Skip to content

Criminal Lawyers in Criminal Compliance for SMEs

Criminal compliance is no longer just for large corporations. Programs tailored to the reality of Spanish SMEs to prevent criminal liability for the company and its directors

Criminal compliance is not a legal requirement for small and medium-sized enterprises (SMEs), but Art. 31 bis of the Spanish Criminal Code (CP) exempts from criminal liability a company that had an effective organisation and management model in place to prevent the offence committed; without one, if an offence on the Art. 31 bis list is committed, the company cannot rely on that exemption and faces fines of up to five times the profit obtained, temporary closure, or a ban on contracting with public authorities. Art. 31 bis 3 CP allows small companies — those filing an abridged profit and loss account — to have the management body itself take on the supervisory functions, without a separate, independent body. Our work designs and audits that model tailored to the SME, and proves its real effectiveness once an investigation is already under way.

Criminal Compliance for SMEs: Concept, Modalities, Benefits and Defence (Art. 31 bis CP)

Criminal compliance for SMEs is the adaptation of crime prevention models from Art. 31 bis CP to the dimensions, resources and specific risks of small and medium-sized enterprises. Since the introduction of corporate criminal liability by Organic Law 5/2010, reformed by Organic Law 1/2015 and expanded by Organic Law 14/2022, SMEs are fully exposed to fines, closure, contracting prohibition and even dissolution for crimes committed within them. Art. 31 bis 2 and 4 CP allows a real, effective and living compliance model, adopted before the offence, to exonerate the legal entity from criminal liability even if the crime was committed. The UNE 19601 standard establishes technical standards and ISO 37301 offers the international framework.

Adapted Modalities for SMEs

The compliance modalities adapted to SMEs contemplate simplified but effective structures. Art. 31 bis 3 CP expressly allows that, in small-sized companies (those that may present an abbreviated profit and loss account under Art. 258 of the Consolidated Text of the Corporate Enterprises Act), the supervisory body functions be assumed by the governing body itself. Adapted modalities include: sectoral risk map focused on typical crimes of the SME sector (construction: labor/environmental/urban planning; hospitality: labor/cash money laundering; technological: cybercrime/intellectual property; industry: environmental/labor safety); simplified decision-making protocols; internal whistleblowing channel (mandatory for companies with 50 or more workers under Act 2/2023); code of ethics and anti-corruption, anti-money laundering and data protection policies; periodic training of employees and managers.

Benefits for the SME

The technical benefits for the SME are significant and quantifiable. First, exoneration or attenuation of criminal liability: a compliance program meeting the six requirements of Art. 31 bis 5 CP can completely eliminate the SME's criminal liability. Second, director protection: compliance documents the due diligence of the governing body, serving as evidence of its diligence in individual investigations for unfair administration, tax fraud or labour crimes, although it does not exempt a director who took part in the offence. Third, access to public contracting: Public Sector Contracts Act 9/2017 prohibits contracting with companies convicted of certain offences (Art. 71.1.a); without compliance, a conviction can destroy the business. Fourth, contractual requirements: banks, large clients, insurers and digital platforms already require compliance programs via contractual clauses. Fifth, compliance with GDPR, LOPDGDD and Act 2/2023 on whistleblower protection, unavoidable for companies with 50 or more employees.

Defence Strategy

The technical defence in criminal investigations of SMEs rests on four consolidated axes. First, proof of ex ante effectiveness of compliance: documentation of program adoption prior to the criminal act (governing body minutes, allocated budget, training delivered, active whistleblowing channel). Second, fraudulent circumvention of the model: where the offence is committed by directors or senior managers, Art. 31 bis 2 CP requires, for exoneration, that the individual perpetrator fraudulently circumvented the model's controls. Third, autonomy and sufficiency of the supervisory body: even in SMEs where the director assumes these functions, it must be proven they acted with criteria of functional independence and diligence. Fourth, external certification under UNE 19601 and ISO 37301: it does not exonerate per se or prove the model's effectiveness, although it may be weighed as an additional element (FGE Circular 1/2016).

Current Forensic Practice

In current forensic practice, SMEs are increasingly the target of criminal investigations by the AEAT, the Labour Inspectorate, the SEPRONA, the UDEF and the Anti-Corruption Prosecutor's Office. Act 2/2023 on Whistleblower Protection, Organic Law 14/2022 reforming embezzlement, Organic Law 1/2025 on Justice Service Efficiency, the EU Regulations DSA, MiCA, AI Act and NIS2 and the statutory requirement of an effectively implemented model as opposed to cosmetic compliance (Art. 31 bis 2 CP) configure a demanding regulatory framework. Compliance is a modest investment against criminal fines that can reach five times the benefit obtained or several hundred thousand euros. At Alonso Sala, with more than 15 years of experience in economic criminal law, we design compliance programs adapted to SMEs from a forensic perspective: we know how they are attacked at trial and configure them to withstand the most demanding judicial scrutiny. We accompany the SME in risk audit, implementation, training, periodic monitoring and, when necessary, defence in criminal investigations.

Most Common Criminal Risks in SMEs by Sector

Sector Main Criminal Risks
Construction Labour, environmental, urban planning crimes, tax fraud
Hospitality / Catering Labour exploitation, cash fraud, money laundering
International Trade Money laundering, bribery of officials, customs evasion
Technology / Software Cybercrime, intellectual property, data misuse
Manufacturing Environmental and labour crimes, damages
Financial Sector Money laundering, tax crimes, fraud, insider trading

Our SME Compliance Program

1

Risk Audit

Identification of the specific criminal risks of your company according to sector, size, and activity.

