Support for Implemented or Implementing REGULATORY COMPLIANCE Systems

Scales of justice in front of a lawyer reviewing compliance protocols.

Important: This article is a reprint of a 2015 publication on compliance systems, criminal liability of legal entities, and external support for prevention models following the reform enacted by Organic Law 1/2015.

Since then, the interpretation of criminal liability models has been shaped by subsequent guidelines, including the Circular 1/2016 issued by the State Attorney General’s Office.

Therefore, this post should be read as a historical reference on the initial phase of implementing and strengthening criminal compliance systems in Spain.

The implementation of compliance systems took on particular importance following the reform of the Penal Code enacted by Organic Law 1/2015. In this context, companies began to pay increasing attention to prevention, oversight, and internal control models aimed at reducing criminal risks and demonstrating a genuine commitment to compliance.

This article analyzes support for regulatory compliance systems that are already in place or in the process of being implemented, with a particular focus on the outsourcing of functions related to continuous improvement, auditing, process adaptation, and support for the Compliance Officer.

Support for regulatory compliance systems that are already in place or being implemented

As you are aware, effective as of the Organic Law 1/2015, the Penal Code requires a prevention or compliance system that meets the specific requirements and conditions set forth in the current Article 31 bis.2, paragraphs 1 through 4, of the Criminal Code, in order to achieve full exemption from criminal liability for both the company and the members of its governing bodies or executives who might potentially be affected.

The reform introduced a significant change in how criminal prevention is understood within organizations. It was no longer simply a matter of reacting to a criminal act after it had occurred, but rather of having pre-established structures for monitoring, control, and prevention that would reduce the risk of crimes being committed within the company.

From this perspective, compliance systems should not be viewed as static documents, but rather as legal and organizational management tools tailored to each company’s specific activities, its internal structure, and the risks inherent to its industry.

Continuous Improvement of the Compliance System

The goal of full exemption requires the implementation of a continuous improvement process based on risks as they are identified or on changes that affect the organization.

This concept of continuous improvement is particularly important because a compliance system can only be effective if it is reviewed, updated, and adapted to the company’s current situation. Business risks can vary due to changes in operations, organizational growth, the addition of new departments, geographic expansion, contracts with third parties, or changes to internal procedures.

For this reason, the compliance system must be reviewed periodically. The identification of new risks, the occurrence of incidents, questions regarding interpretation, or changes in the company’s structure may require adjustments to protocols, manuals, internal controls, or corrective measures.

Outsourcing of Compliance System Support

The outsourcing of continuous improvement services can take place in various areas; for example, from general or specific audits to proposing corrective measures, adapting processes or manuals, resolving inquiries or issues that require specialized knowledge or dedicated attention, as well as providing support to the Compliance Officer or even performing that role as an external consultant.

Outsourcing can be particularly useful when a company needs an independent technical perspective, a specialized review, or ongoing support to strengthen the model’s performance. It may also be relevant when an organization already has a system in place but needs to verify whether that system continues to adequately address the identified risks.

External support can take various forms: document review, model audit, risk analysis, proposals for improvements, updating of manuals, assistance to the supervisory body, resolution of internal inquiries, or guidance on adapting the system to new organizational needs.

External Compliance Officer and Independence of Oversight

With regard to the external Compliance Officer, it is worth highlighting the provisions of Article 31 bis.2.2(a), which establishes that oversight of the operation and compliance with the implemented prevention model must be entrusted to a body within the legal entity that has autonomous powers of initiative and control or that is legally entrusted with the function of supervising the effectiveness of the legal entity’s internal controls.

The reference to autonomy in initiative and oversight was particularly relevant, because the compliance system could not depend exclusively on a formal structure lacking any real oversight capacity. For the model to fulfill its purpose, the body or individual responsible for oversight needed to have sufficient authority to review, issue warnings, propose measures, and take action in response to detected noncompliance or risks.

Based on the text itself, it is recognized that this entity may initially be separate from the legal entity itself but, after becoming part of the company, may be legally entrusted with the function of overseeing the compliance system or may collaborate with the legal entity’s body responsible for that function, since it is clear that the party entrusted with the function of overseeing the effectiveness of the legal entity’s internal controls must be external to the entity.

