Regulation
Compliance programme for SMEs in Spain: 2026 guide
60% of Spanish SMEs still fail to comply with current labour law (IusConfidence, 2026), and most have no formal compliance programme in place. Yet since the 2015 reform of the Spanish Criminal Code (article 31 bis), an effective compliance programme is the only route a company has to be exonerated from corporate criminal liability. In 2026, compliance stops being corporate rhetoric and becomes evidence in court.
What is corporate compliance and why does your SME need it?
Compliance (regulatory compliance) is the set of procedures and good practices a company adopts to identify and classify the legal risks that affect it, put prevention and detection mechanisms in place, and respond properly to any irregularity.
It is not only criminal compliance. A company's obligations in 2026 span several areas:
| Area | Key rules | Main obligation |
|---|---|---|
| Criminal | Art. 31 bis, Spanish Criminal Code | Crime prevention programme |
| Employment | Equality plan | Mandatory for companies with 50+ employees |
| Pay | Pay register | Mandatory for every company |
| Data protection | GDPR + LOPDGDD (the Spanish data protection act) | DPO, record of processing activities, consent |
| Whistleblowing | Ley 2/2023 (the Spanish whistleblowing act) | Mandatory for companies with 50+ employees |
| Environmental | Carbon footprint (RD 214/2025) | Calculation and reduction plan for large companies |
| AI | EU AI Act | Risk classification of the AI systems in use |
| Tax | LIS, Ley Antifraude (the Spanish anti-fraud act) | E-invoicing, SII, fraud prevention |
Why does it matter to an SME?
- An effective compliance programme can exempt the company from criminal liability (art. 31 bis of the Spanish Criminal Code)
- Courts take a positive view of documented internal controls
- Penalties for non-compliance can reach €225,018 (EU Pay Transparency Directive)
- More and more clients and partners require compliance certification before they will sign a contract
Does your company meet its legal obligations? Request a free assessment and we will review your level of regulatory compliance.
What must a criminal compliance programme include?
Article 31 bis of the Spanish Criminal Code (LO 5/2010, reformed in 2015) sets out 6 requirements a compliance programme must meet to be effective:
- Map of criminal risks: identify the activities in which offences affecting the company could be committed
- Decision protocols: set out procedures that define how the company forms its intent and takes decisions
- Control of financial resources: put management models in place that prevent offences being committed with company funds
- Whistleblowing channel: require staff to report possible risks and breaches to the supervisory body
- Disciplinary system: penalise breaches of the programme's measures appropriately
- Periodic review: update the programme when breaches come to light or the organisation changes
Additional requirement: appoint a Compliance Officer or a body within the legal entity with autonomous powers of initiative and control. In SMEs, this function can be outsourced.
Important: "cosmetic" programmes — designed only to look like compliance — do not exempt a company from liability and can be read as evidence of a weak compliance culture. The Fiscalía General del Estado (the Spanish public prosecution service), in its Circular 1/2016 (BOE, 2016), sets clear criteria for assessing whether a compliance programme really works, and gives particular weight to whether it is genuinely embedded in day-to-day operations.
How do you roll out a compliance programme in your SME?
Phase 1: Initial assessment
Assess the current state of regulatory compliance across every area: criminal, employment, tax, data protection, environmental and sector-specific. Identify compliance gaps and prioritise them by risk and impact.
Phase 2: Risk map
Draw up a detailed map of the legal risks specific to the company, based on its activity, sector and size. Classify them by likelihood and impact so that action can be prioritised.
Phase 3: Programme design
Develop policies, procedures and controls for each risk identified. Include a code of ethics, action protocols, a whistleblowing channel and a disciplinary system.
Phase 4: Training the team
Train the whole workforce on the compliance programme, with particular emphasis on the roles most exposed to risk. Training funded through FUNDAE, the Spanish company training scheme, can cover the cost.
Phase 5: Roll-out and monitoring
Put the controls into operation, activate the whistleblowing channel, appoint the Compliance Officer and set a timetable for periodic review.
Phase 6: Audit and continuous improvement
Continuous improvement is not an optional good practice: the Spanish Criminal Code requires periodic verification of the model and its amendment whenever significant breaches of its provisions come to light, or whenever there are changes in the organisation, in the control structure or in the activity carried out that make it necessary (art. 31 bis.5, condition 6 of the Criminal Code). In other words, the review is triggered both by the calendar (at least once a year) and ad hoc by any of those three scenarios.
We recommend running this phase as a stable performance-evaluation cycle. The UNE 19601 standard on criminal compliance management systems — updated in 2025 and aligned with the international standards ISO 37001 (anti-bribery) and ISO 37301 (compliance) (Bureau Veritas, 2025) — organises that cycle around monitoring and measurement, internal audits and management review, so the system keeps pace with legal and business change.
