ILP Abogados
Madrid · Internacional

INTELLIGENCE TOOL

Financial Regulation

Automated reporting, real-time regulatory alerts and data clean rooms for financial institutions and asset managers.

Intelligent regulatory surveillance for institutions that cannot afford surprises.

Financial institutions operate under constant regulatory pressure. DORA, MiCA, MiFID II — each quarter brings new obligations. Our solution automates monitoring so your compliance team can focus on what matters: implementing, not tracking.

These tools are free to use. If you are looking for regulatory advice, please see our financial regulation section.
normavex.ilpabogados.com
riesgo-regulatorio.ilpabogados.com
simulador-derivados.ilpabogados.com

DORA / MiCA / MiFID monitoring

Automated tracking of regulatory changes with customised alerts by institution and regulatory scope.

Regulatory reporting

Automated generation of compliance reports for supervisors — CNMV, Banco de España, AEPD.

Data clean rooms

Secure sharing of regulatory information between institutions without exposing personally identifiable data.

Impact analysis

Assessment of the impact of new regulations on portfolios, operations and existing structures.

NormaVex analyses an internal policy and highlights any deviations from the applicable regulations. The regulatory risk map shows where the enforcement activity of Spanish supervisory authorities is concentrated. The derivatives simulator outlines the obligations associated with a transaction under MiFID II, MiFIR, EMIR and REMIT, with a focus on energy derivatives. All three are free to use and provide an indicative result.

Understand the result

What does the result mean?

Each tool provides a different reading, and none of them constitutes a legal opinion. This is how each result is interpreted.

Gap
Policy auditor
What domestic policy does not cover, or covers only partially, in comparison with the benchmark standard.
Spotlight
Regulatory risk map
Where are the sanctions published by the Bank of Spain, the CNMV and SEPBLAC concentrated?
EMIR
Derivatives simulator
Transaction obligations, from reporting to collateral, with a focus on energy derivatives.

A gap identified by the policy auditor does not in itself constitute a breach. It indicates that the text of the policy does not include, or only partially includes, an obligation that the relevant standard does require. The seriousness of the issue depends on whether the obligation stems from a directly applicable regulation or a Level 2 implementing measure, and the supervisor assesses the matter on the basis of the written text.

The fact that a particular area on the map shows a concentration of sanctions means that supervisory activity is intense in that area and that the breaches giving rise to them are recurring within the sector. It does not imply a breach in itself. For a compliance team, it is a priority for review; it helps to organise the work and justify where resources are allocated.

In the simulator, the output lists the obligations associated with the derivative, the reporting to an authorised registry under EMIR, the potential for centralised clearing if thresholds are exceeded, the exchange of collateral in non-cleared OTC contracts and, for energy derivatives, REMIT obligations towards ACER. If the results indicate that thresholds have been exceeded, that the activity is restricted or that a potential investigation is likely, the case requires professional analysis.

How do I know which financial regulations apply to my organisation?

The order in which the legislation is read matters. Level 1 consists of the Union’s Regulations and Directives; the former are directly applicable, whilst the latter are implemented through transposition, in Spain primarily via Law 6/2023 on Securities Markets and Investment Services. Level 2 comprises the RTS, ITS and delegated acts, which specify deadlines, formats and thresholds. Level 3 comprises the Guidelines and Q&As issued by ESMA and the EBA, and the criteria set by the CNMV.

Here’s an example. A payment institution wishing to hold crypto-assets in custody starts with MiCA at Level 1, which restricts this activity to providers authorised by the CNMV as the competent authority. It then moves on to the RTS and ITS, which set out the application process and governance requirements, and concludes with the guidelines and Q&As from ESMA, the EBA and the CNMV. At the same time, it checks compliance with DORA, which applies across almost the entire sector.

If your organisation requires regulatory advice – from licensing to representing you before the regulator – please see our financial regulation section.

Methodology and sources

What they rely on

All three tools are based on the official texts published on EUR-Lex and in the BOE, in particular DORA (Regulation (EU) 2022/2554), MiCA (Regulation (EU) 2023/1114), EMIR (Regulation (EU) No 648/2012, as amended by Regulation (EU) 2019/834), MiFID II (Directive 2014/65/EU) and REMIT (Regulation (EU) No 1227/2011, as amended by Regulation (EU) No 2024/1106).

Levels 2 and 3 – technical standards, guidelines and Q&As – are taken from publications by ESMA, EBA and the CNMV. The results are for guidance only and do not constitute legal advice.

Frequently asked questions

What people ask on financial regulation

Since when has DORA been in force, and to which organisations does it apply?
DORA, Regulation (EU) 2022/2554, applies from 17 January 2025 to virtually the entire financial sector, including credit institutions, payment institutions and electronic money institutions, investment firms, asset managers, insurers and crypto-asset service providers. It also covers their technology providers, with a specific regime for critical providers.
What are an RTS and an ITS?
These are the regulatory technical standards (RTS) and implementing technical standards (ITS), which constitute Level 2 of the financial regulatory framework. They are drafted by European authorities such as the EBA or ESMA and adopted by the European Commission as regulations, which are directly applicable. They set out the operational details of Level 1, including deadlines, formats, thresholds and the content that policies must reflect.
How do MiCA and MiFID II differ?
MiFID II, Directive 2014/65/EU, regulates services relating to financial instruments. MiCA, Regulation (EU) 2023/1114, regulates crypto-assets that do not fall within its scope, distinguishing between asset-backed tokens, e-money tokens and other crypto-assets. The key distinction lies in the classification of the asset: if a token constitutes a financial instrument, MiFID II applies to it even if it uses DLT technology.
Which derivatives must be reported under EMIR, and to whom?
All of them. EMIR requires that derivatives – both OTC and exchange-traded – be reported to an authorised trade repository by the next business day at the latest. Under EMIR Refit, for OTC contracts between a financial counterparty and a non-financial counterparty that fall below the clearing thresholds, the financial counterparty reports on behalf of both parties.
What is REMIT and who does it affect?
This is Regulation (EU) No 1227/2011 on the integrity and transparency of the wholesale energy market, as amended by Regulation (EU) No 2024/1106. It prohibits insider dealing and market manipulation in the wholesale electricity and gas markets, and requires market participants to register and report their transactions to ACER.
What is an ESMA Guideline, and does it apply to me?
The Guidelines are Level 3 guidelines. They are formally addressed to national authorities, which must state whether they comply with them or explain why they do not, in accordance with Regulation (EU) No 1095/2010. The CNMV usually confirms its adherence to them and incorporates them into its supervisory practice; during an inspection, they have virtually the same effect as a regulatory provision.
How often should internal policies be reviewed?
At least once a year and whenever regulations or business operations change. DORA requires the technology risk management framework to be reviewed at least annually and following serious incidents. Every new RTS, every Guideline and every significant change in business operations should trigger a review of the relevant policies.

Related analysis

On the blog

José Luis Cobo Aragoneses
Page reviewed by
Financial Regulation Division — legal framework of the website (DORA, MiCA, EMIR, supervision by the CNMV and the Bank of Spain).
Updated August 2026

Does your institution need automated regulatory surveillance?

Request a complimentary personalised demo.

Confidential
Response <24h
No obligation