External involvement could also provide greater technical expertise in criminal, commercial, organizational, and regulatory matters. In companies with complex structures or significant risks, support from external professionals helped strengthen the independence, objectivity, and analytical capacity of the compliance system.

Independence, Transparency, and Self-Regulatory Systems

In fact, as a general rule, international self-regulatory systems recognize that a higher degree of outsourcing of the functions or services that make up supervision provides greater assurance of independence and transparency.

The independence of the compliance system is essential to prevent the model from being subject to internal interests that could hinder effective oversight. The oversight function must be able to operate objectively, especially when risks are identified that affect the board of directors, senior management, middle management, or sensitive areas of the organization.

Transparency, for its part, makes it possible to demonstrate that the company does not merely declare a formal commitment to compliance, but rather takes concrete measures to prevent risks, review its internal operations, and address potential violations.

The End of the Regulatory Compliance System

Let’s keep in mind that the purpose of the compliance system is not only to secure exemption from criminal liability for the company but also to demonstrate a clear and unequivocal commitment to compliance with the rules.

This statement is one of the central ideas of the article. Criminal compliance should not be viewed solely as a defensive tool against a potential indictment of the legal entity, but rather as an expression of corporate culture, business diligence, and a commitment to the law.

An effective compliance system makes it possible to organize the company’s operations internally, identify risks, establish controls, document decisions, train the relevant personnel, and create a preventive framework. All of this helps strengthen the organization’s legal certainty and reduce its exposure to criminal, reputational, and operational risks.

Up-to-date Information on Criminal Compliance and Corporate Liability

For more up-to-date information on regulatory compliance, criminal compliance, and the criminal liability of legal entities, please see other content from IN DIEM Abogados on Corporate Compliance, criminal liability of companies and organizations, corporate commitment and corporate compliance, economic criminal law and criminal defense for companies and corporate criminal liability in money laundering cases.


Legal Support for Regulatory Compliance Processes

IN DIEM provides the necessary resources to adapt previous, existing, or newly implemented regulatory compliance processes to robust systems that are aligned with current and international regulations and offer greater assurance of achieving the exemption objective, as well as to provide the external support services required by your regulatory compliance system.

Legal advice in this area may be relevant for companies that need to implement a prevention system, review an existing model, update their internal processes, strengthen the role of the Compliance Officer, or obtain specialized external support for monitoring the system.

It may also be necessary when the company is undergoing a phase of growth, internal reorganization, international expansion, contracting with third parties, taking on new risks, or reviewing its control procedures.

Up-to-date Information on Criminal Compliance and Corporate Liability

For more up-to-date information on regulatory compliance, criminal compliance, and the criminal liability of legal entities, please see other content from IN DIEM Abogados on Corporate Compliance, criminal liability of companies and organizations, corporate commitment and corporate compliance, economic criminal law and criminal defense for companies and corporate criminal liability for money laundering offenses.


Preguntas frecuentes sobre compliance penal y sistemas de cumplimiento normativo

¿Qué es un sistema de cumplimiento normativo o compliance penal?

Un sistema de cumplimiento normativo o compliance penal es un conjunto de medidas, controles, protocolos y procedimientos internos destinados a prevenir riesgos penales dentro de una empresa y acreditar una verdadera cultura de cumplimiento.

¿Para qué sirve un modelo de prevención penal en una empresa?

Sirve para identificar riesgos, establecer controles internos, ordenar responsabilidades, prevenir delitos en el seno de la organización y, en determinados supuestos, contribuir a la exención o atenuación de la responsabilidad penal de la persona jurídica.

¿El compliance penal es solo un documento?

No. Un modelo de compliance no debe limitarse a un manual formal. Debe ser un sistema vivo, adaptado a la actividad real de la empresa, revisado periódicamente y acompañado de controles, formación, canales de comunicación, medidas correctoras y supervisión efectiva.

¿Por qué es importante la mejora continua del sistema de compliance?

Porque los riesgos empresariales cambian con el tiempo. El crecimiento de la empresa, nuevas líneas de negocio, cambios normativos, reorganizaciones internas, contratación con terceros o expansión internacional pueden exigir actualizar protocolos, controles y mapas de riesgos.

