Corporate Compliance

Compliance Consulting for Companies and SMEs

We design and implement your compliance programme: criminal risk prevention (Art. 31 bis), whistleblowing channel (Ley 2/2023, the Spanish whistleblowing law), GDPR and ESG. Protect your company and keep your eligibility for public grants in Spain.

Corporate compliance consulting — regulatory compliance for companies in Spain

90%

Of the companies covered are still not compliant

Which companies need a compliance programme?

Five key regulatory obligations converge in 2025-2026. 90% of the companies covered still have no whistleblowing channel.

Companies covered

  • SMEs with 50+ employees: whistleblowing channel required
  • Every SL and SA: criminal exposure under Art. 31 bis
  • Companies handling personal data: GDPR (the AEPD fines)
  • Companies using AI: the AI Act applies from August 2026

Types of compliance

  • Criminal compliance (Art. 31 bis, UNE 19601)
  • Whistleblowing channel (Ley 2/2023, AIPI)
  • Data protection (GDPR, LOPDGDD)
  • ESG and sustainability (CSRD, ISO 37001)

Key regulations

  • Art. 31 bis of the Criminal Code (exemption from liability)
  • Ley 2/2023: whistleblowing channel, enforced by the AIPI
  • GDPR: the AEPD imposed €40M in fines in 2025
  • AI Act: fines up to €35M or 7% of turnover

Benefits of the programme

  • Legal shield: burden of proof moves to the prosecutor (STS 768/2025)
  • Avoids fines of up to €1M and a ban on public grants
  • Keeps your eligibility for public funding
  • Competitive advantage with clients and banks

How we implement your compliance programme

1

Compliance assessment

We map your regulatory exposure: criminal risk (Art. 31 bis), data protection (GDPR), whistleblowing channel (Ley 2/2023), ESG and sector rules. The output is a gap report with a prioritised risk matrix.

2

Programme design

We design a programme proportionate to your size and sector: internal policies, a code of conduct, a whistleblowing channel that meets AIPI requirements, a compliance officer structure and training materials.

3

Rollout and training

We configure the internal systems, train the management team and the employees, register the person responsible with the AIPI and switch on the whistleblowing channel. The compliance officer role can be outsourced to Tecnocim.

4

Monitoring and audit

We track regulatory change (BOE, AEPD, AIPI, case law), run annual internal audits and update the programme. After STS 768/2025, the courts require an effective programme, not only documents.

Does your company meet its compliance obligations?

90% of the companies covered still have no whistleblowing channel. The AIPI is already issuing fines of up to €1M and a 4-year ban on public grants. Is that your case?

Request a free assessment

Result in 48 hours, no commitment

Compliance in figures

40 M€

GDPR fines imposed by the AEPD in 2025

1 M€

Maximum fine for having no whistleblowing channel

90%

Companies covered with no whistleblowing channel

+30 years

Tecnocim experience in business consulting

Frequently asked questions about corporate compliance

The criminal compliance programme (Art. 31 bis of the Spanish Criminal Code) is not mandatory as such, but every legal entity — including small limited companies — is exposed to criminal liability. Without a documented programme, the company has no defence mechanism if an offence is committed in its context. After the Supreme Court rulings STS 768/2025 and STS 836/2025, a company with a programme forces the prosecution to prove that the programme was ineffective, which is significant legal protection. The whistleblowing channel required by Ley 2/2023, however, IS mandatory for every company with 50 or more employees, with fines of up to €1,000,000 and a 4-year ban on public grants.

Article 31 bis of the Spanish Criminal Code (introduced by LO 5/2010 and substantially reformed by LO 1/2015) sets out the criminal liability of legal entities in Spain. A company can be convicted of offences committed by its directors (in its name and for its benefit) or by employees where there has been a serious failure of supervision. The same article provides that the company can be exempted if, before the offence, it had an adequate prevention model that was effectively supervised by an autonomous compliance body, and if the offence was committed by fraudulently circumventing those controls.

Ley 2/2023, of 20 February, transposes European Directive 2019/1937 and requires every company with 50 or more employees to set up an internal reporting system. Companies with 50 to 249 employees may share resources. The AIPI, the Spanish independent authority for the protection of whistleblowers, has been operating since September 2025 and is already enforcing actively. Companies must notify the AIPI of the person responsible for the system. Fines for having no system range from €600,001 to €1,000,000 (very serious infringement), plus a ban on receiving public grants for 4 years and on contracting with public authorities for 3 years.

Art. 31 bis of the Spanish Criminal Code requires an autonomous body responsible for supervising the compliance programme. In micro-businesses that function can sit with the director. In companies with 50 or more employees, a dedicated compliance officer (internal or external) is strongly advisable and in practice necessary for the programme to be legally effective. Outsourcing the role to a firm such as Tecnocim gives you professional oversight, independence and regulatory monitoring without the cost of a full-time employee. External compliance officer services start at around €90 a month for smaller companies.

The CSRD (Corporate Sustainability Reporting Directive, 2022/2464) requires companies to publish annual sustainability reports under the European ESRS standards. The second wave applies to companies that meet two of three criteria: more than 250 employees, turnover of €50M or more, or total assets of €25M or more. Their first report covers the 2025 financial year and is published in 2026. One important update: the Omnibus I Directive (2026/470/EU, of 26 February 2026) narrows the scope of the CSRD significantly, excluding roughly 90% of the companies initially affected for financial years starting on 1 January 2027.

The exposure has several layers. Criminal (Art. 33.7 of the Criminal Code): fines of up to €20M or 4% of annual global turnover, dissolution of the company, a ban on contracting with public authorities and closure of premises. Whistleblowing channel (Ley 2/2023 and the AIPI): an administrative fine of up to €1,000,000, plus a ban on receiving public grants for 4 years and on public contracting for 3 years. Data protection (GDPR and the AEPD): up to €20M or 4% of global turnover for serious infringements; the AEPD imposed €40M in fines in Spain in 2025. Artificial intelligence (AI Act): up to €35M or 7% of global turnover from August 2026.

Is your company meeting its compliance obligations?

Free assessment of your regulatory exposure. Result in 48 hours.

Request a free assessment
Financiado por la Unión Europea - Gobierno de España, Ministerio de Industria y Turismo - Plan de Recuperación, Transformación y Resiliencia - EOI Escuela de Organización Industrial
Programa Activa Industria 4.0Industria Conectada 4.0