2

Program Drafting

Drafting of the Organization and Management Model (MOG) and prevention policies tailored to your company.

3

Training

Specific training for directors and employees on crime prevention and the internal reporting channel.

4

Supervision

Designation of the compliance body and periodic monitoring of the program to maintain its effectiveness.

Economic Criminal Law in Spain: Tax Fraud, Money Laundering and Corporate Crimes

Economic criminal law encompasses the most severe financial penalties in the Spanish Criminal Code. Tax fraud over €120,000 (Art. 305 CP), money laundering (Art. 301 CP), and corporate crimes (Art. 290-297 CP) are complex offences where defence requires a combination of criminal law expertise and deep accounting/financial knowledge.

Penalty Comparison: Economic Offences

OffenceThresholdPenalty
Tax Fraud (Art. 305)>€120,0001 – 5 years + fine of 1x to 6x
Aggravated Tax Fraud>€600,0002 – 6 years
Money Laundering (Art. 301)Any amount6 months – 6 years
Aggravated Laundering (Arts. 301.1 and 302.1)Drug trafficking, corruption, organisation members or obliged entitiesUpper half (up to 6 years); heads of the organisation, one degree higher (up to 9 years)
Corporate Crime (Art. 290)Balance sheet falsification1 – 3 years
Punishable Insolvency (Art. 259)Conduct in actual or imminent insolvency1 – 4 years

Key Defence Strategies

Tax Regularization Defence (Art. 305.4 CP)

Acknowledge and pay the full tax debt before being notified of a tax audit or, failing that, before the prosecutor or state attorney files a complaint, and criminal liability is excluded. This is the most powerful complete defence in tax fraud cases.

Challenge the €120K Threshold

The tax authority's calculation method is often contestable. Independent forensic accounting can challenge the assessed figure below the criminal threshold.

Money Laundering 'Self-laundering' Issues

Spanish courts have debated whether the primary offender can also be convicted of laundering their own proceeds. Challenge the double jeopardy implications.

Corporate Crime: Harm to Company vs. Shareholders

Corporate crimes under Arts. 290-294 CP do not always require actual harm: falsifying accounts (Art. 290 CP) only requires that the falsification be capable of causing financial harm, and actual harm raises the penalty to the upper half. Showing that the falsification could not harm the company, its members or third parties rules out that offence.

FAQs on SME Criminal Compliance

Are SMEs required to have a criminal compliance program?
There is no direct legal obligation. However, Art. 31 bis CP establishes that the company can be exempt from criminal liability if it had an organization and management model that prevented the type of crime committed. Without compliance, if a listed offence is committed in the circumstances of Art. 31 bis 1 CP, the company cannot rely on that exemption.
What happens if my company is criminally convicted?
The consequences are devastating: fines of up to five times the profit obtained, temporary closure of premises (up to 5 years), temporary or permanent prohibition of activities, prohibition from public contracts, judicial intervention, and reputational damage. A criminal conviction can destroy a company.
Does criminal compliance also protect the director?
Partly. The Art. 31 bis CP exemption applies only to the legal entity, and there is no compliance-based exemption or mitigating factor for the director; but an effective programme shows that reasonable supervision and prevention measures were adopted, which may rule out their liability by omission. It does not protect them if they took part in the offence.
What crimes are most common in SMEs?
The most common crimes in the SME context are: tax and accounting fraud, money laundering (especially in cash-heavy businesses), labour crimes, private corruption (commercial bribery), environmental crimes, and cybercrime.
How can I prepare for a tax inspection that could become criminal?
The key is to anticipate. Before receiving an inspection: review accounting with an independent auditor, document all transactions, know the sector-specific risks. If the tax inspection has already begun and there is a risk of criminal referral, urgently hire a criminal defence lawyer before making any statements.
Do SMEs need criminal compliance?
It is not legally required, but corporate criminal liability (Art. 31 bis CP) applies to companies of any size, so a tailored program reduces risks.
Is an SME's compliance different from a large company's?
Yes. The program must be adapted to the SME's size, sector and specific risks. The law allows the management body to take on the supervisory functions.
Can the sole director be the compliance officer?
In small companies, the management body itself can supervise the prevention model, avoiding the need to outsource this function.
Is a whistleblowing channel mandatory for SMEs?
Law 2/2023 makes it mandatory for companies with 50 or more employees. Smaller ones are not obliged unless they operate in the EU-regulated sectors of Art. 10.1.b (financial services, anti-money laundering, transport safety or the environment), but it is highly advisable.
What criminal risks does an SME face?
Tax offences, offences against workers, environmental offences, fraud, money laundering, private corruption and intellectual property offences are the most common risks.
Does compliance protect against the manager's personal liability?
Compliance protects the legal entity. The personal liability of a manager who takes part in the offence is not excluded by having compliance.
Do subcontractors need compliance?
Yes. Contracting companies may require compliance from their subcontractors. Not having it can block access to important contracts.
Is the risk map mandatory?
It is the core element of compliance. It identifies the company's specific criminal risks and allows adequate controls to be designed.
Do I need criminal law advice to implement compliance?
Yes. The design of the program should be supervised by a criminal lawyer who correctly identifies the risks and designs the appropriate prevention protocols.

Advanced Criminal Defence

Our firm approaches each procedure with rigorous evidentiary analysis and proactive defence strategy.

Need urgent criminal defence?

Contact our specialist criminal defence lawyers. We evaluate your case confidentially.

Related Articles

This page is for information purposes only and does not constitute legal advice: every case requires individual assessment. How this content is produced and verified: editorial policy.

Do you need specialised legal assistance?

The judicial system is complex. We have the criminal-law specialisation and technical resources required to take on the defence.