Our Expert in Spain
No results available
Who this guide is for: in-house counsel, compliance officers, COOs, CFOs, audit committees and boards in Spanish companies assessing UNE 19601 alignment or certification to secure mitigation under Article 31 bis of the Spanish Criminal Code.
What you will get: a plain-language explanation of UNE 19601 requirements, the certification options available, how prosecutors and courts treat standards-based evidence, an audit and evidence checklist, and practical next steps.
UNE 19601 compliance Spain has moved from a niche governance topic to a board-level priority in 2026, as Spanish corporates increasingly formalise their criminal-risk prevention models to evidence “due control” and negotiate mitigation in criminal proceedings. The practical driver is straightforward: when a company faces a corporate criminal liability investigation, a documented, audited and independently validated compliance management system is one of the most persuasive ways to demonstrate that the organisation took genuine steps to prevent offences. Over the past several years, the trend has accelerated, with more organisations aligning their models to UNE 19601 and, in many cases, pursuing formal certification.
The short answer to the question most boards are asking is yes, a well-implemented UNE 19601 programme can materially support mitigation, and in some circumstances the exclusion of liability, under Article 31 bis. This guide explains what the standard requires, whether certification is mandatory, how prosecutors and courts weigh the evidence, and exactly what documentation you need to have in place.
For readers who already understand the criminal-liability framework, the deeper value of UNE 19601 compliance Spain lies in the evidence trail it produces. Courts and the public prosecutor do not reward good intentions; they scrutinise dated, verifiable records that show a functioning system. If you are building or reviewing that evidence trail, our companion resource on how to Prove compliance programme Spain, evidence checklist pairs directly with the standard-level guidance below.
UNE 19601 is the Spanish national standard for criminal compliance management systems. UNE standards in Spain are published by the Spanish Association for Standardisation (UNE, formerly known as AENOR), which develops and issues them, with certification services in this field offered by AENOR. The standard specifies the requirements and provides guidance for establishing, implementing, maintaining and continually improving a management system designed to prevent the commission of criminal offences within an organisation and to reduce the associated criminal risk. Crucially, the standard was written with the Spanish legal context in mind, it is expressly framed around the concept of an organisational model of prevention that mirrors the requirements the Criminal Code sets out for corporate liability.
That native alignment with domestic law is what distinguishes UNE 19601 from purely international frameworks and explains why it has become a reference point for practitioners advising Spanish boards.
The standard is designed to be applicable to organisations of all sizes and sectors, whether public or private. Its scope covers the full lifecycle of a criminal-compliance programme: identifying the offences to which the organisation is exposed, assessing and evaluating criminal risk, designing controls proportionate to that risk, and building the governance, reporting and monitoring architecture needed to keep the system effective over time. Rather than prescribing a rigid list of measures, UNE 19601 sets out a risk-based framework, allowing each organisation to tailor its controls to its own risk profile.
This flexibility is deliberate: a construction group, a financial institution and a technology start-up face very different criminal-risk exposures, and the standard expects each to justify its choices by reference to a documented risk assessment. The intended use, in practice, is twofold, to genuinely reduce the likelihood of offences occurring, and to generate the documentary evidence that demonstrates the organisation exercised due control.
UNE 19601 follows the high-level structure common to modern management-system standards, which makes it straightforward to integrate with other systems an organisation may already operate, such as quality or anti-bribery management. A compliance management system built to the standard rests on several pillars: leadership and governance, including the role of a compliance body or officer with sufficient autonomy and resources; planning that flows from a criminal-risk assessment; operational controls embedded into business processes; support functions such as training, communication and documented information; and performance evaluation through monitoring, internal audit and management review. This continuous-improvement cycle, plan, do, check, act, is not window dressing.
It is precisely the operational discipline that a prosecutor or court will look for when deciding whether a compliance management system in Spain was real and functioning rather than a paper exercise. Understanding how UNE 19601 fits within an overall compliance management system is therefore the foundation for everything that follows.
