Skip to content

Compliance Risk Map: All Your Regulatory Risks in One Place

Comprehensive compliance risk mapping: regulatory obligation register, risk heat maps, multi-regulatory gap analysis (GDPR, NIS2, AI Act, AML), and regulatory change management.

Why fragmented compliance management creates critical risks

12+
European regulations typically applicable to a mid-sized company operating in Spain
Heat map
Instant visualisation of the regulatory risk profile for board and management
€35M
Combined maximum fine from AI Act and GDPR alone for a single company
4.8/5 on Google · 50+ reviews 25+ years experience 5 offices in Spain 500+ clients
Quick assessment

Does this apply to your business?

Do you have a complete inventory of all regulations applicable to your company, with current compliance status for each?

Can you present to your board a regulatory risk heat map showing where the critical compliance risks are?

Does your company have a systematic process that alerts on new regulatory obligations before they take effect?

Have you quantified the effort and cost of remediating existing compliance gaps to prioritise the compliance budget?

0 of 4 questions answered

Our approach

Our compliance risk mapping process

01

Regulatory universe mapping

We identify the complete set of regulations applicable to the organisation based on its sector, activities, operating jurisdictions, and data profile. We build the compliance obligation register with regulatory source, effective date, responsible area, and non-compliance risk level.

02

Multi-regulatory gap analysis

We assess current compliance levels against each applicable regulation, identify existing gaps, and prioritise them by regulatory risk level, potential sanction, and remediation effort. The result is a heat map that immediately visualises the compliance risk profile.

03

Remediation plan and resource allocation

We develop the prioritised remediation plan: corrective actions by regulation and gap, implementation schedule, estimated budget, responsible areas, and tracking metrics. We identify synergies between regulations that allow multiple obligations to be addressed through common initiatives.

04

Compliance dashboard and regulatory change management

We implement the compliance dashboard for periodic monitoring of compliance status by regulation, and the regulatory monitoring system that alerts on new obligations, interpretive guidance, and relevant enforcement decisions before they affect the organisation.

The challenge

The European regulatory landscape is now the most complex in history: GDPR, NIS2, DORA, AI Act, AML/AMLA, MAR, ESG, the Corporate Sustainability Reporting Directive. Companies operating across multiple sectors or countries accumulate dozens of compliance obligations monitored in silos, with no consolidated view of interactions, redundancies, or gaps. The result is inefficient compliance that consumes excessive resources in low-risk areas while leaving high-risk areas exposed.

Our solution

We develop comprehensive compliance risk maps that give management and the board a consolidated, prioritised view of the regulatory universe applicable to their organisation: obligation registers, risk heat maps, gap analysis by regulation, and a regulatory change tracking system that alerts on new obligations before they take effect.

Compliance risk mapping is a structured methodology for identifying, classifying, and prioritising all regulatory obligations applicable to an organisation across multiple legal frameworks — including GDPR, NIS2, DORA, the EU AI Act, AML Law 10/2010, and sector-specific regulations — and assessing the organisation's current compliance status against each. The output is typically a compliance risk register and heat map that enables management to allocate resources efficiently, address the highest-risk gaps first, and maintain a consolidated view of multi-regulatory exposure rather than managing obligations in isolated silos. This methodology is aligned with international compliance standards such as ISO 37301.

Our compliance team combines deep knowledge of the European regulatory landscape with practical experience managing the compliance function in companies across all sectors and sizes.

A Regulatory Landscape That Has Outpaced Traditional Compliance

The European regulatory environment has undergone unprecedented densification in the last five years. GDPR, NIS2, DORA, AI Act, AMLA, the Corporate Sustainability Reporting Directive — each of these regulations is itself a substantial compliance project. For companies operating across multiple sectors or countries, the accumulation of overlapping obligations creates management complexity that traditional compliance models are not designed to handle efficiently.

The Compliance Map as a Management System

The compliance risk map is the response to this complexity — not a static document, but a living management system that provides management with consolidated visibility of the applicable regulatory universe, prioritised by risk level and continuously updated. The difference between an organisation with a good compliance map and one without it is measured not only in avoided sanctions: it is also measured in compliance spend efficiency, the capacity to anticipate regulatory changes, and the quality of information reaching the board for governance decisions.

The Multi-Regulatory Gap Analysis

The multi-regulatory gap analysis is the instrument that turns the map into a real management tool. Knowing that the company is 80% compliant with GDPR but has a critical gap in third-party risk management under NIS2, that the AI Act applies through two systems not identified as high-risk, and that the AML programme does not cover obligations under the new Directive — this allows compliance resources to be prioritised where real risk is highest, rather than over-investing in visible compliance while underestimating areas of greatest enforcement exposure.

