From box-ticking to auditable evidence
“We turn policies and manuals into controls that actually run: sampling, traceability and a remediation plan with deadlines.”
Your annual AML external expert report in Spain: an independent AML/CFT review under Article 28 of Law 10/2010 and Royal Decree 304/2014. We assess the operational effectiveness of your system (not just the paperwork), identify gaps and leave you with a corrective action plan you can defend before SEPBLAC and your internal control body (OCI).
“We turn policies and manuals into controls that actually run: sampling, traceability and a remediation plan with deadlines.”
“We deliver a report you can actually use: what fails, why it fails, the risk it creates and how to close it with evidence.”
“We review document completeness, beneficial ownership (UBO) and record-keeping: the report must withstand an information request.”
“We test risk scenarios to check whether the software raises the right alerts and whether their handling is properly recorded.”
An annual, independent review of the internal control system: operational effectiveness, evidence and proposals for improvement.
It is a thorough, independent and documented review of the entity’s anti-money laundering policies, procedures and internal controls.
Sample-based review of customer files: formal identification, UBO/beneficial owner, profile, risk and record-keeping.
Financial institutions such as banks and insurers. Professionals and advisers such as auditors and external accountants. High-risk sectors and other obliged entities.
Review of content and evidence: up-to-date, role-specific training with a verifiable record.
Prioritized findings + a plan with a timeline: owners, evidence and follow-up to close the gaps.
This is a recurring obligation: the review must be carried out at least once a year. To be covered if an information request arrives, “having a PDF” is not enough. You must be able to show the reference date, the issue date, submission to the board, the corrective action plan and a file backed by evidence.
Annual (at a minimum): every year, it reviews the internal control system, its operational effectiveness and its gaps.
Internal escalation: material deficiencies are reported to the board/OCI, with actions and owners.
Remediation plan: a realistic, verifiable timeline (when issues cannot be fixed “on the spot”).
Record-keeping: add the report and its evidence to your records (KYC/UBO, alerts, training) with a long retention horizon.
Follow-up report: possible in years 2 and 3, where appropriate and if there are no substantial changes.
To act as an external expert, you must have notified SEPBLAC (Spain’s Financial Intelligence Unit) of your intention to do so before starting the activity. At Molina Law Boutique we are registered with SEPBLAC as external experts.
Our review covers the three mandatory areas set out in the regulations implementing Law 10/2010. We audit both physical documentation and digital traceability.
We audit document retention over the 10-year statutory period. We check the completeness of copies of formal identification documents and beneficial ownership declarations across a random sample of customers.
We put your monitoring tool to the test. We simulate risk scenarios to check whether the software generates the right automated alerts and whether they are handled as promptly as SEPBLAC requires.
We review attendance certificates and the content of the courses given to employees. The external expert must confirm that training is up to date and specific to each job role, not generic.
Under certain conditions, Law 10/2010 allows the full audit to be replaced by a follow-up report in the two following years. Understanding this difference keeps costs down without lowering the level of evidence.
| Feature | Full report (standard) | Follow-up report |
|---|---|---|
| When is it due? | First year, or after substantial changes to the control structure. | Years 2 and 3 (if there are no material changes). |
| Scope | Comprehensive audit of all internal control measures and bodies (OCI). | Verification only of the corrective measures previously proposed. |
| Legal basis | Art. 28.1 Law 10/2010 | Art. 28.1 (second paragraph) Law 10/2010 |
| Objective | Identify risks and assess overall operational effectiveness. | Check whether the deficiencies identified have been remedied. |
*Order EHA/2444/2007 sets out technical criteria to determine whether a change requires a return to the full report before the 3 years are up.
We strictly follow Order EHA/2444/2007, using an agile methodology designed not to disrupt your day-to-day operations.
We request and review your Anti-Money Laundering Manual, your customer acceptance policies and the minutes of the internal control body (OCI) to check that, on paper, they comply with the law.
We take a random sample of customer files to audit the correct application of customer due diligence (KYC) measures and document retention under Article 25 of Law 10/2010.
Before closing, we issue a draft setting out the deficiencies found. This lets you implement immediate corrective measures, which will be reflected positively in the final assessment.
