AML & KYC in Spain is governed by a detailed legislative framework that obliges a wide range of businesses to verify clients, monitor transactions and report suspicious activity. Spain';s primary statute, Law 10/2010 on the Prevention of Money Laundering and Terrorist Financing, sets out the core obligations, while a series of Royal Decrees and EU directives have progressively tightened the rules. For international founders and financial operators, non-compliance carries substantial fines, reputational damage and, in serious cases, criminal exposure. This guide explains who is covered, what the rules require, how enforcement works in practice and what recent regulatory changes mean for your business in Spain.
Who is subject to AML & KYC obligations in Spain
Spain';s anti-money laundering regime applies to a broad category of "obligated entities" defined in Law 10/2010. The list goes well beyond banks and payment institutions. It covers lawyers, notaries, accountants, real estate agents, company service providers, casinos, dealers in high-value goods and certain trust and company administrators.
For financial institutions, the obligations are the most demanding. Banks, electronic money institutions, investment firms and insurance companies must maintain full customer due diligence programmes, appoint a compliance officer, and submit to supervision by the Banco de España, the Comisión Nacional del Mercado de Valores (CNMV) or the Dirección General de Seguros, depending on their sector.
Non-financial businesses often underestimate their exposure. A real estate agency handling a property sale above a certain threshold, or a law firm receiving client funds in escrow, is fully subject to the same identification and reporting duties as a regulated financial entity. A common mistake among foreign operators entering Spain is assuming that AML obligations only apply once they obtain a financial licence.
The Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias, known as SEPBLAC, is Spain';s financial intelligence unit and the primary supervisory authority for non-financial obligated entities. SEPBLAC receives suspicious transaction reports, conducts inspections and coordinates with law enforcement and international counterparts.
Core KYC requirements: customer due diligence in Spain
Know Your Customer (KYC) is the process by which an obligated entity identifies and verifies the identity of its clients before establishing a business relationship or executing a significant transaction. In Spain, KYC requirements are structured across three levels: simplified, standard and enhanced due diligence.
Standard due diligence applies to most business relationships. It requires collecting and verifying the client';s full legal name, identification document number, address, nationality and, for legal entities, the identity of the beneficial owner. Beneficial ownership is defined as any natural person who ultimately owns or controls more than 25% of a legal entity. Verification must rely on reliable, independent source documents.
Enhanced due diligence is mandatory in higher-risk situations. These include:
- Clients or transactions involving high-risk third countries designated by the EU.
- Politically exposed persons (PEPs) and their close associates or family members.
- Correspondent banking relationships.
- Non-face-to-face business relationships where identity cannot be confirmed in person.
- Transactions that appear complex, unusually large or lack an obvious economic purpose.
Simplified due diligence is permitted for lower-risk clients, such as listed companies on regulated markets or certain public authorities, but the entity must document its risk assessment justifying the reduced measures.
A non-obvious requirement in Spain is the obligation to keep KYC records for a minimum of ten years after the end of the business relationship. Many smaller obligated entities maintain records for five years and believe they are compliant, only to discover during an inspection that the ten-year rule applies to them under the current regulatory framework.
Transaction monitoring and suspicious activity reporting
Ongoing monitoring is a distinct obligation from initial KYC. Obligated entities in Spain must continuously scrutinise transactions to ensure they are consistent with the entity';s knowledge of the client, the client';s business profile and the client';s risk level. This is not a one-time check at onboarding; it is a continuous process.
When a transaction or pattern of transactions raises suspicion of money laundering or terrorist financing, the obligated entity must file a suspicious transaction report (STR) with SEPBLAC. The report must be submitted promptly, and the entity is prohibited from tipping off the client that a report has been made. Tipping off is itself a criminal offence under Spanish law.
Spain also imposes a separate obligation to report cash transactions above a specified threshold. Businesses that accept or make cash payments above this level must report the transaction to the tax authority, the Agencia Tributaria, using the relevant declaration form. This obligation applies even when there is no suspicion of criminal activity.
