Our Expert in Spain
No results available
Effective third party due diligence spain has become a defining test of whether a corporate compliance programme actually works under real enforcement conditions. Spanish prosecutors now expect documented, risk‑based controls over agents, distributors, suppliers and intermediaries, not policies that exist only on paper. As programmes enter their 2026 refresh cycle, compliance officers, general counsel and procurement teams need a repeatable procedure they can defend before the Ministerio Fiscal (the Public Prosecutor’s Office) and, if it comes to it, before a criminal court. This guide sets out the operational steps, required documents, realistic timelines, costs and red flags for running third‑party reviews in Spain, grounded in Article 31 bis of the Código Penal (Spanish Penal Code) and the surrounding regulatory framework.
Under Article 31 bis of the Código Penal, legal persons can incur criminal liability for offences committed for their benefit by persons acting on their behalf, a category that reaches beyond employees to agents, intermediaries and business partners. A company that has adopted and effectively implemented an adequate organisation and management model (modelo de organización y gestión) that includes suitable measures to prevent offences of that kind can mitigate or exclude that liability, subject to the conditions in Article 31 bis. Third‑party due diligence spain is therefore not merely a procurement formality; it is a core component of the criminal‑risk defence.
The practical benefits are threefold: reduced exposure to corruption and money‑laundering risk carried by counterparties, contractual protection through representations and audit rights, and demonstrable evidence of a functioning programme should prosecutors scrutinise the organisation. Where a bribery or laundering offence originates with an unvetted agent, the absence of documented controls is exactly what an investigator will seize upon.
The controlling provisions sit in Article 31 bis of the Código Penal, which governs corporate criminal liability and sets out the conditions under which an organisation and management model can serve to exempt or mitigate liability. The Fiscalía General del Estado has published guidance (notably Circular 1/2016) on how prosecutors should assess whether a compliance programme is genuine and effective, placing weight on documented risk assessment and controls, including over third parties. Layered onto this is Ley 10/2010 on the prevention of money laundering and terrorist financing, which imposes customer due diligence and beneficial‑ownership obligations on obliged entities. Together these instruments make documented, risk‑based third party due diligence spain an enforcement expectation rather than an optional good practice.
Not every counterparty warrants the same depth of review. A risk‑based approach, the model endorsed by both anti‑money‑laundering law and prosecutorial practice, requires you to calibrate scrutiny to exposure. Begin by defining what counts as a “third party” (tercero) for these purposes:
Score each candidate against four axes and let the highest single factor drive the tier:
A low‑value, low‑risk‑country managed supplier sits in the light tier; a commission agent in a high‑risk jurisdiction with opaque ownership belongs firmly in enhanced due diligence.
The following twelve steps form a defensible, end‑to‑end procedure. Each identifies the responsible owner and a realistic duration. Decision points for enhanced due diligence (EDD) and escalation are flagged where they arise.
Escalation. Where screening surfaces a sanctions hit, credible corruption allegation, or refusal to disclose ownership, escalate immediately to Legal and, depending on severity, to the General Counsel, CEO or board. Assign a remediation owner promptly, ideally within a few working days of an adverse finding.
| Step | Owner | Typical duration |
|---|---|---|
| 1. Intake & scope definition | Compliance officer / Procurement lead | 1–3 days |
| 2. Identification & basic data collection | Procurement / Local ops | 3–7 days |
| 3. KYC & identity verification | Compliance / screening vendor | 3–10 days |
| 4. Sanctions & PEP screening | Legal / Compliance | 1–3 days |
| 5. Financial & reputation checks | Finance / Compliance | 3–7 days |
| 6. Ownership / BO analysis | Legal / Tax | 3–7 days |
| 7. Enhanced on‑site diligence (if triggered) | Compliance / External counsel | 1–3 weeks |
| 8. Risk scoring & decision | Compliance committee / GC | 1–3 days |
| 9. Contract drafting & risk allocation | Legal & commercial teams | 3–10 days |
| 10. Approval & onboarding controls | Senior management | 1–5 days |
| 11. Ongoing monitoring (by tier) | Compliance / IT | Ongoing (quarterly/annual) |
| 12. Record retention & audit trail | Compliance / Records team | Ongoing (per retention policy) |
EDD is not discretionary once certain factors are present. Treat any of the following as an automatic trigger and document the reasoning:
Where a trigger fires, the immediate actions are to pause onboarding, notify Legal, and commission the enhanced steps, bank references, independent verification, and where warranted an on‑site visit or external legal opinion.
| Element | Light (standard) | Enhanced (EDD) | Continuous monitoring |
|---|---|---|---|
| Typical triggers | Low value, low‑risk country, managed supplier | High‑risk country, agent/distributor, PEP, complex ownership | Any onboarded party at medium/high risk |
| Processes | Basic KYC, sanctions check, standard clauses | In‑depth BO analysis, bank reference, on‑site visit, legal opinion | Ongoing sanctions/negative‑media screening, transaction monitoring |
| Time | 1–2 weeks | 2–6 weeks | Continuous (automated + periodic manual) |
| Contractual protections | Standard reps & warranties | Strong audit/termination/AML clauses | Reporting & remediation KPIs |
The documents you request should scale with the risk tier. Verify authenticity independently where you can, and remember that any personal data (identity documents, principals’ details) must be handled under a lawful basis and the data‑minimisation principle set out in the GDPR, applied in Spain together with Ley Orgánica 3/2018 and overseen by the Agencia Española de Protección de Datos (AEPD, the Spanish Data Protection Agency).
