IMPORTANT: This article analyzes corporate compliance, the criminal liability of legal entities, and the criteria set forth in Circular 1/2016 of the State Attorney General’s Office, in accordance with the applicable regulatory and interpretive framework at the time of its publication. Currently, any issue related to this subject should be reviewed on a case-by-case basis, in accordance with Article 31 bis of the Penal Code, and Articles 31 ter through 31 quinquies of the Penal Code, and Circular 1/2016 of the Office of the Attorney General, current case law, and the regulations applicable to each sector of activity.
Corporate compliance has become an essential part of the modern business organization. It is not merely a matter of having internal documents, protocols, or codes of ethics, but rather of building a genuine corporate culture of compliance capable of preventing criminal risks, detecting violations, and responding appropriately to potential criminal conduct.
The criminal liability of legal entities, introduced in Spain by Organic Law 5/2010 and subsequently expanded upon by Organic Law 1/2015, significantly changed the way companies must manage their legal and criminal risks.
Corporate Compliance and Corporate Social Responsibility: Criminal Liability of Legal Entities
Organic Law 5/2010 introduced criminal liability for legal entities into our legal system, in response to the process of international harmonization of criminal law and the need to address corporate crime more effectively.
Subsequently, Organic Law 1/2015 amended the provisions of Article 31-bis of the Penal Code, clarifying and elaborating on the conditions for the criminal liability of legal entities and the importance of organizational and management models.
Article 31-bis establishes a mechanism for attributing criminal liability to a legal entity when certain crimes are committed in its name or on its behalf, and for its direct or indirect benefit, by individuals who hold positions of management, representation, organization, control, or subordination within the entity.
Therefore, a legal entity does not physically act like a natural person, but it may be held criminally liable for crimes committed by natural persons associated with its structure, when the applicable legal conditions are met.
Criminal Liability of the Company and Related Offenses
Criminal liability of a legal entity is attributed based on a connecting factor: the prior commission of a crime by a natural person associated with the company, under the terms set forth in the Penal Code.
Article Article 31-ter of the Penal Code makes clear the compatibility and autonomy between the criminal liability of the legal entity and the criminal liability of the natural person who committed the crime.
This means that the company may be held liable even when the specific individual responsible has not been identified or it has not been possible to bring proceedings against that individual, provided that the legal requirements are met.
The practical implication is clear: companies must have prevention, control, and response systems in place to reduce risks, detect unlawful conduct, and demonstrate a genuine culture of compliance.
The Benefit of Exemption from Criminal Liability
One of the main new features of the criminal liability regime for legal entities is the possibility that a company may be exempt from criminal liability if, prior to the commission of the crime, it has adopted and effectively implemented appropriate organizational and management models designed to prevent crimes or significantly reduce the risk of their commission.
Article 31-bis of the Penal Code sets forth the requirements that must be met for these defenses to be effective.
Among them, the following stand out:
- the adoption and effective implementation of organizational and management models prior to the commission of the crime;
- appropriate surveillance and control measures to prevent crimes of the same nature or significantly reduce the risk;
- oversight of the model’s operation and compliance by a body with autonomous powers of initiative and control;
- fraudulent circumvention of the system by individual perpetrators;
- the absence of any failure or insufficient performance of supervisory, monitoring, and control functions.
This benefit is not granted automatically. It is not enough to simply have a formal compliance program. The company must be able to demonstrate that the model was genuine, effective, well-known, implemented, and reviewed.
Compliance as a culture of compliance, not as criminal insurance
The Circular 1/2016 from the State Attorney General’s Office placed special emphasis on the fact that compliance programs should not be viewed as merely a tool for avoiding criminal penalties.
According to the Attorney General’s Office, the true purpose of organizational and management models is to promote an ethical business culture and a corporate culture of respect for the law.
The commission of a crime within a company must be an accidental occurrence that runs counter to the organization’s culture of compliance—not a consequence that is tolerated, encouraged, or accepted as a profitable risk.
For this reason, compliance programs that are merely formal, generic, copied, or superficial do not adequately fulfill their purpose. An effective compliance model must be integrated into the company’s actual structure, tailored to its risks, and supported by senior management.
The Commitment of Senior Management
Corporate commitment begins with the board of directors and the company’s top executives.
The Prosecutor’s Office has emphasized that any effective compliance model depends on the unequivocal commitment and genuine support of senior management. The behavior of the board of directors, the directors, and top executives is key to instilling a culture of compliance throughout the rest of the organization.
In publicly traded companies, the risk control and management policy is of particular importance within the scope of the board of directors’ responsibilities, in accordance with applicable corporate regulations.
If management sends mixed messages, tolerates violations, maintains practices that are contrary to the law, or acts with indifference toward the compliance program, the model loses its effectiveness and may be considered inadequate.
