Regulatory compliance

External compliance consultant

We build and keep alive the organisation and management model that article 31 bis of the Spanish Criminal Code requires for a company to be exempt from criminal liability: criminal risk map, decision-making protocols, code of ethics, an internal channel compliant with Law 2/2023 and documented periodic verification. The supervisory body stays inside your company, because the law demands it; what we bring is method, evidence and a second opinion from outside.

Formatmonthly, outsourced
StandardsUNE 19601:2025 · Law 2/2023
Applies tolegal entities (art. 31 bis, Criminal Code)

Article 31 bis of the Spanish Criminal Code allows a legal entity to be held criminally liable for offences committed in its name or on its behalf and for its direct or indirect benefit, both by its legal representatives and by those authorised to take decisions, and by those who, being under the authority of the former, were able to commit the acts because the duties of supervision, oversight and control were seriously breached. The practical consequence is that the company sits in the dock next to the individual, with a catalogue of penalties of its own: fines, dissolution, suspension of activities, closure of premises, judicial intervention and disqualification from obtaining public subsidies and aid or from contracting with the public sector. Quotations from Spanish law on this page are our own translation; only the Spanish original published in the BOE is binding.

Paragraph 2 of that same article opens a way out. The legal entity is exempt from liability if the four conditions the paragraph lists are met, the first of which is that the management body has adopted and effectively implemented, before the offence was committed, organisation and management models that include surveillance and control measures suitable for preventing offences of the same nature or for significantly reducing the risk of them being committed. The words that decide a trial are all in that sentence: adopted, implemented effectively and before. A manual signed the week the complaint lands exempts nobody. The paragraph also closes with a nuance that is easy to miss: where those circumstances can only be partly evidenced, that partial evidence is taken into account to mitigate the penalty.

The second condition is the one that causes most confusion in the market, and it deserves to be said plainly: supervision of how the prevention model works and whether it is complied with must be entrusted to a body of the legal entity with autonomous powers of initiative and control, or to a body legally charged with supervising the effectiveness of that same legal entity's internal controls. Of the legal entity. Both alternatives the law offers are internal. No consulting firm can be that body by contract, and anyone offering to “be your external compliance officer” for the purposes of article 31 bis is selling something the law does not allow. What an external consultant does do is build the model, equip that internal body with procedures, training, indicators and minutes, and verify it periodically from outside, with the independence that comes from not reporting into the organisation chart being supervised. The article itself provides one exception, and it is a matter of size: in small legal entities — those authorised to file an abridged profit and loss account — the management body may take on the supervisory functions directly.

The content of the model is not left to the consultant's taste either. Paragraph 5 of article 31 bis sets out six requirements and all six are enforceable: identify the activities in whose scope the offences to be prevented may be committed; establish protocols that give shape to how the entity forms its will and how decisions are taken and executed; have financial resource management models suitable for preventing the offences from being committed; impose a duty to report possible risks and breaches to the body responsible for overseeing how the model works and whether it is observed; establish a disciplinary system that adequately penalises failure to comply with the measures; and carry out periodic verification of the model, amending it whenever relevant breaches come to light or when there are changes in the organisation, in the control structure or in the activity carried out. That sixth requirement is what turns compliance into a service rather than a deliverable: a model nobody reviews stops being effective and, with that, stops exempting anyone.

The fourth requirement — the channel for reporting risks and breaches — stopped being merely a piece of the Criminal Code with Law 2/2023 of 20 February, which regulates the protection of persons who report regulatory breaches and the fight against corruption. Its article 10.1 requires natural and legal persons in the private sector with fifty or more employees to have an Internal Reporting System, and requires the same, with no headcount threshold at all, of those operating in financial services, products and markets, in the prevention of money laundering or terrorist financing, in transport safety and in environmental protection. Letter c) adds political parties, trade unions, employers' organisations and the foundations created by them when they receive or manage public funds, again with no headcount threshold.

Here outsourcing is possible, though with two limits almost nobody explains. Article 6.1 allows an external third party to be used and, in the same paragraph, defines what managing the system means: management of the System is understood to be the receipt of reports. What can be outsourced is the receipt, not the whole system. And article 8 reserves the figure of System Manager for the organisation itself: in the private sector it must be a senior manager of the entity, appointed by the management body and independent from it. Article 6.3 closes the circle by preventing external management from assigning responsibility for the system to anyone other than that internal Manager. Not having one also carries a price of its own, separate from the Criminal Code: article 63.1 classifies certain wilful omissions as very serious, among them failing to have the system, and article 65 reaches fines of up to €1,000,000 and bans on contracting with the public sector. The detail is further down, in the frequently asked questions.