Regulatory Synergies as Efficiency Driver

Synergies between regulations are a significant efficiency source that fragmented compliance management wastes. AI Act impact assessments and GDPR DPIAs can be designed as an integrated process when they affect the same system. NIS2 cybersecurity controls and GDPR technical security requirements are largely satisfied by the same measures. The incident register for DORA and for NIS2 can be unified. Identifying and leveraging these synergies is a central component of the remediation plans we develop, with direct impact on reducing compliance costs — and on ensuring that data protection, AI Act compliance, and enterprise risk management are managed as an integrated system rather than independent silos.

The Board Compliance Dashboard

The compliance dashboard for the board is the final product of the system. A board cannot manage regulatory risk it cannot see: the heat map, presented regularly with changes from the prior period and upcoming regulatory changes with significant impact, gives the board the information it needs to exercise its oversight function without requiring immersion in the technical detail of each regulation. This communication is also documented evidence that the board has fulfilled its regulatory compliance oversight responsibility — directly relevant in any regulatory investigation or corporate due diligence process where a counterparty assesses the organisation’s compliance governance.

The Criminal Liability Dimension

Corporate criminal liability under Article 31 bis of the Spanish Penal Code requires companies to demonstrate that they had an effective compliance programme capable of preventing the offence. The compliance risk map is the documentary foundation of this defence: it shows that the organisation systematically identified the regulatory and criminal risks relevant to its activity, assessed their probability and impact, and implemented controls proportionate to those risks. A company that faces a criminal investigation without a documented, functioning compliance framework has structurally weakened its legal position. Our criminal compliance team works alongside the compliance risk mapping function to ensure the criminal dimension of the risk register is addressed with appropriate rigour.

Compliance Budget Planning

The prioritised compliance budget is one of the most valuable operational outputs of the mapping process. Compliance spend without a risk map defaults to visible compliance — prioritising certifications, audits, and documentation that look like compliance but may not address the areas of highest real risk. The gap analysis by regulation, with estimates of remediation effort, required external resources, and technology implementation costs, provides the basis for a compliance budget that is defensible to the board and rationally allocated across risk priorities.

Ongoing Regulatory Monitoring

The compliance risk map is only as valuable as it is current. European regulatory production has been at a historically high level throughout the 2020s, and the pace is not slowing. Our regulatory monitoring service — integrated with the compliance map — provides structured alerts on new obligations, interpretive guidance from supervisory authorities, and relevant enforcement decisions. The NIS2 compliance and DORA compliance services are coordinated through the same monitoring infrastructure, ensuring that sector-specific obligations are captured within the consolidated risk view.

Sectors Most Affected by Multi-Regulatory Complexity

Financial services: combining DORA, GDPR, AML/CFT, MiFID II, PSD2, and the AI Act creates compliance challenges that cannot be managed in isolated teams. A consolidated compliance map is the only management tool that provides the board with a coherent picture of regulatory exposure across all these frameworks simultaneously.

Healthcare and life sciences: GDPR (health data, Art. 9 special category), NIS2, AI Act (medical device AI), MDR/IVDR, and AEMPS sector regulation create a multi-framework environment where every product launch and digital initiative triggers obligations across multiple authorities. Compliance silos in this sector regularly create gaps at the intersections.

Technology and SaaS companies: GDPR, AI Act (for AI-enabled products), NIS2 (for digital infrastructure providers), and ePrivacy (for digital services with cookies and analytics) create a compliance matrix that must be addressed systematically from product design stage rather than retrofitted after launch.

Retail and e-commerce: GDPR (customer data, marketing consent, loyalty programmes), ePrivacy (cookies, tracking), consumer protection (EU Omnibus Directive), and AI-powered personalisation or pricing create multi-regulatory obligation sets that are frequently underestimated by e-commerce operators until the first regulatory inquiry.

Worked Example: Compliance Map for a FinTech

A Spanish FinTech (55 employees, EUR 8 million revenue) operating a digital lending platform sought compliance risk mapping ahead of a Series B funding round. The investors’ due diligence required documented compliance status across all applicable regulations.

BMC identified 7 applicable regulatory frameworks: GDPR, NIS2 (important entity in financial market infrastructure), DORA (payment institution), AI Act (high-risk credit scoring system), AML/CFT (obliged entity as credit intermediary), ePrivacy, and LSSICE. Gap analysis revealed 3 critical gaps, 6 high gaps, 11 medium gaps. The compliance investment estimate (EUR 180,000 over 12 months) was presented to investors as a use-of-funds line item; the risk heat map satisfied the due diligence requirement and the Series B round closed on schedule.

