Criminal Liability of Companies and Organizations: Risks and Compliance

Black-and-white facade of a corporate building representing an organization’s legal structure.

IMPORTANT: This article analyzes the criminal liability of companies and organizations in accordance with the regulatory and interpretive framework applicable at the time of its publication. Currently, any matter relating to the criminal liability of legal entities, criminal compliance, corporate investigations, crime prevention models, or corporate criminal defense must be reviewed on a case-by-case basis, in accordance with Article 31-bis of the Penal Code, and Articles 31 ter through 31 quinquies of the Penal Code, and Circular 1/2016 of the Office of the Attorney General, current case law, and the regulations applicable to each sector of activity.

The knowledge that a company is under investigation for the possible commission of a crime—whether due to the actions of the board of directors, legal representatives, officers, executives, or employees—raises immediate concerns about the potential harm that may result. Such damage can affect financial costs, reputation, market position, relationships with third parties, and business continuity.

It also often comes as a surprise when it becomes apparent that the organization did not have sufficient prevention, detection, or control mechanisms in place that would have made it possible to prevent—or at least reduce—the risk of unlawful conduct within the corporate structure.

Often, when executives or managers are informed about the criminal and civil liabilities that companies may face following the reforms to the Penal Code, there is an initial sense that the risk is distant. Many companies believe that, since they have not been investigated in the past, this situation of apparent normality will continue into the future.

However, that conclusion is based on a past reality and a regulatory framework that has been largely superseded. The new criminal and procedural landscape requires us to acknowledge that companies and organizations are now particularly vulnerable to the risks of investigation, indictment, sanctions, and reputational damage.

New Legal, Criminal, and Business Landscape

We are facing a legal, criminal, procedural, social, and competitive landscape in which corporate compliance has become one of the main pillars of enterprise risk management.

There are several reasons for this trend: the expansion of criminal liability for legal entities, the broadening of the scope of punishable conduct, the strengthening of investigative mechanisms, and the increasing use of potential regulatory violations in internal and external disputes.

1. Principle of Corporate and Business Liability

The regulatory framework applicable to companies, particularly in criminal matters, has been significantly strengthened.

For a long time, the principle of individual liability and sanctions focused primarily on the natural person. However, Spanish criminal law has evolved toward a new concept in which an individual’s actions can be attributed to the organization within which they occur, especially when the company derives or stands to derive a direct or indirect benefit.

This new stance taken by companies effectively shifts the focus of criminal enforcement toward the legal entity, which may become directly liable for criminal offenses alongside the individual who participated in the acts.

2. Expansion of Punishable Conducts

Not only has the scope of those subject to criminal liability been expanded—from individuals to organizations or companies—but the scope of liability has also been broadened through the inclusion of new crimes and circumstances in which a company may be held criminally liable.

This means that business risk is higher, because a company’s day-to-day operations may be linked to criminal, regulatory, economic, tax, environmental, labor, technological, or consumer issues.

3. New Research Mechanisms

Investigative mechanisms involving organizations and companies have also evolved. The procedural reform introduced by Law 41/2015, which took effect on December 6, 2015, marked a significant advance in the areas of technological, police, and judicial investigations.

This reform introduced more modern tools for criminal investigations, adapting the Code of Criminal Procedure to new technological realities and more complex forms of crime.

For companies, this means that investigations may cover communications, computer systems, internal documentation, financial transactions, technological devices, relationships with third parties, and activities carried out within the organization.

4. Internal and External Conflicts: Extension to Compliance Areas

Internal conflicts—such as those that may arise among executives, employees, managers, or partners—and external conflicts—with customers, suppliers, competitors, or government agencies—may also be affected by information regarding potential regulatory violations.

In certain contexts, parties involved in a conflict may use data or evidence of noncompliance as a means of exerting pressure, making accusations, negotiating, or destabilizing the situation.

As a result, criminal and regulatory risks are no longer treated as an isolated issue but become an integral part of the organization’s business, procedural, and reputational strategy.

The Evolution of the Criminal Legal System

The legal system has evolved in three main directions:

  1. Extend criminal liability to organizations and companies.
  2. Increase the number of violations that are subject to penalties.
  3. Establish broader and more sophisticated investigative mechanisms.

