ILP Abogados
Madrid · Internacional

PRACTICE AREAS

Compliance

Compliance is not a cost. It is a competitive advantage.

We specialise in regulatory compliance for regulated entities, listed companies, universities, private equity funds, fund management companies, crypto-asset service providers, crowdfunding platforms, securities firms and payment institutions. We design and implement crime prevention models under Article 31 bis of the Criminal Code, reporting channels in accordance with Law 2/2023, and anti-money laundering programmes – an area in which we are experts – with policies, protocols, due diligence and KYC procedures aligned with the European framework. Compliance cannot be a blank cheque; that is why we build programmes that work within the specific reality of each organisation.

Our Approach · Programmes, not documents

Since the reform of the Criminal Code, legal persons have been held criminally liable for offences committed within their organisation and for their benefit (Article 31 bis of the Criminal Code). However, the same provision offers a way out: the adoption and effective implementation, prior to the commission of the offence, of an organisational and management model suitable for preventing it may exempt the company from liability — and, where the conditions are only partially met, mitigate that liability. Compliance is not a mere formality: it is the difference between being held criminally liable and not.

In addition to this core criminal law framework, there are other layers of compliance: the internal reporting system — the whistleblowing channel required by Law 2/2023 for companies with 50 or more employees —, the prevention of money laundering and terrorist financing for entities subject to Act 10/2010, and the sector-specific regulatory compliance requirements. All of these rest on the same foundation: an honest risk assessment tailored to the company’s actual business activities.

We have designed compliance programmes for listed companies, universities, venture capital firms, portfolio companies of investment funds and financial institutions. We do not sell off-the-shelf documents: a copied template does not meet the effectiveness test required by Article 31 bis. We build programmes that work within the reality of each organisation — with applicable protocols, training that is actually delivered and regular monitoring — because only a dynamic programme provides protection.

Our advice is strategic. We apply a robust framework of legal criteria that fully complies with regulations and is rooted in the organisation’s actual operations, ensuring that compliance does not become a blank cheque signed off on a manual that nobody follows. And we pay particular attention to the convergence between anti-money laundering and data protection – two frameworks that intersect in KYC, document retention and the disclosure of information, and which only work when designed in tandem.

Regulados

Listed companies, universities, private equity funds, asset management firms, crypto-asset providers, crowdfunding platforms, securities firms and payment institutions

PBC/FT

Experts in anti-money laundering, policies, protocols, due diligence and KYC within the European framework

31 bis CP

Criminal prevention models and the reporting channel under Act 2/2023

SERVICES

What we do

Criminal compliance (Article 31a of the Criminal Code)

Organisational and management models for crime prevention: criminal risk mapping, decision-making and action protocols, compliance body and disciplinary regime. Designed to meet the effectiveness test required for the defence. Specialists in regulated entities, ranging from listed companies and asset management firms to crypto-asset providers, crowdfunding platforms, securities firms and payment institutions.

Whistleblowing channel (Law 2/2023)

Implementation of the internal reporting system: policy, communications management procedure, appointment of the person responsible for the system, and safeguards regarding confidentiality and the protection of whistleblowers. Mandatory for companies with 50 or more employees.

Prevention of money laundering (AML/CFT)

We are experts in anti-money laundering. We develop the policies and protocols required by Law 10/2010 and its Regulations (RD 304/2014), we manage due diligence and KYC in accordance with the requirements of the European framework, and we prepare the organisation for the new EU AML package (Regulation (EU) 2024/1624).

Risk map and matrix

Comprehensive identification of compliance risks associated with the business activity, analysis of probability and impact, prioritisation and remediation plans. This forms the foundation of the entire programme: without an honest assessment, there can be no effective model.

Internal investigations

Procedures for dealing with indications of irregularities and conducting internal investigations in accordance with due process: preservation of evidence, confidentiality and advice on the decisions to be taken following the investigation.

