Our Expert in Spain
No results available
Understanding how to implement a corporate criminal compliance programme in Spain in 2026 is now a practical necessity for any legal person operating in the country. Spain’s Código Penal (Penal Code) holds companies directly liable for offences committed on their behalf or for their benefit, and an effective compliance programme is the principal statutory mechanism to mitigate, or even exclude, that liability. This guide walks compliance officers, general counsels, in‑house legal teams and business owners through each procedural step, from board approval to external effectiveness testing. It reflects the 2026 enforcement landscape, including heightened prosecutorial scrutiny, NIS2 cybersecurity obligations and renewed AML supervisory guidance from SEPBLAC and the Banco de España.
A corporate criminal compliance programme in Spain is a documented system of governance, risk controls, reporting channels, training and monitoring designed to prevent, detect and respond to criminal conduct attributable to the organisation. Its legal objective is defined by the Código Penal: where an effective programme exists and the entity can demonstrate it was genuinely operative before the offence, courts may reduce or fully exclude corporate criminal liability.
The compliance programme requirements in Spain apply to all legal persons, sociedad anónima, sociedad limitada, foundations, associations and branches of foreign entities, regardless of size. In practice, the compliance programme is most urgent for medium and large companies, entities in sectors regulated by the CNMC, organisations within the scope of Directive (EU) 2022/2555 (NIS2) and financial institutions subject to AML oversight by SEPBLAC and the Banco de España.
The programme must be a living system, not a static document. Industry observers expect that programmes which cannot demonstrate periodic testing, updated risk maps and genuine board oversight will receive no credit from prosecutors or courts. The 2026 enforcement environment places particular weight on documented effectiveness, meaning evidence that the programme actually works, not merely that it was written down.
Every entity incorporated or operating in Spain through a legal person is exposed to corporate criminal liability under the Código Penal. However, certain triggers should accelerate your timeline. These include high‑risk commercial activities (public procurement, regulated financial services, international trade), operations involving personal data at scale, exposure to bribery or corruption risk, and designation as an essential or important entity under NIS2.
Before the programme design begins, several organisational prerequisites must be in place. First, the board of directors (or equivalent governing body) must formally authorise the programme and allocate a dedicated budget. Second, an accountable owner must be appointed, typically the General Counsel, Chief Risk Officer or a dedicated Chief Compliance Officer. Third, a core project team should be assembled, drawing on legal, human resources, IT and finance functions. For groups with multi‑jurisdictional operations, the scope must clearly define which Spanish legal entities and business lines are covered.
External specialist counsel is advisable where the company lacks in‑house criminal law expertise, where the risk mapping involves complex regulatory sectors, or where the organisation is already under investigation. GDPR considerations arise from the outset: any processing of personal data for compliance purposes, employee monitoring, whistleblowing reports, third‑party screening, must be assessed against the requirements of the Agencia Española de Protección de Datos (AEPD). Mapping your data access points and preparing an organisational chart at the start of the project will save significant time later. Browse the Compliance practice area directory for qualified specialists.
How do you set up a compliance programme in Spain? The process follows seven sequential steps, each producing specific deliverables that prosecutors and regulators will expect to see if the programme is ever tested. The table below summarises the steps, responsible parties and typical durations before the detailed walkthrough.
| Step | Who does it | Typical duration |
|---|---|---|
| Scoping & governance set‑up (board resolution, appoint owner) | Board / General Counsel / CRO | 1–4 weeks |
| Criminal risk mapping (process mapping, interviews) | Internal legal + external counsel / risk consultants | 4–8 weeks |
| Design controls & policies (policy drafting) | Legal + HR + IT + external counsel | 4–8 weeks |
| Whistleblowing channel & reporting | Legal + IT + HR | 2–6 weeks |
| Role‑based training rollout | HR / Compliance team | 4–12 weeks (staged rollout) |
| Monitoring & testing (internal testing) | Internal audit / Compliance | Ongoing, periodic cycles (quarterly/annual) |
| External audit / effectiveness testing | External auditor / forensic firm | 1–4 weeks per audit; annual/biannual cadence |
The programme begins with a formal board resolution authorising its creation, scope and budget. This resolution is one of the most important pieces of evidence prosecutors will request, it demonstrates that the governing body took the initiative and that the programme has institutional backing rather than being a retroactive defensive measure.
