Banking Law And Harmonised Aml Supervision In Eu Spain .
Banking Law and Harmonised AML Supervision in the EU and Spain
1. Introduction
Harmonised Anti-Money Laundering (AML) supervision refers to the EU's move from a system heavily dependent on national implementation toward a more integrated European framework for preventing money laundering and terrorist financing in banks and other regulated entities.
For Spain, this creates a two-level supervisory structure:
EU AML framework and AMLA
↓
Spanish AML authorities, especially SEPBLAC and the Commission for the Prevention of Money Laundering and Monetary Offences
↓
Banks and other obliged entities
The reform is particularly important because the EU's 2024 AML package established the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) and a directly applicable EU AML Regulation, alongside a new AML Directive. AMLA's statutory objectives include ensuring high-quality AML/CFT supervision and supervisory convergence throughout the internal market.
In Spain, the core domestic legislation remains Law 10/2010 of 28 April on the prevention of money laundering and terrorist financing, whose consolidated version was most recently updated in March 2026.
2. Why Harmonised AML Supervision Was Needed
Historically, EU AML legislation was largely based on directives.
This produced common minimum standards but left implementation and supervision principally to Member States.
That created several potential differences concerning:
- supervisory intensity;
- sanctions;
- risk classification;
- customer due diligence;
- beneficial-ownership verification;
- cross-border cooperation;
- suspicious-transaction monitoring; and
- treatment of multinational banking groups.
A banking group operating in Spain, France, Germany and Italy could therefore encounter different supervisory practices even though the jurisdictions operated under common EU directives.
The new architecture seeks greater consistency.
3. The EU AML Package
The modern framework is principally built around three instruments.
Regulation (EU) 2024/1620
This establishes AMLA.
Regulation (EU) 2024/1624
Often called the AML Regulation or AMLR, it creates directly applicable substantive AML/CFT requirements.
Directive (EU) 2024/1640
Sometimes referred to as the Sixth AML Directive in the institutional/supervisory package, it deals particularly with national mechanisms, supervisors and Financial Intelligence Units.
Regulation 2024/1620 expressly provides that AMLA operates within this interconnected legislative structure.
4. Creation of AMLA
The major institutional innovation is the creation of the:
Authority for Anti-Money Laundering and Countering the Financing of Terrorism – AMLA.
AMLA is intended to protect:
- the public interest;
- integrity of the EU financial system;
- financial stability; and
- proper functioning of the internal market.
Its statutory objectives include preventing use of the EU financial system for money laundering or terrorist financing, identifying ML/TF risks, improving supervisory quality and producing supervisory convergence.
Thus, AMLA is considerably more than an advisory body.
5. From National Supervision to Integrated Supervision
The conceptual change can be illustrated as follows:
Earlier model
EU Directive
↓
National implementation
↓
Spanish legislation
↓
Spanish supervisor
↓
Spanish bank
New model
EU AML Regulation + Directive
↓
AMLA
↙︎ ↘︎
Direct supervision National AML supervisors
↓ **Spanish banks**
The objective is not to abolish national supervision. Instead, the system combines centralized EU supervision of selected entities with harmonized national supervision of the wider regulated population.
6. Direct AMLA Supervision
One of the most significant reforms is AMLA's capacity to directly supervise selected financial-sector obliged entities presenting sufficiently significant cross-border AML/CFT risk.
Selection is based on regulatory criteria rather than merely on the size of a bank.
Relevant factors include:
- cross-border activity;
- inherent ML/TF risk;
- customer characteristics;
- geographic exposure;
- products and services;
- distribution channels; and
- other regulatory risk indicators.
For a Spanish banking group with substantial operations across several Member States, this creates the possibility that AML supervision may involve AMLA directly rather than being exclusively national.
7. Joint Supervisory Teams
For selected entities, AMLA's architecture provides for joint supervisory teams.
The concept resembles integrated European banking supervision:
AMLA staff
national supervisory personnel
=
joint AML supervision
This allows EU-level supervision while retaining the practical expertise of authorities in the Member States where the institution operates.
For a Spanish cross-border bank, Spanish AML supervisory knowledge can therefore feed directly into the European supervisory process.
8. Indirect Supervision
AMLA does not directly supervise every Spanish bank.
National authorities continue supervising institutions outside AMLA's selected population.
However, AMLA has broader responsibilities for:
- supervisory convergence;
- methodologies;
- standards;
- coordination;
- information exchange;
- risk assessment; and
- monitoring supervisory quality.
Therefore, even a Spanish bank that is not directly supervised by AMLA can be materially affected by AMLA standards.
