Skip to content
CNMV · EU-wide

Spain’s AML law after MiCA — CASPs as obliged subjects, the SEPBLAC report, and crypto correspondent relationships

Fintech Passport
August 19, 2026 · 10-min read
Spain’s AML law after MiCA — CASPs as obliged subjects, the SEPBLAC report, and crypto correspondent relationships

A Spanish crypto authorisation is about to acquire a step that is not in MiCA: a mandatory SEPBLAC report — and asking for it can stop the authorisation clock for up to three months. Spain’s proyecto de ley de digitalización y modernización del sector financiero, published in the Boletín Oficial de las Cortes Generales on 27 July 2026, completes the national adaptation to Regulation (EU) 2023/1114 (MiCA) and Regulation (EU) 2023/1113 (the transfer of funds regulation) by rewriting parts of Spain’s AML law. This is a bill in parliamentary passage, not law — but the changes it makes to Ley 10/2010 land on payment service providers as much as on crypto firms.

1. Crypto-asset service providers become obliged subjects

Article 6 of the bill adds a new letter (z) to Article 2(1) of Ley 10/2010, the Spanish AML/CFT law, making proveedores de servicios de criptoactivos obliged subjects in their own right. Three definitional changes underneath it decide who that actually catches.

A crypto-asset becomes a digital representation of value or of a right that can be transferred and stored electronically using distributed ledger or similar technology, as defined in Article 3(1)(5) of Regulation (EU) 2023/1114 — except where it falls into the categories in Article 2(2), (3) and (4) of that regulation, or where it meets the requirements to be treated as funds. That last exclusion matters to e-money institutions: an instrument that qualifies as funds is handled by the payments regime, not this one.

A crypto-asset service provider becomes a legal person or other undertaking whose business is the professional provision of one or more crypto-asset services to clients and which is authorised to do so, by reference to Article 3(1)(15) of MiCA, when carrying on one or more of the services defined in Article 3(1)(16) — with the exception of providing advice on crypto-assets under Article 3(1)(16)(h). The carve-out is that narrow: advice, and only advice. A firm that advises and also executes, custodies or operates a platform is inside.

And a self-hosted address is defined by reference to Article 3(20) of Regulation (EU) 2023/1113, which imports the transfer of funds regulation’s own vocabulary into the AML law rather than inventing a Spanish one.

2. The SEPBLAC report — two duties, not one

The alert-level summary of this bill is that SEPBLAC will issue a mandatory report in CASP authorisations. The text is more than that. It creates two parallel duties, and the second is easy to miss.

The rewritten second additional provision of Ley 10/2010 requires the CNMV to request a report from SEPBLAC’s Servicio Ejecutivo in the administrative procedures under Regulation (EU) 2023/1114 that fall within CNMV competence, where under that regulation AML/CFT matters fall to be assessed — with the effects that Ley 39/2015 attaches to informes preceptivos. A brand-new seventh additional provision imposes the identical duty on the Banco de España for MiCA procedures within its competence. Separately, a new letter (l) in Article 45(4) adds to SEPBLAC’s own functions the task of reporting on the adequacy of internal control measures in CASP authorisation procedures.

So the split follows MiCA’s own supervisory split: the CNMV route covers the CASP authorisations and the Banco de España route covers what sits with it, including asset-referenced and e-money token business. A firm planning a Spanish token issuance rather than a service authorisation is inside this too.

What a preceptive report does do is stop the clock. Article 80(3) provides that where a report is not issued in time the procedure normally continues — except for a preceptive report, where the maximum period to resolve may be suspended under Article 22(1)(d). That paragraph suspends the resolution period for the time between the request and receipt of the report, with both events communicated to the interested parties, and sets a hard limit: the suspension may not exceed three months in any case, and if the report has not arrived by then the procedure continues.

QuestionAnswer under Ley 39/2015
Must the supervisor ask SEPBLAC?Yes — that is what preceptivo means
Is SEPBLAC’s view binding?Not stated to be — Article 80(1) makes reports non-binding absent an express provision
Default period to issue a report10 days, unless another period is set (Article 80(2))
Effect if it is lateThe resolution period may be suspended (Articles 80(3) and 22(1)(d))
Maximum suspensionThree months; after that the procedure continues without it
Who must be toldThe applicant — both the request and the receipt must be communicated

Facts: a firm plans a Spanish CASP authorisation and has built its timetable off MiCA’s own assessment periods, with the AML policy pack scheduled as a late work item because “the CNMV reviews it during the assessment window”.

