Banking Law And Financial Stability Digital Monitoring Spain .
Banking Law and Financial Stability: Digital Monitoring in Spain
Introduction
Digital monitoring has become an important part of banking supervision in Spain. Modern supervisors do not rely only on periodic paper-based reports or traditional inspections. They increasingly use continuous data collection, automated analysis, supervisory technology (SupTech), stress testing, cybersecurity monitoring and digital-risk indicators to identify problems in banks before those problems become systemic.
Spanish banking supervision operates within the Single Supervisory Mechanism (SSM), led by the European Central Bank (ECB), with Banco de España participating as the national competent authority. Banco de España states that its continuous off-site supervision includes regular analysis of institutions' economic and financial developments, SREP assessments, recovery-plan reviews and other monitoring activities.
The 2025 Banco de España Supervision Report specifically identifies SupTech activities as part of the supervisory model.
Legal and Regulatory Framework
1. Law 10/2014
Law 10/2014 on the regulation, supervision and solvency of credit institutions provides an important foundation for Spanish prudential supervision.
The framework allows supervisory authorities to obtain information, assess institutions' risks and impose corrective measures where weaknesses are identified. Banco de España identifies Law 10/2014 as part of the current legal basis for banking supervision and financial stability.
Digital monitoring strengthens these powers by allowing supervisory authorities to analyse information continuously rather than waiting for a crisis.
2. Single Supervisory Mechanism
Since 2014, significant Spanish banks have been supervised within the SSM under Regulation (EU) No. 1024/2013.
The ECB and national supervisors receive and analyse information concerning supervised institutions. Banco de España explains that the supervisory model combines prudential regulation, continuous supervision, corrective measures and sanctions.
3. Continuous Off-Site Supervision
Continuous off-site supervision is particularly relevant to digital monitoring.
Banco de España describes its objectives as checking compliance with prudential regulation and maintaining an updated assessment of an institution's supervisory risk profile. The profile considers risks relating to future solvency, profitability and liquidity and the possibility that problems could affect the financial system.
Digital systems make this process more frequent and data-driven.
4. SupTech
SupTech refers to technology used by supervisory authorities to improve supervision.
The Banco de España's 2025 supervision report identifies SupTech as part of its supervisory activities. The ECB has also developed AI-supported supervisory tools. Its 2024 Annual Report describes tools including Athena, which assists supervisors in extracting and comparing information from very large collections of documents, and Heimdall, which supports assessments concerning the suitability of bank board members.
5. Digital Operational Resilience Act
The Digital Operational Resilience Act (DORA) has applied since January 2025. It establishes requirements concerning ICT security, operational resilience, testing and third-party technology risks.
Banco de España's 2026 Financial Stability Report identifies DORA as an important component of the framework for addressing technological and third-party risks. It also notes that ECB Banking Supervision has placed operational cyber resilience among its supervisory priorities for 2026–2028.
Financial Stability Implications
A. Earlier Identification of Bank Problems
Digital monitoring can identify deteriorating liquidity, capital, profitability or asset quality earlier than periodic traditional assessments.
This is important because financial instability can develop rapidly. A supervisory system capable of identifying unusual changes in bank indicators can allow authorities to investigate before weaknesses become systemic.
B. Cybersecurity Risk
Digital banking creates a second type of financial-stability risk: technological disruption.
Cyberattacks can affect payment systems, customer access, trading systems and critical banking infrastructure. Banco de España's 2026 Financial Stability Report specifically discusses the financial-stability implications of technological disruption in cybersecurity.
The ECB has also stated in 2026 that AI is changing the cyber-threat landscape and that supervisors need stronger monitoring of third-party dependencies and greater information sharing concerning vulnerabilities and incidents.
C. Artificial Intelligence and Automated Decisions
Banks increasingly use algorithms for:
- credit assessment;
- fraud detection;
- customer monitoring;
- transaction surveillance;
- anti-money-laundering controls;
- risk modelling; and
- portfolio management.
These systems can improve risk detection but can also create legal problems if automated decisions are inaccurate, discriminatory or insufficiently explainable.
D. Data Concentration and Third-Party Risk
Digital banks frequently depend on cloud providers, software vendors, payment processors and other technology companies.
A failure affecting an important technology provider could therefore affect several banks simultaneously. DORA's third-party ICT framework addresses part of this systemic risk.
E. Macroprudential Monitoring
Digital monitoring also supports macroprudential supervision.
Banco de España describes financial stability as the ability of the financial system to absorb shocks without disrupting financial intermediation and creating additional economic damage. Its macroprudential framework uses monitoring and analytical tools to identify systemic vulnerabilities.
The ECB similarly uses quantitative tools, including macro stress testing and network analysis, to identify and assess systemic risks.
Important Case Laws
Because "digital monitoring" is a relatively new supervisory concept, Spanish courts do not yet have a large body of judgments specifically titled around SupTech. The following cases are therefore relevant because they establish principles concerning automated banking decisions, data monitoring, financial information, supervisory intervention and digital-era risk controls.
1. SCHUFA Scoring — CJEU, Case C-634/21, 7 December 2023
The Court of Justice considered automated credit scoring under Article 22 GDPR.
The Court held that automated establishment of a probability value concerning an individual's ability to meet payment obligations can constitute automated individual decision-making when a third party relies substantially on that value in deciding whether to establish, implement or terminate a contractual relationship.