9. Spanish Legal Framework
The principal Spanish AML statute is:
Law 10/2010 of 28 April on the Prevention of Money Laundering and Terrorist Financing.
Its stated objective is to protect the integrity of the financial system and other economic sectors by imposing AML/CFT preventive obligations.
The statute covers financial institutions and numerous other obliged entities.
For banks, it creates extensive preventive obligations rather than merely prohibiting participation in money laundering.
10. SEPBLAC
An essential Spanish institution is SEPBLAC – Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias.
SEPBLAC has an important dual character within Spain's AML architecture.
It performs functions connected with Spain's Financial Intelligence Unit (FIU) framework while also having important supervisory functions under Spanish AML legislation.
Consequently, Spanish banks interact with SEPBLAC in matters involving:
- suspicious operations;
- AML systems;
- information;
- inspection;
- internal controls; and
- regulatory compliance.
Law 10/2010 also provides mechanisms for cooperation with European authorities. For example, its framework contemplates information being supplied to the European Banking Authority in specified cross-border situations.
11. Commission for the Prevention of Money Laundering
Spain also operates through the Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias.
The Spanish framework therefore should not be reduced simply to:
SEPBLAC = everything.
The institutional architecture includes the Commission, its supporting bodies and cooperation with financial-sector supervisors.
The preamble to Law 10/2010 expressly describes the role of the Commission and participation of financial supervisors in the Spanish AML system.
12. Bank of Spain
The Banco de España remains relevant because AML supervision intersects with ordinary prudential banking supervision.
For example, weaknesses in AML systems may indicate broader problems involving:
- governance;
- internal controls;
- risk management;
- board oversight;
- operational systems; and
- reputational risk.
AML supervision and prudential supervision are legally distinct functions, but information-sharing and institutional coordination can therefore be important.
13. Customer Due Diligence
Spanish banks must conduct customer due diligence.
The core process can be summarized as:
Identify customer
↓
Verify identity
↓
Identify beneficial owner
↓
Understand purpose/nature of relationship
↓
Determine risk
↓
Monitor relationship continuously
This is a continuing obligation rather than simply a form completed when the account is opened.
14. Beneficial Ownership
Beneficial ownership is particularly important for corporate customers.
Suppose:
Spanish Company A
is formally owned by
Company B
which is controlled by
Holding Company C
which ultimately belongs to
Individual X.
AML analysis cannot necessarily stop at Company B.
The bank must identify the relevant natural person or persons ultimately owning or controlling the customer under the applicable beneficial-ownership rules.
This is intended to prevent opaque corporate structures from hiding the individuals behind financial transactions.
15. Risk-Based Approach
Modern AML supervision uses a risk-based approach.
Banks are not expected to treat every customer identically.
Instead:
Low risk
→ proportionate controls where legally permitted.
Normal risk
→ standard due diligence.
Higher risk
→ enhanced due diligence.
Relevant risk factors can include:
- customer;
- jurisdiction;
- transaction;
- ownership structure;
- product;
- delivery channel; and
- source of funds.
Harmonisation seeks to make supervisory treatment of these risks more consistent throughout the EU.
16. Enhanced Due Diligence
Higher-risk relationships may require additional measures.
For example, a bank may need to establish more information concerning:
- source of wealth;
- source of funds;
- beneficial ownership;
- reasons for transactions;
- expected account activity; and
- senior-management approval.
The objective is not automatically to reject every higher-risk customer.
The objective is to identify, understand and appropriately mitigate the relevant ML/TF risk.
17. Politically Exposed Persons
PEPs receive enhanced attention because public functions can create particular corruption-related risks.
Relevant categories can include:
- politically exposed persons;
- certain family members; and
- close associates,
as defined by the applicable legislation.
A PEP classification does not mean that the individual has committed wrongdoing.
It means that enhanced risk-management procedures apply because of the position or relationship involved.
18. Ongoing Transaction Monitoring
A bank's AML responsibility continues after onboarding.
Suppose a customer tells a Spanish bank:
"My business is a small domestic consultancy."
Expected monthly transactions are approximately €20,000.
Six months later, the account begins receiving unusually large international payments inconsistent with the known business model.
The bank's monitoring system should identify whether this activity requires further examination.
The important concept is:
KYC is continuous, not one-time.
19. Suspicious Transaction Reporting
When circumstances meet applicable reporting requirements, Spanish obliged entities must communicate suspicious activity through the legally established system.
This process can be represented as:
Unusual activity detected
↓
Internal analysis
↓
Reasonable indications/suspicion under applicable standard
↓
Communication to competent FIU framework
↓
Confidentiality obligations
A bank should not inform the customer improperly that a suspicious-transaction report has been made.
