[codicts-css-switcher id=”346″]

Global Law Experts Logo
third party due diligence spain

How to Conduct Third‑party Due Diligence in Spain: Step‑by‑step Guide for Compliance Officers

By Global Law Experts
– posted 52 minutes ago

Effective third party due diligence spain has become a defining test of whether a corporate compliance programme actually works under real enforcement conditions. Spanish prosecutors now expect documented, risk‑based controls over agents, distributors, suppliers and intermediaries, not policies that exist only on paper. As programmes enter their 2026 refresh cycle, compliance officers, general counsel and procurement teams need a repeatable procedure they can defend before the Ministerio Fiscal (the Public Prosecutor’s Office) and, if it comes to it, before a criminal court. This guide sets out the operational steps, required documents, realistic timelines, costs and red flags for running third‑party reviews in Spain, grounded in Article 31 bis of the Código Penal (Spanish Penal Code) and the surrounding regulatory framework.

Overview, why third‑party due diligence matters in Spain

Under Article 31 bis of the Código Penal, legal persons can incur criminal liability for offences committed for their benefit by persons acting on their behalf, a category that reaches beyond employees to agents, intermediaries and business partners. A company that has adopted and effectively implemented an adequate organisation and management model (modelo de organización y gestión) that includes suitable measures to prevent offences of that kind can mitigate or exclude that liability, subject to the conditions in Article 31 bis. Third‑party due diligence spain is therefore not merely a procurement formality; it is a core component of the criminal‑risk defence.

The practical benefits are threefold: reduced exposure to corruption and money‑laundering risk carried by counterparties, contractual protection through representations and audit rights, and demonstrable evidence of a functioning programme should prosecutors scrutinise the organisation. Where a bribery or laundering offence originates with an unvetted agent, the absence of documented controls is exactly what an investigator will seize upon.

Legal backdrop, corporate liability and enforcement

The controlling provisions sit in Article 31 bis of the Código Penal, which governs corporate criminal liability and sets out the conditions under which an organisation and management model can serve to exempt or mitigate liability. The Fiscalía General del Estado has published guidance (notably Circular 1/2016) on how prosecutors should assess whether a compliance programme is genuine and effective, placing weight on documented risk assessment and controls, including over third parties. Layered onto this is Ley 10/2010 on the prevention of money laundering and terrorist financing, which imposes customer due diligence and beneficial‑ownership obligations on obliged entities. Together these instruments make documented, risk‑based third party due diligence spain an enforcement expectation rather than an optional good practice.

Eligibility, which third parties to review and risk‑based scope

Not every counterparty warrants the same depth of review. A risk‑based approach, the model endorsed by both anti‑money‑laundering law and prosecutorial practice, requires you to calibrate scrutiny to exposure. Begin by defining what counts as a “third party” (tercero) for these purposes:

  • Agents and distributors. Commercial intermediaries (agente, distribuidor) acting on the company’s behalf, especially on commission.
  • Suppliers and vendors. Goods and service providers, including outsourced functions.
  • Consultants and lobbyists. Parties engaged to influence outcomes or secure business.
  • Joint‑venture partners and co‑investors. Entities sharing control or revenue.
  • Sub‑agents and subcontractors. Cascade relationships delegated by your direct counterparty.

Quick risk‑screen matrix (high / medium / low)

Score each candidate against four axes and let the highest single factor drive the tier:

  • Geography. Counterparties or payment routes in high‑corruption or sanctioned jurisdictions push toward high risk.
  • Function. Commission‑based agents interacting with public officials rank higher than a routine managed supplier.
  • Value. High‑value or long‑term contracts justify deeper review.
  • Sector. Regulated or historically corruption‑prone sectors (construction, energy, defence, healthcare procurement) elevate the tier.

A low‑value, low‑risk‑country managed supplier sits in the light tier; a commission agent in a high‑risk jurisdiction with opaque ownership belongs firmly in enhanced due diligence.

