Skip to main content
Spain's Public Integrity Law Demands Compliance OverhaulAnti-Corruption & AML
6 min readFor Compliance Training Managers

Spain's Public Integrity Law Demands Compliance Overhaul

The Challenge

The Council of Ministers in Spain has approved a Draft Organic Law on Public Integrity, fundamentally changing compliance for companies doing business with the public sector. This is not a minor update; it's a restructuring of corporate accountability. Criminal compliance models are now mandatory for public procurement, and internal reporting systems must align with broader integrity frameworks.

The core challenge is clear: companies that previously relied on voluntary practices now face mandatory requirements with significant consequences. The draft extends the statutes of limitation for corruption offenses from five to seven years, introduces fines based on annual turnover or unlawful benefit, and mandates Recusal from public contracts. Previously, companies could face penalties but still bid on government work. Now, that safety net is gone.

For compliance teams, this creates an immediate planning dilemma. The law isn't in effect yet and may change during the legislative process. Waiting for final approval could mean rushing to update systems under pressure, while moving too early risks building to specifications that might change.

Navigating the Environment

Spain's regulatory environment has been tightening, and this draft represents a significant shift. Companies face overlapping mandates: the Spanish Capital Companies Act governs corporate disclosure, the Whistleblower Protection Act sets internal reporting requirements, and now this draft law links those systems together.

The draft proposes amending the Whistleblower Protection Act to require entities with internal reporting systems to also have a "compliance or integrity system" in place. This means your speak-up program can't be a standalone HR function anymore. It must connect to your criminal compliance framework, conflict-of-interest protocols, and public procurement controls.

The timing adds complexity. With the draft's status uncertain, companies face regulatory ambiguity during the design phase. Should you build to the current text or anticipate amendments? How much capital should you allocate to system changes before the final language is set?

Resource allocation is another constraint. The draft requires mandatory registration of shareholdings with the Commercial Registry and additional disclosure obligations. These aren't one-time tasks; they require ongoing monitoring and reporting infrastructure. For companies already stretched thin, adding new workflows and controls means tough choices about headcount, technology investment, and program priorities.

A Strategic Approach

The draft doesn't specify a company's response, but it suggests a clear path forward. Companies are focusing on three areas: compliance model documentation, procurement process redesign, and reporting system integration.

First, the criminal compliance model requirement for public sector contracting demands documentation discipline. The draft specifies "an appropriate organization and management model for integrity and the prevention of criminal offenses, together with effective supervision thereof." This means more than policy statements; you need documented risk assessments, control procedures, monitoring mechanisms, and evidence of active supervision.

Second, procurement teams are redesigning processes to capture conflict-of-interest declarations from all participants. This isn't just a form to sign; it requires systems to track participants, identify potential conflicts, and maintain records that can withstand scrutiny during the extended seven-year limitation period.

Third, compliance teams are mapping connections between internal reporting channels and broader integrity frameworks. The draft's amendment to the Whistleblower Protection Act requires publicizing "the general principles governing internal reporting systems and the protection of whistleblowers" within a documented compliance or integrity system. This integration work reveals gaps. Does your Standards of Business Conduct reference your reporting channels? Are your training materials consistent across these systems?

Anticipated Impact

Since the legislation is still a draft, there are no implementation results yet. However, we can assess the regulatory impact it creates.

The extension of statutes of limitation from five to seven years increases the compliance record-retention burden by 40%. Companies need to maintain investigation files, training records, and due diligence documentation for two additional years. This isn't just about storage costs; it's about ongoing data governance and retrieval capability.

The shift from discretionary to mandatory Recusal for public contracts changes the risk calculus entirely. Under the previous framework, a compliance failure might result in fines but preserve market access. Now, a single substantiated corruption case triggers automatic exclusion from public subsidies, grants, and contracting opportunities. For companies where government work represents significant revenue, this transforms compliance from a legal obligation to an existential business requirement.

The introduction of fines based on annual turnover or unlawful benefit creates exposure that scales with company size. This penalty structure makes robust compliance programs a financial necessity.

Lessons Learned

The draft's status as proposed legislation offers a unique opportunity to prepare. However, this window also creates the risk of preparing for the wrong final version.

If this process were repeating, the lesson would be to start with integration work first. Connecting internal reporting systems to compliance frameworks and documenting those connections takes longer than expected. It requires coordination across legal, HR, compliance, and operations. Starting early, even before final legislative language, means you're building the infrastructure that will be required regardless of specific regulatory details.

The second adjustment would be treating the criminal compliance model requirement as a documentation project, not just a policy project. Many companies have adequate controls but poor documentation. The draft's emphasis on "effective supervision" means you need evidence that your compliance program operates in practice. Starting documentation practices now builds the track record you'll need when the law takes effect.

Third, companies should invest in conflict-of-interest disclosure systems earlier. This requirement affects every public procurement participant, touching business development, project teams, and external partners. Building the intake and tracking infrastructure for these declarations before it's mandatory allows you to test the workflow and identify problems when the stakes are lower.

Takeaways for Your Team

If your company does business with the Spanish public sector or plans to, start mapping your compliance program against the draft's requirements now. You don't need to wait for final approval to identify gaps.

Document your criminal compliance model with specificity. "We have a Standards of Business Conduct" isn't enough. You need documented risk assessments, control procedures, monitoring activities, and evidence of supervision. Build those artifacts now, even if the final law's language shifts.

Integrate your internal reporting channels into your broader compliance framework explicitly. Don't treat your speak-up program as separate from your anti-corruption policies, conflict-of-interest procedures, and procurement controls. The draft requires visible connections between these systems. Make those connections clear in your documentation and training.

Extend your record retention periods for corruption-related documentation to seven years. The draft's statute of limitations extension means you need to maintain investigation files, due diligence records, and compliance evidence for longer periods. Adjust your Record Retention Policy now to avoid scrambling later.

Treat public contract Recusal as a binary outcome. The shift from discretionary to mandatory exclusion means there's no middle ground. A substantiated compliance failure ends your ability to pursue government work. That reality should inform your risk tolerance and resource allocation for compliance controls.

Finally, build conflict-of-interest declaration systems that scale. If you're bidding on public contracts, you'll need to capture declarations from all participants. Design intake processes, tracking mechanisms, and documentation workflows that can handle volume without creating bottlenecks.

The Draft Organic Law on Public Integrity isn't final, but its direction is clear. Companies that prepare now will adapt faster when the law takes effect. Those that wait will face compressed timelines and higher implementation costs in a regulatory environment that no longer tolerates gaps.

You Might Also Like