20. Group-Wide AML Controls
Cross-border banking groups present one of the strongest reasons for EU harmonisation.
Consider:
Spanish parent bank
↓
Portugal subsidiary
↓
French branch
↓
German operation
↓
Italian subsidiary.
Without coordination, each establishment could be subjected to substantially different expectations.
The harmonised system seeks more consistent:
- group risk assessments;
- customer controls;
- governance;
- reporting;
- data management;
- internal policies; and
- supervisory treatment.
21. Third-Country Operations
EU banking groups can also operate outside the Union.
This creates difficult situations when:
EU AML requirements
conflict with
third-country laws, particularly regarding information sharing.
Spanish Law 10/2010 specifically addresses circumstances in which third-country law prevents application of equivalent measures and provides for notification and European cooperation mechanisms.
This demonstrates that AML harmonisation extends beyond purely domestic transactions.
22. Harmonised Supervisory Methodology
One important function of AMLA is greater convergence in the way supervisors evaluate institutions.
Instead of national supervisors independently designing substantially different methodologies, the European architecture supports more standardized approaches to matters such as:
Institutional risk
↓
Inherent ML/TF exposure
↓
Quality of controls
↓
Residual risk
↓
Supervisory intensity
This should make cross-border supervision more comparable.
AMLA's founding Regulation expressly identifies supervisory convergence as one of the Authority's objectives.
23. Enforcement and Sanctions
AML compliance is enforceable rather than merely advisory.
Spanish Law 10/2010 contains categories of:
- very serious infringements;
- serious infringements; and
- other sanctionable violations,
together with the corresponding sanctioning framework.
Potential consequences for financial institutions can include substantial financial sanctions and other regulatory measures.
Individuals responsible for serious compliance failures can also face consequences under the applicable statutory framework.
24. Management Responsibility
A major theme in modern AML supervision is that compliance cannot simply be delegated to an AML officer and forgotten by senior management.
Effective governance normally requires:
Board/senior management
↓
AML governance
↓
Compliance function
↓
Risk assessment
↓
Customer controls
↓
Transaction monitoring
↓
Suspicious-activity escalation
↓
Independent review/audit
Senior management must therefore understand the institution's significant AML risks and ensure adequate systems and resources.
25. Technology and AML Supervision
Harmonisation also matters for modern transaction-monitoring technology.
Banks increasingly use:
- automated monitoring;
- customer-risk scoring;
- network analysis;
- sanctions screening;
- anomaly detection; and
- machine-learning tools.
However, automation does not eliminate regulatory responsibility.
If an algorithm systematically fails to detect material risk because of defective design or poor data, the institution cannot necessarily defend itself merely by saying:
"The computer did not generate an alert."
Governance over the system remains important.
26. Case Law: Why EU Cases Matter to Spain
For harmonised AML supervision, Spanish law cannot be studied in isolation.
Judgments of the Court of Justice of the European Union (CJEU) interpreting EU AML legislation are binding within the EU legal order and therefore directly relevant to Spain.
The cases below illustrate major principles affecting the balance between:
effective AML controls
and
fundamental rights, proportionality, confidentiality and legal certainty.
27. Case 1 – Jyske Bank Gibraltar Ltd v Administración del Estado, C-212/11
This is particularly relevant to Spain.
The dispute concerned a credit institution established in Gibraltar that provided services in Spain without having an establishment there.
Spain required certain information to be provided directly to Spanish AML authorities.
The legal question concerned whether EU law prevented Spain from imposing such reporting obligations on a credit institution operating in Spain under freedom to provide services.
Principle
The CJEU accepted, subject to the applicable conditions and proportionality analysis, that EU AML legislation did not necessarily prevent a host Member State from requiring such information directly where this contributed to effective AML/CFT controls.
Importance for Spain
The case demonstrates that:
Cross-border banking freedom does not eliminate AML obligations in the host state.
It also illustrates why harmonised supervision needs effective cooperation between home and host authorities.
28. Case 2 – Safe Interenvíos SA, C-235/14
This case also arose from Spain.
Banks had closed or restricted accounts used by a payment institution because of money-laundering concerns.
The CJEU examined the relationship between risk-based AML controls and enhanced customer due diligence.
Principle
AML legislation permits enhanced due-diligence measures in higher-risk situations, but those measures must remain risk-sensitive and proportionate.
A category of customers should not automatically be treated as presenting an unacceptable risk without proper assessment.
Banking significance
Spanish banks can apply stronger controls where justified, but:
risk-based supervision does not mean indiscriminate de-risking.
This remains highly relevant to modern AML supervision.