No. UNE 19601 certification is voluntary. There is no statutory requirement compelling any Spanish company to certify, or even to align, with the standard. The Criminal Code does not mandate a specific standard; it describes the characteristics an effective prevention model must display, and organisations are free to demonstrate compliance in whatever way they choose. That said, the absence of a legal obligation should not be mistaken for the absence of pressure. In practice, a significant and growing number of Spanish organisations treat UNE 19601 alignment as a de facto expectation, driven by commercial, contractual and reputational forces rather than by statute.
Several situations turn a voluntary standard into a practical necessity. Public-sector procurement is a common trigger: contracting authorities and large private buyers increasingly require evidence of a robust criminal-compliance programme, and certification provides an efficient, independently verified way to satisfy that requirement. Supply-chain due diligence has the same effect, a certified counterparty is easier to onboard and reassures customers concerned about their own liability exposure. Sectors with heightened regulatory scrutiny, such as finance, construction, pharmaceuticals and energy, often treat certification as a baseline expectation. Group companies operating across borders may also adopt UNE 19601 to give their Spanish operations a recognised local anchor.
In each of these cases, the decision is commercial, but the outcome is the same: certification, while never legally compulsory, becomes something a company may find difficult to operate without. For boards weighing the investment, the question is rarely whether the standard is mandatory and more often whether the market they serve will tolerate its absence.
The value of UNE 19601 compliance Spain to a criminal defence lies in the specific controls the standard requires, each of which maps to an element that prosecutors and courts examine when assessing corporate criminal liability. The following breakdown highlights the clauses that generate the most persuasive evidence.
The starting point of any credible programme is a documented criminal-risk assessment that identifies the offences to which the organisation is realistically exposed, evaluates the likelihood and impact of each, and prioritises controls accordingly. UNE 19601 expects this assessment to be systematic, evidence-based and periodically updated. For prosecutors, a dated and reasoned risk map is often the single most telling document: it shows whether the company genuinely understood its exposure or simply copied a generic template. Evidence examples include the risk-assessment methodology, the risk register with owners and residual-risk ratings, and records showing when the assessment was last reviewed and why.
The standard requires clear, accessible policies and procedures that translate risk findings into concrete rules of conduct. These typically include a criminal-compliance policy approved at the highest level, a code of conduct, and detailed procedures covering high-risk activities such as gifts and hospitality, procurement, and interactions with public officials. What matters evidentially is not merely the existence of these documents but proof that they were formally approved, communicated and kept current. Evidence examples include board or governing-body minutes approving the policy, version-controlled procedure documents, and distribution records confirming employees received them.
A programme is only as strong as employees’ awareness of it. UNE 19601 requires training tailored to roles and risk exposure, together with ongoing communication that reinforces expected behaviour. Prosecutors frequently probe whether staff in high-risk functions actually received relevant, current training. Evidence examples include attendance logs, completion certificates, training content dated to the relevant period, and records of refresher sessions.
An effective, confidential internal reporting channel is central to the standard and to demonstrating due control. It also intersects with Law 2/2023 of 20 February on the protection of persons who report regulatory infringements and the fight against corruption, which transposed the EU Whistleblower Directive and requires many organisations in Spain to operate an internal reporting system with defined guarantees. The system must allow concerns to be raised without fear of retaliation, ensure they are investigated, and record the outcome. Courts view a functioning whistleblowing channel, with evidence that reports were received and acted upon, as strong proof that the system operated in reality.
Evidence examples include the channel’s operating procedure, anonymised logs of reports received, and records of the investigations they triggered.
Finally, UNE 19601 requires the organisation to monitor the effectiveness of its controls, conduct internal audits, and feed findings back into the system through management review and corrective action. This is where many programmes fail, controls are designed but never tested. A prosecutor examining a compliance audit in Spain will look for evidence that the company actively supervised its own model. Evidence examples include internal-audit reports, monitoring dashboards or key indicators, corrective-action plans with completion dates, and management-review minutes recording decisions to improve the system.
