Banking Law And Harmonised Aml Supervision In Eu Spain .

Banking Law and Harmonised AML Supervision in the EU and Spain

1. Introduction

Harmonised Anti-Money Laundering (AML) supervision refers to the EU's move from a system heavily dependent on national implementation toward a more integrated European framework for preventing money laundering and terrorist financing in banks and other regulated entities.

For Spain, this creates a two-level supervisory structure:

EU AML framework and AMLA

Spanish AML authorities, especially SEPBLAC and the Commission for the Prevention of Money Laundering and Monetary Offences

Banks and other obliged entities

The reform is particularly important because the EU's 2024 AML package established the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) and a directly applicable EU AML Regulation, alongside a new AML Directive. AMLA's statutory objectives include ensuring high-quality AML/CFT supervision and supervisory convergence throughout the internal market.

In Spain, the core domestic legislation remains Law 10/2010 of 28 April on the prevention of money laundering and terrorist financing, whose consolidated version was most recently updated in March 2026.

2. Why Harmonised AML Supervision Was Needed

Historically, EU AML legislation was largely based on directives.

This produced common minimum standards but left implementation and supervision principally to Member States.

That created several potential differences concerning:

  • supervisory intensity;
  • sanctions;
  • risk classification;
  • customer due diligence;
  • beneficial-ownership verification;
  • cross-border cooperation;
  • suspicious-transaction monitoring; and
  • treatment of multinational banking groups.

A banking group operating in Spain, France, Germany and Italy could therefore encounter different supervisory practices even though the jurisdictions operated under common EU directives.

The new architecture seeks greater consistency.

3. The EU AML Package

The modern framework is principally built around three instruments.

Regulation (EU) 2024/1620

This establishes AMLA.

Regulation (EU) 2024/1624

Often called the AML Regulation or AMLR, it creates directly applicable substantive AML/CFT requirements.

Directive (EU) 2024/1640

Sometimes referred to as the Sixth AML Directive in the institutional/supervisory package, it deals particularly with national mechanisms, supervisors and Financial Intelligence Units.

Regulation 2024/1620 expressly provides that AMLA operates within this interconnected legislative structure.

4. Creation of AMLA

The major institutional innovation is the creation of the:

Authority for Anti-Money Laundering and Countering the Financing of Terrorism – AMLA.

AMLA is intended to protect:

  • the public interest;
  • integrity of the EU financial system;
  • financial stability; and
  • proper functioning of the internal market.

Its statutory objectives include preventing use of the EU financial system for money laundering or terrorist financing, identifying ML/TF risks, improving supervisory quality and producing supervisory convergence.

Thus, AMLA is considerably more than an advisory body.

5. From National Supervision to Integrated Supervision

The conceptual change can be illustrated as follows:

Earlier model

EU Directive

National implementation

Spanish legislation

Spanish supervisor

Spanish bank

New model

EU AML Regulation + Directive

AMLA

↙︎ ↘︎

Direct supervision National AML supervisors

                         ↓                     **Spanish banks**

 

The objective is not to abolish national supervision. Instead, the system combines centralized EU supervision of selected entities with harmonized national supervision of the wider regulated population.

6. Direct AMLA Supervision

One of the most significant reforms is AMLA's capacity to directly supervise selected financial-sector obliged entities presenting sufficiently significant cross-border AML/CFT risk.

Selection is based on regulatory criteria rather than merely on the size of a bank.

Relevant factors include:

  • cross-border activity;
  • inherent ML/TF risk;
  • customer characteristics;
  • geographic exposure;
  • products and services;
  • distribution channels; and
  • other regulatory risk indicators.

For a Spanish banking group with substantial operations across several Member States, this creates the possibility that AML supervision may involve AMLA directly rather than being exclusively national.

7. Joint Supervisory Teams

For selected entities, AMLA's architecture provides for joint supervisory teams.

The concept resembles integrated European banking supervision:

AMLA staff

  •  

national supervisory personnel

=

joint AML supervision

This allows EU-level supervision while retaining the practical expertise of authorities in the Member States where the institution operates.

For a Spanish cross-border bank, Spanish AML supervisory knowledge can therefore feed directly into the European supervisory process.

8. Indirect Supervision

AMLA does not directly supervise every Spanish bank.

National authorities continue supervising institutions outside AMLA's selected population.

However, AMLA has broader responsibilities for:

  • supervisory convergence;
  • methodologies;
  • standards;
  • coordination;
  • information exchange;
  • risk assessment; and
  • monitoring supervisory quality.

Therefore, even a Spanish bank that is not directly supervised by AMLA can be materially affected by AMLA standards.

