Criminal Compliance for SMEs: A Practical Guide for Spanish Companies
In this article
Key Takeaways
- Genuine vs cosmetic compliance
- Five elements
- Art. 31 bis requirements
- Whistleblower channel (Law 2/2023)
Corporate criminal liability does not distinguish by size: a limited company with five employees can be investigated just like a listed one. It may be exempt if, before the events, it had an effective prevention programme, proportionate to its risks and genuinely supervised, meeting the requirements of Art. 31 bis 5 CP: a risk map, protocols, financial management, a whistleblowing channel, a disciplinary system and periodic review.
Need help with your case? Talk to a criminal defence lawyer at Alonso Sala.
Corporate criminal liability has existed since the 2010 reform of the Criminal Code, and the 2015 reform regulated the compliance exemption and a regime adapted to small companies (Art. 31 bis 3). Even so, criminal compliance for SMEs is still seen as a luxury for large corporations.
What Genuine Compliance Looks Like for an SME
The law requires the model to have been effectively implemented: a paper programme — with no real training, no effective channel, no supervision — will NOT provide a criminal exemption. It must be shown that the programme was genuinely designed to prevent the offence, was implemented and was supervised.
If you need specialist legal advice, consult our criminal compliance service for SMEs for a confidential assessment of your case.
In practice this means the programme must exist before the offence is committed, not after; it must address the risk that actually materialised; and the company must be able to prove all of it with documents, records and dates.
The Five Essential Elements
- Risk map: the criminal risks specific to your sector and size.
- Prevention protocols: rules for each identified risk.
- Whistleblower channel: mandatory for companies with 50 or more employees (Law 2/2023).
- Training: regular, documented, in risk areas.
- Supervision: a compliance officer with real authority.
Cost and Implementation
For an SME of 10-50 employees with no unusual risk: 4-8 weeks of implementation. The cost is minimal compared with the potential criminal exposure — fines that can reach several times the benefit obtained or the amount defrauded (Art. 52 CP), besides other penalties under Art. 33.7.
Implementation typically follows the same sequence: risk assessment first, then drafting of protocols, then training and the whistleblower channel, and finally the supervision and review cycle. From that point on, maintaining the programme is a matter of periodic reviews and of keeping the documentation alive as the business changes.
How to Build Each Element
The five elements only work if they are tailored to the actual business. The risk map starts with interviews with the people who run day-to-day operations: who handles money, who deals with public administrations, who signs contracts. From there, each identified risk needs a written protocol short enough to be read and applied — a 200-page manual nobody opens is precisely the "paper programme" the courts dismiss.
The whistleblower channel must guarantee confidentiality and protect whoever reports from retaliation; for companies with 50 or more employees it is a legal obligation under Law 2/2023, but smaller firms benefit from it too, because it shows the programme is real. Training should be documented, with attendance records and materials kept on file: if an offence ever occurs, that file is the evidence that the company did its part. Finally, supervision requires a body of the company itself (in small companies, the management body may take it on) with genuine autonomy and direct access to management, which may rely on external support.
What Happens If an Offence Occurs Anyway
No programme prevents every crime, and the law does not demand that it should. What it demands is that the offence happened despite a serious prevention effort, with the individual offender, where a manager, fraudulently circumventing the controls. A company that can document its risk map, protocols, training and supervision is in a position to argue full exemption from criminal liability; one that cannot may still seek a mitigation of the penalty. The difference between those outcomes — and a conviction with fines that can reach several times the benefit obtained — is decided by the paperwork generated long before any investigation begins.
Common Mistakes in SME Compliance
The errors seen most often: buying a generic template that does not even mention the company's actual activity; appointing a compliance officer with no time, budget or authority; setting up a whistleblower channel that nobody knows exists; and never reviewing the programme after the initial implementation. A programme that has not been updated as the business changed is easy for a prosecutor to characterise as cosmetic.
Need a criminal defence lawyer?
If you are facing a criminal matter, our team of specialist lawyers can help. Contact us for a case evaluation.
Official text: article 31 bis of the Spanish Criminal Code (BOE)
Frequently asked questions
Does criminal compliance also apply to SMEs?
Yes. Corporate criminal liability does not distinguish by size: a limited company with five employees can be investigated just like a listed one. An SME often concentrates more risk, because decisions depend on a handful of people and internal controls are informal, with the same hands signing, paying and supervising.
What are the five essential elements?
A risk map of the criminal risks specific to the sector and size, prevention protocols for each identified risk, a whistleblower channel (mandatory for companies with 50 or more employees under Law 2/2023), regular and documented training, and supervision by a compliance officer with real authority (in SMEs allowed to file an abridged profit and loss account, the management body itself may take it on: Art. 31 bis 3). The requirements of Art. 31 bis 5 CP also apply: management of financial resources, a disciplinary system and periodic verification of the model.
Does an SME need the same programme as a multinational?
No. The key is proportionality: an SME does not need a large corporation's manual, but it does need a programme tailored to its actual risks. Five protocols that are followed and documented are worth more than two hundred pages nobody has read.
What mistakes invalidate a compliance programme?
Buying a generic manual without adapting it to the actual activity, having a whistleblower channel that nobody manages, giving training with no documented record of who was trained and when, and appointing a compliance officer with no authority or resources to genuinely supervise.
How is the programme assessed in criminal proceedings?
The court examines when it was approved, what training was given, how reports were handled and what the person responsible for supervision did. The programme must exist and function before the events occurred; the documentation generated day by day is the best evidence that it was not a paper programme.
Do you need criminal defence in this area?
We are criminal defence lawyers specialising in criminal compliance. We act urgently to protect your rights.
This page is for information purposes only and does not constitute legal advice: every case requires individual assessment. How this content is produced and verified: editorial policy.