AML Compliance: Protect Your Business from Money Laundering Risk
AML/CFT compliance programme for entities subject to Spain's Law 10/2010: policies, procedures, training, and SEPBLAC liaison.
Does this apply to your business?
Does your company qualify as an obligated entity under Law 10/2010, and if so, does your AML programme meet its minimum requirements?
Are your KYC procedures identifying and verifying the ultimate beneficial owners of your corporate clients?
Do you have a documented protocol for detecting and reporting suspicious transactions to the SEPBLAC within the required timeframe?
When did you last conduct an independent review of your AML risk assessment and prevention manual?
0 of 4 questions answered
Our AML compliance process
Risk assessment
We identify and assess the AML/CFT risks specific to your company based on your clients, products, distribution channels, and geographic areas of activity.
Programme design
We draft the prevention manual, customer due diligence (KYC) policies, enhanced due diligence procedures, and the internal control framework.
Implementation & training
We implement the procedures, train staff and management bodies, and appoint or advise the designated representative to the SEPBLAC.
Maintenance & audits
We conduct periodic programme reviews, update procedures in response to regulatory changes, manage SEPBLAC communications, and prepare the company for inspections.
The challenge
Penalties for non-compliance with Spain's AML Law can exceed one million euros. Beyond the regulatory risk, exposure to money laundering operations generates reputational and criminal risk for those responsible. Many obligated entities do not have the minimum controls required by law in place.
Our solution
We design and implement comprehensive anti-money laundering and counter-terrorist financing (AML/CFT) programmes tailored to each company's risk profile. From the prevention manual to SEPBLAC communications, we cover all requirements of Law 10/2010 and its implementing regulations.
Anti-money laundering (AML) compliance in Spain is governed by Law 10/2010 on the Prevention of Money Laundering and Terrorist Financing (as amended by RDL 7/2021 transposing the EU's 6th AML Directive), which imposes obligations on a defined list of obligated entities — including financial institutions, law firms, notaries, real estate agents, accountants, and company formation agents. These entities must apply customer due diligence (KYC), maintain internal prevention manuals, establish whistleblowing channels, report suspicious transactions to SEPBLAC (Spain's Financial Intelligence Unit), and designate an internal compliance representative. Non-compliance can result in sanctions exceeding EUR 1 million and criminal liability for individual managers.
Our AML compliance team has experience implementing prevention programmes for entities across multiple sectors: financial, real estate, legal, accounting, and business services.
The Compliance Obligation Many Businesses Underestimate
Spain’s Law 10/2010 on the Prevention of Money Laundering and Terrorist Financing applies to a much wider range of businesses than most companies realise. Beyond the obvious financial institutions, the law covers auditors, tax advisers, lawyers involved in real estate or corporate transactions, estate agents, real estate developers, accountants, trust service providers, and any professional adviser managing third-party funds or assets. Many SMEs in these sectors have never properly assessed whether they are obligated entities — or if they have, their compliance programme has not kept pace with regulatory developments.
The SEPBLAC has become progressively more active in its inspection and enforcement activity. Administrative sanctions for serious violations now routinely exceed one million euros. Personal liability for management bodies is also expressly provided for in the law: directors who allow a non-compliant programme to persist are not shielded by the corporate structure.
What an Effective AML Programme Actually Looks Like
The minimum requirements of Law 10/2010 are not met by a generic prevention manual downloaded from the internet. An effective programme requires a genuine risk assessment: a structured analysis of your specific client base, the products and services you provide, the geographic jurisdictions involved, and your distribution channels. Different businesses face radically different AML risk profiles, and the controls must be calibrated accordingly.
KYC is the operational heart of the programme. For corporate clients, this means going beyond the registered company to identify and verify the ultimate beneficial owners — the natural persons who ultimately control the entity. The beneficial-ownership register (RBE) provides a starting point, but its data cannot be relied on exclusively: discrepancies must be investigated. For politically exposed persons (PEPs) and clients from high-risk jurisdictions, enhanced due diligence is required, with documented justification for accepting the business relationship.