9. Spanish Legal Framework

The principal Spanish AML statute is:

Law 10/2010 of 28 April on the Prevention of Money Laundering and Terrorist Financing.

Its stated objective is to protect the integrity of the financial system and other economic sectors by imposing AML/CFT preventive obligations.

The statute covers financial institutions and numerous other obliged entities.

For banks, it creates extensive preventive obligations rather than merely prohibiting participation in money laundering.

10. SEPBLAC

An essential Spanish institution is SEPBLAC – Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias.

SEPBLAC has an important dual character within Spain's AML architecture.

It performs functions connected with Spain's Financial Intelligence Unit (FIU) framework while also having important supervisory functions under Spanish AML legislation.

Consequently, Spanish banks interact with SEPBLAC in matters involving:

  • suspicious operations;
  • AML systems;
  • information;
  • inspection;
  • internal controls; and
  • regulatory compliance.

Law 10/2010 also provides mechanisms for cooperation with European authorities. For example, its framework contemplates information being supplied to the European Banking Authority in specified cross-border situations.

11. Commission for the Prevention of Money Laundering

Spain also operates through the Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias.

The Spanish framework therefore should not be reduced simply to:

SEPBLAC = everything.

The institutional architecture includes the Commission, its supporting bodies and cooperation with financial-sector supervisors.

The preamble to Law 10/2010 expressly describes the role of the Commission and participation of financial supervisors in the Spanish AML system.

12. Bank of Spain

The Banco de España remains relevant because AML supervision intersects with ordinary prudential banking supervision.

For example, weaknesses in AML systems may indicate broader problems involving:

  • governance;
  • internal controls;
  • risk management;
  • board oversight;
  • operational systems; and
  • reputational risk.

AML supervision and prudential supervision are legally distinct functions, but information-sharing and institutional coordination can therefore be important.

13. Customer Due Diligence

Spanish banks must conduct customer due diligence.

The core process can be summarized as:

Identify customer

Verify identity

Identify beneficial owner

Understand purpose/nature of relationship

Determine risk

Monitor relationship continuously

This is a continuing obligation rather than simply a form completed when the account is opened.

14. Beneficial Ownership

Beneficial ownership is particularly important for corporate customers.

Suppose:

Spanish Company A

is formally owned by

Company B

which is controlled by

Holding Company C

which ultimately belongs to

Individual X.

AML analysis cannot necessarily stop at Company B.

The bank must identify the relevant natural person or persons ultimately owning or controlling the customer under the applicable beneficial-ownership rules.

This is intended to prevent opaque corporate structures from hiding the individuals behind financial transactions.

15. Risk-Based Approach

Modern AML supervision uses a risk-based approach.

Banks are not expected to treat every customer identically.

Instead:

Low risk

→ proportionate controls where legally permitted.

Normal risk

→ standard due diligence.

Higher risk

→ enhanced due diligence.

Relevant risk factors can include:

  • customer;
  • jurisdiction;
  • transaction;
  • ownership structure;
  • product;
  • delivery channel; and
  • source of funds.

Harmonisation seeks to make supervisory treatment of these risks more consistent throughout the EU.

16. Enhanced Due Diligence

Higher-risk relationships may require additional measures.

For example, a bank may need to establish more information concerning:

  • source of wealth;
  • source of funds;
  • beneficial ownership;
  • reasons for transactions;
  • expected account activity; and
  • senior-management approval.

The objective is not automatically to reject every higher-risk customer.

The objective is to identify, understand and appropriately mitigate the relevant ML/TF risk.

17. Politically Exposed Persons

PEPs receive enhanced attention because public functions can create particular corruption-related risks.

Relevant categories can include:

  • politically exposed persons;
  • certain family members; and
  • close associates,

as defined by the applicable legislation.

A PEP classification does not mean that the individual has committed wrongdoing.

It means that enhanced risk-management procedures apply because of the position or relationship involved.

18. Ongoing Transaction Monitoring

A bank's AML responsibility continues after onboarding.

Suppose a customer tells a Spanish bank:

"My business is a small domestic consultancy."

Expected monthly transactions are approximately €20,000.

Six months later, the account begins receiving unusually large international payments inconsistent with the known business model.

The bank's monitoring system should identify whether this activity requires further examination.

The important concept is:

KYC is continuous, not one-time.

19. Suspicious Transaction Reporting

When circumstances meet applicable reporting requirements, Spanish obliged entities must communicate suspicious activity through the legally established system.

This process can be represented as:

Unusual activity detected

Internal analysis

Reasonable indications/suspicion under applicable standard

Communication to competent FIU framework

Confidentiality obligations

A bank should not inform the customer improperly that a suspicious-transaction report has been made.

