Spain's Draft Organic Law on Public Integrity introduces a mandatory compliance checkpoint for companies pursuing public sector contracts. You'll need to demonstrate "an appropriate organization and management model for integrity and the prevention of criminal offenses, together with effective supervision thereof." If your organization bids on Spanish government contracts, you must have a criminal compliance model that meets this standard before the law takes effect.
This template provides a framework based on ISO 37301 compliance management principles and the Spanish Criminal Code's Article 31 bis requirements for organizational liability exemption. Use it as your baseline, then customize it based on your sector and procurement scope.
Purpose of the Template
This compliance model template meets the Draft Law's public procurement requirement. It establishes the governance structure, control activities, and documentation trail that Spanish authorities will expect when evaluating your eligibility to contract with public entities.
The template covers:
- Governance and oversight structure
- Risk assessment methodology for corruption and integrity violations
- Control procedures for procurement interactions
- Whistleblower integration requirements
- Training and communication protocols
- Monitoring and supervision mechanisms
You're building a system that demonstrates proactive corruption prevention, not just policy documentation.
Prerequisites
Before implementing this template, confirm you have:
Organizational commitment: Executive leadership must formally approve the compliance model and allocate resources for implementation. The Draft Law requires "effective supervision," meaning this can't be a paper exercise.
Whistleblower system: The Draft amends the Retaliation Protection Act to require that your internal reporting system integrates with your compliance framework. If you don't have a whistleblower hotline that meets Law 2/2023 requirements, implement one first.
Records retention capability: The Draft extends the statute of limitations from five to seven years for corruption offenses. Your compliance documentation must be retained for at least seven years.
Conflict-of-interest declarations: All personnel involved in public procurement must complete these declarations. Prepare your declaration template before rolling out the broader model.
The Template
1. Governance Structure
Compliance Committee Composition:
- Chair: Independent director or senior executive without procurement responsibilities
- Members: Legal counsel, finance director, procurement lead, HR representative
- Reporting line: Direct to Board of Directors or Audit Committee
Committee Charter:
- Quarterly review of compliance monitoring reports
- Annual risk assessment approval
- Authority to investigate potential violations
- Budget control for compliance resources
2. Risk Assessment Protocol
Annual Corruption Risk Assessment:
Identify exposure points:
- Public procurement bid processes
- Contract execution and change orders
- Interactions with government officials
- Political donations or sponsorships (note: the Draft increases scrutiny here)
- Subcontractor selection for public contracts
For each exposure point, document:
- Inherent risk level (likelihood × impact)
- Existing controls
- Residual risk after controls
- Mitigation actions if residual risk exceeds tolerance
Red Flag Indicators:
- Requests for unusual payment terms or structures
- Third-party intermediaries with unclear roles
- Pressure to expedite procurement decisions
- Conflicts of interest in evaluation panels
3. Control Procedures
Pre-Bid Controls:
- Conflict-of-interest declaration from all bid team members
- Due diligence on any partners or subcontractors (minimum: commercial registry verification, beneficial ownership review, sanctions screening)
- Gift and hospitality pre-approval for any interactions during bid period
Bid Execution Controls:
- Segregation of duties: separate personnel for technical proposal, pricing, and submission
- Two-person rule for all meetings with procurement officials
- Meeting log requirement (date, attendees, topics, outcomes)
- Documentation retention flag (seven-year hold)
Post-Award Controls:
- Contract change order review by Compliance Committee if value exceeds 10% of original contract
- Quarterly vendor performance review including integrity metrics
- Subcontractor payment verification (ensure payments match contract terms and deliverables)
4. Whistleblower Integration
Your whistleblower system must include:
Policy Integration Statement: "This internal reporting system operates as part of [Company Name]'s compliance and integrity framework, established to prevent corruption and offenses against public administration. Reports received through this channel inform our ongoing risk assessment and control effectiveness evaluation."
Reporting Categories Specific to Public Procurement:
- Bid manipulation or collusion
- Bribery or improper payments
- Conflicts of interest
- Fraudulent invoicing
- Retaliation against employees who refuse improper requests
Retaliation Protection Procedures: Document your investigation timeline and interim protection measures. The Draft emphasizes retaliation protection, and Spanish courts will scrutinize your response to reports.
5. Training Requirements
Annual Training (Mandatory):
- All employees: General integrity and anti-corruption principles (60 minutes)
- Procurement team: Public sector compliance requirements (120 minutes)
- Executive leadership: Organizational liability under Criminal Code Article 31 bis (90 minutes)
Documentation: Maintain training completion records with test scores. Minimum passing score: 80%.
Customizing the Template
Sector-Specific Risks: If you operate in construction, healthcare, or defense, add control procedures for sector-specific corruption patterns. Construction companies should include controls around permit expediting. Healthcare organizations need protocols for interactions with public hospital procurement.
Company Size Adjustments: Smaller organizations can combine the Compliance Committee with existing audit or risk committees, but maintain the independent chair requirement. You still need separation between procurement execution and compliance oversight.
Procurement Volume: If you pursue fewer than three public contracts annually, simplify the monitoring cadence to semi-annual reviews. If you're a frequent bidder, consider monthly compliance metrics reporting.
Geographic Scope: If you bid on contracts from multiple Spanish autonomous communities, document any regional variations in procurement rules. Catalonia and the Basque Country sometimes impose additional requirements.
Validation Steps
Before declaring your model operational:
1. Documentation Completeness Check:
- Compliance Committee charter signed by Board
- Risk assessment completed with executive approval
- Control procedures documented in accessible format
- Whistleblower policy updated with integration language
- Training materials prepared and delivery scheduled
2. Control Testing:
- Run a simulated bid process and verify that all control steps execute
- Submit a test whistleblower report and confirm investigation workflow
- Review a sample of conflict-of-interest declarations for completeness
3. Gap Analysis Against Draft Law:
- Confirm your model addresses "organization and management for integrity"
- Verify "effective supervision" through Committee meeting schedule and reporting
- Check that your whistleblower system meets the amended Retaliation Protection Act language
4. Legal Review: Have external counsel review your model against Article 31 bis Criminal Code requirements. The Draft increases penalties substantially (fines based on annual turnover or unlawful benefit, mandatory disqualification from public contracts), so your model must withstand regulatory scrutiny.
5. Board Certification: Obtain formal Board resolution adopting the compliance model. This creates the governance record that demonstrates organizational commitment.
The Draft Law hasn't taken final form yet, but the compliance model requirement for public procurement is clear. Build your framework now while you have time to test and refine it. Once the law enters force, you'll need this system operational to maintain your public sector contract eligibility.