Window-dressing compliance programs
One of the main risks in the area of regulatory compliance is implementing compliance programs that exist only on paper.
A program that is merely for show may consist of generic documents, protocols that are not enforced, ineffective reporting channels, nonexistent training, outdated risk maps, or controls that are not followed in practice.
The Prosecutor’s Office views negatively any models that do not aim to create a genuine culture of compliance, but rather seek only to create the appearance of compliance before third parties, authorities, or in criminal proceedings.
Therefore, the effectiveness of a compliance program must be assessed based on how it is actually implemented: how decisions are made, how risks are managed, how obligations are communicated, how complaints are investigated, and how the company responds to violations.
Crime Detection and Company Response
The detection of criminal conduct is an essential component of an effective compliance program.
A prevention model should not only aim to prevent crimes from being committed. It should also make it possible to detect them, investigate them internally, document what happened, correct deficiencies, and report the facts to the authorities when appropriate.
A company’s response to unlawful conduct is a key factor in assessing its ethical commitment. A swift, firm, and transparent response can demonstrate that the offense was an isolated incident and contrary to the corporate culture.
Conversely, concealment, passivity, unjustified delays in reporting, failure to cooperate with law enforcement, or allowing individuals involved in criminal conduct to remain in their positions can seriously weaken the company’s position.
Review and Continuous Improvement of the Compliance Program
A compliance program cannot be static. It must be reviewed periodically and updated when there are changes to the company’s structure, its business activities, its risks, its internal organization, the regulatory framework, or the circumstances identified in internal audits and investigations.
An immediate review of the program following the detection of a violation can be a significant demonstration of the company’s commitment to compliance.
Measures that can enhance the model’s effectiveness include:
- updating the criminal risk map;
- review of internal protocols;
- improving reporting channels;
- strengthening of financial controls;
- regular training for administrators, managers, and employees;
- documented internal investigations;
- proportionate disciplinary measures;
- active cooperation with the authorities when appropriate.
Internal Investigation, Remedying the Harm, and Collaboration
A company that detects unlawful conduct must act with due diligence. An internal investigation makes it possible to reconstruct the facts, identify those responsible, preserve evidence, assess risks, and take corrective action.
The Prosecutor’s Office views favorably the immediate restitution and compensation for the damage, active cooperation with the investigation, and the provision of information relevant to the criminal proceedings.
These actions can reveal the legal entity’s level of ethical commitment and demonstrate that the compliance program was not merely a formality, but a genuine tool for prevention and response.
Conversely, the concealment of facts, lack of cooperation, tolerance of unlawful conduct by the board of directors, or the widespread nature and prolonged duration of criminal practices within the organization are viewed negatively.
The compliance body
The body responsible for overseeing the operation of the prevention model must have autonomy, adequate resources, the ability to take the initiative, and sufficient access to the information necessary to carry out its functions.
The specific structure may vary depending on the company’s size, activities, and structure. In small organizations, certain functions can be organized more simply, while in complex companies, a specialized body or compliance department may be necessary.
The key is to ensure that the compliance function is not merely a formality and that the supervisory body can act effectively, in a well-documented manner, and independently with regard to the risks it is tasked with controlling.
Basic Elements of a Crime Prevention Model
A criminal compliance program must be tailored to the specific characteristics of each company. However, there are certain elements that are generally considered essential for assessing its effectiveness:
- identification of high-risk activities in which crimes may be committed;
- protocols and procedures that define the company’s decision-making process and the adoption of decisions;
- financial resource management models designed to prevent the commission of crimes;
- a channel for reporting information or complaints regarding risks and violations;
- a disciplinary system that imposes sanctions for noncompliance with the model;
- Periodic review and modification of the model as needed.
These elements must be integrated into the company’s day-to-day operations. The goal is not to accumulate documents, but to establish effective mechanisms for prevention, control, detection, and response.
Corporate Compliance and Responsible Business Management
Compliance should not be viewed solely as a legal requirement. It is also part of responsible business management, aimed at protecting the company, its executives, employees, customers, suppliers, partners, and investors.
A strong culture of compliance helps improve decision-making, reduce risks, protect corporate reputation, streamline internal processes, and build trust in the market.
In highly regulated sectors—such as finance, technology, healthcare, real estate, public procurement, anti-money laundering, data protection, and cryptoassets—compliance programs take on even greater importance.
Why It’s Important to Implement a Compliance Program
Implementing a compliance program can be crucial for preventing criminal risks and demonstrating the company’s due diligence in the event of legal proceedings.
An appropriate model allows for:
- identify criminal and regulatory risks;
- establish effective internal controls;
- train administrators, managers, and employees;
- detect irregular behavior;
- respond to noncompliance;
- document due diligence;
- reduce the risk of criminal liability for the legal entity;
- strengthen our ethical culture and build internal and external trust.