All of this is part of an evolution in criminal law within the European Union, where the various legal systems have gradually incorporated principles of corporate criminal liability, prevention, investigation, and regulatory compliance.

Notable Cases of Vulnerabilities at Large Companies

Among the high-profile or well-known cases that illustrate the criminal vulnerability of large organizations, the following can be cited.

The Barcelona/Neymar Case

Court: Barcelona Investigating Court No. 22.

Case: Preliminary Proceedings 1957/2015.

Subject: Fútbol Club Barcelona was investigated for alleged tax crimes related to the acquisition of soccer player Neymar’s rights, as part of an investigation into possible contractual fraud and payments linked to the transaction.

The Bankia Case

Court: Central Investigating Court No. 4 of the National High Court.

Case: Preliminary Proceedings 59/2012.

Subject: Bankia was investigated for matters related to investor fraud, corporate crimes, and breach of fiduciary duty, with possible consequences regarding compensation for those who suffered losses.

The Volkswagen Case

Court: Central Investigating Court No. 2 of the National High Court.

Case: Preliminary Proceedings 91/2015.

Subject: Volkswagen was accused of acts related to fraud, crimes against consumers, environmental crimes, catastrophic risk, public health, document forgery, misleading advertising, and crimes against the Treasury.

Volkswagen itself set aside a large global contingency reserve related to this matter, which illustrates how a technical, regulatory, and reputational risk can turn into a global legal problem for a company.

A Counterbalance to Vulnerability: Compliance

In light of these regulatory developments and the increased risk of criminal liability for the business sector, the legal system has established incentives for companies to implement crime prevention systems or corporate compliance programs.

These systems can have significant effects in criminal matters, both in terms of preventing crimes and in mitigating or, in certain cases, excluding the criminal liability of a legal entity, provided that the legal requirements are met.

The message to companies is clear: business owners are free to decide whether or not to implement a crime prevention system, but the absence of controls can significantly increase the organization’s criminal, financial, and reputational exposure.

The government has also strengthened its investigative mechanisms, equipping law enforcement and judicial authorities with more modern and sophisticated tools to investigate criminal conduct in the business sector.

At the same time, the law provides for significant criminal law benefits for companies that demonstrate the existence of effective organizational, preventive, monitoring, and control measures.

Even when a company is already under investigation, taking steps to cooperate, remedy the situation, conduct an internal review, and ensure compliance can influence the assessment of its liability and potentially mitigate criminal consequences.

IN DIEM Abogados offers services to develop and implement effective regulatory compliance systems and corporate compliance programs tailored to the needs of each company, in order to counter the rising trend of criminal vulnerability among companies and organizations.

Criminal Liability, Compliance, and Business Risk Prevention

The criminal liability of legal entities requires companies to review their internal organization, decision-making processes, financial controls, communication channels, and crime prevention mechanisms.

Corporate criminal liability is not limited to large companies. It can also affect medium-sized companies, small and medium-sized enterprises (SMEs), family-owned businesses, professional organizations, associations, foundations, and organizations that engage in activities subject to legal, regulatory, or internal control requirements.

Therefore, prevention should not be viewed as a purely administrative measure, but rather as a practical business management tool designed to identify risks, reduce contingencies, detect noncompliance, and respond appropriately.

The Importance of Crime Prevention Models

Criminal compliance models make it possible to organize a company’s operations from a preventive perspective. Their effectiveness depends on whether they are tailored to the size, activities, structure, and actual risks of each organization.

A compliance program must be well-known, implemented, monitored, and reviewed periodically. It is not enough to simply adopt internal codes or generic protocols if there is no genuine corporate culture of compliance.

Common elements of a criminal prevention model include a risk assessment, action protocols, a reporting channel, a disciplinary system, internal training, financial controls, and the body responsible for overseeing the model’s operation.

Corporate Criminal Defense and Internal Investigations

When a company is involved in a criminal investigation, it is essential to act quickly, preserve documentation, analyze the scope of the facts, and assess the appropriate litigation strategy.