The technical standard rests on that legal base. UNE 19601:2025, “Sistemas de gestión del compliance penal. Requisitos con orientación para su uso” — criminal compliance management systems — is the Spanish reference for structuring and auditing a crime prevention model, and its 2025 edition supersedes the earlier 2017 one. One point is worth being precise about, because it is often misread: UNE 19601 is not a law and obliges nobody. It is a Spanish standard adopted voluntarily. Its value is evidential and organisational: it gives the model a recognisable structure, it forces evidence to be left for every requirement and, if the organisation chooses to be certified by a certification body, it produces an independent third-party report backing its diligence. None of that replaces the assessment a judge will make of how effective the model really was, but it changes the starting point. When a company wants to go beyond criminal risk and govern its compliance as a whole, the next step is ISO 37301, which Summum Calidad handles.

When the model is built changes its legal effect, and this is rarely explained clearly. The exemption in paragraph 2 requires the model to have been adopted and effectively implemented before the offence was committed. If proceedings are already under way, what remains is the mitigating circumstance in letter d) of article 31 quater: having established, before the oral hearing begins, effective measures to prevent and detect offences that might in future be committed with the resources or under the cover of the legal entity. The heading of that article makes all its mitigating circumstances conditional on the action being taken after the offence was committed and through the company's legal representatives. It mitigates; it does not exempt. The difference is measured in years of disqualification and in whether the company survives.

Summum has been supporting organisations in regulatory compliance since 2007, with more than 2,000 digitalisation projects delivered and close to 200 ISO certification processes accompanied across the group. We work from five offices — Valladolid (head office), Burgos, Palencia, Aranda de Duero and Las Palmas de Gran Canaria — and that means the consultant who reviews your model is someone you know in person. The UNE 19601 criminal compliance programme describes the implementation project; this page describes the figure who builds it and keeps it alive afterwards, month by month. If you also need to cover data protection, the equivalent figure in that field is the outsourced DPO, which can be a third party, and if the assignment is about governance, corporate bodies and company protocols, that work sits in corporate governance.

In practice the work looks like case 08 among our published cases: an industrial multinational with a Spanish parent that, after a sector crisis, asked us to shield the organisation with an auditable programme. Criminal risk map, code of ethics, whistleblowing channel, compliance committee and training across six management levels, with the programme certified to UNE 19601 and the external audit passed.

We do not publish a fixed fee because the real scope depends on variables that change a great deal from one organisation to another: the number of companies in the group and of work centres, which catalogue of offences is relevant to the activity, whether an internal channel is already operating, whether there are court proceedings or inspections open, whether the organisation wants to reach certification to UNE 19601 or a defensible model is enough, and how much training has to be delivered. We settle it on a first call at no cost, after understanding the real activity, because any figure given before that assessment would be an approximation of little use. We do not promise a particular outcome before a judge, nor do we replace legal defence: we support the organisation so that it reaches any request with the model, the minutes and the evidence the rules require.

How the external compliance consultant works.

The process · four stages
01

Assessment and criminal risk map

We walk through the real activity, process by process, to identify in which areas offences could be committed and with what likelihood and impact. It is the first of the six requirements in article 31 bis.5 and it conditions everything else: a map copied from another sector does not identify your own risks.

02

Documented model and decision protocols

Code of ethics, criminal compliance policy, protocols setting out how the company forms its will and how decisions are taken and executed, financial controls, disciplinary system and an internal channel compliant with Law 2/2023. All of it with the traceability a UNE 19601:2025 audit requires.

03

The company constitutes the supervisory body, and we train

The supervisory body is constituted by the company, because the law requires it to be a body of the legal entity. We give it rules of procedure, an annual work plan, minute templates and indicators, and we train the board, middle management and exposed staff, with attendance records and assessment.

04

Periodic verification and updating

Scheduled review of the model with a report and minutes, plus an extraordinary review whenever a relevant breach appears or the organisation, the control structure or the activity changes. It is the sixth requirement of article 31 bis.5 and the only way the model is still effective three years from now.