During this phase, the board appoints an accountable programme owner (the GC, CRO or a dedicated CCO) and forms a project steering group with representatives from legal, HR, IT and finance. The steering group defines the assessment perimeter: which legal entities, geographies and business lines fall within scope. For groups operating across multiple Spanish entities or internationally, each entity’s exposure must be assessed individually.
Key deliverables at this stage are the signed board resolution (retained permanently), a project plan with milestones and a preliminary stakeholder register identifying process owners across the business.
Criminal risk mapping is the analytical core of the programme. The objective is to map every relevant business process against the Código Penal’s catalogue of offences for which legal persons can be held liable. These offences span fraud, bribery, money laundering, offences against workers’ rights, environmental crimes, data‑protection infringements, market abuse, tax offences and, increasingly relevant in 2026, cyber‑intrusions affecting critical services.
The method combines structured interviews with process owners, document review (contracts, financial flows, procurement procedures), transactional sampling and preliminary control testing. Each risk is rated by likelihood and impact, and a control gap register is produced showing where existing controls are absent or insufficient.
The deliverable is a documented risk map, version‑dated and signed by the programme owner. It must include the evidence base (interview logs, data sources reviewed) so that an independent auditor or prosecutor can verify that the assessment was thorough and genuine. This is the document that prosecutors will scrutinise most closely, a generic template with no company‑specific analysis carries no evidentiary weight.
With the risk map complete, the programme moves to designing the controls and policies that will prevent, detect or respond to each identified risk. The essential parts of an effective compliance programme at this stage include a code of conduct, an anti‑bribery and anti‑corruption policy, an AML/KYC linkage policy (where the entity handles financial flows), a whistleblowing policy, IT and cybersecurity controls (mandatory for NIS2‑scope entities), and sector‑specific policies where relevant.
Each policy must be mapped back to the risk register, creating a governance matrix that shows which control addresses which risk. Key performance indicators should be defined for each control, for example, percentage of high‑risk transactions screened, average time to close a whistleblowing report, or training completion rates among board members.
The deliverables are the governance matrix, each written policy in final form, and the KPI definitions. All policies require formal board endorsement (or endorsement by the delegate body authorised in the board resolution). Policies that exist on paper but were never formally approved or communicated to employees will be treated as ineffective by prosecutors.
Spain’s whistleblowing regime requires organisations to deploy a secure, accessible internal reporting channel. The channel must guarantee confidentiality (and where possible, anonymity), be accessible to employees, contractors and third parties, and operate in compliance with GDPR, specifically the AEPD’s guidance on data protection impact assessments for whistleblowing systems.
During this phase, the compliance team configures the channel (typically a SaaS platform), establishes an internal reporting flow (triage, investigation, resolution, closure), and aligns the disciplinary policy with applicable labour law. The deliverables are the published whistleblowing policy, channel configuration documentation, a completed privacy impact assessment filed with the AEPD, and a data retention schedule.
Training transforms written policies into operational behaviour. The programme must include a role‑based training plan distinguishing between board members, senior management, high‑risk operational teams and general staff. For entities within NIS2 scope, specific cybersecurity awareness training is mandatory and must be documented.
Training is delivered in staged rollouts, senior leadership first, followed by high‑risk teams and then the broader workforce. Each session must generate verifiable evidence: attendance registers, training materials distributed, and assessment scores. An LMS (learning management system) is the most efficient way to produce these records at scale. The training plan should be refreshed annually and updated whenever a material change in risk profile or regulation occurs.
A compliance programme that is never tested cannot demonstrate effectiveness. What evidence do prosecutors look for to mitigate corporate liability? Above all, they look for documented proof that the controls described in the programme were periodically tested and, where weaknesses were found, that remediation was carried out.
Monitoring activities include periodic controls testing (walkthroughs, re‑performance of key controls), transaction sampling (screening a random sample of high‑risk transactions against the control framework), and process walkthroughs with department heads. Internal audit should conduct at least one full cycle before the first external review. Every test must generate a written report showing the scope, methodology, findings and remediation actions.