Step‑by‑step third party due diligence spain process

The following twelve steps form a defensible, end‑to‑end procedure. Each identifies the responsible owner and a realistic duration. Decision points for enhanced due diligence (EDD) and escalation are flagged where they arise.

  1. Intake and scope definition (Compliance / Procurement lead, 1–3 days). Log the request, capture the business rationale, identify the counterparty type and complete the quick risk‑screen matrix. This step fixes the diligence tier and the documents you will request.
  2. Identification and basic data collection (Procurement / Local operations, 3–7 days). Obtain the legal name, registration number, registered address, ownership summary and the names of principals and authorised signatories. Issue the standard due‑diligence questionnaire.
  3. KYC and identity verification (Compliance / screening vendor, 3–10 days). Verify corporate existence against the Registro Mercantil (Commercial Registry) and confirm the identity of individuals and signatories. Where personal data is collected, fix a lawful basis under the GDPR before processing (see 2026 changes below).
  4. Sanctions and PEP screening (Legal / Compliance, 1–3 days). Screen the entity, principals and beneficial owners against EU and UN sanctions lists and politically exposed person (PEP) databases. Any positive match triggers escalation and, ordinarily, EDD.
  5. Financial and reputation checks (Finance / Compliance, 3–7 days). Review solvency using financial statements and run negative‑media (adverse media) searches. Insolvency signals, litigation history or corruption allegations raise the tier.
  6. Ownership and beneficial‑owner analysis (Legal / Tax, 3–7 days). Establish ultimate beneficial ownership (UBO), cross‑checking against the central beneficial‑ownership register (Registro Central de Titularidades Reales) where applicable. Opaque or multi‑layered structures are a classic EDD trigger.
  7. On‑site or enhanced due diligence where needed (Compliance / External counsel, 1–3 weeks). For high‑risk parties, commission an independent legal opinion, obtain bank references, and conduct an on‑site visit or interviews. This is the heart of third party due diligence spain for elevated‑risk counterparties.
  8. Risk scoring and decision (Compliance committee / General Counsel, 1–3 days). Consolidate findings into a documented risk score and a clear decision: approve, approve with conditions, or reject. Record the reasoning; this is the artefact prosecutors examine.
  9. Contractual risk allocation and remediation plan (Legal / Commercial, 3–10 days). Embed anti‑bribery representations, audit rights, compliance warranties and termination‑for‑cause clauses. Attach any remediation conditions (for example, mandatory training or ownership disclosure) to onboarding.
  10. Approval and onboarding controls (Senior management, 1–5 days). Secure sign‑off at the appropriate authority level, activate payment controls, and record the counterparty in the vendor master with its risk tier.
  11. Ongoing monitoring and periodic review (Compliance / IT, ongoing). Re‑screen against sanctions and adverse‑media feeds and refresh the review by tier. Continuous monitoring is the expectation for medium‑ and high‑risk parties.
  12. Record retention and audit trail (Compliance / Records, ongoing). Preserve the full file, questionnaire, screening results, decision memo, signed contract, under the retention policy, balancing evidential value against GDPR data‑minimisation obligations.

Escalation. Where screening surfaces a sanctions hit, credible corruption allegation, or refusal to disclose ownership, escalate immediately to Legal and, depending on severity, to the General Counsel, CEO or board. Assign a remediation owner promptly, ideally within a few working days of an adverse finding.

Step / Who / Duration timeline

Step Owner Typical duration
1. Intake & scope definition Compliance officer / Procurement lead 1–3 days
2. Identification & basic data collection Procurement / Local ops 3–7 days
3. KYC & identity verification Compliance / screening vendor 3–10 days
4. Sanctions & PEP screening Legal / Compliance 1–3 days
5. Financial & reputation checks Finance / Compliance 3–7 days
6. Ownership / BO analysis Legal / Tax 3–7 days
7. Enhanced on‑site diligence (if triggered) Compliance / External counsel 1–3 weeks
8. Risk scoring & decision Compliance committee / GC 1–3 days
9. Contract drafting & risk allocation Legal & commercial teams 3–10 days
10. Approval & onboarding controls Senior management 1–5 days
11. Ongoing monitoring (by tier) Compliance / IT Ongoing (quarterly/annual)
12. Record retention & audit trail Compliance / Records team Ongoing (per retention policy)