What is included

What the service includes.

The operational detail: what we deliver when building the model and what we keep alive afterwards, month by month.

  • Criminal risk map by process

    Identification and assessment of the criminal risks relevant to the activity, with the likelihood and impact matrix, the controls that exist and those that are missing, and traceability between each risk and the process where it lives.

  • Complete organisation and management model

    Criminal compliance policy, code of ethics, decision protocols, controls over financial resources, disciplinary system and internal investigation procedure. The six requirements of article 31 bis.5, each with its documentary evidence.

  • Internal channel compliant with Law 2/2023

    An Internal Reporting System with the safeguards of Law 2/2023: anonymous channel, System Manager appointed within the entity itself, published policy, register and the legal deadlines for acknowledgement and resolution. Full detail in the whistleblowing channel service.

  • Rules and work plan for the supervisory body

    Documentation with which the company gives its internal body autonomous powers of initiative and control: rules of procedure, functional reporting line, budget, annual plan, minute templates and a reporting channel to the management body.

  • Training by level of exposure

    Separate sessions for the management body, for managers with decision-making power and for staff in exposed areas, with our own materials, a test and minutes that serve as evidence of effective implementation.

  • Documented periodic verification

    Scheduled review of the model with a conclusions report and action plan, and an extraordinary review when relevant breaches or organisational changes occur. Without this, the model does not meet the sixth requirement of article 31 bis.5.

  • Preparation for the UNE 19601:2025 audit

    When the organisation wants to be certified, we prepare the system for the certification body's audit: gap analysis against the requirements of the standard, evidence in order and support during the audit itself. The certificate is issued by the body, never by us.

  • Support during requests and inspections

    If an administrative request arrives or proceedings are opened, we organise and hand over the model documentation and the history of minutes. We work alongside the company's legal department or criminal law firm, without replacing them.

  • Coordination with the rest of compliance

    Data protection, anti-money-laundering, equality, transparency and public procurement all share evidence with the criminal model. We set it up once and reuse it, instead of running five systems that never talk to each other.

What this service is not

Four limits worth putting in writing before signing, because in criminal compliance the market promises things the law does not allow.

Your company's supervisory body

Article 31 bis.2, second condition, requires supervision of the model to be entrusted to a body of the legal entity, and both alternatives the law gives are internal. That body is constituted by the company and cannot be subcontracted. We equip it with method, documentation and external verification; we do not take its place.

Criminal Code, art. 31 bis.2
A UNE 19601 certificate

The certificate is issued by a certification body after its own audit. We prepare the system and support the process, but we do not audit or certify what we have implemented: that would be judge and party.

UNE 19601:2025
Legal defence in criminal proceedings

We do not take on the conduct of the defence or criminal law advice on a specific case. We provide the model, the minutes and the evidence, and we work alongside the firm running the defence.

Criminal Code, art. 31 quater
A manual that is delivered and closed

A model without periodic verification breaches the sixth requirement of article 31 bis.5 and stops being effective. That is why the service is monthly and not a project with an end date.

Criminal Code, art. 31 bis.5
Regulatory framework

The regulatory framework.

Article 31 bis of the Spanish Criminal Code, Law 2/2023 for the internal channel and UNE 19601:2025 as the technical reference standard.

CP Art. 31 bis Applies to this service
L 2/2023 Internal system Applies to this service
UNE 19601:2025 Voluntary technical reference
AIPI Whistleblowers Competent authority

Frequently asked questions about the external compliance consultant.

Am I required to have a criminal compliance model?

There is no general obligation in Spain to have a crime prevention model: article 31 bis.2 of the Criminal Code frames it as grounds for exempting the legal entity from criminal liability, not as a duty whose breach is penalised in itself. What is compulsory, and with a penalty regime of its own, is the Internal Reporting System under Law 2/2023: for natural and legal persons in the private sector with fifty or more employees and, with no headcount threshold, for those operating in financial markets, anti-money-laundering and counter-terrorist financing, transport safety and environmental protection, as well as political parties, trade unions, employers' organisations and their foundations when they receive or manage public funds. In practice, many companies arrive at the full model by a third route: a large client, a public tender or a corporate transaction that requires it by contract.