¿Qué funciones puede tener un Compliance Officer?

El Compliance Officer o responsable de cumplimiento puede supervisar el funcionamiento del modelo, revisar controles internos, detectar riesgos, proponer mejoras, coordinar formación, atender consultas, canalizar incidencias y colaborar en la documentación de la cultura de cumplimiento de la empresa.

¿Puede una empresa contar con un Compliance Officer externo?

Sí, una empresa puede apoyarse en profesionales externos para reforzar la supervisión del sistema, realizar auditorías, revisar procesos, actualizar manuales o asistir al órgano interno de cumplimiento. La intervención externa puede aportar especialización, independencia y objetividad.

¿Qué ventajas tiene externalizar el apoyo al sistema de cumplimiento?

La externalización puede aportar una visión técnica independiente, ayudar a detectar deficiencias, proponer medidas correctoras, reforzar la transparencia del modelo y acompañar a la empresa en revisiones periódicas, auditorías internas o adaptación a nuevos riesgos.

¿Qué relación existe entre compliance penal y responsabilidad penal de la empresa?

La responsabilidad penal de la persona jurídica puede surgir cuando determinados delitos se cometen en el ámbito de la empresa. Un modelo de prevención adecuado, eficaz y realmente implantado puede ser relevante para acreditar diligencia, prevenir riesgos y defender a la organización.

¿Cuándo debe revisarse un modelo de compliance ya implantado?

Debe revisarse cuando cambian la actividad, estructura, normativa, riesgos, órganos de dirección, procedimientos internos, relaciones con terceros o mercados en los que opera la empresa. También conviene revisarlo tras una incidencia, denuncia interna o auditoría.

¿Cómo puede ayudar IN DIEM Abogados en materia de compliance penal?

IN DIEM Abogados puede asesorar en la implantación, revisión y actualización de sistemas de cumplimiento normativo, auditorías de compliance, apoyo al Compliance Officer, análisis de riesgos penales, protocolos internos y defensa penal de empresas y administradores.


Legal Advice on Regulatory Compliance and Criminal Compliance

IN DIEM Abogados advises companies, administrators, executives, and organizations on matters related to regulatory compliance, criminal compliance, risk prevention, criminal liability of legal entities, economic criminal law, and the review of internal control systems.

Legal advice may be important for designing, reviewing, or strengthening prevention models; analyzing criminal risks; adapting internal processes; reviewing protocols; supporting the compliance function; and establishing oversight mechanisms appropriate to each organization’s structure.

For an initial assessment, you can contact IN DIEM Abogados by IN DIEM consultation.


In-person, online, and urgent service. 24-hour support.

IN DIEM Abogados provides in-person and online legal services from its offices in Madrid, Seville, Málaga, Marbella, Estepona, Las Palmas de Gran Canaria, Almería and Huelva, providing coverage to customers throughout the country.

The firm has a multidisciplinary team composed of specialized attorneys and professionals with experience in the judicial, tax, and administrative fields, which allows it to approach each matter from a technical, strategic, and practical perspective.

In addition, IN DIEM Abogados offers online assistance and urgent assistance when the nature of the matter requires an immediate response or a quick initial assessment of the case.

For an initial consultation, you can contact IN DIEM Abogados by IN DIEM consultation.


Want to know more about Abogados IN DIEM? Here’s a short introductory video…

You can find us in Seville, Madrid, Las Palmas de Gran Canaria, Málaga, Huelva, Punta Umbría, Tomares, Coria del Río, Dos Hermanas, Mairena del Alcor, Estepona, Marbella, and Mairena del Aljarafe. We look forward to serving you.

To acknowledge some of you, here’s this link.

Leave a Reply

Your email address will not be published. Required fields are marked *

Legal Vision

Other posts on our blog that might interest you

Group of People Affected by the Bankruptcy of Icelandic Airline Fly Play: Consumer Rights and Ways to File a Claim

Right of the Accused to Testify Last. The Dani Alves Case

IN DIEM Abogados: Christmas Greetings and 2017 Special Campaign

Interview with IN DIEM on T5: Toxic Dumps in Coria del Río

IN DIEM Lawyers in Coria del Río: Security Committee. Canal Sur

Rotary Smart Meeting Seville 2016