Common Mistakes We Fix

  1. Managing compliance in departmental silos. Data protection in legal, cybersecurity in IT, AML in operations — with no consolidated view. The result is overlapping effort where frameworks share requirements, and gaps where no single team feels ownership.

  2. Prioritising visible compliance over risk-based compliance. Certifications and policies that look like compliance without addressing the highest-probability, highest-impact risks. Regulators inspect substance, not appearance.

  3. Not updating the compliance map when the business changes. New products, markets, acquisitions, and technology integrations change the compliance risk profile. A map that is not updated regularly becomes a misleading comfort rather than a risk management tool.

  4. Treating compliance as a cost centre. Without a quantified risk assessment, compliance investment cannot be prioritised. The compliance risk map enables decisions based on expected risk reduction — the same logic applied to any other risk management investment.

  5. Not preparing for regulatory investigations proactively. Investigations are more manageable when the organisation can produce a documented programme, a gap analysis, and evidence of good-faith remediation. Without this documentation, a compliance gap looks like negligence; with it, the same finding can be contextualised as a known and managed risk.

How We Work

Phase 1 — Regulatory scope assessment (2-3 weeks): identification of all applicable regulatory frameworks based on sector, activities, size, and geographic scope.

Phase 2 — Gap analysis and heat map (3-4 weeks): assessment of current compliance status against each identified obligation, producing the risk heat map with probability and impact ratings for the board.

Phase 3 — Remediation roadmap and ongoing monitoring: prioritised action plan with timelines, responsibility assignments, and investment estimates; ongoing regulatory monitoring to capture new obligations and update the map quarterly.

The compliance risk map is delivered as both a board-ready governance document and a working operational management tool.

The Criminal Liability Dimension

Corporate criminal liability under Article 31 bis of the Spanish Penal Code requires companies to demonstrate that they had an effective compliance programme capable of preventing the offence. The compliance risk map is the documentary foundation of this defence: it shows that the organisation systematically identified the regulatory and criminal risks relevant to its activity, assessed their probability and impact, and implemented controls proportionate to those risks. A company that faces a criminal investigation without a documented, functioning compliance framework has structurally weakened its legal position. Our criminal compliance team works alongside the compliance risk mapping function to ensure the criminal dimension of the risk register is addressed with appropriate rigour.

The Board Compliance Dashboard

A board cannot manage regulatory risk it cannot see. The compliance dashboard translates the risk map’s technical content into board-level reporting: a heat map updated quarterly showing which regulatory risks are red (critical, immediate action required), amber (significant, remediation in progress), yellow (moderate, managed), and green (compliant). The dashboard also shows upcoming regulatory changes with impact assessments — allowing the board to allocate resources to emerging obligations before they become enforcement risks.

This communication is also documented evidence that the board has fulfilled its regulatory compliance oversight responsibility — directly relevant in any regulatory investigation or corporate due diligence process where a counterparty assesses the organisation’s compliance governance quality.

Compliance Budget Planning

The prioritised compliance budget is one of the most valuable operational outputs of the mapping process. Compliance spend without a risk map defaults to visible compliance — prioritising certifications, audits, and documentation that look like compliance but may not address the areas of highest real risk. The gap analysis by regulation, with estimates of remediation effort, required external resources, and technology implementation costs, provides the basis for a compliance budget that is defensible to the board and rationally allocated across risk priorities.

Companies that approach compliance budgeting from a risk map perspective consistently spend less than those that budget by regulatory framework independently — because the synergies between frameworks (shared controls, integrated assessments, unified documentation) are only visible in a consolidated view. The compliance risk map directly enables this efficiency.

Regulatory Synergies as an Efficiency Driver

Synergies between regulations are a significant efficiency source that fragmented compliance management wastes. AI Act impact assessments and GDPR DPIAs can be designed as an integrated process when they affect the same system. NIS2 cybersecurity controls and GDPR technical security requirements are largely satisfied by the same measures. The incident register for DORA and for NIS2 can be unified. Identifying and leveraging these synergies is a central component of the remediation plans we develop, with direct impact on reducing compliance costs.

The compliance risk map quantifies these synergies: for each remediation project, we identify which other regulatory obligations are simultaneously satisfied by the same control implementation. A single endpoint detection and response (EDR) deployment may satisfy NIS2 Art. 21 malware detection requirements, GDPR Art. 32 technical security measures, DORA ICT risk management controls, and ISO 27001 Annex A controls simultaneously. Without the consolidated map, this cross-regulatory efficiency is invisible.