Achieving certification involves an independent certification body assessing the organisation’s compliance management system against the requirements of UNE 19601. In Spain, AENOR is a well-known certification body offering audits against the standard, and organisations should select a body whose certification is recognised in their market. The process begins with defining the scope of certification, which legal entities, sites and activities are covered, followed by a documentation review and an on-site audit. Multi-site organisations can often be certified under a single scheme covering multiple locations, provided the compliance management system is consistently applied.
Timelines and costs vary considerably with the size and complexity of the organisation; smaller companies may complete the process in a matter of months, while large groups with multiple sites and risk profiles should plan for a longer runway and a correspondingly higher investment.
Auditors do not simply confirm that documents exist; they test whether the system operates as designed. Expect the audit to examine the criminal-risk assessment and its currency, the authority and independence of the compliance function, the adequacy of policies and their communication, the operation of the reporting channel, and, critically, the evidence that controls have been monitored and improved. Auditors will interview staff across functions to verify that the programme is understood and applied, sample records such as training logs and investigation files, and probe whether senior management genuinely owns the system.
A programme that looks complete on paper but cannot show operational evidence will struggle to pass, which is precisely the discipline that makes certification valuable in a criminal-defence context.
Certification is not a one-off event. It is maintained through periodic surveillance audits, during which the certification body checks that the system remains effective and that corrective actions from previous audits have been implemented. This ongoing cycle produces exactly the kind of continuous, dated evidence that supports mitigation: a surveillance-audit report showing the system was reviewed and improved in the period preceding an incident is far more compelling than a certificate issued years earlier and left to lapse.
Article 31 bis of the Spanish Criminal Code establishes the framework for corporate criminal liability and, importantly, provides that liability may be excluded or mitigated where the organisation has adopted and effectively implemented, before the offence was committed, an appropriate model of organisation and management to prevent offences of the type committed or to significantly reduce the risk of their commission. UNE 19601 was designed to help organisations build precisely such a model. The controls described above map directly onto the elements that the Criminal Code contemplates: a risk assessment identifying exposures, controls to manage those risks, resources and a body charged with supervising the model, an appropriate disciplinary system, and mechanisms for reporting and continuous improvement.
Where a company can show that its UNE 19601-aligned system met these elements and was functioning at the relevant time, it strengthens the argument that the organisation exercised due control and that any offence occurred despite, rather than because of, its efforts.
The Fiscalía General del Estado has issued guidance on how corporate compliance programmes should be assessed, emphasising substance over form. Prosecutors are directed to look beyond the existence of a written programme and to evaluate whether it was genuinely implemented, adequately resourced, and capable of detecting and preventing the specific conduct in question. This is where standards-based systems add weight: a UNE 19601-aligned programme, independently audited, provides a structured body of evidence, dated risk maps, board approvals, training records, audit reports and investigation files, that responds directly to prosecutorial expectations. The key point is that certification alone is never conclusive; what persuades a prosecutor is evidence that the certified system actually operated.
A company that treats certification as the finish line rather than the starting point risks holding a certificate that its own records fail to support.
Spanish courts, including the Supreme Court, have developed a body of case law on corporate criminal liability that reinforces the substance-over-form approach. In assessing whether a prevention model justifies mitigation or exclusion of liability, courts examine whether the model was suitable for the risks in question, whether it was effectively implemented and monitored, and whether the offence resulted from a genuine failure of controls or from a deliberate circumvention of an otherwise functioning system. Judgments consistently reward organisations that can demonstrate a living programme with evidence of ongoing supervision, and view unfavourably those whose models existed only on paper.
In practice, this means the value of UNE 19601 compliance Spain to a defence depends less on the certificate itself and more on the contemporaneous evidence trail the standard obliges the company to maintain. Recurring patterns from decided cases point to a consistent theme: organisations with dated, verifiable records of risk assessment, training and monitoring tend to fare markedly better than those relying on generic documentation produced after the fact.
