Update of the SEPBLAC digital certificate and report on the penalties imposed in 2025
1. Communications to SEPBLAC
A recent renewal of the digital certificate of the Executive Service of the Commission for the Prevention of Money Laundering and Financing of Terrorism ("SEPBLAC") requires the review and updating of the digital certificate of all regulated entities using the Monthly Transaction Report ( hereinafter, «DMO»).
Within the framework of the obligations incumbent upon regulated entities regarding the prevention of money laundering and the financing of terrorism ("AML/CFT"), Article 20 of Law 10/2010, of 28 April («Law 10/2010») establishes the duty to communicate certain operations to SEPBLAC in a systematic manner. In application of this obligation, Article 27 of Royal Decree 304/2014, of 5 May (hereinafter, «RD 304/2014») establishes the categories of operations that must be periodically notified to SEPBLAC.
Conversely, in the event that no reportable transactions have occurred, the obligated parties must submit a negative quarterly statement, thereby ensuring the continuity of information on this matter. Similarly, both reports must be submitted through the electronic channels provided by SEPBLAC and, in particular, using the software application DMO.
In this context, it is especially important to emphasize that SEPBLAC has recently announced the renewal of the digital certificate necessary for accessing and using the DMO application, meaning that regulated entities must review and update their electronic identification and digital signature systems to ensure continued compliance with their information obligations.
This technical update must be carried out before 30 June 2026 and is part of the process of strengthening the security and reliability of communication channels with the supervisory authority, as well as gradually adapting to more stringent technological standards.
2. Report on penalties relating to AML/CFT
The Report on penalties and requests to obligated entities in the area of preventing money laundering and financing of terrorism (AML/CFT) for the financial year 2025, published by the Commission for the Prevention of Money Laundering and Monetary Offences of the Treasury, offers a detailed overview of the infractions detected by supervisors in the AML/CFT field and the corresponding penalty amounts.
During that financial year, a total of 51 final administrative penalties were imposed, all classified as serious infractions, highlighting that the most sanctioned infractions refer to:
- Deficient internal control policies and procedures.
- Lack of special scrutiny of transactions.
- Failure to comply with enhanced measures and continuous monitoring.
Regarding the amount of the penalties, the minimum (and most commonly applied) is set at €60,000.00, while the highest penalty is €12,274,340.00.
An analysis of the sanctioned infractions during 2025 yields the following results, based on:
- The classification of the entity, based on the sector or type of entity in which the sanctioned infractions occurred:
- Entities professionally engaged in currency exchange activities (12 sanctioned infractions).
- Credit institutions (10 sanctioned infractions).
- Insurance entities (9 sanctioned infractions).
- Payment institutions (7 sanctioned infractions).
- Online gambling entities (7 sanctioned infractions).
- Casinos (6 sanctioned infractions).
- Type of sanctioned non-compliance:
- Lack of adequate policies and procedures (10 sanctioned infractions).
- Non-compliance with the obligation to conduct special scrutiny of transactions (7 sanctioned infractions).
- Non-compliance with the application of enhanced due diligence measures (7 sanctioned infractions).
- Non-compliance with continuous monitoring measures of the business relationship (6 sanctioned infractions).
- Non-compliance with formal identification obligations (6 sanctioned infractions).
- Non-compliance with the obligation to obtain information about the purpose and nature of the business relationship (4 sanctioned infractions).
However, the report itself specifically notes that the detected infractions are not directly related to a poorer performance in the examined sectors, but rather are linked to stricter requirements from supervisors, given the risk associated with each sector.
Informative note from the Governance and Compliance Department of ECIJA Madrid.

LATEST FROM #ECIJA

The renewal of the SEPBLAC digital certificate requires all entities subject to these regulations to review and update their digital certificates before 30 June 2026, in order to have the latest version of the online procedure and to submit the relevant notifications to this body.

The implementation of the Internal Information System has raised practical questions in many organizations regarding the allocation of internal responsibilities and, in particular, how this fits with the role of the Data Protection Officer.

Rosario Alonso, analyses the debate currently facing the US Supreme Court regarding the limits of access to personal data and how this discussion also connects with the current challenges in Chile.

ECIJA Barcelona is positioned as a strategic ally of the digital health ecosystem thanks to its transversal approach that connects law, technology and business.

The National High Court has issued a guilty verdict against one of the largest international networks involved in audiovisual piracy.

ECIJA Ecuador analyses new obligations before the UAFE for sports operators.

ECIJA Ecuador analyses new law that strengthens education and economic reactivation.

ECIJA GPA analyses the new Social Transparency Law and its obligations.

ECIJA Ecuador incorporates Víctor Granados as partner to strengthen corporate and regulatory areas.






