Corporate Compliance in Spain

Implement a corporate compliance program in Spain (cumplimiento normativo) and reduce legal, criminal and reputational risk without slowing down growth. Risk map, code of ethics, whistleblowing channel, training and audit.

100% Free

Need to implement compliance? Free legal assessment

Tell us your situation and we'll tell you which controls you need to put in place.

+50 companies advised24h responseNo obligation

Compliance tailored to each company

Scaling fintechs, fund managers, regulated firms or fast-growing companies: each profile has different risks, controls and evidence.

Fintech / Scale-up

From scattered procedures to traceable controls

"We standardized policies, evidence and owners. The team went from 'firefighting' to running an orderly, auditable system."

Asset manager / Funds

Support with reviews and information requests

"We prepared the documentation and internal workflows. Response times went down and review criteria became more consistent."

Regulated company

Practical, role-based training

"Sessions with real cases and checklists. Fewer operational doubts and a team better able to spot risk signals."

Compliance

Continuous improvement: gaps → roadmap

"We identified quick wins and prioritized risks. Senior management got a phased plan with milestones, owners and evidence."

What are the risks of non-compliance?

Without a compliance program, a company is exposed to sanctions, criminal liability, lost business and reputational damage.

Administrative fines and sanctions for regulatory breaches, depending on the sector and the applicable rules.

Corporate criminal liability: fines, disqualifications, suspension of activities or court-ordered measures (Article 31 bis of the Spanish Criminal Code).

Loss of contracts, public tenders and business opportunities due to a lack of controls and evidence of compliance.

Criminal Codeup to 5 years of day-fines

Dissolution, suspension of activities or a ban on contracting with the public sector. An effective program can exempt the company or mitigate its liability.

InvestigationsHigh costs

Costly internal investigations, employment disputes and loss of talent when there are no protocols and no whistleblowing channel.

ReputationLoss of trust

Reputational damage and loss of trust among clients, partners, investors and financial institutions.

Want to implement corporate compliance with confidence?

Find the compliance plan that fits your size, sector and risk level. Risk map, policies, whistleblowing channel, training and audit.

Corporate compliance in Spain: common questions

What is corporate compliance?

Corporate compliance is the set of policies, procedures and controls a company uses to comply with the law, prevent breaches and demonstrate due diligence to third parties.

The goal is prevention and evidence: clear policies, workable procedures and controls that are actually carried out. A good starting point is an assessment and a risk map with an action plan.

Who needs a compliance program in Spain?

Any company benefits, especially if it operates in regulated sectors, contracts with the public sector, is growing fast, is raising investment or has complex supply chains.

For regulated firms (financial institutions, fintechs, fund managers), compliance is not optional: it is a condition for authorization and supervision.

What do a code of ethics and internal policies include?

The code of ethics sets the standard of conduct. It must be backed by specific policies:

  • Anti-corruption and conflicts of interest.
  • Gifts, hospitality and sponsorships.
  • Competition and dealings with third parties.
  • Expense controls and approvals.

Policies should be short and clear, with examples and approval workflows. If people don't understand them, they don't protect you.

How does a whistleblowing channel work?

A whistleblowing channel (canal de denuncias) lets you detect issues early. It must come with a management protocol: receipt, admission, investigation, measures and closure, with traceability.

A good design protects confidentiality, reduces internal conflict and improves your ability to respond to criminal or regulatory risks.

What is third-party due diligence?

Many risks come in through third parties: intermediaries, consultants, partners or critical suppliers. A robust system includes:

  • Third-party risk assessment.
  • Compliance clauses in contracts.
  • Validation of payments and services rendered.
  • Periodic monitoring and renewal.
What is the role of the Compliance Officer?

The Compliance Officer coordinates policies, training, the whistleblowing channel, controls and audits. The role needs autonomy, resources and a clear reporting line to the board of directors.

The Compliance Officer must report using indicators: training, incidents, third parties reviewed, audits and corrective actions. Without reporting, compliance loses its effectiveness.

How do you train your team in compliance?

Training must be practical, role-based and focused on real situations. Training senior management is not the same as training sales, procurement or finance.

  • Initial training + periodic refreshers.
  • Micro-cases and checklists for day-to-day work.
  • Attendance records and assessment (evidence).
  • "Tone from the top": messages from leadership.
What are the consequences of non-compliance?

Non-compliance can lead to administrative sanctions, criminal risk for the company as a legal entity, lost contracts and reputational damage.

  • Fines and court-ordered measures (Article 31 bis of the Criminal Code).
  • Loss of public tenders and financing.
  • Internal investigations and legal costs.
  • Broken trust with clients and investors.

A well-implemented compliance program reduces the likelihood of incidents and strengthens your position in inspections and investment processes.

A Practical Guide to Corporate Compliance

A compliance program is not "paperwork": it is a system of workable controls that your team can carry out and that leave evidence. The key is a risk-based approach.

Prevention

What compliance aims to achieve

Reducing legal, criminal and reputational risks through clear internal policies, consistent criteria and traceability. A good program protects your operations, reputation and business relationships.

Controls

Minimum required controls

Risk map, code of ethics, anti-corruption and third-party policies, whistleblowing channel, role-based training, internal controls and reporting to the board of directors.

Evidence

What makes the difference

Having a manual is not enough: you have to prove it is applied. Records, approvals, audits, training with evidence and corrective actions closed.