In practice, SEPBLAC has increased its use of data analytics to identify patterns across the financial system. Entities that file few or no STRs despite operating in high-risk sectors are increasingly likely to attract supervisory attention. A common mistake is treating the STR obligation as a last resort rather than a routine compliance tool.
If you are establishing or reviewing your transaction monitoring programme in Spain, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Internal controls, governance and the compliance officer requirement
Law 10/2010 and its implementing Royal Decree 304/2014 require obligated entities to establish a formal internal control framework. This framework must include written policies and procedures, a designated compliance officer (the "representante ante el SEPBLAC"), an internal audit function and a risk-based approach to client and transaction risk assessment.
The compliance officer must be a senior manager with sufficient authority to implement the AML programme and direct access to the board. For smaller entities, the owner or director may fulfil this role, but the function cannot be left vacant or assigned to a junior employee without adequate authority.
The risk-based approach is central to the current framework. Entities must conduct and document a business-wide risk assessment, identifying the money laundering and terrorist financing risks specific to their client base, products, services, delivery channels and geographic exposure. This assessment must be reviewed and updated regularly, and it forms the basis for calibrating due diligence and monitoring intensity.
Group-level obligations also apply. Spanish subsidiaries of international groups must implement group-wide AML policies, and the parent must ensure that branches and subsidiaries in third countries apply equivalent standards where local law permits. Where local law in a third country does not permit equivalent standards, the group must apply additional measures and notify SEPBLAC.
Many international groups entering Spain assume their existing global compliance programme is sufficient. In practice, Spain requires a localised programme that specifically addresses Spanish legal requirements, is documented in Spanish where required by SEPBLAC, and is overseen by a locally appointed compliance officer.
Recent regulatory developments and EU alignment
Spain has been progressively implementing the EU';s successive Anti-Money Laundering Directives. The Fourth, Fifth and Sixth Directives have each introduced significant changes, including expanded beneficial ownership transparency, stricter rules on virtual asset service providers and enhanced criminal liability for legal persons.
The EU';s AML Package, which includes a new AML Regulation directly applicable across all member states, a new directive and the establishment of the European Anti-Money Laundering Authority (AMLA), represents the most significant structural change to the European AML framework in decades. AMLA will directly supervise certain high-risk financial entities across the EU, including in Spain, and will coordinate supervisory convergence among national authorities.
For Spain, recent developments include:
- Stricter supervision of virtual asset service providers, which must register with the Banco de España and comply with full AML obligations.
- Enhanced scrutiny of real estate transactions, particularly those involving non-resident buyers and high-value properties.
- Increased enforcement activity by SEPBLAC, with a growing number of formal sanctions issued against both financial and non-financial entities.
- Alignment with FATF recommendations following Spain';s mutual evaluation, which identified areas for improvement in beneficial ownership transparency and non-financial sector supervision.
The FATF mutual evaluation process is significant for businesses operating in Spain. FATF';s findings influence how Spanish authorities prioritise supervisory resources and what sectors face heightened scrutiny. Following the evaluation, Spain has taken steps to strengthen its beneficial ownership register, which is maintained by the Registro Mercantil and the Registro de Titulares Reales.
A practical scenario: a fintech company incorporated in the EU and expanding into Spain through a branch must register the branch with the Registro Mercantil, appoint a local compliance officer, file its AML programme with SEPBLAC and ensure its onboarding technology meets Spanish KYC standards. The process typically takes several weeks and requires legal and compliance input from the outset.
A second scenario: a law firm advising on Spanish real estate transactions for non-resident clients must conduct full KYC on each client, assess the source of funds, apply enhanced due diligence where the client is a PEP or the transaction involves a high-risk jurisdiction, and maintain records for ten years. Failure to do so exposes the firm to SEPBLAC sanctions and potential criminal liability for the individual partners.