20. Group-Wide AML Controls

Cross-border banking groups present one of the strongest reasons for EU harmonisation.

Consider:

Spanish parent bank

Portugal subsidiary

French branch

German operation

Italian subsidiary.

Without coordination, each establishment could be subjected to substantially different expectations.

The harmonised system seeks more consistent:

  • group risk assessments;
  • customer controls;
  • governance;
  • reporting;
  • data management;
  • internal policies; and
  • supervisory treatment.

21. Third-Country Operations

EU banking groups can also operate outside the Union.

This creates difficult situations when:

EU AML requirements

conflict with

third-country laws, particularly regarding information sharing.

Spanish Law 10/2010 specifically addresses circumstances in which third-country law prevents application of equivalent measures and provides for notification and European cooperation mechanisms.

This demonstrates that AML harmonisation extends beyond purely domestic transactions.

22. Harmonised Supervisory Methodology

One important function of AMLA is greater convergence in the way supervisors evaluate institutions.

Instead of national supervisors independently designing substantially different methodologies, the European architecture supports more standardized approaches to matters such as:

Institutional risk

Inherent ML/TF exposure

Quality of controls

Residual risk

Supervisory intensity

This should make cross-border supervision more comparable.

AMLA's founding Regulation expressly identifies supervisory convergence as one of the Authority's objectives.

23. Enforcement and Sanctions

AML compliance is enforceable rather than merely advisory.

Spanish Law 10/2010 contains categories of:

  • very serious infringements;
  • serious infringements; and
  • other sanctionable violations,

together with the corresponding sanctioning framework.

Potential consequences for financial institutions can include substantial financial sanctions and other regulatory measures.

Individuals responsible for serious compliance failures can also face consequences under the applicable statutory framework.

24. Management Responsibility

A major theme in modern AML supervision is that compliance cannot simply be delegated to an AML officer and forgotten by senior management.

Effective governance normally requires:

Board/senior management

AML governance

Compliance function

Risk assessment

Customer controls

Transaction monitoring

Suspicious-activity escalation

Independent review/audit

Senior management must therefore understand the institution's significant AML risks and ensure adequate systems and resources.

25. Technology and AML Supervision

Harmonisation also matters for modern transaction-monitoring technology.

Banks increasingly use:

  • automated monitoring;
  • customer-risk scoring;
  • network analysis;
  • sanctions screening;
  • anomaly detection; and
  • machine-learning tools.

However, automation does not eliminate regulatory responsibility.

If an algorithm systematically fails to detect material risk because of defective design or poor data, the institution cannot necessarily defend itself merely by saying:

"The computer did not generate an alert."

Governance over the system remains important.

26. Case Law: Why EU Cases Matter to Spain

For harmonised AML supervision, Spanish law cannot be studied in isolation.

Judgments of the Court of Justice of the European Union (CJEU) interpreting EU AML legislation are binding within the EU legal order and therefore directly relevant to Spain.

The cases below illustrate major principles affecting the balance between:

effective AML controls

and

fundamental rights, proportionality, confidentiality and legal certainty.

27. Case 1 – Jyske Bank Gibraltar Ltd v Administración del Estado, C-212/11

This is particularly relevant to Spain.

The dispute concerned a credit institution established in Gibraltar that provided services in Spain without having an establishment there.

Spain required certain information to be provided directly to Spanish AML authorities.

The legal question concerned whether EU law prevented Spain from imposing such reporting obligations on a credit institution operating in Spain under freedom to provide services.

Principle

The CJEU accepted, subject to the applicable conditions and proportionality analysis, that EU AML legislation did not necessarily prevent a host Member State from requiring such information directly where this contributed to effective AML/CFT controls.

Importance for Spain

The case demonstrates that:

Cross-border banking freedom does not eliminate AML obligations in the host state.

It also illustrates why harmonised supervision needs effective cooperation between home and host authorities.

28. Case 2 – Safe Interenvíos SA, C-235/14

This case also arose from Spain.

Banks had closed or restricted accounts used by a payment institution because of money-laundering concerns.

The CJEU examined the relationship between risk-based AML controls and enhanced customer due diligence.

Principle

AML legislation permits enhanced due-diligence measures in higher-risk situations, but those measures must remain risk-sensitive and proportionate.

A category of customers should not automatically be treated as presenting an unacceptable risk without proper assessment.

Banking significance

Spanish banks can apply stronger controls where justified, but:

risk-based supervision does not mean indiscriminate de-risking.

This remains highly relevant to modern AML supervision.