8-step corporate compliance checklist

  1. Assessment and risk map: legal, criminal and regulatory risks based on your activity and sector.
  2. Code of ethics and internal policies: anti-corruption, competition, conflicts of interest, third parties and expenses.
  3. Whistleblowing channel: set-up, management protocol and internal investigations with traceability.
  4. Third-party due diligence: assessment, clauses, payment validation and periodic monitoring.
  5. Role-based training: senior management, sales, procurement, finance and HR, with evidence.
  6. Internal controls: third-party validation, payment controls, approvals and incident monitoring.
  7. Compliance Officer and governance: roles, RACI, KPI-based reporting and a reporting line to the board of directors.
  8. Audit and continuous improvement: periodic reviews, corrective actions and updates whenever things change.

If you need to implement compliance in practice, see our corporate compliance services or request the external expert report.

Compliance Playbook

Corporate Compliance in Practice

Pillar
What is expected
Typical evidence

Risk map

Identify real risks by activity, sector, clients, third parties and sales channel.

Risk matrix, action plan, owners and review schedule.

Code of ethics + policies

Standards of conduct and clear policies with workable approval workflows.

Versioned code, signed policies, acknowledgments of receipt and periodic reviews.

Whistleblowing channel

Early detection with a protocol: receipt, investigation, measures and closure.

Log of reports, investigations, resolutions and channel metrics.

Third-party due diligence

Assess risk, include clauses, validate payments and monitor on an ongoing basis.

Assessment forms, contracts with clauses, validations and renewals.

Training + audit

Role-based training and periodic reviews to measure effectiveness and close gaps.

Training records, audit reports, KPIs and remediation plan.

Typical compliance red flags

Indicators that increase the company's legal and reputational exposure.

  • No risk map or no up-to-date compliance assessment.
  • A generic code of ethics that is not applied in real operations.
  • A whistleblowing channel with no management protocol or no real use.
  • Third parties and intermediaries with no risk assessment and no compliance clauses.
  • "One-off" training with no refreshers, no evidence and no adaptation to each role.
Operational glossary

Key Concepts in Corporate Compliance

If you are implementing corporate compliance, these terms come up in audits, in dealings with regulators and in day-to-day operations.

ComplianceBasics

Regulatory compliance

A system of policies, procedures and controls to comply with the law, prevent breaches and demonstrate due diligence to third parties.

Useful for: program design, audit, training.
Art. 31 bis Criminal CodeCriminal

Corporate criminal liability

A company can be held criminally liable. An effective compliance program can exempt it from that liability or mitigate it.

Key: adequacy + effectiveness + evidence.
Risk mapAssessment

Risk identification and assessment

A matrix that identifies legal, criminal and regulatory risks by activity, sector and operations, with proportionate controls.

Evidence: matrix + action plan + review.
Whistleblowing channelDetection

Whistleblowing

A mechanism that allows employees and third parties to report wrongdoing confidentially, with a management and investigation protocol.

Mandatory: Law 2/2023 on whistleblower protection.
Due diligenceThird parties

Third-party assessment

The process of vetting suppliers, intermediaries and partners to detect compliance risks before signing with them.

Evidence: assessment form + clauses + monitoring.
Compliance OfficerGovernance

Head of compliance

The person who coordinates, supervises and follows up on the compliance program. The role needs autonomy, resources and a clear reporting line.

Key: independence + reporting + KPIs.
Tone from the topCulture

Management commitment

Leadership must show its commitment to compliance through actions: communication, resources, example and consequences.

Without tone from the top, the program loses credibility.
Anti-corruptionPolicy

Bribery and corruption prevention

A policy that prohibits improper payments, excessive gifts and facilitation payments, and sets approval and recording controls.

E.g.: gifts, sponsorships, donations, intermediaries.
Continuous improvementAudit

Program review and update

Internal audits, gap detection, corrective actions and updates whenever the business or the regulations change.

Outcome: report + remediation plan.
📥 Free download

Corporate Compliance Checklist in 8 steps

The operational guide we use with our clients to implement an adequate and effective compliance program under Article 31 bis of the Spanish Criminal Code, aligned with UNE 19601 and ISO 37301.

  • 8 actionable steps (risk map, code of ethics, whistleblowing channel, due diligence...)
  • The evidence and documentation that inspectors and judges expect
  • Tailored to fintechs, fund managers and regulated companies
✓

Done! Your checklist is downloading

If the download hasn't started, click the button. Have a specific question? Diego replies on WhatsApp.

Book a call

Tell us your situation and we'll explain how to implement a compliance program tailored to your company.

Corporate Compliance in Spain: Legal Framework and Criminal Liability

Corporate compliance in Spain rests on the reform of the Spanish Criminal Code (Organic Law 1/2015), which regulates the criminal liability of legal entities (Article 31 bis) and the possibility of exemption or mitigation through an effective compliance program. This framework is complemented by Law 2/2023 on whistleblower protection, which requires companies to have a whistleblowing channel, and by sector-specific regulations.

Corporate criminal liability in Spain

Since the 2015 reform, companies can be convicted of offenses committed by their representatives, directors or employees if adequate controls were not in place. An adequate and effective compliance program can fully exempt the company from criminal liability or significantly mitigate it. Circular 1/2016 of the Spanish Attorney General's Office (Fiscalía General del Estado) and the case law of the Supreme Court set out the assessment criteria.

Mandatory whistleblowing channel

Law 2/2023 requires companies with 50 or more employees (and certain sectors regardless of headcount) to have an internal reporting system (whistleblowing channel) with guarantees of confidentiality, protection against retaliation and documented handling of the reports received.

Compliance as a competitive advantage

Beyond crime prevention, a mature compliance program strengthens the company's position in public tenders, investor due diligence processes and relationships with banks and partners, and demonstrates sound corporate governance to clients and regulators.

Art. 31 bis Criminal CodeOrganic Law 1/2015Law 2/2023Attorney General Circular 1/2016UNE 19601ISO 37001ISO 37301