From scattered procedures to traceable controls
"We standardized policies, evidence and owners. The team went from 'firefighting' to running an orderly, auditable system."
Implement a corporate compliance program in Spain (cumplimiento normativo) and reduce legal, criminal and reputational risk without slowing down growth. Risk map, code of ethics, whistleblowing channel, training and audit.
Need to implement compliance? Free legal assessment
Tell us your situation and we'll tell you which controls you need to put in place.
Six elements to build a compliance program that is workable, auditable and proportionate to your risk.
Identification of legal, criminal and regulatory risks based on your activity, sector and operations. The starting point of any compliance program.
Criminal risk map, crime prevention protocol and a program to exempt the company from, or mitigate, its corporate criminal liability.
Code of conduct and policies on anti-corruption, conflicts of interest, gifts, competition and third parties, plus expense controls.
A channel with a management protocol: receipt, admission, investigation, measures and closure, with traceability and confidentiality.
Risk assessment of suppliers and intermediaries, contractual clauses, payment validation and periodic monitoring.
Controls performed, approvals recorded, periodic audits, corrective actions closed and reporting to the board of directors.
Scaling fintechs, fund managers, regulated firms or fast-growing companies: each profile has different risks, controls and evidence.
"We standardized policies, evidence and owners. The team went from 'firefighting' to running an orderly, auditable system."
"We prepared the documentation and internal workflows. Response times went down and review criteria became more consistent."
"Sessions with real cases and checklists. Fewer operational doubts and a team better able to spot risk signals."
"We identified quick wins and prioritized risks. Senior management got a phased plan with milestones, owners and evidence."
Without a compliance program, a company is exposed to sanctions, criminal liability, lost business and reputational damage.
Administrative fines and sanctions for regulatory breaches, depending on the sector and the applicable rules.
Corporate criminal liability: fines, disqualifications, suspension of activities or court-ordered measures (Article 31 bis of the Spanish Criminal Code).
Loss of contracts, public tenders and business opportunities due to a lack of controls and evidence of compliance.
Dissolution, suspension of activities or a ban on contracting with the public sector. An effective program can exempt the company or mitigate its liability.
Costly internal investigations, employment disputes and loss of talent when there are no protocols and no whistleblowing channel.
Reputational damage and loss of trust among clients, partners, investors and financial institutions.
Find the compliance plan that fits your size, sector and risk level. Risk map, policies, whistleblowing channel, training and audit.
Corporate compliance is the set of policies, procedures and controls a company uses to comply with the law, prevent breaches and demonstrate due diligence to third parties.
The goal is prevention and evidence: clear policies, workable procedures and controls that are actually carried out. A good starting point is an assessment and a risk map with an action plan.
Any company benefits, especially if it operates in regulated sectors, contracts with the public sector, is growing fast, is raising investment or has complex supply chains.
For regulated firms (financial institutions, fintechs, fund managers), compliance is not optional: it is a condition for authorization and supervision.
The code of ethics sets the standard of conduct. It must be backed by specific policies:
Policies should be short and clear, with examples and approval workflows. If people don't understand them, they don't protect you.
A whistleblowing channel (canal de denuncias) lets you detect issues early. It must come with a management protocol: receipt, admission, investigation, measures and closure, with traceability.
A good design protects confidentiality, reduces internal conflict and improves your ability to respond to criminal or regulatory risks.
Many risks come in through third parties: intermediaries, consultants, partners or critical suppliers. A robust system includes:
The Compliance Officer coordinates policies, training, the whistleblowing channel, controls and audits. The role needs autonomy, resources and a clear reporting line to the board of directors.
The Compliance Officer must report using indicators: training, incidents, third parties reviewed, audits and corrective actions. Without reporting, compliance loses its effectiveness.
Training must be practical, role-based and focused on real situations. Training senior management is not the same as training sales, procurement or finance.
Non-compliance can lead to administrative sanctions, criminal risk for the company as a legal entity, lost contracts and reputational damage.
A well-implemented compliance program reduces the likelihood of incidents and strengthens your position in inspections and investment processes.
A compliance program is not "paperwork": it is a system of workable controls that your team can carry out and that leave evidence. The key is a risk-based approach.
Reducing legal, criminal and reputational risks through clear internal policies, consistent criteria and traceability. A good program protects your operations, reputation and business relationships.
Risk map, code of ethics, anti-corruption and third-party policies, whistleblowing channel, role-based training, internal controls and reporting to the board of directors.
Having a manual is not enough: you have to prove it is applied. Records, approvals, audits, training with evidence and corrective actions closed.
If you need to implement compliance in practice, see our corporate compliance services or request the external expert report.
Identify real risks by activity, sector, clients, third parties and sales channel.
Risk matrix, action plan, owners and review schedule.
Standards of conduct and clear policies with workable approval workflows.
Versioned code, signed policies, acknowledgments of receipt and periodic reviews.
Early detection with a protocol: receipt, investigation, measures and closure.
Log of reports, investigations, resolutions and channel metrics.
Assess risk, include clauses, validate payments and monitor on an ongoing basis.
Assessment forms, contracts with clauses, validations and renewals.
Role-based training and periodic reviews to measure effectiveness and close gaps.
Training records, audit reports, KPIs and remediation plan.
Indicators that increase the company's legal and reputational exposure.
If you are implementing corporate compliance, these terms come up in audits, in dealings with regulators and in day-to-day operations.
A system of policies, procedures and controls to comply with the law, prevent breaches and demonstrate due diligence to third parties.
A company can be held criminally liable. An effective compliance program can exempt it from that liability or mitigate it.
A matrix that identifies legal, criminal and regulatory risks by activity, sector and operations, with proportionate controls.
A mechanism that allows employees and third parties to report wrongdoing confidentially, with a management and investigation protocol.
The process of vetting suppliers, intermediaries and partners to detect compliance risks before signing with them.
The person who coordinates, supervises and follows up on the compliance program. The role needs autonomy, resources and a clear reporting line.
Leadership must show its commitment to compliance through actions: communication, resources, example and consequences.
A policy that prohibits improper payments, excessive gifts and facilitation payments, and sets approval and recording controls.
Internal audits, gap detection, corrective actions and updates whenever the business or the regulations change.
The operational guide we use with our clients to implement an adequate and effective compliance program under Article 31 bis of the Spanish Criminal Code, aligned with UNE 19601 and ISO 37301.
Corporate compliance in Spain rests on the reform of the Spanish Criminal Code (Organic Law 1/2015), which regulates the criminal liability of legal entities (Article 31 bis) and the possibility of exemption or mitigation through an effective compliance program. This framework is complemented by Law 2/2023 on whistleblower protection, which requires companies to have a whistleblowing channel, and by sector-specific regulations.
Since the 2015 reform, companies can be convicted of offenses committed by their representatives, directors or employees if adequate controls were not in place. An adequate and effective compliance program can fully exempt the company from criminal liability or significantly mitigate it. Circular 1/2016 of the Spanish Attorney General's Office (Fiscalía General del Estado) and the case law of the Supreme Court set out the assessment criteria.
Law 2/2023 requires companies with 50 or more employees (and certain sectors regardless of headcount) to have an internal reporting system (whistleblowing channel) with guarantees of confidentiality, protection against retaliation and documented handling of the reports received.
Beyond crime prevention, a mature compliance program strengthens the company's position in public tenders, investor due diligence processes and relationships with banks and partners, and demonstrates sound corporate governance to clients and regulators.