For the review to be verifiable, it helps to rely on a dashboard of qualitative compliance indicators: number of incidents detected, percentage of staff who have completed the training, response time of the internal whistleblowing channel and audit results. These indicators feed the management review and document that the programme is genuinely alive, not a cosmetic model.
Finally, every review must reassess and update the criminal risk map whenever the activity, the corporate structure or the regulatory framework changes (art. 31 bis of the Spanish Criminal Code). Oversight of this whole cycle sits with the Compliance Officer or compliance body, which holds autonomous powers of initiative and control and is what sustains continuous improvement over time.
Indicative implementation cost:
| Company profile | Criminal compliance cost | Full compliance cost |
|---|---|---|
| Micro-SME (1–10 employees) | €2,000 – €5,000 | €3,000 – €8,000 |
| SME (10–50 employees) | €5,000 – €12,000 | €8,000 – €20,000 |
| SME (50–250 employees) | €10,000 – €25,000 | €15,000 – €40,000 |
The cost of NOT having compliance can be far higher: fines of up to €225,018 for breaching pay transparency rules, penalties for having no whistleblowing channel and, in the worst case, criminal liability for the company and its directors. Spanish courts have handed down rulings with multi-million-euro fines against companies that had no criminal compliance programme when offences were committed within them.
Benefits of compliance beyond meeting the law:
- Competitive advantage: more and more large companies require compliance certification from their suppliers
- Investor confidence: business angels and investment funds take a positive view of a company that has compliance in place
- Lower insurance premiums: liability insurers offer better terms to companies with compliance programmes
- Organisational culture: a compliance-driven environment attracts and retains talent
- Access to public tenders: regulatory compliance criteria are a requirement in public procurement
In Catalunya, the Cupons ACCIÓ strategy vouchers (up to €8,000) can fund the initial compliance assessment as part of a wider review of the company's business model.
What specific obligations does your company have in 2026?
Obligations vary with size:
All companies:
- An up-to-date pay register
- A protocol against sexual harassment and harassment on grounds of sex
- Compliance with the GDPR and LOPDGDD
- E-invoicing (Ley Antifraude, the Spanish anti-fraud act)
- Occupational risk prevention
Companies with 50+ employees (in addition to the above):
- A registered, current equality plan
- A whistleblowing channel (Ley 2/2023, the Spanish whistleblower protection act)
- A pay audit
Companies carrying out R&D&I (in addition to the above):
- Risk classification of AI systems under the EU AI Act
- Documentation of tax deductions backed by a binding technical report (informe motivado) for legal certainty
A Fractional CFO with a compliance mindset can align regulatory compliance with financial strategy, making sure the company takes up the tax incentives available (R&D&I tax deductions, Social Security contribution reductions) without compliance risk. Obtaining the Sello Pyme Innovadora, the Spanish innovative SME seal, can strengthen your company's credibility and open up further tax advantages. To digitalise compliance, Kit Digital can fund document management and automation tools.
How can you fund Compliance Officer training through FUNDAE?
Training for the Compliance Officer — and awareness training for the workforce on criminal compliance (art. 31 bis of the Spanish Criminal Code, standard UNE 19601) — can be funded as company-programmed training through FUNDAE, provided it meets the requirements of the Spanish subsidised training scheme. That lets your SME pay for compliance training with no material extra outlay.
The credit comes from the vocational training contribution, which amounts to 0.7% of the contribution base for occupational contingencies (0.60% paid by the company and 0.10% by the employee) and is paid monthly to Spanish Social Security (FUNDAE, 2026). A percentage of the amount paid the previous year is then available as a reduction, depending on average headcount: 100% (1–9 employees), 75% (10–49), 60% (50–249) and 50% (250 or more), in line with the latest update and each year's Ley de Presupuestos Generales del Estado (the Spanish state budget act).
The calculation is straightforward: annual credit = previous year's vocational training contribution × percentage by headcount. Companies with more than 5 employees must also put up private co-funding (a share of the total training cost that the credit does not cover); those with up to 5 employees are exempt, and according to FUNDAE micro-companies have a guaranteed minimum credit.
One practical recommendation: companies with fewer than 50 employees can carry unused credit over the following two financial years, provided they say so before 30 June (FUNDAE, 2026). Planning compliance training within this framework lets you meet Phase 4 of the programme and optimise the credit available at the same time.
Do you want to roll out a compliance programme in your company? At Tecnocim Innova we help you design and implement a compliance programme suited to your size and sector through our compliance consultancy, integrated with the management of grants and employment obligations. Contact us for a no-obligation review.
Related services
Corporate Compliance
Criminal compliance programme (Art. 31 bis), whistleblowing channel (Ley 2/2023), GDPR and ESG. Outsourced compliance...
View service →Innovation Consultancy
We support your company through digital transformation, change management and innovation strategy.
View service →Free assessment for companies with revenue above €500,000
Get grant and tax deduction updates by email
Calls, deadlines and regulatory changes, once a month.
Related articles
Regulation
Regulation