Geographic Coverage

We design and maintain compliance risk maps for companies across all Spanish territories. For multinational organisations, we coordinate with EU counsel to extend the map to cover compliance obligations in other member states, producing a single consolidated group compliance view. Our regulatory monitoring service covers EU-level regulatory developments and national transpositions across all major EU jurisdictions, updated monthly with an alert service for significant changes.

For companies with operations in the Basque Country and Navarra (Haciendas Forales), the Canary Islands (IGIC and specific ZEC obligations), or Ceuta and Melilla (IPSI), the compliance risk map must account for the specific tax and regulatory frameworks applicable in these territories alongside the national and EU frameworks — creating an additional compliance dimension that national-level mapping exercises typically overlook.

Compliance Risk Mapping in M&A and Investment Transactions

Compliance risk maps are increasingly used as due diligence instruments in M&A transactions and capital rounds. Acquirers, investors, and their advisers use the compliance risk map to:

  • Identify regulatory risks that are not reflected in the financial statements (unquantified GDPR or DORA exposure, pending AEPD investigations, AML programme gaps that could trigger SEPBLAC scrutiny).
  • Assess the remediation cost to bring the target to a compliant state — a direct input to valuation adjustments and purchase price conditions.
  • Identify representations and warranties that should be included in the purchase agreement regarding the completeness and accuracy of the compliance programme.
  • Evaluate whether any regulatory authorisations held by the target are at risk due to compliance gaps (banking licences, investment firm authorisations, insurance operating licences).

We prepare compliance risk maps on behalf of sellers — as a pre-sale exercise to identify and remediate compliance gaps before buyer due diligence — and on behalf of buyers, as an independent compliance due diligence exercise that informs the acquisition decision and the purchase agreement negotiation. In both roles, the compliance risk map is the foundation of the compliance dimension of the transaction.

ISO 37301 and International Compliance Standards

The compliance risk map methodology is aligned with ISO 37301:2021 (Compliance Management Systems — Requirements with guidance for use), which is the international standard for compliance management. ISO 37301 requires organisations to:

  • Identify and assess compliance obligations (equivalent to the regulatory scope assessment phase of the compliance risk map).
  • Assess the risks of non-compliance (equivalent to the gap analysis and heat map).
  • Implement controls to address compliance risks (equivalent to the remediation roadmap).
  • Monitor and evaluate compliance performance (equivalent to the ongoing monitoring service).

For organisations seeking ISO 37301 certification — which is increasingly required in regulated sectors and in supplier qualification processes — the compliance risk map provides the documented compliance obligation register and risk assessment that the certification process requires. We design compliance risk maps that simultaneously serve as operational management tools and as ISO 37301 certification documentation.

The Compliance Function in Corporate Governance

The compliance risk map is the instrument that connects the compliance function to the board of directors. Under the Spanish corporate governance framework (LSC, CNMV Good Governance Code), the board is responsible for overseeing the company’s compliance with applicable regulations and for ensuring that the compliance management system is adequate. The compliance dashboard — derived from the risk map — is the standard mechanism for discharging this oversight obligation.

For companies subject to CSRD (Corporate Sustainability Reporting Directive), the compliance function’s oversight of the organisation’s material regulatory risks is a disclosed element of the annual sustainability report under ESRS G1 (Business Conduct). The compliance risk map provides the evidentiary foundation for this disclosure.

Track record

Real results in compliance risk management

Our compliance team was overwhelmed trying to keep up with the pace of new European regulations without a clear view of where the priority risks were. BMC built the complete map: 14 applicable regulations, a gap analysis for each, and a heat map that for the first time allowed us to present the board with a real picture of our regulatory risk. Within six months we had remediated the three critical gaps identified.

Iberian Health Group S.A.
Chief Compliance Officer

Experienced team with local insight and international reach

What our compliance risk mapping service includes

Regulatory universe mapping and obligation register

Identification of all applicable regulations, construction of the compliance obligation register with regulatory source, effective date, responsible area, and non-compliance risk level.

Gap analysis and risk heat map

Assessment of current compliance levels by regulation, identification and quantification of gaps, and construction of the regulatory risk heat map prioritised by impact and likelihood.

Prioritised remediation plan

Action plan by regulation and gap: corrective actions, schedule, owners, estimated budget, and tracking metrics. Identification of regulatory synergies to maximise compliance efficiency.

Compliance dashboard for management and board

Compliance dashboard with key compliance indicators (KCIs), updated heat map, remediation status, and alerts on relevant regulatory changes.

Regulatory monitoring system

Implementation of the regulatory change tracking system: monitoring of new regulations, interpretive guidance, enforcement decisions, and regulatory proposals with organisational impact.