Delivery of the digitally signed final report, ready to be made available to SEPBLAC. We include practical recommendations and a roadmap for the next annual review.
If the report has to “hold up” under review, what makes the difference is evidence: tests, sampling, dates and a documented remediation plan.
Make clear which date “closes” the review period (so the report is not outdated or inconsistent).
Document what was tested, what the results were and what issues were found. Avoid a purely “declarative” report.
State the size and criteria: customer types, products, periods and % reviewed. If statistical sampling is used, define the population, method, confidence level and error analysis.
If some deficiencies cannot be fixed immediately, have a plan with a precise timeline formally approved.
KYC, beneficial ownership, analyses performed and supporting documents: ready to hand over quickly if an information request arrives.
The purpose of the external expert report is not just to tick a box, but to identify and remedy operational deficiencies that SEPBLAC treats as serious infringements.
Having a generic manual that is not applied in practice. The law requires real operational effectiveness, not just effectiveness on paper.
Collecting ID documents is not enough. The notarial beneficial ownership deed (acta de titularidad real) is missing, or there are errors in complex corporate structures.
Article 29 requires ongoing training. A typical mistake: generic courses that ignore sector-specific risks (real estate, crypto, jewelry, etc.).
Failing to apply enhanced measures to high-risk customers (PEPs or high-risk jurisdictions). This is penalized as a failure of customer due diligence.
Beyond the “document” itself, what matters in an inspection is traceability: deadlines, tests, sampling and a remediation plan.
Key to avoiding “formal compliance without operational effectiveness”.
If the report does not explain “how” the review was done (and with what sample), that is usually the first weak point when an information request arrives.
Reduces sanction and reputational risk in inspections.
What “adds up” in an inspection is consistency between risk, control and evidence.
To avoid inconsistencies, align your record-keeping policy with your internal control system: keep the report and its evidence together with your KYC/UBO files, alerts and training records.
Serious infringement: failing to carry out the annual external review when it applies.
Significant fines: starting at high amounts and potentially rising with net worth/turnover.
Reputational risk: information requests, inspections and loss of trust from banks, clients and investors.
Operational roadblocks: friction in onboarding and with suppliers, bank accounts and audits.
Reaction costs: fixing things late usually costs more than implementing and documenting them properly in time.
We help you produce a complete, rigorous, evidence-based report: sampling, findings, corrections and documentation ready for any information request.
The AML/CFT external expert report is an independent audit of the internal anti-money laundering control system. Its purpose is to assess the system’s operational effectiveness, identify deficiencies and propose corrections or improvements.
It must be kept available to SEPBLAC and to the entity’s internal control body (OCI).
It is not a mere “formality”: it is a key defensive document for information requests, inspections and access to banking.
As a general rule, it is a recurring obligation that applies every year (at a minimum). In certain cases, it can be replaced by a follow-up report in the two following years if there are no material changes.
What matters is keeping the annual cycle going and staying consistent across reference date, tests, issue date and corrective measures.
Mainly Law 10/2010 (Article 28) and its implementing regulation, Royal Decree 304/2014. The technical and independence criteria are set out in specific rules, including Order EHA/2444/2007.
The key: an independent review, traceable tests, conclusions and an improvement plan.
A full review of the system: AML/CFT manual, OCI, identification (KYC), beneficial owner (UBO), transaction monitoring, alerts, training (Art. 29), record-keeping and risk assessment.
It ensures strict compliance with Law 10/2010 and its AML implementing regulation. It identifies weaknesses in your internal control systems before they create greater risks, and it strengthens your credibility with authorities, clients and strategic partners.
It provides a formal report that demonstrates the company’s proactive accountability, along with concrete measures to improve procedures and reduce risk.
To speed things up: your current manual, OCI minutes/structure, risk assessment, customer acceptance policy, KYC/UBO files, alert/monitoring logs, training records and evidence of previous corrective measures.
If everything is in order, sampling is more efficient and the report is of higher quality.
You risk penalties, information requests and reputational damage, as well as friction with banks, investors and partners.
Prevention is far cheaper than fixing things against the clock.
It depends on your size, sector, number of customer files and the complexity of your operations. The decisive factors are the actual scope of the sampling and the evidence available.
We give you a tailored quote after a quick assessment of your risk and documentation.