Our programmes are designed to be operational, not decorative. We train staff to apply the procedures in their daily work, not just to have attended a compliance presentation. When a transaction triggers a red flag, the team should know what to do: how to escalate, how to document the assessment, and when the obligation to report to the SEPBLAC arises.
AML in Corporate Transactions
When a company is being acquired, AML compliance is a critical dimension of due diligence. An inadequate programme inherited through an acquisition creates immediate regulatory exposure for the buying group. We conduct AML-specific due diligence reviews for acquirers of obligated entities, quantify the remediation cost, and advise on the representations and warranties that should be included in the sale agreement to protect the buyer.
For businesses undergoing restructuring that changes their client base or geographic footprint, the AML risk assessment must be updated to reflect the new profile. A programme designed for a domestic client base may be wholly inadequate after an international expansion.
Real results in AML compliance
We had a SEPBLAC inspection announced with 10 days' notice and our AML programme was essentially a document from 2018 that no one had touched since. BMC ran a rapid gap remediation, updated the risk assessment and KYC procedures, prepared the compliance file, and briefed our management team. The inspection identified minor process gaps but no sanctions. Their crisis management was exceptional.
Experienced team with local insight and international reach
What our AML compliance service includes
AML Risk Assessment
Structured identification and assessment of money-laundering and terrorist-financing risks specific to your client base, products, channels, and geographies, with a formal risk matrix and scoring model.
Prevention Manual & KYC Policies
Drafting of the complete AML prevention manual, standard and enhanced customer due-diligence procedures, beneficial-ownership identification protocols, and PEP screening processes.
SEPBLAC Representation
Appointment and advisory support for the designated representative to the SEPBLAC, management of mandatory communications, and suspicious transaction report preparation.
Staff Training
Role-specific training programmes for front-line staff, management bodies, and the compliance function on AML obligations, red-flag identification, and reporting procedures.
Pre-Inspection Preparation & Audits
Independent programme effectiveness reviews, gap remediation, compliance file preparation, and management coaching ahead of SEPBLAC inspections.
Results that speak for themselves
Commercial debt portfolio recovery
92% portfolio recovery in 4 months, with out-of-court settlements in 78% of cases.
Comprehensive employment defense for industrial multinational
100% favorable outcomes: 5 advantageous conciliation agreements and 3 fully upheld court rulings.
GDPR compliance programme for a hospital group: from investigation to full compliance
AEPD investigation closed with no sanction. Full GDPR compliance achieved across all group centres within 6 months.
Analysis and perspectives
Sectors where we apply this service
Frequently asked questions about AML compliance
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
Anti-Money Laundering (AML)
Legal
First step
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
Request your diagnostic
You may also be interested in
Entity Management
Full-service corporate entity administration that frees your leadership team from the operational burden of compliance.
Saber másDue Diligence
Exhaustive risk and opportunity analysis for informed, confident investment decisions.
Saber másTax Compliance
Comprehensive management of periodic tax obligations: return filing, tax calendar, compliance audits, and representation before the Spanish Tax Agency (AEAT).
Saber másCompliance Risk Mapping
Comprehensive compliance risk mapping: regulatory obligation register, risk heat maps, multi-regulatory gap analysis (GDPR, NIS2, AI Act, AML), and regulatory change management.
Saber másCriminal Compliance
Corporate criminal compliance programmes to exempt or mitigate the criminal liability of legal entities under Article 31 bis of the Spanish Criminal Code.
Saber másData Protection & Privacy
GDPR and LOPDGDD compliance, outsourced DPO, and comprehensive privacy management for businesses.
Saber másKey terms
Due Diligence
Due diligence is the structured investigation and analysis of a target company or asset before a…
Read definitionForeign Investment in Spain
Foreign direct investment (FDI) in Spain refers to capital, technology, or productive resources…
Read definitionSociedad Limitada (SL) — Spanish Limited Liability Company
A Sociedad Limitada (SL) is Spain's most common corporate structure, equivalent to a UK Limited…
Read definition