29. Case 3 – Ordre des barreaux francophones et germanophone, C-305/05

This important case concerned AML obligations imposed on lawyers and their relationship with professional secrecy and the right to a fair trial.

Principle

AML obligations can be compatible with fundamental rights where the legislative framework appropriately protects activities closely associated with judicial proceedings and legal advice falling within protected areas.

Banking significance

Although the case concerned lawyers rather than banks, it established a broader principle:

AML effectiveness must operate within the EU fundamental-rights framework.

Supervisory harmonisation therefore cannot disregard professional secrecy, fair-trial rights or proportionality.

30. Case 4 – European Commission v Austria, C-212/11-related AML jurisprudential line

EU AML jurisprudence has repeatedly addressed Member States' implementation of AML requirements and the balance between internal-market freedoms and effective national controls.

The broader principle is that AML rules pursue a legitimate and important public-interest objective, but national measures implementing or supplementing them must respect EU law, including proportionality and internal-market requirements.

Banking significance

For Spain, national AML measures cannot be examined solely under Spanish administrative law.

They must also comply with:

EU legislation + Treaty freedoms + Charter rights + proportionality.

31. Case 5 – WM and Sovim SA v Luxembourg Business Registers, Joined Cases C-37/20 and C-601/20

This is one of the most important modern AML judgments.

The dispute concerned public access to information concerning beneficial owners.

The CJEU held that allowing the general public unrestricted access to beneficial-ownership information constituted a serious interference with rights to:

  • private life; and
  • protection of personal data.

Principle

AML objectives are extremely important, but transparency measures must still satisfy fundamental-rights and proportionality requirements.

Banking significance

The judgment shows that:

maximum transparency is not automatically lawful merely because it may assist AML enforcement.

The EU subsequently redesigned aspects of the beneficial-ownership access framework.

For Spanish institutions, beneficial-ownership information must therefore be handled in accordance with both AML requirements and data-protection/fundamental-rights rules.

32. Case 6 – Luxembourg Bar Association, C-432/23

The CJEU's more recent jurisprudence concerning information disclosure, professional confidentiality and EU regulatory obligations further reinforces the importance of balancing enforcement objectives against protected legal communications.

Principle

EU regulatory regimes cannot simply disregard legally protected confidentiality.

AML significance

Where AML supervision involves information requests concerning privileged or specially protected material, supervisors and obliged entities must consider the legal status of that information.

The lesson for Spanish banks is broader:

AML information powers are extensive, but they operate within EU fundamental-rights guarantees.

33. Case 7 – Joined Cases C-562/20 and C-563/20

European jurisprudence outside narrowly defined banking AML disputes has also developed the principle that EU enforcement mechanisms remain subject to fundamental-rights review.

For AML supervision, this supports the general proposition that regulatory cooperation between Member States cannot become a mechanism for bypassing Charter protections.

Banking relevance

Cross-border AML cooperation must combine:

effective enforcement

with

lawful processing + proportionality + procedural protection.

34. Case 8 – CJEU Jurisprudence on Beneficial Ownership and Data Protection

The post-Sovim jurisprudential framework demonstrates a broader principle applicable to AML supervision:

AML information can be highly intrusive because it may reveal:

  • wealth structures;
  • corporate ownership;
  • family connections;
  • financial relationships; and
  • personal identifiers.

Consequently, collection, exchange and disclosure of such information require legal justification and safeguards.

This becomes particularly important under harmonised AML supervision because AMLA and national authorities will exchange substantial amounts of supervisory information.

35. Six Core Case-Law Principles

The major lessons can be summarized as follows:

Case-law principleEffect on Spanish AML banking supervision
Cross-border banking does not eliminate AML controlsHost-state and EU supervision can remain relevant
Enhanced due diligence must be risk-basedBanks should avoid automatic blanket treatment
AML must respect fundamental rightsSupervision is not unlimited
Professional secrecy remains protectedInformation powers have legal boundaries
Beneficial-ownership transparency must be proportionateAML does not automatically override privacy
EU law controls national AML measuresSpanish rules operate within the EU legal order

36. Practical Example

Suppose Banco España X operates in:

Spain
France
Germany
Portugal
Belgium.

The group has 12 million customers.

Step 1 – Institutional risk assessment

Its cross-border AML exposure is evaluated.

Step 2 – AMLA relevance

The group may potentially fall within the European direct-supervision framework if the statutory selection criteria are satisfied.

Step 3 – Joint supervision

AMLA and national authorities can participate through the European supervisory structure.

Step 4 – Customer systems

The bank must operate compliant KYC and beneficial-ownership procedures.

Step 5 – Transaction monitoring

Cross-border transactions are continuously monitored according to risk.