Can an external consultant be the supervisory body under article 31 bis?

No. The second condition of article 31 bis.2 requires supervision of how the model works and whether it is complied with to be entrusted to a body of the legal entity with autonomous powers of initiative and control, or to a body legally charged with supervising the effectiveness of that same legal entity's internal controls. Both options are internal. A contracted third party is not a body of the legal entity, so no consulting firm can hold that position by contract. What is possible, and what we do, is for the internal body to exist formally while an external consultant provides it with method, documentation, training and periodic verification. The article itself provides a single exception, and it is a matter of size: in small legal entities, those authorised to file an abridged profit and loss account, the supervisory functions may be assumed by the management body.

What is the difference between an external compliance consultant and an outsourced DPO?

They are different figures, and on the key point the rules are opposite. The Data Protection Officer is a role regulated by article 37 of the GDPR, can be a third party under a services contract and is formally notified to the Spanish Data Protection Agency. The criminal compliance supervisory body, by contrast, has to be internal because article 31 bis.2 of the Criminal Code requires it. An external compliance consultant works on the legal entity's criminal risk and on the Law 2/2023 channel; an outsourced DPO works on the processing of personal data. They meet at the whistleblowing channel and in the handling of internal investigations, which is why it helps for the same team to run both.

Is UNE 19601 compulsory?

No. UNE 19601 is a Spanish technical standard adopted voluntarily, not a law, and no Spanish legal text requires it to be implemented or certified. Its usefulness lies elsewhere: it offers a recognisable structure for the model, it forces evidence to be left for every requirement and, if the company is certified, it produces an independent third-party report backing its diligence. When citing it, cite the edition in force: UNE 19601:2025, “Sistemas de gestión del compliance penal. Requisitos con orientación para su uso”, which supersedes UNE 19601:2017.

My company is small — do I have to create a compliance committee?

Not necessarily. Article 31 bis.3 of the Criminal Code provides that in small legal entities — defined as those authorised to file an abridged profit and loss account — the model's supervisory functions may be assumed directly by the management body. That simplifies the structure but does not lower the content: the six requirements of paragraph 5 remain the same, and the management body has to be able to show that it genuinely exercises that supervision, with minutes and evidence. In an SME the work goes into making it proportionate and sustainable, not into reducing it to a document.

Can I outsource the management of the whistleblowing channel?

Partly, and the small print is worth reading. Article 6.1 of Law 2/2023 allows an external third party to be used and, in the same paragraph, sets the scope: management of the System is understood to be the receipt of reports. In other words, what is outsourced is the receipt, not the whole system. The third party must offer guarantees of independence, confidentiality, data protection and secrecy of communications (art. 6.2) and has the status of processor (art. 6.4). For its part, article 8 requires the System Manager, in the private sector, to be a senior manager of the entity appointed by the management body, and article 6.3 prevents external management from assigning responsibility for the system to anyone else. The competent authority at state level is the Independent Authority for the Protection of Whistleblowers.

There is already an investigation open. Is there any point in building the model now?

There is, though not for the same purpose. The exemption in article 31 bis.2 requires the model to have been adopted and effectively implemented before the offence was committed, so a later model cannot produce that effect. What remains is the mitigating circumstance in article 31 quater, letter d): having established, before the oral hearing begins, effective measures to prevent and detect offences that might in future be committed with the resources or under the cover of the legal entity. It reduces the penalty; it does not remove it. And the deadline is real: once the oral hearing has begun, that door closes too.

What am I exposed to if I do not have the Internal Reporting System?

Article 63.1 of Law 2/2023 classifies certain wilful acts and omissions as very serious infringements, and its letter g) is failure to comply with the obligation to have an Internal Reporting System on the terms required by that law. The requirement of intent matters: not every gap automatically falls into that band. Where it does, article 65.1.b) sets a fine for legal entities of between €600,001 and €1,000,000 for very serious infringements. Article 65.2 also allows the Independent Authority for the Protection of Whistleblowers to order, alongside the fine, a public reprimand, a ban on obtaining subsidies or other tax benefits for up to four years and a ban on contracting with the public sector for up to three years. These are discretionary measures, not automatic consequences, but for a company that regularly bids for public contracts the last one usually weighs more than the fine.

Shall we build it
together?

Request your free initial assessment — we reply within 24h.