Importance: Banks using automated credit-monitoring systems cannot treat algorithmic scoring as legally irrelevant simply because the final contractual decision is technically made by a bank employee.
2. CJEU, Case C-203/22, 27 February 2025
The CJEU further addressed automated credit profiling and the right to obtain meaningful information about the logic involved.
The Court held that where automated decision-making or profiling is covered by Article 22 GDPR, the data subject can require information explaining, in a concise, transparent and intelligible manner, the procedure and principles actually applied to produce a result such as a credit profile.
Importance: Digital banking supervision must consider not only whether algorithms operate efficiently but also whether their use complies with transparency and data-protection requirements.
3. SRB v EDPS — General Court, Case T-557/20, 26 April 2023
This case arose from the resolution of Banco Popular Español. The General Court examined personal-data issues involving the Single Resolution Board and the treatment of information concerning shareholders and creditors affected by the bank's resolution.
Importance: Digital supervisory and resolution systems can contain large amounts of sensitive financial and personal information. Regulatory authorities therefore have to reconcile effective supervision with data-protection obligations.
4. Banco Santander v ECB — General Court, Case T-610/24
Banco Santander challenged an ECB supervisory decision concerning the prudential treatment of deferred tax assets originating in Banco Santander Brasil and incorporated into Santander on a consolidated basis. The case demonstrates judicial review of ECB prudential supervision of a major Spanish banking group. The proceedings remained pending, with an ECB appeal subsequently registered before the CJEU in 2026.
Importance: Digital monitoring ultimately feeds into supervisory decisions concerning capital and prudential risk. Such decisions remain subject to legal review.
5. Banco Santander – Supreme Court, 9 April 2018
The Spanish Supreme Court confirmed substantial CNMV sanctions against Banco Santander concerning the marketing of Valores Santander. The case concerned failures to obtain sufficient information about customers and properly assess their profiles before marketing the product.
Importance: Customer profiling must be based on relevant information rather than simplistic segmentation. This principle remains relevant where banks increasingly automate customer classification.
6. Supreme Court – Banco Popular/Santander, 16 May 2023
The Supreme Court confirmed a €1 million CNMV sanction against Santander as successor to Banco Popular for omissions or misleading information concerning executive remuneration in annual reports.
Importance: Digital reporting and automated regulatory monitoring do not reduce the underlying responsibility of banks to ensure that information submitted to markets and supervisors is accurate.
7. Banco Popular/Santander – Supreme Court, STS 5185/2025
The Supreme Court considered investor claims concerning information supplied in connection with Banco Popular's share offering and the consequences of the bank's subsequent resolution. The Court applied the CJEU's 2022 reasoning concerning the interaction between investor claims and the EU bank-resolution framework.
Importance: Digital monitoring can provide authorities with extensive information, but the legal consequences of supervisory and resolution actions remain governed by substantive EU and Spanish banking law.
Enforcement and Supervisory Measures
Digital monitoring becomes meaningful only when authorities can act on identified risks.
The Spanish supervisory framework allows measures including:
- additional supervisory requirements;
- corrective recommendations;
- recovery and remediation plans;
- intervention or replacement of administrators where legally justified;
- sanctions;
- enhanced capital or liquidity requirements where applicable; and
- macroprudential measures addressing systemic risks.
Banco de España expressly identifies corrective measures and sanctions as elements of its supervisory model.
Challenges of Digital Monitoring
Algorithmic Error
Automated systems may generate false positives or false negatives. Supervisors therefore need human review and validation.
Data Quality
Poor-quality or incomplete banking data can produce misleading risk indicators. Digital monitoring does not eliminate the need for reliable underlying data.
Privacy
Supervisory authorities may process large quantities of personal and financial information. GDPR and other data-protection requirements therefore remain relevant.
Cybersecurity
A supervisory system itself becomes a potential target for cyberattacks. Protection of supervisory databases and communication channels is consequently part of financial stability.
Explainability
AI-based supervisory decisions can become difficult to explain. This is particularly important where an institution faces a significant supervisory measure based partly on automated analysis.
Conclusion
Digital monitoring is becoming an important component of Spanish banking supervision and financial-stability policy. Banco de España's continuous off-site supervision, SupTech activities and participation in the SSM allow supervisory authorities to analyse banking risks more continuously.
The development of DORA, AI-based supervision, cybersecurity monitoring, automated risk analysis and macroprudential data systems means that financial stability increasingly depends on both traditional banking controls and technological resilience. The 2026 Banco de España Financial Stability Report specifically identifies technological disruption and cybersecurity as financial-stability issues, while ECB Banking Supervision has made operational cyber resilience a major supervisory priority for 2026–2028.
The case law adds an important legal dimension: SCHUFA establishes limits and transparency requirements for automated credit scoring; SRB v EDPS demonstrates the data-protection implications of digital resolution processes; and Spanish banking cases show that technology does not remove banks' responsibilities concerning customer profiling, accurate information and prudential compliance.
Thus, digital monitoring in Spain should be understood not simply as a technological upgrade to banking supervision, but as an increasingly important part of the legal architecture for early-risk detection, cyber resilience, responsible automated decision-making and protection of overall financial stability.

comments