Skip to content
Spain

Modelo 290 — Spain’s annual FATCA account return

Fintech Passport
September 9, 2026 · 11-min read
Modelo 290 — Spain’s annual FATCA account return

Spain decided years ago that an issuer of loadable payment means is a depository institution. That sentence, buried in article 2 of the order that created Modelo 290, is why the Spanish FATCA return reaches firms that have never taken a deposit. Modelo 290 is the annual return through which a Spanish reporting financial institution tells the Agencia Tributaria about accounts held by certain US persons, sent as an XML message over a web service with its own uniqueness rules, correction grammar and size ceiling. This piece sets out who files, what goes in, and how the transmission behaves.

1. What Modelo 290 is

Modelo 290 — Declaración informativa anual de cuentas financieras de determinadas personas estadounidenses — was approved by Orden HAP/1136/2014 of 30 June 2014, which also sets the Spanish due-diligence and reporting rules under the Spain–United States FATCA agreement signed in Madrid on 14 May 2013. Article 13 creates the return; article 15 leaves its format and design to whatever is published on the Agencia Tributaria’s electronic office, which is where the technical specification actually lives.

It is not Spain’s CRS return: Modelo 290 is bilateral and US-specific, while Modelo 289 covers the mutual-assistance regime. An institution with both populations files both, from the same due-diligence work but into two channels. The Modelo 290 procedure is GI38 in the sede electrónica.

2. Who files — and the definition that catches a payments firm

Article 1 puts the obligation on entities that are a custodial institution, a depository institution, an investment entity or a specified insurance company and that qualify as a Spanish reporting financial institution. Article 2 then defines each category for Spanish purposes, and the depository limb is the one that surprises people: it covers entities accepting deposits in the ordinary course of a banking or similar business, and states that the category includes credit institutions and entities that issue means of payment capable of being loaded before use.

Custodial institutions hold financial assets for others as a substantial part of their business, expressly including investment firms. Investment entities are caught by a 50% gross-income test over the shorter of the three years ended on the preceding 31 December or the entity’s life. Article 1.2 then removes the non-reporting Spanish institutions listed in Annex II. Every reporting institution must also register with the IRS and obtain a GIIN, which becomes part of the return and of every record identifier inside it.

3. What gets reported

Article 3 lists the reportable accounts: depository accounts, custodial accounts, cash-value insurance contracts (excluding reinsurance between two insurers), annuity contracts, and equity or debt interests in certain entities. Periodic payments from the Annex II social-provision instruments fall outside the annuity concept, and anything Annex II excludes is not a financial account at all.

Two date boundaries do the heavy lifting, and both are Spanish adjustments rather than the agreement’s own dates. Pre-existing and new accounts are separated by 30 June 2014 and 1 July 2014. And for Annex II section II paragraph A.1, the reference to 1 January 2014 reads as 1 July 2014. Article 8 then lets an account opened after 30 June 2014 by a customer who already held one at that date be treated as pre-existing, without re-documenting the customer, provided the pre-existing procedures are applied in time and all the accounts are treated as one for both due diligence and reporting.

4. The three elections worth taking deliberately

The order gives Spanish institutions options that change the size of the exercise. Each has a condition attached.

ArticleElectionThe condition
5Apply the Annex I balance or value thresholds and other exclusionsMay be exercised for all accounts or separately for a clearly identifiable group — a business line, a location — but not account by account
6Use third-party service providersResponsibility for correct compliance stays with the institution, which must first check the provider has adequate due-diligence and record-keeping procedures
9Aggregate balances across the institution and related entitiesRequired only to the extent systems link the accounts by a data item such as customer number or NIF and permit aggregation; negative balances count as zero

The aggregation carve-out is unusually practical: where an institution is not permitted to give a customer an integrated statement of all positions because of data-protection restrictions, article 9 says the requirement is not met and aggregation must not be performed for that holder. Article 10 supplies the supporting definitions — related entities as more than 50% of capital and more than 50% of voting rights held together, and a relationship manager as an employee who regularly advises, recommends, monitors or facilitates transactions for particular holders.