Decision matrix, when to trigger Enhanced Due Diligence (EDD)

EDD is not discretionary once certain factors are present. Treat any of the following as an automatic trigger and document the reasoning:

  • High‑risk jurisdiction. Counterparty, ownership or payment routing through high‑corruption or sanctioned countries.
  • Politically exposed persons. A PEP among owners, directors or beneficial owners.
  • Commission‑based intermediaries. Agents remunerated by success fee, particularly where public contracts are involved.
  • Opaque ownership. Nominee shareholders, shell layers or refusal to identify the UBO.
  • High‑value transactions. Contracts whose value materially increases exposure.
  • Adverse media. Credible reports of bribery, fraud or sanctions breaches.

Where a trigger fires, the immediate actions are to pause onboarding, notify Legal, and commission the enhanced steps, bank references, independent verification, and where warranted an on‑site visit or external legal opinion.

Comparison, light vs enhanced vs continuous monitoring

Element Light (standard) Enhanced (EDD) Continuous monitoring
Typical triggers Low value, low‑risk country, managed supplier High‑risk country, agent/distributor, PEP, complex ownership Any onboarded party at medium/high risk
Processes Basic KYC, sanctions check, standard clauses In‑depth BO analysis, bank reference, on‑site visit, legal opinion Ongoing sanctions/negative‑media screening, transaction monitoring
Time 1–2 weeks 2–6 weeks Continuous (automated + periodic manual)
Contractual protections Standard reps & warranties Strong audit/termination/AML clauses Reporting & remediation KPIs

Required documents, checklist and handling

The documents you request should scale with the risk tier. Verify authenticity independently where you can, and remember that any personal data (identity documents, principals’ details) must be handled under a lawful basis and the data‑minimisation principle set out in the GDPR, applied in Spain together with Ley Orgánica 3/2018 and overseen by the Agencia Española de Protección de Datos (AEPD, the Spanish Data Protection Agency).

Document / data point When required Notes
Legal entity certificate (Registro Mercantil extract) All corporate third parties Verify via Registro Mercantil; ensure recent (≤3 months)
Company statutes & articles Medium / high risk Check authorised signatories
Beneficial ownership / UBO declaration All; essential for AML and high risk Cross‑check the Registro Central de Titularidades Reales where applicable
ID documents for principals / agents Agents, PEPs, signatories Handle under GDPR; fix lawful basis before collection
Tax & VAT registration Suppliers / vendors Verify tax status and VAT registration
Financial statements (last 2 years) Vendors / partners (medium/high risk) For solvency and fraud checks
Banking details & payment references High‑value contracts Confirm independently with the bank where possible
Anti‑bribery / compliance policy & training evidence Agents / commercial intermediaries Assess adequacy of the third party’s own controls
References & client list Agents / distributors Use for reputation checks
Contracts with sub‑agents / subcontractors Where delegation occurs Review cascade obligations
Certificates (ISO, AML, KYC provider reports) As applicable Use as supplemental evidence

For supplier due diligence spain and vendor due diligence spain specifically, prioritise tax and VAT verification and financial statements; for agent due diligence spain, prioritise UBO, anti‑bribery controls and references. A downloadable Third‑Party Due Diligence Questionnaire & Template (Spain) accompanies this guide to standardise collection.

Timeline and deadlines, realistic durations and SLAs

Set service levels by tier so the business knows what to expect and adverse findings are not left unattended:

  • Low‑risk onboarding: target completion within 10 working days.
  • Medium‑risk onboarding: target 15–20 working days.
  • High‑risk onboarding requiring EDD: target 30 working days, reflecting the 2–6 week enhanced‑diligence window.
  • Adverse‑finding escalation: assign a remediation owner within a few working days of the finding.

These SLAs align with the Step / Who / Duration table above. Where an on‑site visit in a foreign jurisdiction is required, allow additional lead time for travel and scheduling.

