SEPBLAC
- What is SEPBLAC?
- What are SEPBLAC's main functions?
- Who are the obligated entities under SEPBLAC?
- Control mechanisms: Key business obligations to SEPBLAC
- SEPBLAC sanction regime: Consequences of non-compliance
- SEPBLAC operational assessment: implications for the business ecosystem
- Compliance strategies and best practices before SEPBLAC
- Sources and recommended reading
What is SEPBLAC?
SEPBLAC (Executive Service of the Commission for the Prevention of Money Laundering and Monetary Offences) is the supervisory authority and Financial Intelligence Unit (FIU) of Spain. Its main function is to protect the integrity of the financial system by preventing, detecting, and prosecuting anti-money laundering and countering the financing of terrorism (AML/CFT).
Unlike traditional banking regulators focused on solvency (such as the Bank of Spain or the CNMV), SEPBLAC operates as a specialized body dedicated to monitoring regulatory compliance. For any fintech, payment institution, or merchant operating in Spain, SEPBLAC is the key point of contact to which suspicious transaction alerts are reported and internal control policies are justified.
What are SEPBLAC's main functions?
SEPBLAC plays a fundamental dual role within the Spanish legal framework, acting simultaneously in intelligence and supervision:
- Financial Intelligence Unit (FIU): Receives, analyzes, and processes suspicious transaction reports submitted by obligated entities. When it detects indications of a crime, it prepares intelligence reports that are forwarded to the Public Prosecutor's Office or judicial authorities.
- Supervision and Inspection: Evaluates whether financial institutions and professionals effectively apply the required due diligence, internal control, and prevention measures mandated by law.
- International Collaboration: Exchanges information with other international FIUs (through the Egmont Group) to trace suspicious cross-border financial flows.
- Regulatory Guidance and Recommendations: Publishes risk catalogs, operational guidelines, and sectoral warnings to help businesses detect criminal patterns.
Who are the obligated entities under SEPBLAC?
The regulatory scope defined by Article 2.1 of Law 10/2010 is broad and covers both financial and non-financial sectors:
- Financial and FinTech Sector: Credit institutions, payment institutions, electronic money institutions (EMIs), payment gateways, investment firms, life insurance companies, and providers of crypto-asset exchange or custody services.
- Non-Financial Sectors: Real estate developers and agents, auditors, tax advisors, lawyers (when managing funds or real estate), dealers in jewelry or art, lotteries, and casinos.
Control mechanisms: Key business obligations to SEPBLAC
Companies classified as obligated entities must establish a structured internal control system across the following phases:
- Appointment of a SEPBLAC Representative: Formally designate a resident executive in Spain responsible for direct communication with the agency.
- Due Diligence (KYC/KYB and Beneficial Owner): Formally identify all clients and verify the identity of the beneficial owner (natural person owning more than 25% of capital or control) before starting a business relationship.
- Special Examination and Suspicious Activity Reporting: Analyze any anomalous operation inconsistent with the client's profile. If indications of a crime persist, a Suspicious Activity Report (Form F19 or via the CTL application) must be submitted immediately.
- Systematic Reporting: Report monthly to SEPBLAC specific transactions required by law (such as cash movements exceeding €30,000 or transfers involving certain territories).
- Procedures Manual and External Audit: Maintain an updated AML/CFT manual and subject the prevention system to an annual review by an accredited External Expert.
SEPBLAC sanction regime: Consequences of non-compliance
Failure to comply with regulatory obligations carries a strict sanction regime managed in coordination with the Commission for the Prevention of Money Laundering and Monetary Offences:
- Very Serious infringements: Fines of up to €10 million, or 10% of total annual turnover, along with the revocation of administrative authorization to operate.
- Serious infringements: Minimum fines ranging from €150,000 to €1.5 million, public reprimands, and temporary disqualification of executives.
- Minor infringements: Minor financial penalties up to €60,000 for technical errors or non-systematic omissions.
📌 SEPBLAC Reminder: The adoption of prevention measures must be strictly guided by the Risk-Based Approach (RBA). SEPBLAC has reiterated that entities should not resort to de-risking or the mass, unjustified closing of accounts, but rather apply a proportional, documented analysis on a case-by-case basis.
SEPBLAC operational assessment: implications for the business ecosystem
Complying with SEPBLAC requirements demands a balance between regulatory rigor and business agility:
| Aspect | Positive Implication (Integrity & Security) | Operational Implication (Compliance Burden) |
|---|---|---|
| Reputation & Trust | Guarantees a market protected against organized crime and fraud. | Requires rigorous onboarding processes (KYC/KYB) that can slow conversion. |
| Regulatory Supervision | Provides clear, equal rules for all competitors in the market. | Increases compliance operating costs (RegTech tools, audits). |
| International Credibility | Facilitates the opening of correspondent accounts by aligning with EU and FATF standards. | Requires continuous investment in internal staff training and alert management. |
| Risk Mitigation | Prevents involuntary involvement of the company in money laundering schemes. | Risk of severe penalties or administrative disqualification for reporting omissions. |
Compliance strategies and best practices before SEPBLAC
To ensure smooth alignment between commercial operations and SEPBLAC requirements, the following measures are recommended:
- RegTech Automation: Integrate digital identity verification solutions and real-time screening for sanctions lists and Politically Exposed Persons (PEPs).
- Structured Document Retention: Store all due diligence documentation and special examination files for a minimum of 10 years.
- Regular Staff Training: Design annual training programs tailored to specific employee roles to identify suspicious patterns.
- Active Compliance Culture: Establish an Internal Control Body (OCI) equipped with the independence needed to make quick decisions regarding dubious transactions.
Sources and recommended reading
- Law 10/2010, of April 28, on the prevention of money laundering and terrorist financing.
- Royal Decree 304/2014, of May 5, approving the Regulations of Law 10/2010.
- SEPBLAC Typology Catalogs on Suspicious Transactions.
- SEPBLAC: Recommendations on Special Examination and Suspicious Activity Reporting.
Was this term useful?
1 of 1 I found it useful

Leave a Comment