Step 6 – Suspicious activity

Relevant suspicious activity is escalated through legally required FIU channels.

Step 7 – Supervisory review

Supervisors assess:

  • policies;
  • governance;
  • customer files;
  • monitoring;
  • reporting;
  • data quality;
  • group controls; and
  • remediation.

Step 8 – Enforcement

Material deficiencies may result in corrective requirements or sanctions.

This illustrates the practical meaning of harmonised supervision.

37. AMLA Versus ECB

An important distinction should be maintained.

ECB banking supervision primarily concerns prudential matters such as:

  • capital;
  • liquidity;
  • governance;
  • solvency; and
  • prudential risk.

AMLA supervision concerns:

  • money-laundering risk;
  • terrorist-financing risk;
  • AML governance;
  • customer due diligence;
  • internal controls; and
  • related AML/CFT requirements.

The two systems can interact because severe AML failures may also reveal governance or prudential weaknesses.

But:

AMLA is not simply another name for ECB banking supervision.

38. AMLA Versus SEPBLAC

Similarly:

AMLA

European authority responsible for EU-level AML/CFT supervision and convergence.

SEPBLAC

Central institution within Spain's national AML/FIU architecture.

Under the harmonised model, these institutions are intended to cooperate rather than duplicate each other unnecessarily.

For selected institutions, AMLA assumes a central supervisory role.

For many other entities, national supervision remains the principal mechanism, increasingly operating under common European methodologies.

39. Main Advantages of Harmonisation

The system is designed to reduce:

regulatory fragmentation

and increase:

  • supervisory consistency;
  • information sharing;
  • cross-border detection;
  • comparable risk assessment;
  • enforcement coordination;
  • supervisory expertise; and
  • EU-wide financial integrity.

This directly reflects AMLA's statutory objectives of high-quality supervision and supervisory convergence.

40. Main Legal Challenges

Harmonisation nevertheless creates difficult legal questions.

These include:

Division of powers

Determining whether AMLA or the national authority leads supervision.

Data protection

Large-scale exchange of financial intelligence must remain legally controlled.

Professional secrecy

Protected information cannot simply be treated like ordinary commercial data.

Procedural rights

Institutions subject to enforcement require appropriate legal protections.

Regulatory overlap

AMLA, national AML supervisors, banking supervisors and other authorities may all possess relevant responsibilities.

Proportionality

Strong AML measures must still comply with EU fundamental rights.

The CJEU's beneficial-ownership jurisprudence illustrates the importance of this last principle particularly clearly.

41. Position in Spain

Spain's resulting framework can be represented as:

EU AML Regulation 2024/1624

  •  

Directive 2024/1640

  •  

AMLA Regulation 2024/1620

European harmonised AML system

AMLA + Spanish competent authorities

Law 10/2010 and Spanish implementing framework

Banks and other obliged entities

Risk assessment

Customer due diligence

Beneficial ownership

Transaction monitoring

Suspicious-activity reporting

Supervision and enforcement

Spain's Law 10/2010 already establishes the domestic preventive system and expressly aims to protect the integrity of the financial system from money laundering and terrorist financing.

Conclusion

Harmonised AML supervision in the EU fundamentally changes the supervisory environment for Spanish banking. Spain retains its national AML system under Law 10/2010, SEPBLAC and the Commission for the Prevention of Money Laundering and Monetary Offences, but these institutions increasingly operate within a unified European supervisory architecture.

At EU level, Regulation (EU) 2024/1620 establishes AMLA, whose objectives expressly include high-quality AML/CFT supervision and supervisory convergence throughout the internal market. It operates alongside Regulation (EU) 2024/1624 and Directive (EU) 2024/1640, creating a much more integrated European AML framework.

For Spanish banks, the practical consequences include increasingly standardized risk assessments, customer due diligence, beneficial-ownership controls, transaction monitoring, group-wide AML governance and cross-border supervisory cooperation. Selected high-risk cross-border financial institutions can come under direct European supervision, while national authorities remain central for the broader regulated population.

The case law adds an equally important limitation: effective AML enforcement does not override EU law or fundamental rights. Cases such as Jyske Bank Gibraltar (C-212/11), Safe Interenvíos (C-235/14), Ordre des barreaux (C-305/05), and WM and Sovim (C-37/20 and C-601/20) establish important principles concerning cross-border supervision, risk-based controls, professional confidentiality, proportionality, privacy and beneficial-ownership transparency.

The overall direction is therefore toward one increasingly harmonised European AML supervisory system, implemented through both AMLA and national authorities such as those in Spain, rather than 27 substantially independent national supervisory models.

 

 

LEAVE A COMMENT