Criminal Compliance

Criminal compliance.

Since the reform that introduced the criminal liability of legal entities, a company can be convicted for crimes committed within its organization. The best defense does not begin with a summons: it starts years earlier, with a criminal compliance program that prevents crime and demonstrates the organization’s diligence.

What the Criminal Code states

Article 31 bis regulates the criminal liability of legal entities and the possibility of being exempt or having liability mitigated if the entity possesses an appropriate organization and management model, adopted and effectively implemented prior to the commission of the offense. Having it on paper is not enough: it must be real, active, and supervised.

What an effective program includes

A risk map adapted to the activity, protocols and controls, a whistleblowing channel compliant with informant protection regulations, training for administrators and executives, and an autonomous supervisory body. We design it considering how it will stand up in court, not just to pass an audit.

Why Barbancho

We design compliance from a defense perspective: we know what a judge requires to grant an exemption because we defend those cases. The litigation perspective applied to prevention is the difference between a decorative program and one that truly protects.

International dimension

For groups with a presence in several countries, we align the Spanish program with group standards (German, Swiss, or British parent companies) and with transnational anti-money laundering or anti-corruption frameworks, ensuring that compliance functions coherently across all jurisdictions.

(24h Emergency)

Index

Frequently asked questions

What is asked first.

Can a company face criminal trial?

Yes. Since the introduction of Article 31 bis of the Criminal Code, legal entities can be held criminally liable for offenses committed within their organization.

Does compliance prevent conviction?

An appropriate, genuine, and supervised model can exempt or mitigate the criminal liability of the company.

Is a standard program sufficient?

No. It must be based on a risk map specific to the activity and be effectively implemented.

document.addEventListener('click', function(e) { const question = e.target.closest('.faq-question'); if (!question) return; const item = question.closest('.faq-item'); if (!item) return; item.classList.toggle('is-open'); });