5. Self-certifications and documentary evidence

Article 7 is permissive on form and strict on content. A self-certification may be taken in any way — electronic and telephone channels included — that lets the institution keep evidence of its content and date and show it came from the holder or their representative, and it may sit across more than one document. For a new individual account whose only tax residence is Spain it can even be a verbal confirmation, provided nothing indicates a US connection and the statement is reasonable against the account-opening file.

The minimum content is fixed: full name or company name, full address, country or countries of tax residence, the tax identification number for each, and citizenship. US forms are accepted. On validity, self-certifications are valid indefinitely; so is documentary evidence issued by an authorised public body, evidence not subject to renewal, and evidence supplied by non-reporting institutions or by US persons that are not specified US persons. Other documentary evidence is generally valid until the last day of the third calendar year after the year it was provided, or later if its own expiry is later. A change of circumstances capable of affecting the holder’s status ends validity — but a tax-residence certificate simply passing the period it was issued for is expressly not one.

The consequence of bad documentation belongs in procedures: where an institution knows, or may come to know, that a self-certification or documentary evidence is incorrect or unreliable, it cannot rely on it, must request a new one, and if the customer does not provide it must treat the account as a reportable US account until it can verify the status correctly.

6. The return: window and content

The filing window is 1 January to 31 May for the immediately preceding year. That is not the original wording — article 13.2 as enacted said 31 March, and was replaced by the third final provision of Orden HAP/1695/2016 of 25 October, aligning Modelo 290 with the new Modelo 289. Anyone working from the 2014 text will diarise the wrong date.

The Annex sets the content. For the institution: NIF, GIIN, name, a structured address, country of residence, the ejercicio, and whether the return is complementaria or sustitutiva with the reference of the return replaced — supplied for both the sponsored investment entity and the sponsor where the filer acts as a sponsoring entity. For each account: the account number, which may be an IBAN, an ISIN, a policy or annuity reference, or any other identifier the institution uses; the balance or total value at the end of the calendar year or other relevant reference period, or immediately before closure; and the currency. For each holder: the US TIN (the EIN for an entity, and more than one may be declared), the name split into first name, second name and surnames, or the company name, and the address.

7. Sending it: the GI38 web service

Modelo 290 is machine-to-machine by design. The AEAT’s published specification uses SOAP 1.1 in document/literal style over HTTPS, presentation and receipt each described by its own XML schema, with errors returned as SOAP FAULT elements — a Server faultcode for a server-side problem, a Client faultcode for a malformed or incorrect message. Sending requires a recognised electronic certificate held by the obliged party, an authorised representative for the procedure, or a colaborador social.

Six mechanics decide whether a campaign runs cleanly:

  • Size. The presentation XML is capped provisionally at 512 KB, so a large book must be split across presentations by design.
  • PresentationCode. Shaped 290 + ejercicio + a remainder that must guarantee uniqueness for that filer and year. It is also the duplicate guard: a second presentation carrying a code already processed is treated as the same presentation rather than a new one.
  • PresentationType. Normal or Simulation. The simulation flag is the rehearsal mechanism — and forgetting to remove it is the reason a firm believes it has filed when it has not.
  • DataQuality. Maximum returns rejections for errors and warnings for anomalies; Medium rejects only for errors. Maximum first is a free data-quality report.
  • DocTypeIndic. FATCA1 new data, FATCA2 corrected at the IRS’s request, FATCA3 cancelled, FATCA4 modified on the institution’s own initiative. Since 1 October 2015 these cannot be mixed: one presentation carries one type, and every element bearing a DocTypeIndic — ReportingFI, Sponsor and AccountReport — must carry the same value.
  • DocRefId. Shaped <GIIN>.ES-<NIF>-<ejercicio>-<remainder>, with a full stop separating the GIIN from the rest. The service validates that the identifier has not been received before and rejects information that reuses one.

