Perspectivas
Perspective 001Regulation

What Spain's recent AML enforcement activity says about regulatory expectations.

Supervisory focus has moved beyond policies to the evidence that governance, accountability and controls operate in practice. Spain offers a useful case study.

El texto completo de este análisis se publica en inglés. La estructura, las cifras y las referencias son las mismas en ambas versiones del sitio.

Por Everett MorganSummer 202612 min read
Madrid Cuatro Torres financial district at sunset
Introduction

The last twelve months of supervisory activity in Spain have set out, in unusually clear terms, what European AML supervisors now expect regulated firms to be able to demonstrate.

SEPBLAC's 2025 Annual Report, published in May 2026, records a year of on-site and thematic inspection work across banks, payment institutions, investment firms and other obliged entities. One line in the report matters more than most of the statistics. SEPBLAC says its inspection strategy is putting more weight on substantive testing and less on procedural review. In plain English, having the procedure is not the same thing as proving the control works.

That is the factual anchor for everything else in this Perspective. It also lands alongside a series of published sanctions: €3.9193 million against ING Bank NV, Spain branch, €605,424 across two sanctions against Banca March, and €17.601 million concerning legacy Bankia conduct published after Bankia's absorption into CaixaBank.

Read together, the report and the notices describe a supervisory environment in which a policy manual, a committee calendar and a Business-Wide Risk Assessment are the minimum expectation rather than evidence of an effective control framework. What gets tested is whether customer due diligence, monitoring and reporting actually work on the relationships and transactions the supervisor chooses to sample.

The themes also matter beyond Spain. AMLA will begin direct supervision of selected high-risk cross-border financial groups in 2028, while its wider role is intended to drive greater consistency in how national supervisors assess AML/CFT risk and controls. For that reason alone, recent Spanish enforcement deserves close attention from any Board, MLRO or head of compliance in a European regulated firm.

Key findings
  1. 01SEPBLAC states that its inspection strategy is putting more weight on substantive testing and less on procedural review. Having the procedure is not the same thing as proving the control works.
  2. 02Customer due diligence weaknesses recur throughout SEPBLAC's inspection findings: outdated documentation, weak understanding of a customer's real economic activity, gaps in ongoing monitoring and weaknesses in remote onboarding.
  3. 03SEPBLAC's thematic work on internal alert systems identified poorly calibrated thresholds, absence of appropriate scenarios, alerts excluded without sufficient justification and resource saturation that can prevent timely detection.
  4. 04Suspicious-transaction reporting is assessed on both formal quality and substantive relevance, including how long a firm takes to report after the activity occurs and the quality of the analysis supporting the communication.
  5. 05The ING Spain sanction of €3.9193 million concerned a failure to report suspicion where indications had already been identified internally. Information existed inside the organisation and did not produce the required outcome.
  6. 06Banca March was fined €605,424 across two sanctions concerning failures in enhanced due diligence and the required special examination of potentially suspicious activity, treated as very serious in the context of previous enforcement for the same type of failure.
  7. 07A €17.601 million sanction concerning legacy Bankia conduct was published after Bankia's absorption into CaixaBank, a reminder that historic AML failures can remain live regulatory issues years later.

What the published record actually says

It is worth being careful here about the difference between what SEPBLAC and the BOE have published and what I think those findings mean. The first part of this article stays with the record. The interpretation comes afterwards, and it is mine.

The ING Spain sanction

The ING Spain case is a particularly stark example. The published sanction concerned a failure to report suspicion where indications had already been raised internally. The significance is not that the firm lacked an AML framework. It is that information capable of triggering a regulatory obligation existed inside the organisation and did not produce the required outcome. The penalty was €3.9193 million.

I would want to know, in any firm, how that happens. Not who to blame, but where the information stopped. In my experience it is usually a handover: an analyst raises something, it moves into a queue, the queue has a backlog, and nobody owns the decision to report or not report by a particular date.

The Banca March sanctions

Banca March was fined €605,424 across two sanctions concerning failures in enhanced due diligence and the required special examination of potentially suspicious activity. The published decision is particularly relevant because the infringements were treated as very serious in the context of previous enforcement for the same type of failure. The sanctions were under appeal before the Supreme Court when published.

What I take from this is narrow and important. Repetition changes the character of a finding. A weakness a supervisor has already told you about is not the same weakness the second time around.

Legacy Bankia conduct and the CaixaBank successor position

The publication of a €17.601 million sanction concerning legacy Bankia conduct, following Bankia's absorption into CaixaBank, is another reminder that historic AML failures can remain live regulatory issues years later. The underlying conduct was historic Bankia conduct. It does not tell you anything about CaixaBank's current control environment, and it should not be read that way.