Boards frequently ask how UNE 19601 compares with the international ISO standards. The three serve overlapping but distinct purposes, and the right choice depends on your risk profile, stakeholders and geographic footprint. UNE 19601 is a Spain-specific criminal-compliance standard; ISO 37301 is an international compliance management systems standard with a broader, cross-cutting focus; and ISO 37001 is an international anti-bribery management systems standard focused specifically on bribery prevention. The table below summarises the key differences.
| Feature | UNE 19601 | ISO 37301 | ISO 37001 |
|---|---|---|---|
| Primary focus | Criminal-compliance management systems framed around Spanish corporate criminal liability | General compliance management systems across all obligations | Anti-bribery management systems |
| Certification availability in Spain | Available through certification bodies such as AENOR | Available internationally and in Spain | Available internationally and in Spain |
| Consistency with Article 31 bis mitigation evidence | High, designed to align with the Criminal Code’s prevention-model requirements | Moderate, supports compliance broadly but not framed to Spanish criminal law | Moderate, strong for bribery risk, narrower on other offences |
| Best for bribery controls | Covers bribery within a wider criminal-risk scope | Covers bribery as one of many obligations | Strongest, dedicated anti-bribery focus |
| Typical users | Spanish companies prioritising criminal-liability mitigation | International organisations seeking a broad compliance framework | Organisations with significant bribery exposure or cross-border corruption risk |
For a company operating primarily in Spain whose main concern is reducing corporate criminal liability, UNE 19601 is usually the natural anchor because it is framed directly around the domestic legal test. Multinationals may prefer to build their global system to ISO 37301 for consistency across jurisdictions, then align their Spanish operations to UNE 19601 to secure the local criminal-law framing. Organisations with acute bribery and corruption exposure, for example those bidding on international public contracts, often add ISO 37001 for its dedicated anti-bribery controls.
These standards are not mutually exclusive; because they share a common management-system structure, many organisations integrate two or all three, using UNE 19601 as the criminal-compliance backbone in Spain while layering international standards on top for cross-border credibility.
The following checklist groups the documentary evidence a company should maintain, organised by control family. For each item, keep the evidence dated, version-controlled and assigned to an owner. A well-organised compliance audit in Spain will draw on exactly these records.
A realistic implementation or upgrade of a UNE 19601 programme typically spans six to nine months, depending on the organisation’s size and maturity. A workable sequence is as follows: in the first two months, conduct a gap analysis against the standard and refresh the criminal-risk assessment; in months two to four, design or revise policies, procedures and the reporting channel, and secure formal board approval; in months four to six, roll out training and embed operational controls; and in the final months, run an internal audit, remediate findings, and, if pursuing certification, engage a certification body for the external audit. The threshold decision is whether to certify or to align without certification.
Alignment-only may suffice for organisations whose stakeholders do not demand a certificate, but certification adds independent validation that can carry weight in procurement and, potentially, before a court. Internal resourcing is critical: the compliance function must have genuine autonomy and budget, and boards should engage external legal counsel and auditors early, particularly to validate that the model meets the Article 31 bis requirements rather than merely the standard’s clauses.
UNE 19601 compliance Spain has become a practical priority for organisations that want to defend themselves effectively against corporate criminal liability in 2026. The standard’s real value lies not in the certificate but in the disciplined, dated evidence trail it obliges a company to maintain, the risk assessments, board approvals, training logs, investigation files and audit reports that prosecutors and courts examine when applying Article 31 bis. Whether you pursue full certification or alignment-only, the priority is a living system that can prove it functioned when it mattered. Boards and in-house counsel evaluating their position should begin with a gap analysis and a certification-readiness review to identify where their evidence is strong and where it needs reinforcement.
For a compliance gap analysis or certification-readiness review, contact Jordi Sot Ball-Llosera, GLE Spain compliance expert profile through Global Law Experts.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jordi Sot Ball-Llosera at Toda & Nel-lo, a member of the Global Law Experts network.
posted 51 seconds ago
posted 22 minutes ago
posted 42 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message