Deliverables include test reports, a remediation plan with assigned owners and deadlines, and evidence that corrective actions were closed. Where a control failure is material, the compliance officer must escalate to the board and document the escalation, the board’s response and the timeline for remediation.
The final step converts the compliance programme from a one‑off project into a continuous management cycle. An annual review of the risk map, policies and controls should be presented to the board, together with KPI data showing programme performance over the preceding period. The risk register must be updated to reflect new offences, regulatory changes and operational developments.
External assurance, an independent audit conducted by a qualified external firm, is the strongest evidence of programme effectiveness. Industry observers expect Spanish prosecutors to give significant weight to programmes backed by at least one external effectiveness audit within the first 12–24 months and repeated on a regular cadence thereafter. The external auditor’s report, engagement letter and any remediation evidence should be retained as part of the programme’s evidence pack. This pack, comprising the risk map, board minutes, audit reports, training records and disciplinary records, is the combined body of evidence the entity would present to a court or prosecutor if its liability were ever challenged.
What documents and tests prove a compliance programme is effective for criminal liability mitigation? The table below sets out the core documents needed for a compliance programme, together with notes on who issues each document, the recommended format and retention expectations.
| Document | Notes (who issues it, format, validity) |
|---|---|
| Board resolution approving compliance programme | Issued by the Board; signed minutes (PDF); retain permanently |
| Criminal risk map / risk register | Internal document; versioned PDF/Excel; include evidence of interviews and data sources; review date on header |
| Code of Conduct & core policies (anti‑bribery, AML, IT security) | Drafted by Legal; published to employees; signed acknowledgement forms retained for 5+ years |
| Whistleblowing policy & channel records | Channel provider logs + case file summaries; privacy impact assessment (AEPD) and retention schedule |
| Third‑party due diligence files (KYC/KYB) | Vendor/KYC documents, risk assessment forms, dated evidence of screening |
| Training attendance & assessment records | HR / LMS export CSVs showing completion and assessment scores |
| Internal testing reports & remediation logs | Internal audit/compliance test reports with evidence and closure records |
| External audit / effectiveness report | External auditor report (signed), engagement letter, remediation evidence |
| Disciplinary records (if any) | HR records (redacted if necessary) demonstrating consistent enforcement |
| Relevant IT logs & incident response reports (NIS2 scope) | IT/SIEM exports, incident tickets, forensic reports; retain per NIS2 / regulatory guidance |
| AML reporting evidence (if applicable) | STR filings, AML risk assessments, SEPBLAC correspondence |
| Data processing / DPIA evidence for whistleblowing | AEPD DPIA output and retention compliance records |
Every document should be version‑controlled, dated and stored in a secure, auditable repository. The ability to produce this evidence pack rapidly, within days rather than weeks, is itself a strong indicator of programme maturity that prosecutors will note.
How long does it take to implement a compliance programme? Industry observers estimate that a company starting from scratch needs six to twelve months to design, implement and embed a programme that will withstand regulatory or prosecutorial scrutiny. The precise timeline depends on the number of legal entities in scope, the complexity of the business, and whether external counsel or consultants are engaged.
| Milestone | Timeframe | Board reporting |
|---|---|---|
| Board resolution & project initiation | Month 0 | Board minute recorded at approval |
| Scoping, governance set‑up, initial risk mapping | Months 0–2 | Progress report to board at month 2 |
| Policy drafting, whistleblowing channel live, senior management training | Months 2–4 | Policy endorsement at board meeting |
| Full training rollout, controls implemented, start internal testing | Months 4–8 | KPI dashboard first presented at month 6 |
| External effectiveness audit & board effectiveness report; remediation closed | Months 9–12 | Annual effectiveness report to board |
| Annual review and continuous improvement cycle | After month 12 | Annual board update; external audit every 12–24 months |
Several triggers can compress this timeline. An incoming regulatory inspection, a pending investigation, or an imminent NIS2 compliance deadline may require accelerated delivery. In these circumstances, engaging specialist external counsel from the outset and running workstreams in parallel (risk mapping alongside policy drafting, for instance) can reduce the overall duration to four to six months, though this increases external advisory costs significantly. The key is that no step should be skipped entirely, as an incomplete programme is unlikely to carry weight with prosecutors.