It does tell you something about acquisitions. If you take on a book, you take on its history, including the parts that have not yet surfaced.

Customer due diligence

CDD weaknesses recur throughout SEPBLAC's inspection findings. The reported themes include outdated documentation, weak understanding of customers' real economic activity, gaps in ongoing monitoring and weaknesses in remote onboarding arrangements.

None of that is exotic. A file that was adequate at onboarding stops being adequate when the customer's activity changes and nobody looks again. The part that gets firms into trouble is the second item on that list. Knowing who a customer is has never been the same as understanding what they actually do for a living, and it is the second question that a supervisor tests against the transactions.

Internal alert systems and transaction monitoring

SEPBLAC's thematic work on internal alert systems identified poorly calibrated thresholds, gaps in scenario coverage, alerts excluded without sufficient justification and resource saturation. Those are not documentation problems. They are evidence that the monitoring system may not be capturing the risks it was designed to detect.

The saturation point deserves attention. A system that produces more work than the team can absorb does not fail visibly. It fails quietly, through delay, and delay is what turns a detectable pattern into a late report or no report at all. I would expect a firm to be able to show how thresholds were set, why the scenario set fits its own business, what has been excluded from monitoring and on whose authority, and how long alerts are actually taking to clear.

Suspicious-transaction reporting

SEPBLAC assesses suspicious-transaction reporting on both formal quality and substantive relevance, including how long it takes a firm to report after the suspicious activity occurs and the quality of the analysis supporting the communication.

Filing is not the finish line. A report that arrives months after the activity, or that sets out the transaction without setting out the reasoning, has not really discharged anything. The ING case is the sharp end of the same point.

Sanctions and geopolitical risk controls

Sanctions and restrictive-measures controls have drawn sustained attention across European supervision, reflecting the volume of listings since 2022 and the operational strain that has placed on firms. I am deliberately keeping this section higher level, because the specific supervisory findings I would want to cite are not in the published Spanish material.

The pace of geopolitical change means controls that were sensible a year ago can become stale very quickly. That is a reason to revisit screening logic, list coverage and escalation criteria on a schedule rather than after an incident.

What I take from this

Everything below this line is interpretation. It draws on the Spanish material and on similar European enforcement and remediation work I have been involved in.

What I take from this, and from similar European enforcement work, is that governance evidence matters only if it shows challenge, decision and follow-through. A Board that approves a Business-Wide Risk Assessment has done something administratively. A Board whose minutes show it pushed back on a risk rating, asked for a number that was missing, and returned to the answer at the next meeting has done something a supervisor can actually see.

For much of the last decade it was possible to satisfy an AML inspection with the right documents: an approved BWRA, a current policy suite, a committee structure and a training programme. SEPBLAC's own description of its inspection strategy tells you that is no longer a safe assumption in Spain, and the pattern across other European supervisors points the same way.

In practice, substantive testing means sampling files and asking why a particular risk rating was assigned. It means sitting in an alert review and asking how the analysts decided what to escalate. It means reading a Board pack and asking a director to explain the firm's three largest financial crime exposures. Where the answers are hesitant or generic, the finding tends to write itself.

The practical implication for me is that legacy does not mean historic from a risk perspective. If an old customer relationship is still live, weaknesses in that file are part of today's control environment, not yesterday's problem. Acquired portfolios and dormant relationships are the two places this gets missed most often.

Why this matters for regulated firms

The practical implications of these themes reach well beyond the compliance function.

If the underlying customer risk information is unreliable, everything built on it becomes harder to trust: monitoring, prioritisation, escalation and ultimately the quality of suspicious-activity decisions. That is not a CDD team problem. It is a firm-wide data problem that happens to surface in the CDD team.

Where monitoring is calibrated to a generic template rather than to the firm's actual business, the firm can end up generating alerts that do not matter while missing patterns that do. The first exhausts analyst capacity and erodes decision quality. The second exposes the firm to the risks the monitoring was meant to detect.

Where Board packs report volumes rather than risk, senior management cannot exercise the oversight expected of them. The Board approves what it is shown, and what it is shown does not answer the question it needs to answer. That is where a weakness in MI can become a governance problem, and potentially an accountability problem for the people responsible for acting on it.

Where sanctions controls lag geopolitical change, the firm is relying on yesterday's screening logic to detect today's risk. The pace of geopolitical change means controls that were sensible a year ago can become stale very quickly.

Potential consequences

The realistic consequences here are not hypothetical. They are visible in the published notices.

