In terms of regulatory compliance, companies tend to prioritise those obligations whose impact is more visible and immediate: tax, employment, data protection or cybersecurity.

However, there are other areas which, despite having significant legal and reputational implications, continue to receive much less attention from organisations. One of them is criminal compliance.

According to the study “Priorities in Regulatory Compliance. A Snapshot of Compliance in Spanish Companies” prepared by Adlanter based on 122 Spanish companies, 33.6% of companies admit that they do not currently manage this area of compliance.

This figure is particularly relevant considering that criminal compliance not only seeks to prevent internal breaches, but also to protect the company against potential criminal liability arising from the actions of directors, employees or related third parties.

In this article, we analyse why criminal compliance remains a pending issue for many companies, what risks are involved in failing to manage it properly, and why prevention should increasingly be addressed as a strategic matter.

What is criminal compliance?

Criminal compliance encompasses the set of policies, procedures and internal controls aimed at preventing the commission of crimes within an organisation.

Its main purpose is to reduce the risk of the company becoming involved in unlawful conduct committed in the course of its business activity.

Although many companies have traditionally associated this area only with large corporations, the reality is that any organisation may face situations that generate criminal liability.

Among others, conduct may arise in connection with:

  • Internal fraud.
  • Misappropriation.
  • Corruption between private parties.
  • Tax offences.
  • Money laundering.
  • Disclosure of secrets.
  • Offences against privacy and data protection.
  • Environmental offences.
  • Offences against workers’ rights.

Preventing these risks requires establishing internal mechanisms that make it possible to identify, detect and respond to potential breaches before serious legal consequences arise.

Corporate criminal liability is no longer a theoretical issue

Since the reform of the Spanish Criminal Code introduced by Organic Law 5/2010, legal entities may be held criminally liable for certain offences committed within them.

This means that the company may be investigated, tried and criminally sanctioned independently of the individual liability of its directors or employees.

In certain cases, the consequences may include:

  • Significant financial penalties.
  • Temporary suspension of activities.
  • Closure of establishments.
  • Disqualification from contracting with the Public Administration.
  • Judicial intervention.
  • Dissolution of the company.

Beyond the direct financial impact, these types of proceedings often generate reputational damage that is difficult to reverse.

For this reason, criminal compliance is no longer a matter reserved for large business groups and is beginning to form part of the core of corporate governance.

 

I want to speak to an expert

 

A concerning figure: many companies believe they are protected when they are not

One of the most striking findings of the study carried out by Adlanter is the contradiction between perception and reality.

Although criminal compliance is given relatively low priority among the areas analysed, many organisations consider their level of compliance to be higher than the level of attention they actually devote to it.

At the same time, one in three companies admits that it does not manage this area at all.

This phenomenon may reflect a common situation in many organisations: assuming that certain legal risks do not affect the business simply because no previous incidents have occurred.

However, the absence of incidents does not necessarily mean proper prevention.

In many cases, the risk simply remains invisible until a problem arises.

What elements should a criminal compliance system include?

An effective criminal prevention model does not merely consist of having formal documentation. Its implementation must be adapted to the specific reality of each organisation and include effective control mechanisms.

A criminal compliance system usually includes elements such as:

  • Identification and assessment of criminal risks.
  • Internal protocols for prevention and supervision.
  • Corporate code of ethics.
  • Internal whistleblowing channel.
  • Internal investigation procedures.
  • Regular training for employees and directors.
  • Ongoing supervision and updating of controls.

The effectiveness of the system depends on these measures becoming a real part of the company’s internal operations, rather than being limited to merely documentary compliance.

The real cost often appears when there is no prevention

Many companies postpone these types of projects because they believe there is no immediate risk, or because other regulatory areas seem more urgent.

However, precisely one of the main objectives of criminal compliance is to act before the problem appears.

When an internal investigation, an employee complaint or judicial action arises, the margin for reaction is usually much smaller.

At that point, the organisation must not only manage the potential breach, but also prove what prevention mechanisms were already in place.

And in many cases, the absence of adequate controls ends up aggravating the situation.

Criminal compliance is beginning to consolidate as a business priority

Adlanter’s study shows a clear reality. Although areas such as tax, employment or data protection continue to occupy the top level of priority, criminal compliance remains one of the most neglected areas among Spanish companies.

This creates a scenario of latent risk that many organisations are still not managing properly.

As regulatory demands increase and corporate responsibility becomes more relevant, having solid preventive mechanisms is no longer a purely reputational option, but a responsible business management decision.

Prevention remains the best tool for corporate protection

In terms of criminal compliance, many organisations do not react until the problem appears.

However, when criminal liability comes into play, the impact often extends far beyond a possible financial penalty.

Protecting the company requires anticipation, internal control and preventive management capable of identifying risks before they generate legal, economic or reputational consequences that are difficult to reverse.

In an increasingly demanding regulatory environment, prevention is no longer a recommendation but an essential part of corporate legal certainty.

Nuestros expertos

  • Adlanter

    Expertos en asesoría fiscal, laboral, mercantil, contable, movilidad internacional y gestión del talento. Compartimos análisis, novedades normativas y contenido especializado para ayudar a empresas y profesionales a tomar decisiones informadas y afrontar con seguridad los retos de un entorno empresarial en constante evolución.

Conversation

Do you have any questions?

If you have any questions after reading "Criminal Compliance in Companies: The Invisible Risk Many Organisations Still Fail to Manage", we are here to help you.

Let's talk. We guide you clearly and step by step.