The costs of implementing a corporate criminal compliance programme in Spain vary substantially by company size, sector and complexity. The table below presents indicative market ranges. All professional services fees are subject to VAT at the applicable Spanish rate. Internal salary costs (such as a newly hired CCO) are treated as employment expenses.
| Item | Typical amount (estimate) | Notes |
|---|---|---|
| External criminal risk mapping (consultant + counsel) | €5,000 – €40,000 | Range depends on company size and number of entities; VAT applies |
| Policy drafting & legal review | €3,000 – €20,000 | Modular pricing; smaller firms at the lower end |
| Whistleblowing channel (SaaS) | €2,000 – €15,000 p.a. | Depends on provider, languages, anonymity features; VAT applies |
| Training (LMS + content development) | €1,000 – €15,000+ | Per course + per‑user licensing; NIS2 cyber modules may add cost |
| External effectiveness audit / forensic review | €6,000 – €50,000 | Independent scope, sample size, technical work impacts fee |
| CCO / compliance officer salary (if hiring) | €45,000 – €120,000 p.a. | Dependent on market and seniority; payroll taxes apply |
For a mid‑sized company with a single Spanish entity and moderate risk profile, the total first‑year external cost (excluding a new CCO hire) typically falls between €20,000 and €80,000. Groups with multiple entities, cross‑border exposure or NIS2 obligations should budget toward the higher end. Ongoing annual costs for monitoring, testing and channel maintenance are generally lower than the initial investment. Consult a qualified lawyer in Spain for a scope‑specific estimate.
The 2026 enforcement environment introduces several procedural changes that directly affect how companies implement a corporate criminal compliance programme in Spain. Compliance officers should integrate these into their project plans now rather than retrofitting them later.
Draft Organic Public Integrity Act (DOPIA). In early 2026, the Spanish government approved a draft bill aimed at strengthening the public integrity framework. Early indications suggest that entities engaging with the public sector, through procurement, subsidies or public contracts, will need to document integrity policies and include public‑sector engagement clauses in their compliance programmes. Boards should record their awareness of, and response to, this legislative initiative in board minutes.
NIS2 cybersecurity obligations. Does NIS2 change compliance programme obligations in Spain? Yes. Organisations designated as essential or important entities under Directive (EU) 2022/2555 must demonstrate that their cybersecurity risk management measures are proportionate to the identified risks. For the criminal compliance programme, this means that IT and cyber controls must be documented, tested and evidenced in the same manner as financial or anti‑bribery controls. Incident response reports, SIEM logs and cybersecurity training records should form part of the programme’s evidence pack. NIS2 compliance in Spain requires the compliance programme to extend into technical territory that many organisations have historically treated as a separate IT function.
AML / SEPBLAC / Banco de España guidance. Supervisory attention to AML/CTF compliance has intensified in 2026. Where an entity handles financial flows, AML risk assessments, KYC/KYB screening records and suspicious transaction report filings must be integrated into the compliance programme’s third‑party due diligence files. The likely practical effect will be that prosecutors increasingly expect to see AML/SEPBLAC traceability as part of the broader criminal compliance evidence pack.
Prosecutorial focus (Fiscalía General del Estado). Spanish prosecutors now expect a living programme, one with a documented, current risk map, periodic testing evidence, remediation records and disciplinary consistency. A programme that was created years ago but never updated or tested will carry little or no weight in criminal proceedings. The actionable response is to add an external audit clause into the programme with a 12–24 month cadence, create a combined evidence pack that maps each policy to the relevant Penal Code offence, and maintain secure, GDPR‑compliant whistleblowing evidence aligned with AEPD requirements.
The following pitfalls recur in programmes that fail to satisfy prosecutorial or regulatory scrutiny. Each is paired with a concrete remedy.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 5 hours ago
No results available
Find the right Legal Expert for your business
Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message