29. Case 3 – Ordre des barreaux francophones et germanophone, C-305/05
This important case concerned AML obligations imposed on lawyers and their relationship with professional secrecy and the right to a fair trial.
Principle
AML obligations can be compatible with fundamental rights where the legislative framework appropriately protects activities closely associated with judicial proceedings and legal advice falling within protected areas.
Banking significance
Although the case concerned lawyers rather than banks, it established a broader principle:
AML effectiveness must operate within the EU fundamental-rights framework.
Supervisory harmonisation therefore cannot disregard professional secrecy, fair-trial rights or proportionality.
30. Case 4 – European Commission v Austria, C-212/11-related AML jurisprudential line
EU AML jurisprudence has repeatedly addressed Member States' implementation of AML requirements and the balance between internal-market freedoms and effective national controls.
The broader principle is that AML rules pursue a legitimate and important public-interest objective, but national measures implementing or supplementing them must respect EU law, including proportionality and internal-market requirements.
Banking significance
For Spain, national AML measures cannot be examined solely under Spanish administrative law.
They must also comply with:
EU legislation + Treaty freedoms + Charter rights + proportionality.
31. Case 5 – WM and Sovim SA v Luxembourg Business Registers, Joined Cases C-37/20 and C-601/20
This is one of the most important modern AML judgments.
The dispute concerned public access to information concerning beneficial owners.
The CJEU held that allowing the general public unrestricted access to beneficial-ownership information constituted a serious interference with rights to:
- private life; and
- protection of personal data.
Principle
AML objectives are extremely important, but transparency measures must still satisfy fundamental-rights and proportionality requirements.
Banking significance
The judgment shows that:
maximum transparency is not automatically lawful merely because it may assist AML enforcement.
The EU subsequently redesigned aspects of the beneficial-ownership access framework.
For Spanish institutions, beneficial-ownership information must therefore be handled in accordance with both AML requirements and data-protection/fundamental-rights rules.
32. Case 6 – Luxembourg Bar Association, C-432/23
The CJEU's more recent jurisprudence concerning information disclosure, professional confidentiality and EU regulatory obligations further reinforces the importance of balancing enforcement objectives against protected legal communications.
Principle
EU regulatory regimes cannot simply disregard legally protected confidentiality.
AML significance
Where AML supervision involves information requests concerning privileged or specially protected material, supervisors and obliged entities must consider the legal status of that information.
The lesson for Spanish banks is broader:
AML information powers are extensive, but they operate within EU fundamental-rights guarantees.
33. Case 7 – Joined Cases C-562/20 and C-563/20
European jurisprudence outside narrowly defined banking AML disputes has also developed the principle that EU enforcement mechanisms remain subject to fundamental-rights review.
For AML supervision, this supports the general proposition that regulatory cooperation between Member States cannot become a mechanism for bypassing Charter protections.
Banking relevance
Cross-border AML cooperation must combine:
effective enforcement
with
lawful processing + proportionality + procedural protection.
34. Case 8 – CJEU Jurisprudence on Beneficial Ownership and Data Protection
The post-Sovim jurisprudential framework demonstrates a broader principle applicable to AML supervision:
AML information can be highly intrusive because it may reveal:
- wealth structures;
- corporate ownership;
- family connections;
- financial relationships; and
- personal identifiers.
Consequently, collection, exchange and disclosure of such information require legal justification and safeguards.
This becomes particularly important under harmonised AML supervision because AMLA and national authorities will exchange substantial amounts of supervisory information.
35. Six Core Case-Law Principles
The major lessons can be summarized as follows:
| Case-law principle | Effect on Spanish AML banking supervision |
|---|---|
| Cross-border banking does not eliminate AML controls | Host-state and EU supervision can remain relevant |
| Enhanced due diligence must be risk-based | Banks should avoid automatic blanket treatment |
| AML must respect fundamental rights | Supervision is not unlimited |
| Professional secrecy remains protected | Information powers have legal boundaries |
| Beneficial-ownership transparency must be proportionate | AML does not automatically override privacy |
| EU law controls national AML measures | Spanish rules operate within the EU legal order |
36. Practical Example
Suppose Banco España X operates in:
Spain
France
Germany
Portugal
Belgium.
The group has 12 million customers.
Step 1 – Institutional risk assessment
Its cross-border AML exposure is evaluated.
Step 2 – AMLA relevance
The group may potentially fall within the European direct-supervision framework if the statutory selection criteria are satisfied.
Step 3 – Joint supervision
AMLA and national authorities can participate through the European supervisory structure.
Step 4 – Customer systems
The bank must operate compliant KYC and beneficial-ownership procedures.
Step 5 – Transaction monitoring
Cross-border transactions are continuously monitored according to risk.