| Document / data point | When required | Notes |
|---|---|---|
| Legal entity certificate (Registro Mercantil extract) | All corporate third parties | Verify via Registro Mercantil; ensure recent (≤3 months) |
| Company statutes & articles | Medium / high risk | Check authorised signatories |
| Beneficial ownership / UBO declaration | All; essential for AML and high risk | Cross‑check the Registro Central de Titularidades Reales where applicable |
| ID documents for principals / agents | Agents, PEPs, signatories | Handle under GDPR; fix lawful basis before collection |
| Tax & VAT registration | Suppliers / vendors | Verify tax status and VAT registration |
| Financial statements (last 2 years) | Vendors / partners (medium/high risk) | For solvency and fraud checks |
| Banking details & payment references | High‑value contracts | Confirm independently with the bank where possible |
| Anti‑bribery / compliance policy & training evidence | Agents / commercial intermediaries | Assess adequacy of the third party’s own controls |
| References & client list | Agents / distributors | Use for reputation checks |
| Contracts with sub‑agents / subcontractors | Where delegation occurs | Review cascade obligations |
| Certificates (ISO, AML, KYC provider reports) | As applicable | Use as supplemental evidence |
For supplier due diligence spain and vendor due diligence spain specifically, prioritise tax and VAT verification and financial statements; for agent due diligence spain, prioritise UBO, anti‑bribery controls and references. A downloadable Third‑Party Due Diligence Questionnaire & Template (Spain) accompanies this guide to standardise collection.
Set service levels by tier so the business knows what to expect and adverse findings are not left unattended:
These SLAs align with the Step / Who / Duration table above. Where an on‑site visit in a foreign jurisdiction is required, allow additional lead time for travel and scheduling.
Budgeting for third party due diligence spain means accounting for internal hours, external screening, and specialist counsel for the elevated‑risk cases. The ranges below are indicative for the Spanish market and will vary with volume, provider and complexity; they should be validated against current supplier quotations rather than relied upon as fixed prices.
| Cost item | Indicative range (EUR) | Notes |
|---|---|---|
| Basic screening (automated KYC/PEP/sanctions) | Low tens of euros per entity | Per check via SaaS screening vendors; volume pricing applies |
| Enhanced screening & reports | Several hundred to low thousands per party | Negative‑media, financial checks, ownership analysis |
| External counsel EDD / legal opinion | From low thousands upward | Depends on complexity, jurisdiction, on‑site work |
| On‑site visit (travel + time) | Variable, typically low thousands per visit | For high‑risk foreign jurisdictions |
| Internal compliance hours (per review) | Variable | Depends on seniority and depth of review |
| Document translation & notarisation | Variable | For non‑Spanish documents |
| Ongoing monitoring subscription | Annual subscription (volume‑based) | Platform pricing varies by volume and features |
The most efficient model tiers spend: automated screening for the volume of low‑risk parties, reserving external counsel and on‑site work for the minority of high‑risk relationships that genuinely warrant it.
Several developments sharpen the case for rigorous third party due diligence spain in the current cycle:
The likely practical effect is that static, one‑off onboarding checks will increasingly be viewed as insufficient; the direction of travel favours documented, ongoing third‑party risk assessment spain across the counterparty lifecycle.
Most third‑party failures trace back to a small set of recurring red flags. Treat the following as warning signs demanding heightened scrutiny or, in serious cases, refusal to onboard:
Common process errors compound these: onboarding before diligence completes, failing to document the decision rationale, and neglecting to re‑screen after onboarding. Where a red flag materialises post‑contract, available remedies include suspension of payments, exercising audit rights, withholding or escrow of sums, mandatory remediation, and ultimately termination for cause under the anti‑bribery clause. If findings suggest suspected criminal conduct, coordinate with legal counsel on internal escalation and any decision to report to the authorities, and, where the entity is an obliged party under Ley 10/2010, on any suspicious‑activity reporting to the SEPBLAC (the Spanish financial intelligence unit).
Robust third party due diligence spain is now inseparable from a credible corporate compliance programme. By running a documented, risk‑based process, scoping, screening, verifying ownership, scoring risk, allocating contractual protections and monitoring continuously, compliance officers create both a genuine control and the evidential record that Article 31 bis and prosecutorial practice reward. As enforcement expectations and monitoring technology advance through 2026, the organisations that fare best will be those treating third‑party review as an ongoing, defensible lifecycle rather than a one‑off gate. Use the checklist, timelines and templates in this guide as the operational backbone of that programme, and reserve enhanced diligence and external counsel for the relationships that genuinely demand them.
For the underlying framework, see the Global Law Experts primer on Spanish corporate criminal compliance (2026). To standardise your process, request the Third‑Party Due Diligence Questionnaire & Template (Spain).
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.
posted 22 minutes ago
posted 37 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 5 hours ago
posted 5 hours ago
posted 6 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message