project plans now rather than retrofitting them later.

Draft Organic Public Integrity Act (DOPIA). In early 2026, the Spanish government approved a draft bill aimed at strengthening the public integrity framework. Early indications suggest that entities engaging with the public sector, through procurement, subsidies or public contracts, will need to document integrity policies and include public‑sector engagement clauses in their compliance programmes. Boards should record their awareness of, and response to, this legislative initiative in board minutes.

NIS2 cybersecurity obligations. Does NIS2 change compliance programme obligations in Spain? Yes. Organisations designated as essential or important entities under Directive (EU) 2022/2555 must demonstrate that their cybersecurity risk management measures are proportionate to the identified risks. For the criminal compliance programme, this means that IT and cyber controls must be documented, tested and evidenced in the same manner as financial or anti‑bribery controls. Incident response reports, SIEM logs and cybersecurity training records should form part of the programme’s evidence pack. NIS2 compliance in Spain requires the compliance programme to extend into technical territory that many organisations have historically treated as a separate IT function.

AML / SEPBLAC / Banco de España guidance. Supervisory attention to AML/CTF compliance has intensified in 2026. Where an entity handles financial flows, AML risk assessments, KYC/KYB screening records and suspicious transaction report filings must be integrated into the compliance programme’s third‑party due diligence files. The likely practical effect will be that prosecutors increasingly expect to see AML/SEPBLAC traceability as part of the broader criminal compliance evidence pack.

Prosecutorial focus (Fiscalía General del Estado). Spanish prosecutors now expect a living programme, one with a documented, current risk map, periodic testing evidence, remediation records and disciplinary consistency. A programme that was created years ago but never updated or tested will carry little or no weight in criminal proceedings. The actionable response is to add an external audit clause into the programme with a 12–24 month cadence, create a combined evidence pack that maps each policy to the relevant Penal Code offence, and maintain secure, GDPR‑compliant whistleblowing evidence aligned with AEPD requirements.

Common Pitfalls and How to Avoid Them

The following pitfalls recur in programmes that fail to satisfy prosecutorial or regulatory scrutiny. Each is paired with a concrete remedy.

  • Policies never formally approved by the Board. Minute and publish Board approval for every core policy; record version number and approval date on the document header.
  • Whistleblowing channel not assessed for GDPR compliance. Conduct a Data Protection Impact Assessment (DPIA) and document the processing legal basis in line with AEPD guidance before the channel goes live.
  • Generic risk map with no company‑specific analysis. Conduct interviews with process owners and document the data sources reviewed; a template that cannot demonstrate bespoke analysis carries no evidentiary weight.
  • No external validation of programme effectiveness. Schedule an independent external effectiveness audit within the first 12–24 months and repeat on a regular cadence.
  • Training delivered but not evidenced. Retain attendance registers, materials distributed and assessment scores; use an LMS that generates exportable completion records.
  • Controls never tested after implementation. Establish a periodic testing calendar (quarterly or annual) and assign internal audit or compliance resources to execute it.
  • AML/KYC records not integrated into the compliance file. For entities handling financial flows, ensure third‑party due diligence files include KYC/KYB screening evidence and are cross‑referenced in the risk register.
  • Disciplinary policy inconsistently applied. Document every disciplinary action (or decision not to act) arising from a compliance breach and retain redacted records in the evidence pack.
  • No board reporting on programme KPIs. Present compliance KPIs to the board at least annually; minute the discussion and any decisions taken.
  • Evidence pack not retrievable within days. Store all programme documents in a centralised, version‑controlled repository with access controls; test retrieval time before you need it.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.

Sources

  1. Código Penal (Spanish Penal Code), official BOE consolidated text
  2. EUR‑Lex, Directive (EU) 2022/2555 (NIS2)
  3. SEPBLAC, Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales
  4. Banco de España
  5. Agencia Española de Protección de Datos (AEPD)
  6. Fiscalía General del Estado
  7. Comisión Nacional de los Mercados y la Competencia (CNMC)

FAQs

How do you set up a compliance programme in Spain?
Begin with a formal board resolution authorising the programme and appointing an accountable owner. Then conduct a criminal risk map aligned to the Código Penal, design controls and policies for each identified risk, deploy a whistleblowing channel, roll out role‑based training, implement periodic testing, and obtain an external effectiveness audit. See the full step‑by‑step procedure above for detailed deliverables at each stage.
The six most critical evidentiary items are: the signed board resolution, the version‑dated criminal risk map, published policies with employee acknowledgement forms, whistleblowing channel records (including DPIA), internal testing reports with remediation evidence, and an external auditor’s effectiveness report. Courts and prosecutors assess whether these documents are genuine, current and company‑specific.
A typical implementation takes six to twelve months from board resolution to external effectiveness audit. The timeline depends on the number of entities in scope, the complexity of the business and whether workstreams are run sequentially or in parallel. Accelerated delivery in four to six months is possible with dedicated external counsel but increases advisory costs.
Entities designated as essential or important under Directive (EU) 2022/2555 must demonstrate proportionate cybersecurity risk management. In the compliance programme context, this means IT and cyber controls must be documented, tested and evidenced alongside traditional financial and anti‑bribery controls. Incident response reports, SIEM logs and cyber training records should form part of the programme’s evidence pack.
A foreign company operating in Spain through a Spanish legal entity, such as a branch, subsidiary or sociedad limitada, must ensure that the compliance programme specifically covers the Spanish entity’s operations, risks and regulatory environment. A group‑level programme designed for another jurisdiction will not satisfy Spanish prosecutors unless it is localised to address Penal Code offence categories, Spanish labour law, AEPD data protection requirements and any applicable sector‑specific regulation.
Missing a regulatory deadline does not automatically invalidate the programme, but it weakens the evidence of effectiveness. The recommended response is to document the reason for the delay, escalate to the board, implement an accelerated remediation plan and record the corrective action taken. Prosecutors and regulators will assess whether the organisation responded promptly and transparently to the missed deadline.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Implement a Corporate Criminal Compliance Programme in Spain in 2026: Step‑by‑step

Send welcome message

Custom Message