Internal investigations can be useful for reconstructing what happened, identifying potential liabilities, taking corrective action, and demonstrating the organization’s due diligence.

Early action helps protect the company, its directors, executives, and employees, and reduces reputational, financial, and legal risks.

Criminal Liability of Legal Entities and a Culture of Compliance

The existence of a compliance program should not be viewed as merely an internal document or as an automatic guarantee of exemption from liability. In order for it to have a meaningful impact, it must be a genuine, effective, up-to-date model tailored to the company’s specific risks.

A culture of compliance requires senior management involvement, clear internal communication, regular training, adequate controls, and the ability to respond to violations.

In this regard, criminal compliance not only serves a defensive purpose in the event of legal proceedings, but also plays a preventive and organizational role within the company.

Preguntas frecuentes sobre vulnerabilidad penal de empresas

¿Qué significa que una empresa sea penalmente vulnerable?

Significa que puede estar expuesta a responsabilidad penal, sanciones, investigaciones, daños reputacionales o consecuencias económicas por delitos cometidos en su ámbito de organización.

¿Qué empresas deberían tener un programa de compliance?

Toda empresa con actividad organizada, trabajadores, directivos, proveedores, clientes o riesgos regulatorios debería valorar la implantación de un modelo de prevención adaptado a su tamaño, sector y actividad.

¿El compliance sirve solo para grandes empresas?

No. También puede ser relevante para pymes, empresas familiares, asociaciones, fundaciones y sociedades profesionales, siempre que existan riesgos penales o regulatorios que deban prevenirse.

¿Qué ocurre si una empresa no tiene controles internos?

La ausencia de controles puede dificultar la prevención de delitos, la detección de incumplimientos y la defensa de la empresa ante una investigación penal o administrativa.

¿Cuándo conviene revisar el modelo de compliance?

Debe revisarse periódicamente y siempre que cambien la actividad, la estructura interna, la normativa aplicable, los riesgos de la empresa o se detecte una incidencia relevante.

Experts in criminal compliance and corporate defense

At IN DIEM Abogados, we advise companies, directors, executives, and professionals on matters related to the criminal liability of legal entities, corporate compliance, internal investigations, corporate criminal defense, and the prevention of criminal risks.

Our team analyzes each organization from legal, criminal, business, and strategic perspectives, assessing the actual risks associated with its operations, its internal structure, its decision-making processes, its existing controls, and the specific needs of each entity.

  • Design and implementation of criminal compliance programs.
  • Review of crime prevention models.
  • Internal Investigations and Response to Noncompliance.
  • Criminal defense for companies, administrators, and executives.
  • Preventive advice on criminal and regulatory risks.

If you need advice on corporate criminal liability, compliance, or corporate criminal defense, please contact our team for an initial legal assessment.


In-person, online, and urgent service. 24-hour support.

IN DIEM Abogados provides in-person, online, and emergency legal assistance from its offices in Madrid, Seville, Málaga, Marbella, Estepona, Las Palmas de Gran Canaria, Almería, and Huelva, serving clients throughout Spain.

The firm has a multidisciplinary team composed of specialized attorneys and professionals with experience in the judicial, tax, commercial, technology, criminal, civil, administrative, labor, and corporate fields, which allows us to approach each matter from a technical, strategic, and practical perspective.

In addition, IN DIEM Abogados offers urgent assistance when the nature of the matter requires an immediate response or a quick initial assessment of the case.

For an initial consultation, you can contact IN DIEM Abogados to receive an initial assessment tailored to the circumstances of your case.


Would you like to learn more about us? Here’s a video for you…

Leave a Reply

Your email address will not be published. Required fields are marked *

Legal Vision

Other posts on our blog that might interest you

Group of People Affected by the Bankruptcy of Icelandic Airline Fly Play: Consumer Rights and Ways to File a Claim

Right of the Accused to Testify Last. The Dani Alves Case

IN DIEM Abogados: Christmas Greetings and 2017 Special Campaign

Interview with IN DIEM on T5: Toxic Dumps in Coria del Río

IN DIEM Lawyers in Coria del Río: Security Committee. Canal Sur

Rotary Smart Meeting Seville 2016