An accepted receipt carries a result of Accepted, a reference, a timestamp, a 16-character CSV secure verification code and an Expediente, plus per-DocRefId validation details that can include warnings as well as errors. Article 14 explains why a receipt can be good and bad news at once: where a return contains errors, only the account-holder pairs with no ground for rejection are accepted, the response lists accepted and rejected pairs with reasons, and the institution must correct and re-present the rejected ones. Cancellations also cascade: cancelling every account of a sponsor or of a reporting institution effectively cancels that sponsor or institution, even across several presentations.

8. Three worked examples

Example one: the e-money issuer that thought FATCA was a bank problem. Facts: a Spanish institution issues prepaid balances and cards; no deposit-taking licence, no custody. Rule: article 2 puts entities issuing means of payment loadable before use inside the depository category, and article 1 makes such an entity a reporting institution unless Annex II excludes it. Action: test the Annex II exclusions first; if none applies, obtain a GIIN, run the pre-existing/new split at 30 June and 1 July 2014, and file for every year a reportable account is identified. Outcome: an obligation found by reading article 2 rather than by receiving a notice.

Example two: the threshold election that has to be a policy. Facts: a firm with a very large low-balance retail book wants the Annex I thresholds only where they help. Rule: article 5 allows the election for all accounts or separately for a clearly identifiable group, such as a business line or location. Action: write it as a documented scope statement per business line, applied consistently, rather than letting operations apply thresholds account by account. Outcome: a defensible election instead of an inconsistency that shows up as a pattern in the file.

Example three: the rehearsal that became a filing, and the correction that was refused. Facts: a firm’s test run is accepted as a live return, and a follow-up presentation mixing new accounts with self-initiated modifications is rejected wholesale. Rule: PresentationType distinguishes Normal from Simulation, and since 1 October 2015 FATCA1 and FATCA4 records cannot travel together. Action: rehearse at Simulation with DataQuality = Maximum, keep the flag in configuration rather than in code, and split corrections into one presentation per DocTypeIndic with matching values on ReportingFI, Sponsor and AccountReport. Outcome: a clean receipt with a CSV and an Expediente.

Does an e-money or payment institution in Spain have to file Modelo 290?

If it issues means of payment that can be loaded before use, article 2 of Orden HAP/1136/2014 places it in the depository-institution category, so it is a reporting financial institution unless Annex II of the agreement excludes it. The absence of deposit-taking is not an answer.

When is Modelo 290 due?

Between 1 January and 31 May for the preceding year, following the amendment of article 13.2 by Orden HAP/1695/2016. The original 31 March date is superseded.

What happens if part of the file is wrong?

Only the account-holder pairs with no ground for rejection are accepted. The response message lists accepted and rejected pairs with reasons, and the institution must correct the rejected ones and present them again.

Can new records and corrections go in the same submission?

No. Since 1 October 2015 a presentation may contain only one DocTypeIndic value, and every element carrying one must use the same value.

9. What to do, today

  • Classify the entity against article 2 first, and record the reasoning — particularly the loadable-payment-means limb of the depository definition.
  • Fix the filing window as 1 January to 31 May, from the amended article 13.2, not the 2014 text.
  • Make the article 5 election an approved policy with a defined scope, and the article 9 aggregation position a documented systems fact.
  • If a provider does the due diligence, evidence the prior check of its procedures.
  • Build the DocRefId and PresentationCode generators to guarantee uniqueness per NIF and year, log every value sent, and split by DocTypeIndic in the pipeline itself so a mixed presentation cannot be assembled.
  • Run the first pass at DataQuality Maximum in Simulation, read the warnings, then file at Normal.
  • Write the unreliable-documentation rule into onboarding: no acceptable self-certification means the account is reportable until the status is verified.

Related: Modelo 289 — Spain’s annual CRS account return · FATCA for EU e-money institutions · CRS — when an EMI is a reportable financial institution · Modelo 196 — Spain’s account reporting

Related reads.