Costs and fees, cost drivers and budgeting

Budgeting for third party due diligence spain means accounting for internal hours, external screening, and specialist counsel for the elevated‑risk cases. The ranges below are indicative for the Spanish market and will vary with volume, provider and complexity; they should be validated against current supplier quotations rather than relied upon as fixed prices.

Cost item Indicative range (EUR) Notes
Basic screening (automated KYC/PEP/sanctions) Low tens of euros per entity Per check via SaaS screening vendors; volume pricing applies
Enhanced screening & reports Several hundred to low thousands per party Negative‑media, financial checks, ownership analysis
External counsel EDD / legal opinion From low thousands upward Depends on complexity, jurisdiction, on‑site work
On‑site visit (travel + time) Variable, typically low thousands per visit For high‑risk foreign jurisdictions
Internal compliance hours (per review) Variable Depends on seniority and depth of review
Document translation & notarisation Variable For non‑Spanish documents
Ongoing monitoring subscription Annual subscription (volume‑based) Platform pricing varies by volume and features

The most efficient model tiers spend: automated screening for the volume of low‑risk parties, reserving external counsel and on‑site work for the minority of high‑risk relationships that genuinely warrant it.

What changes in 2026, regulatory and enforcement updates to watch

Several developments sharpen the case for rigorous third party due diligence spain in the current cycle:

  • Prosecutorial expectations under Article 31 bis. The Fiscalía General del Estado continues to assess whether compliance programmes are real and effective, with documented third‑party controls central to that judgement. Programmes refreshed in 2026 should evidence risk‑based screening, decision memos and monitoring.
  • AML and sanctions enhancements. Obligations under Ley 10/2010 on beneficial ownership and customer due diligence, together with the EU’s new AML package (including Regulation (EU) 2024/1624 and the creation of the EU Anti‑Money Laundering Authority, AMLA) and tightening EU sanctions enforcement, raise the bar for identifying UBOs and screening counterparties.
  • Data‑protection discipline. The AEPD’s application of the GDPR and Ley Orgánica 3/2018 requires a defined lawful basis, for example contractual necessity, legitimate interest, legal obligation or, where appropriate, consent, for collecting KYC personal data, with data minimisation and retention limits. Building this into the questionnaire and retention policy is now expected practice.
  • Automation and continuous monitoring. The market is moving decisively toward SaaS screening and continuous monitoring. Continuous negative‑media and sanctions monitoring is increasingly the default for medium‑ and high‑risk vendors rather than an add‑on.

The likely practical effect is that static, one‑off onboarding checks will increasingly be viewed as insufficient; the direction of travel favours documented, ongoing third‑party risk assessment spain across the counterparty lifecycle.

Common pitfalls and red flags, triggers, remediation and termination

Most third‑party failures trace back to a small set of recurring red flags. Treat the following as warning signs demanding heightened scrutiny or, in serious cases, refusal to onboard:

  • Commission‑only agents with no track record. Success‑fee intermediaries lacking demonstrable capability or history.
  • Opaque or shifting ownership. Refusal or inability to identify the ultimate beneficial owner.
  • Payments to third‑country shell companies. Requests to route funds through unrelated jurisdictions or entities.
  • Refusal to provide documents. Resistance to standard KYC or questionnaire requests.
  • Adverse media. Credible reports of corruption, fraud or sanctions breaches.
  • PEP involvement. Politically exposed persons among owners or decision‑makers.
  • Sanctioned or high‑risk jurisdictions. Nexus to sanctioned parties or high‑corruption countries.
  • Unusual payment structures. Over‑invoicing, cash demands, or vague “consultancy” fees.

Common process errors compound these: onboarding before diligence completes, failing to document the decision rationale, and neglecting to re‑screen after onboarding. Where a red flag materialises post‑contract, available remedies include suspension of payments, exercising audit rights, withholding or escrow of sums, mandatory remediation, and ultimately termination for cause under the anti‑bribery clause. If findings suggest suspected criminal conduct, coordinate with legal counsel on internal escalation and any decision to report to the authorities, and, where the entity is an obliged party under Ley 10/2010, on any suspicious‑activity reporting to the SEPBLAC (the Spanish financial intelligence unit).

