Article 31 bis of the Spanish Criminal Code allows a legal entity to be held criminally liable for offences committed in its name or on its behalf and for its direct or indirect benefit, both by its legal representatives and by those authorised to take decisions, and by those who, being under the authority of the former, were able to commit the acts because the duties of supervision, oversight and control were seriously breached. The practical consequence is that the company sits in the dock next to the individual, with a catalogue of penalties of its own: fines, dissolution, suspension of activities, closure of premises, judicial intervention and disqualification from obtaining public subsidies and aid or from contracting with the public sector. Quotations from Spanish law on this page are our own translation; only the Spanish original published in the BOE is binding.
Paragraph 2 of that same article opens a way out. The legal entity is exempt from liability if the four conditions the paragraph lists are met, the first of which is that the management body has adopted and effectively implemented, before the offence was committed, organisation and management models that include surveillance and control measures suitable for preventing offences of the same nature or for significantly reducing the risk of them being committed. The words that decide a trial are all in that sentence: adopted, implemented effectively and before. A manual signed the week the complaint lands exempts nobody. The paragraph also closes with a nuance that is easy to miss: where those circumstances can only be partly evidenced, that partial evidence is taken into account to mitigate the penalty.
The second condition is the one that causes most confusion in the market, and it deserves to be said plainly: supervision of how the prevention model works and whether it is complied with must be entrusted to a body of the legal entity with autonomous powers of initiative and control, or to a body legally charged with supervising the effectiveness of that same legal entity's internal controls. Of the legal entity. Both alternatives the law offers are internal. No consulting firm can be that body by contract, and anyone offering to “be your external compliance officer” for the purposes of article 31 bis is selling something the law does not allow. What an external consultant does do is build the model, equip that internal body with procedures, training, indicators and minutes, and verify it periodically from outside, with the independence that comes from not reporting into the organisation chart being supervised. The article itself provides one exception, and it is a matter of size: in small legal entities — those authorised to file an abridged profit and loss account — the management body may take on the supervisory functions directly.
The content of the model is not left to the consultant's taste either. Paragraph 5 of article 31 bis sets out six requirements and all six are enforceable: identify the activities in whose scope the offences to be prevented may be committed; establish protocols that give shape to how the entity forms its will and how decisions are taken and executed; have financial resource management models suitable for preventing the offences from being committed; impose a duty to report possible risks and breaches to the body responsible for overseeing how the model works and whether it is observed; establish a disciplinary system that adequately penalises failure to comply with the measures; and carry out periodic verification of the model, amending it whenever relevant breaches come to light or when there are changes in the organisation, in the control structure or in the activity carried out. That sixth requirement is what turns compliance into a service rather than a deliverable: a model nobody reviews stops being effective and, with that, stops exempting anyone.
The fourth requirement — the channel for reporting risks and breaches — stopped being merely a piece of the Criminal Code with Law 2/2023 of 20 February, which regulates the protection of persons who report regulatory breaches and the fight against corruption. Its article 10.1 requires natural and legal persons in the private sector with fifty or more employees to have an Internal Reporting System, and requires the same, with no headcount threshold at all, of those operating in financial services, products and markets, in the prevention of money laundering or terrorist financing, in transport safety and in environmental protection. Letter c) adds political parties, trade unions, employers' organisations and the foundations created by them when they receive or manage public funds, again with no headcount threshold.
Here outsourcing is possible, though with two limits almost nobody explains. Article 6.1 allows an external third party to be used and, in the same paragraph, defines what managing the system means: management of the System is understood to be the receipt of reports. What can be outsourced is the receipt, not the whole system. And article 8 reserves the figure of System Manager for the organisation itself: in the private sector it must be a senior manager of the entity, appointed by the management body and independent from it. Article 6.3 closes the circle by preventing external management from assigning responsibility for the system to anyone other than that internal Manager. Not having one also carries a price of its own, separate from the Criminal Code: article 63.1 classifies certain wilful omissions as very serious, among them failing to have the system, and article 65 reaches fines of up to €1,000,000 and bans on contracting with the public sector. The detail is further down, in the frequently asked questions.
The technical standard rests on that legal base. UNE 19601:2025, “Sistemas de gestión del compliance penal. Requisitos con orientación para su uso” — criminal compliance management systems — is the Spanish reference for structuring and auditing a crime prevention model, and its 2025 edition supersedes the earlier 2017 one. One point is worth being precise about, because it is often misread: UNE 19601 is not a law and obliges nobody. It is a Spanish standard adopted voluntarily. Its value is evidential and organisational: it gives the model a recognisable structure, it forces evidence to be left for every requirement and, if the organisation chooses to be certified by a certification body, it produces an independent third-party report backing its diligence. None of that replaces the assessment a judge will make of how effective the model really was, but it changes the starting point. When a company wants to go beyond criminal risk and govern its compliance as a whole, the next step is ISO 37301, which Summum Calidad handles.
When the model is built changes its legal effect, and this is rarely explained clearly. The exemption in paragraph 2 requires the model to have been adopted and effectively implemented before the offence was committed. If proceedings are already under way, what remains is the mitigating circumstance in letter d) of article 31 quater: having established, before the oral hearing begins, effective measures to prevent and detect offences that might in future be committed with the resources or under the cover of the legal entity. The heading of that article makes all its mitigating circumstances conditional on the action being taken after the offence was committed and through the company's legal representatives. It mitigates; it does not exempt. The difference is measured in years of disqualification and in whether the company survives.
Summum has been supporting organisations in regulatory compliance since 2007, with more than 2,000 digitalisation projects delivered and close to 200 ISO certification processes accompanied across the group. We work from five offices — Valladolid (head office), Burgos, Palencia, Aranda de Duero and Las Palmas de Gran Canaria — and that means the consultant who reviews your model is someone you know in person. The UNE 19601 criminal compliance programme describes the implementation project; this page describes the figure who builds it and keeps it alive afterwards, month by month. If you also need to cover data protection, the equivalent figure in that field is the outsourced DPO, which can be a third party, and if the assignment is about governance, corporate bodies and company protocols, that work sits in corporate governance.
In practice the work looks like case 08 among our published cases: an industrial multinational with a Spanish parent that, after a sector crisis, asked us to shield the organisation with an auditable programme. Criminal risk map, code of ethics, whistleblowing channel, compliance committee and training across six management levels, with the programme certified to UNE 19601 and the external audit passed.
We do not publish a fixed fee because the real scope depends on variables that change a great deal from one organisation to another: the number of companies in the group and of work centres, which catalogue of offences is relevant to the activity, whether an internal channel is already operating, whether there are court proceedings or inspections open, whether the organisation wants to reach certification to UNE 19601 or a defensible model is enough, and how much training has to be delivered. We settle it on a first call at no cost, after understanding the real activity, because any figure given before that assessment would be an approximation of little use. We do not promise a particular outcome before a judge, nor do we replace legal defence: we support the organisation so that it reaches any request with the model, the minutes and the evidence the rules require.