ING Spain produced a €3.9193 million penalty on a reporting failure. Banca March produced €605,424 across two sanctions against a considerably smaller institution, with the infringements treated as very serious given previous enforcement for the same type of failure. The scale of the penalty differed. The nature of the underlying weakness did not.

Beyond financial penalties, the consequences can include public censure and remediation obligations that can become multi-year programmes. Supervisory scrutiny can remain materially heightened long after the original finding. For some firms, findings restrict the pace at which they can onboard new customers or enter new markets until remediation is complete.

There is also a set of consequences that does not appear on any published decision. Remediation programmes consume management attention on a scale that is difficult to appreciate from outside one. Skilled resources are redirected from business priorities. External advisers and monitors impose their own overhead. Reputation recovers slowly and unevenly, and in institutional segments the memory of an enforcement action is long.

In my experience, finding these weaknesses yourself is usually considerably cheaper than fixing them after the supervisor has found them for you.

Questions Boards and MLROs should now ask

The most productive response to recent Spanish supervisory activity is not to redraft policies. It is to test whether the framework you already operate would withstand the kind of substantive examination SEPBLAC says it is now conducting.

These are the questions I would want a Board and MLRO to be ready to answer before the next inspection. Firms that can answer them from evidence rather than from memory are in a defensible position. Firms that cannot have at least identified where to begin.

  1. 01Would we be able to evidence effective Board oversight of financial crime risk if a supervisor asked us to demonstrate it in the next 30 days?
  2. 02Are we relying on the existence of policies, or can we show, file by file, that the controls those policies describe operate as intended?
  3. 03Have our transaction monitoring scenarios and thresholds been independently reviewed against our current customer base, products and delivery channels, and when was that review last refreshed?
  4. 04Could we justify, on the evidence held on file, every high-risk customer relationship we currently maintain?
  5. 05Does our Board and executive management information explain the firm's financial crime risk, or does it report operational volumes such as alerts raised, cases closed and training completed?
  6. 06Have our sanctions and adverse media controls kept pace with geopolitical change over the last 24 months, including screening logic, list coverage and escalation criteria?
  7. 07When was the last independent challenge to our SAR decision-making, and were the results shared with the Board?

How Claritas can help

Claritas Risk Advisory works with smaller and mid-sized regulated firms in Spain and across Europe on the specific issues raised by recent SEPBLAC activity. Our work centres on three areas: independent AML governance reviews that test whether frameworks operate as documented, regulatory readiness assessments carried out ahead of expected supervisory engagement, and targeted remediation of the weaknesses those reviews identify.

The advice is grounded in experience gained inside major international financial institutions and in direct engagement with supervisors, inspections and remediation programmes. It is designed to be proportionate to the firm receiving it, and to leave the firm better able to answer the questions supervisors are now asking. The direction is consistent with the new EU AML framework and AMLA's move towards more harmonised, risk-based supervision: firms increasingly need to demonstrate how their controls operate in practice.

References
  • SEPBLAC. Memoria de Actividades 2025 (Annual Report, published May 2026). sepblac.es/es/sobre-sepblac/memorias-de-actividades
  • Boletín Oficial del Estado. Sanction notice concerning ING Bank NV, Sucursal en España (failure to report suspicion where indications had been identified internally, €3.9193 million). boe.es (search: ING Bank NV, Ley 10/2010)
  • Boletín Oficial del Estado. Sanction notices concerning Banca March SA (enhanced due diligence and special examination obligations, €605,424 across two sanctions, under appeal before the Supreme Court when published). boe.es (search: Banca March, Ley 10/2010)
  • Boletín Oficial del Estado. Sanction notice concerning historic Bankia SA conduct, published in respect of the successor position following absorption into CaixaBank SA (€17.601 million). boe.es (search: Bankia, CaixaBank, Ley 10/2010)
  • Anti-Money Laundering Authority (AMLA). Official material on direct supervision of selected obliged entities from 2028 and supervisory convergence. amla.europa.eu
  • SEPBLAC. Official website. sepblac.es/en
Sobre el autor
Everett Morgan
Founder & Principal Adviser, Claritas Risk Advisory

Everett has more than twenty years' experience in financial crime, AML governance, regulatory compliance and operational risk gained within Deutsche Bank, Morgan Stanley and BNP Paribas. He established Claritas Risk Advisory to provide smaller regulated financial institutions with experienced independent judgement, practical insight and proportionate recommendations.

¿Necesita una opinión independiente?

Preparing for regulatory change starts with understanding where your organisation stands today.

If you would like to discuss your financial crime framework or explore how Claritas Risk Advisory can help, I would be pleased to arrange a confidential conversation.

Empecemos con una conversación