ILP Abogados
Madrid · Internacional

PRACTICE AREAS

Financial Regulatory

Nothing is impossible in financial regulation.

We advise regulated entities, listed companies, private equity funds, asset managers, crypto-asset service providers, crowdfunding platforms, securities firms and payment institutions throughout their regulatory lifecycle. We secure licences from the CNMV and the Bank of Spain, develop DORA compliance programmes, MiFID II, MiCA, EMIR, MiFIR and REMIT compliance programmes, including the finalisation of ISDA and CMOF agreements and the reporting of derivatives; we represent clients during inspections and sanctioning proceedings; and we structure tokenisation and DLT projects. We work in joint teams of lawyers and engineers; the outcome is not just a report, but a system that complies.

Our Approach · From standard to system

Financial regulation is not limited to a list of rules. It is structured within a complex hierarchy, with Directives and Regulations establishing the Level 1 framework, Delegated Regulations, ITS and RTS specifying their application at Level 2, and the Guidelines, Q&As and Guidance Notes issued by the European supervisory authorities, which provide guidance on interpretation at Level 3. Navigating this regulatory architecture with ease, and anticipating how each level influences the next, forms the basis of our work.

The service covers the entire lifecycle of the relationship with the regulator, from the implementation of EU directives and regulations and the obtaining of the necessary authorisations and registrations to operate in the financial sector, through to the day-to-day interpretation and application of the regulations and the defence of companies and organisations before the authorities during inspections, formal notices and disciplinary proceedings.

And we go beyond mere interpretation. We work in joint teams comprising lawyers and systems engineers, which enables us to translate every requirement – be it an EBA RTS, an ESMA Guideline or a CNMV Q&A – into a real technical solution, featuring reporting architectures, risk management frameworks, internal control systems or infrastructure for the issuance and custody of digital assets. Compliance ceases to be merely a document and becomes a functioning system.

Regulados

Listed companies, universities, private equity funds, asset management firms, crypto-asset providers, crowdfunding platforms, securities firms and payment service providers

DORA

MiCA, MiFID II, EMIR, MiFIR and REMIT

CNMV

Bank of Spain, SEPBLAC

SERVICES

What we do

Authorisations and registrations

Procedures with the CNMV, the Bank of Spain and European supervisory authorities. Licences to operate as an ESI, EDE, EP or CASP under MiCA. Registration of management companies, platforms and investment vehicles.

Compliance with DORA, MiFID II, MiCA, EMIR, MiFIR and REMIT

Digital Operational Resilience (DORA) programmes, MiFID II product governance, obligations of issuers and providers under MiCA, EMIR and MiFIR reporting, and REMIT supervision of the wholesale energy market. Ongoing alignment with European ITS and RTS.

Derivatives: EMIR, ISDA and CMOF

We provide end-to-end EMIR compliance advice, including the execution of ISDA and CMOF agreements, registration with trade repositories and regulated market platforms, and assistance with the reporting of exchange-traded and OTC derivatives.

Presentation to supervisors

Representation in disciplinary proceedings and inspections by the CNMV and the Bank of Spain. Administrative appeals and judicial review proceedings against supervisory decisions.

Tokenisation and DLT

Legal structuring of STOs, token issuances and DLT platforms. Advice on regulatory sandboxes, anti-money laundering measures for crypto transactions and licensing under MiCA.

Anti-Money Laundering (AML/CFT)

AML/CFT manuals and procedures for regulated entities, risk analysis and relations with SEPBLAC. This also applies to crypto-assets and DLT platforms, where supervisory requirements are at their highest.

Funds, fund managers, platforms and investment vehicles

Incorporation and registration of management companies (SGIIC, SGEIC), crowdfunding platforms and investment vehicles (IIC, ECR, FIL). Marketing in Spain, the European passport and ongoing relations with the CNMV.

METHOD

How we work

1

Regulatory assessment

An overview of the obligations applicable to your business, covering the three regulatory levels and the supervisory authority’s expectations.

2

Action plan

The necessary licences, compliance gaps, a realistic timetable and a finalised budget must be in place before starting.

3

Legal + Tech Implementation

Policies and procedures, together with their technical translation, reporting, internal controls and data architecture, in collaboration with our engineers.

4

Ongoing support

Monitoring developments from ESMA, EBA and the CNMV, providing support during inspections and ensuring the compliance system is kept up to date.

EXPERIENCE

Proven track record

Regulados

Listed companies, universities, private equity funds, asset management firms, crypto-asset providers, crowdfunding platforms, securities firms and payment service providers

DORA

MiCA, MiFID II, EMIR, MiFIR and REMIT

CNMV

Bank of Spain, SEPBLAC

We regularly advise regulated entities across the entire spectrum – from listed companies and asset managers to crypto-asset providers, crowdfunding platforms, securities firms and payment institutions – on licensing, ongoing compliance and representation before supervisory authorities. We also publish our views openly, with technical analyses of MiCA, DORA, stablecoins and payment services, which you can read on our blog.

FREQUENTLY ASKED QUESTIONS

What clients ask before engaging us

Do I need a licence to provide services relating to crypto-assets in Spain?

Generally speaking, yes. Under the MiCA Regulation, crypto-asset service providers (CASP) require authorisation, and in Spain the competent authority is the CNMV. We analyse your business model, determine whether your activity is a reserved activity, and prepare the complete authorisation application.

How long does it take to obtain authorisation from the CNMV or the Bank of Spain?

It depends on the type of licence and, above all, on the quality of the application, because the main cause of delays is the regulator’s requests for further information. We prepare the complete application package – including the programme of activities, governance structure, financial soundness and technical resources – to minimise the number of rounds of amendments and shorten the actual processing time.

Who does DORA apply to, and from when?

DORA will apply from 17 January 2025 to virtually all financial institutions, banks, ESIs, payment institutions, insurers and asset managers, and will also cover their ICT suppliers, particularly those providing critical services. It requires a framework for technology risk management, resilience testing and control of outsourcing.

I have received a notice of inspection or a formal demand from the CNMV. What should I do?

Do not respond without a strategy, as the information provided during the inspection phase will influence any subsequent disciplinary proceedings. We prepare the response, manage communications with the supervisory authority and, should the case proceed, we conduct the defence through administrative and contentious-administrative channels.

Does MiCA apply to my token?

It depends on the nature of the token. MiCA distinguishes between asset-referenced tokens (ARTs), electronic money tokens (EMTs) and other crypto-assets, each of which is subject to different regimes; if the token is a financial instrument, MiFID II applies, not MiCA. The legal classification of the token is the first step in any project.

What are the risks of operating without the required licence?

The financial sector is subject to strict regulatory restrictions. Operating without authorisation may result in heavy fines, an order to cease trading, and reputational damage that is difficult to reverse. If you are unsure whether your activity is subject to these restrictions, it is best to clarify this before launching, not afterwards.

Do you work with fintech start-ups or only with organisations that are already regulated?

Both. We support start-ups from the design of their business model – including the regulatory sandbox – through to authorisation and ongoing compliance, and we advise regulated entities on their ongoing obligations, new products and international expansion.

Do you need advice on financial regulation?

From licensing to ongoing compliance, with lawyers and engineers working as a single team. Initial consultation with no obligation.

See all practice areas →