Conclusion

Robust third party due diligence spain is now inseparable from a credible corporate compliance programme. By running a documented, risk‑based process, scoping, screening, verifying ownership, scoring risk, allocating contractual protections and monitoring continuously, compliance officers create both a genuine control and the evidential record that Article 31 bis and prosecutorial practice reward. As enforcement expectations and monitoring technology advance through 2026, the organisations that fare best will be those treating third‑party review as an ongoing, defensible lifecycle rather than a one‑off gate. Use the checklist, timelines and templates in this guide as the operational backbone of that programme, and reserve enhanced diligence and external counsel for the relationships that genuinely demand them.

For the underlying framework, see the Global Law Experts primer on Spanish corporate criminal compliance (2026). To standardise your process, request the Third‑Party Due Diligence Questionnaire & Template (Spain).

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.

Sources

  1. Código Penal (Spanish Penal Code), consolidated text (BOE)
  2. Ley 10/2010, de prevención del blanqueo de capitales y de la financiación del terrorismo (consolidated, BOE)
  3. Ley Orgánica 3/2018, de Protección de Datos Personales y garantía de los derechos digitales (BOE)
  4. Reglamento (UE) 2016/679 (GDPR), EUR‑Lex
  5. Agencia Española de Protección de Datos (AEPD)
  6. Fiscalía General del Estado (FGE)
  7. SEPBLAC, Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales
  8. OECD, Anti‑Bribery Convention & good practice guidance
  9. Colegio de Registradores (Registro Mercantil)
  10. Comisión Nacional del Mercado de Valores (CNMV)
  11. European Commission

FAQs

How do you perform third party due diligence spain step‑by‑step?
Follow the twelve‑step process above: intake and scoping, data collection, KYC, sanctions and PEP screening, financial and reputation checks, beneficial‑owner analysis, enhanced diligence where triggered, risk scoring and decision, contractual protection, approval, ongoing monitoring and record retention. Low‑risk reviews typically complete in 1–2 weeks; high‑risk EDD in 2–6 weeks.
Request a recent Registro Mercantil extract, company statutes, a UBO declaration, identity documents for principals, tax and VAT registration, financial statements, references, and evidence of the party’s own anti‑bribery controls. Cross‑check ownership against the Registro Central de Titularidades Reales. See the Required documents table for the full list and handling notes.
Set SLAs by tier: around 10 working days for low‑risk onboarding, 15–20 days for medium risk, and up to 30 days where enhanced due diligence applies. Assign a remediation owner promptly after any adverse finding to avoid stalled files.
Commission‑only agents, opaque ownership, payments to third‑country shells, PEP involvement, sanctioned jurisdictions, adverse media and refusal to provide documents all warrant EDD. Where credible evidence of bribery emerges, remedies escalate from payment suspension and audit through to termination for cause and, where warranted, reporting to the competent authorities.
Yes, provided you rely on a valid lawful basis, typically contractual necessity, legal obligation, legitimate interest or, where appropriate, consent. Follow AEPD guidance and Ley Orgánica 3/2018, apply data minimisation, retain only what is necessary for the retention period, and document your basis. Building this into the due‑diligence questionnaire keeps third party KYC spain compliant with the GDPR.
Frequency should follow the risk tier: high‑risk parties should be subject to continuous monitoring with frequent re‑screening, medium‑risk parties reviewed on a regular (for example quarterly or semi‑annual) basis, and low‑risk parties at least annually. Continuous sanctions and negative‑media monitoring is the recommended default for high‑risk relationships.
pt pma indonesia
By Jonathon Richards

posted 37 minutes ago

aml due diligence germany
By Global Law Experts

posted 2 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Conduct Third‑party Due Diligence in Spain: Step‑by‑step Guide for Compliance Officers

Send welcome message

Custom Message