Training and auditing

Training for board members, senior management and staff — a culture of compliance is built from within — and an audit of existing programmes with specific improvement plans, including alignment with the UNE 19601 certification standard.

METHOD

How we work

1

Risk map

We analyse the company’s actual operations — its sector, business activities and structure — and identify and prioritise its criminal and regulatory risks.

2

Model design

Policies, protocols, a reporting channel and a compliance body tailored to the organisation’s needs, with assigned responsibilities and controls.

3

Implementation and training

Effective roll-out of the programme: approval by the governing body, internal communication and training for managers and staff.

4

Verification and updating

Regular review of the model and updating it when there are changes to the business activity, structure or regulations — an out-of-date programme does not constitute an exemption.

EXPERIENCE

Proven track record

Regulados

Listed companies, universities, private equity funds, asset management firms, crypto-asset providers, crowdfunding platforms, securities firms and payment institutions

PBC/FT

Experts in anti-money laundering, policies, protocols, due diligence and KYC within the European framework

31 bis CP

Criminal prevention models and the reporting channel under Act 2/2023

ILP Abogados has drafted compliance programmes for listed companies, universities, venture capital firms and portfolio companies of venture capital funds, and provides regular training on this subject to financial institutions. We regularly publish analyses on compliance — ranging from the role of the compliance officer to the requirements of the UNE 19601 standard — which you can read on our blog: the best way to see how we work is to read our posts.

FREQUENTLY ASKED QUESTIONS

What clients ask before engaging us

Is my company required to have a whistleblowing channel?

Yes, if you have 50 or more employees: Act 2/2023 requires you to set up an internal reporting system, complete with management procedures, a designated system manager and safeguards to protect whistleblowers. Furthermore, certain organisations — including, amongst others, those in regulated sectors such as the financial sector or those subject to anti-money laundering regulations — are obliged to do so regardless of their workforce size. We implement the complete system and help to manage it.

Does a compliance programme provide protection from criminal liability?

It may do so. Article 31 bis of the Criminal Code provides that a legal person shall be exempt from liability if, prior to the commission of the offence, it had adopted and effectively implemented an organisational and management model suitable for preventing offences such as the one committed. If the conditions are only partially met, this acts as a mitigating factor. The key is actual effectiveness: a document tucked away in a drawer does not provide an exemption.

What does a crime prevention model involve?

As a minimum: a map of the criminal risks associated with the business, protocols for decision-making and the formation of corporate will, financial resource management models, a whistleblowing channel, a disciplinary regime and a compliance body with independent supervisory powers. All of this must be documented, approved by the board of directors and reviewed periodically.

How often should the programme be updated?

Article 31 bis requires the model to be reviewed periodically and amended where significant breaches come to light or where there are changes to the organisation, the control structure or the business activities. In practice, we recommend a scheduled periodic review, as well as ad hoc reviews in the event of regulatory changes, corporate transactions or incidents.

Is it necessary to train staff?

Yes. The effectiveness of the model — which is what is assessed in court — depends on those responsible for implementing it being familiar with it. Training for managers and staff is an essential part of the programme and of the compliance culture; we deliver this training on a regular basis, including to financial institutions, tailored to each role and level of risk.

Who should take on the role of compliance officer?

Article 31 bis requires that oversight of the model be entrusted to a body with autonomous powers of initiative and control; in small legal entities, this role may be assumed by the board of directors itself. This function may be carried out internally or by external advisers: the key factors are its independence, its resources and its direct access to the board of directors.

Can the compliance model be certified?

Yes. The UNE 19601 standard sets out the requirements for criminal compliance management systems and can be certified by independent third parties. Certification does not replace the court’s assessment of effectiveness, but it brings structure to the system and serves as a valuable indication of the organisation’s commitment. We design programmes in line with this standard.

Do you need advice on compliance?

Prevention programmes for social security contributors, universities, investment funds and financial institutions. First consultation with no obligation.

See all practice areas →