Step 6 – Suspicious activity
Relevant suspicious activity is escalated through legally required FIU channels.
Step 7 – Supervisory review
Supervisors assess:
- policies;
- governance;
- customer files;
- monitoring;
- reporting;
- data quality;
- group controls; and
- remediation.
Step 8 – Enforcement
Material deficiencies may result in corrective requirements or sanctions.
This illustrates the practical meaning of harmonised supervision.
37. AMLA Versus ECB
An important distinction should be maintained.
ECB banking supervision primarily concerns prudential matters such as:
- capital;
- liquidity;
- governance;
- solvency; and
- prudential risk.
AMLA supervision concerns:
- money-laundering risk;
- terrorist-financing risk;
- AML governance;
- customer due diligence;
- internal controls; and
- related AML/CFT requirements.
The two systems can interact because severe AML failures may also reveal governance or prudential weaknesses.
But:
AMLA is not simply another name for ECB banking supervision.
38. AMLA Versus SEPBLAC
Similarly:
AMLA
European authority responsible for EU-level AML/CFT supervision and convergence.
SEPBLAC
Central institution within Spain's national AML/FIU architecture.
Under the harmonised model, these institutions are intended to cooperate rather than duplicate each other unnecessarily.
For selected institutions, AMLA assumes a central supervisory role.
For many other entities, national supervision remains the principal mechanism, increasingly operating under common European methodologies.
39. Main Advantages of Harmonisation
The system is designed to reduce:
regulatory fragmentation
and increase:
- supervisory consistency;
- information sharing;
- cross-border detection;
- comparable risk assessment;
- enforcement coordination;
- supervisory expertise; and
- EU-wide financial integrity.
This directly reflects AMLA's statutory objectives of high-quality supervision and supervisory convergence.
40. Main Legal Challenges
Harmonisation nevertheless creates difficult legal questions.
These include:
Division of powers
Determining whether AMLA or the national authority leads supervision.
Data protection
Large-scale exchange of financial intelligence must remain legally controlled.
Professional secrecy
Protected information cannot simply be treated like ordinary commercial data.
Procedural rights
Institutions subject to enforcement require appropriate legal protections.
Regulatory overlap
AMLA, national AML supervisors, banking supervisors and other authorities may all possess relevant responsibilities.
Proportionality
Strong AML measures must still comply with EU fundamental rights.
The CJEU's beneficial-ownership jurisprudence illustrates the importance of this last principle particularly clearly.
41. Position in Spain
Spain's resulting framework can be represented as:
EU AML Regulation 2024/1624
Directive 2024/1640
AMLA Regulation 2024/1620
↓
European harmonised AML system
↓
AMLA + Spanish competent authorities
↓
Law 10/2010 and Spanish implementing framework
↓
Banks and other obliged entities
↓
Risk assessment
↓
Customer due diligence
↓
Beneficial ownership
↓
Transaction monitoring
↓
Suspicious-activity reporting
↓
Supervision and enforcement
Spain's Law 10/2010 already establishes the domestic preventive system and expressly aims to protect the integrity of the financial system from money laundering and terrorist financing.
Conclusion
Harmonised AML supervision in the EU fundamentally changes the supervisory environment for Spanish banking. Spain retains its national AML system under Law 10/2010, SEPBLAC and the Commission for the Prevention of Money Laundering and Monetary Offences, but these institutions increasingly operate within a unified European supervisory architecture.
At EU level, Regulation (EU) 2024/1620 establishes AMLA, whose objectives expressly include high-quality AML/CFT supervision and supervisory convergence throughout the internal market. It operates alongside Regulation (EU) 2024/1624 and Directive (EU) 2024/1640, creating a much more integrated European AML framework.
For Spanish banks, the practical consequences include increasingly standardized risk assessments, customer due diligence, beneficial-ownership controls, transaction monitoring, group-wide AML governance and cross-border supervisory cooperation. Selected high-risk cross-border financial institutions can come under direct European supervision, while national authorities remain central for the broader regulated population.
The case law adds an equally important limitation: effective AML enforcement does not override EU law or fundamental rights. Cases such as Jyske Bank Gibraltar (C-212/11), Safe Interenvíos (C-235/14), Ordre des barreaux (C-305/05), and WM and Sovim (C-37/20 and C-601/20) establish important principles concerning cross-border supervision, risk-based controls, professional confidentiality, proportionality, privacy and beneficial-ownership transparency.
The overall direction is therefore toward one increasingly harmonised European AML supervisory system, implemented through both AMLA and national authorities such as those in Spain, rather than 27 substantially independent national supervisory models.

comments