Guides

Reference guides

Post-Brexit: your British company operating in Spain with the right structure

post-Brexit advisory for UK companies operating in Spain: entity structuring, customs and VAT, work permits for British nationals, UK-Spain tax treaty optimisation and data protection compliance.

View guide

AML compliance in Spain 2026: what your business must know about anti-money laundering regulation

Spain AML compliance 2026: SEPBLAC obligations, risk-based approach, PBC manual, UBO verification, and suspicious transaction reporting. Expert service from BMC.

View guide

Comprehensive legal services for businesses

Comprehensive legal advisory for businesses: commercial, employment, contracts, regulatory compliance, and dispute resolution. A dedicated legal team to protect your company.

View guide

Buy property in Spain with confidence — and without the horror stories

Buying property in Spain 2026: NIE, conveyancing, ITP tax, mortgage advice, and due diligence for foreign buyers. Step-by-step guide from BMC property lawyers.

View guide

The collective agreement that governs your workforce: understand it and negotiate from strength

Spain collective bargaining guide: union negotiation obligations, ERE/ERTE triggers, works council rights, agreement registration, and how BMC protects employer interests.

View guide

Your commercial lease agreement: get the clauses right before you sign

Spain commercial lease guide: LAU legal framework, rent review clauses, break options, guarantee structures, and key negotiation points for tenants and landlords.

View guide

Service Lead

Bárbara Botía Sainz de Baranda

Senior Lawyer — Legal Division

Registered no. 11,233, Málaga Bar Association (ICAM) Law Degree, University of Murcia BBA in Business Administration, University of Murcia
FAQ

Frequently asked questions about compliance risk mapping

The scope depends on the company's sector and activities, but for a mid-sized company operating in Spain and the EU the map typically includes: GDPR and LOPDGDD (privacy), NIS2 (cybersecurity for essential and important entities), AI Act (AI systems), AML/AMLA (money laundering, where applicable), Corporate Criminal Liability (criminal compliance), labour law, tax law, and sector-specific regulation. Financial entities add DORA, MiFID II, IDD, CRR/CRD. Listed entities add MAR and the Corporate Sustainability Reporting Directive.
A compliance heat map is a visual representation of the organisation's regulatory risk profile: each regulation or set of obligations is placed in a two-dimensional matrix according to current non-compliance likelihood and potential impact (sanction, reputation, operations). The result is an immediate image of where critical risks lie (red), important risks requiring attention (yellow), and well-managed areas (green). It is the most effective tool for communicating compliance risk to the board and senior management.
Recent European regulations are designed with awareness of their overlaps, but in practice the interactions generate both synergies and conflicts. AI Act impact assessments and GDPR DPIAs must be coordinated for AI systems processing personal data. NIS2 and DORA incident management obligations have different timelines and addressees. Systematically identifying and managing these interactions is a significant source of efficiency for compliance functions.
The compliance obligation register is the central document of the compliance management system: it captures all legal and regulatory obligations applicable to the organisation, the regulatory source of each, the effective date, the business area or process responsible for compliance, existing controls satisfying the obligation, current compliance level, and the individual within the organisation accountable for the obligation.
The compliance map requires active maintenance. The regulatory monitoring system we implement continuously tracks new regulations and amendments to applicable regulations, interpretive guidance from supervisory authorities, relevant enforcement decisions that clarify application criteria, and regulatory proposals that will be effective within the next 12-24 months. This regulatory intelligence is channelled to the compliance team to update the map and alert on changes requiring action.
Yes — and this is one of its most valuable uses. The quantified gap analysis by regulation — with estimates of remediation effort, required external resources, and technology implementation costs — is the most solid basis for building the compliance function budget and justifying it to management. Companies that prioritise the compliance budget without a risk map tend to over-invest in visible compliance and underestimate the areas of greatest real risk.
The board needs a compliance view that enables it to fulfil its oversight responsibility without getting lost in technical detail. The compliance dashboard we design for the board presents: the consolidated regulatory risk heat map, changes in the risk profile from the prior period, identified non-compliances and their remediation plan, material regulatory changes in the period and upcoming ones with significant impact, and the status of key compliance indicators (KCIs).
A compliance audit is a point-in-time exercise assessing compliance level at a specific moment, typically for a single regulation. The compliance risk map is a permanent, multi-regulatory system providing a consolidated, up-to-date view of the applicable regulatory universe, prioritising compliance risks comparatively across regulations, and integrating regulatory change continuously. The audit is a photograph; the map is the navigation system.
First step

Start with a free diagnostic

Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.

Compliance Risk Mapping

Legal

Talk to the partner in charge

Response within 24 business hours. First meeting free.

Services
Contact
Insights