The existence of a compliance program does not in itself guarantee immunity from liability, but its absence can seriously hinder the company’s defense in criminal proceedings.
IN DIEM Law Firm and Corporate Compliance Consulting
At IN DIEM Abogados, we advise companies, directors, executives, and professionals on matters related to corporate compliance, criminal risk prevention, criminal liability of legal entities, internal investigations, and corporate criminal defense.
Our approach combines criminal legal analysis with a practical understanding of business organization, enabling us to design compliance models tailored to each entity’s size, industry, business activities, structure, and actual risks.
The goal is for compliance to be not just a formal document, but a useful tool for preventing risks, organizing business operations, strengthening corporate culture, and responding appropriately to potential violations.
Preguntas frecuentes sobre corporate compliance y responsabilidad penal de empresas
¿Qué es el corporate compliance?
El corporate compliance es el conjunto de políticas, protocolos, controles y medidas internas que una empresa implanta para prevenir incumplimientos legales, detectar riesgos y promover una cultura corporativa de cumplimiento.
¿Una empresa puede tener responsabilidad penal?
Sí. El Código Penal español prevé la responsabilidad penal de las personas jurídicas cuando determinados delitos son cometidos en nombre o por cuenta de la empresa y en su beneficio directo o indirecto, siempre que concurran los requisitos legales.
¿Tener un programa de compliance evita siempre la responsabilidad penal?
No siempre. El programa debe ser real, eficaz, adecuado a los riesgos de la empresa, aplicado antes de la comisión del delito y supervisado correctamente. Un modelo meramente formal o de fachada puede no ser suficiente.
¿Qué debe incluir un modelo de prevención penal?
Debe incluir identificación de riesgos, protocolos de decisión, controles financieros, canal de denuncias, sistema disciplinario, órgano de supervisión, formación, revisión periódica y mecanismos de actualización y reacción ante incumplimientos.
¿Qué importancia tiene la alta dirección en el compliance?
La alta dirección es esencial para que el programa sea eficaz. Si los administradores y directivos no apoyan el cumplimiento, toleran incumplimientos o transmiten mensajes ambiguos, el modelo pierde credibilidad y eficacia.
¿Cuándo conviene revisar un programa de compliance?
Conviene revisarlo periódicamente y siempre que cambie la actividad de la empresa, su estructura, su mapa de riesgos, la normativa aplicable o cuando se detecte una conducta irregular que revele posibles debilidades del modelo.
Experts in corporate compliance, corporate criminal liability, and corporate criminal defense
At IN DIEM Abogados, we provide legal advice to companies, directors, executives, professionals, and organizations on matters related to corporate compliance, criminal liability of legal entities, crime prevention, internal investigations, whistleblower channels, codes of ethics, and corporate criminal defense.
Our team analyzes each organization from legal, criminal, business, and strategic perspectives, assessing the actual risks associated with its operations, its internal structure, its decision-making processes, its existing controls, and the specific needs of each entity.
- Design and implementation of criminal compliance programs.
- Review and update of crime prevention models.
- Advice to governing bodies and senior management.
- Internal Investigations and Response to Noncompliance.
- Criminal defense for companies, administrators, and executives.
If you need advice on corporate compliance, corporate criminal liability, or the prevention of criminal risks, please contact our team for an initial legal assessment.
In-person, online, and urgent service. 24-hour support.
IN DIEM Abogados provides in-person, online, and emergency legal assistance from its offices in Madrid, Seville, Málaga, Marbella, Estepona, Las Palmas de Gran Canaria, Almería, and Huelva, serving clients throughout Spain.
The firm has a multidisciplinary team composed of specialized attorneys and professionals with experience in the judicial, tax, commercial, technology, criminal, civil, administrative, labor, and corporate fields, which allows us to approach each matter from a technical, strategic, and practical perspective.
In addition, IN DIEM Abogados offers urgent assistance when the nature of the matter requires an immediate response or a quick initial assessment of the case.
- Online Legal Advice for online consultations, clients outside the city, or matters that can be handled remotely.
- 24-Hour Emergency Legal Services for situations requiring immediate legal assistance.
- IN DIEM Abogados Offices for in-person service and nationwide coverage in Spain.
For an initial consultation, you can contact IN DIEM Abogados to receive an initial assessment tailored to the circumstances of your case.
Want to know more about Abogados IN DIEM? Here’s a short introductory video…
You can find us in Seville, Madrid, Las Palmas de Gran Canaria, Málaga, Huelva, Punta Umbría, Tomares, Coria del Río, Dos Hermanas, Mairena del Alcor, Estepona, Marbella, and Mairena del Aljarafe. We look forward to serving you.
To acknowledge some of you, here’s this link.