Enforcement, penalties and supervisory trends in Spain
SEPBLAC has the authority to impose administrative sanctions for breaches of Law 10/2010. Sanctions are classified as minor, serious and very serious, with financial penalties scaled accordingly. Very serious infringements can result in fines reaching a significant percentage of annual turnover or, for financial institutions, the revocation of authorisation.
Beyond financial penalties, SEPBLAC can require an entity to replace its compliance officer, implement a remediation plan under supervisory oversight, or publish the sanction in the official gazette, which carries significant reputational consequences. For individuals, senior managers can be held personally liable for serious and very serious infringements.
Criminal liability under the Spanish Penal Code applies to both natural and legal persons for money laundering offences. Legal persons can face fines, dissolution, suspension of activities and prohibition from receiving public subsidies. The threshold for criminal exposure is lower than many foreign operators assume.
Supervisory trends in Spain reflect broader European priorities. SEPBLAC has increased its focus on:
- Non-financial obligated entities, particularly law firms, accountants and real estate agents, which historically received less supervisory attention than financial institutions.
- Virtual asset service providers and crypto-related businesses.
- Entities with inadequate beneficial ownership identification procedures.
- Cross-border transactions and correspondent relationships with higher-risk jurisdictions.
Many underestimate the reputational dimension of AML enforcement in Spain. A published sanction, even a minor one, can affect banking relationships, client confidence and the ability to obtain regulatory approvals in other EU jurisdictions.
For a review of your current AML and KYC programme in Spain, reach out to info@vlolawfirm.com. We can assist with documents, filings and compliance gap analysis.
Frequently asked questions
What happens if a business in Spain fails to file a suspicious transaction report?
Failure to file an STR when there are reasonable grounds for suspicion is a serious infringement under Law 10/2010. SEPBLAC can impose substantial financial penalties and require remediation measures. In cases where the failure is systematic or deliberate, criminal liability may arise for the individuals responsible. Beyond the formal sanction, the entity';s banking relationships and regulatory standing in Spain and other EU jurisdictions can be affected. Regulators increasingly share information across borders, so a Spanish enforcement action can have consequences in other member states.
How long does it take to set up a compliant AML programme in Spain, and what does it cost?
The timeline depends heavily on the size and complexity of the entity. A small non-financial obligated entity, such as a law firm or real estate agency, can establish a basic compliant programme within four to eight weeks if it engages experienced legal and compliance advisers from the outset. A regulated financial institution or fintech requires a more extensive programme, including technology integration, which typically takes several months. Costs vary significantly: professional fees for programme design and documentation usually start from the low thousands of EUR for smaller entities, while larger institutions face substantially higher investment. Ongoing costs include annual review, training and any required technology.
Does Spain require a local compliance officer, or can the function be handled from another EU country?
Spain requires each obligated entity operating in Spain to designate a representative before SEPBLAC. For branches and subsidiaries of foreign groups, this representative must be based in Spain and have sufficient authority to implement the AML programme locally. Remote oversight from a parent company';s compliance team in another EU country does not satisfy this requirement. The representative is personally accountable to SEPBLAC and must be reachable for inspections and information requests. Groups that centralise compliance functions abroad often discover this requirement only when SEPBLAC initiates an inspection, at which point remediation is more costly and disruptive.
Conclusion
Spain';s AML and KYC framework is comprehensive, actively enforced and continuing to evolve in line with EU regulatory developments. Obligated entities - whether financial institutions, professional service firms or businesses handling high-value transactions - face real legal and reputational risk if their programmes are not properly designed and maintained. The introduction of AMLA and the new EU AML Regulation will further raise the bar for compliance across all member states, including Spain.
VLO Law Firms advises international clients on AML and KYC matters in Spain. We can assist with compliance programme design, SEPBLAC registration and representation, beneficial ownership analysis, suspicious transaction reporting procedures and regulatory gap assessments. To request a consultation, contact: info@vlolawfirm.com