What the rule says: under the bill the CNMV must request a SEPBLAC report where AML/CFT matters fall to be assessed, and requesting it can suspend the resolution period for as long as it takes to arrive, up to three months.

What the practitioner does: moves the internal-control documentation to the front of the file rather than the back — because Article 45(4)(l) tells SEPBLAC to report specifically on the adequacy of internal control measures — and plans on the basis that the elapsed calendar may exceed the statutory assessment period, since suspension time is not counted against it.

Outcome: the AML pack becomes a gating deliverable at filing, and the board timetable carries a suspension contingency rather than a fixed grant date. Our note on CASP authorisation in Spain covers the rest of the application file.

3. Correspondent relationships, rewritten for crypto

The least-discussed change in Article 6 is the rewrite of Article 13 of Ley 10/2010 on cross-border correspondent banking, and it reaches payment firms directly. The definition now expressly covers relationships between credit institutions, between financial institutions, and between credit institutions and financial institutions including payment institutions — and expressly includes relationships established for operations with crypto-assets or transfers of crypto-assets. Calling an arrangement a partnership rather than a correspondent relationship will not take it outside the article.

A new paragraph 2 bis then sets a crypto-specific standard. In cross-border correspondent relationships involving the execution of crypto-asset services with a client entity not established in the Union that provides equivalent services, the CASP must verify that the client entity is authorised or registered; must update the correspondent due-diligence information periodically, and whenever new risks arise in relation to that client entity; and must use what it gathers to determine, on a risk basis, the measures needed to mitigate the associated risks.

Two prohibitions and one record-keeping duty complete it. Credit institutions and CASPs may not establish or maintain correspondent relationships that, directly or through a sub-account, allow the represented entity’s own clients to execute transactions — the payable-through account prohibition, now extended to crypto. The shell-bank prohibition stands. And where a credit institution or a CASP decides to end a correspondent relationship for reasons connected to AML/CFT, it must document and record that decision: de-risking becomes an evidenced act, not a quiet commercial one.

4. What becomes a serious infringement

Article 6 also rewrites Article 52(5) of Ley 10/2010 to classify as infracciones graves the breaches set out in Article 29 of Regulation (EU) 2023/1113, and — the limb that matters most for a payments reader — breaches of the obligations in Articles 4 to 24 and Article 26 of that regulation by payment service providers and by crypto-asset service providers.

That range is the operative core of the transfer of funds regulation: the information that must accompany a transfer, the duties of the payer’s, payee’s and intermediary providers, the detection of missing or incomplete information, what to do about repeatedly failing counterparties, and the equivalent obligations for crypto-asset transfers. It is not a crypto-only clause — a payment institution that has treated data-quality on originator and beneficiary information as an operational metric now has a Spanish infringement classification attached to it.

Facts: a payment institution’s screening shows a steady share of inbound transfers arriving with incomplete beneficiary information from one intermediary counterparty. The issue sits on an operations backlog as a data-quality ticket.

What the rule says: the obligations on detecting missing information and on handling counterparties that repeatedly fail to supply it sit inside the Articles 4 to 24 range, and under the amended Article 52(5) failing them is classified as a serious infringement.

What the practitioner does: reclassifies the backlog item as a compliance finding with an owner and a deadline, and documents the escalation path for the counterparty — because the regulation’s structure expects a decision about the relationship, and the amended Article 13(5) expects that decision to be recorded if it ends the relationship.

5. The register transition, and where it leaves everyone

The bill also tidies up the old Banco de España register of virtual-currency exchange and custodian-wallet providers. Its transitional provisions record that the register lost operability on the date Regulation (EU) 2023/1114 became fully applicable, that it survives for information purposes only, and that applications for registration still unresolved at that date lapse automatically for want of subject matter. Firms that were on the register on that date could continue providing the same services under a grandfathering window that has now closed, after which CNMV authorisation under Articles 62 and 63 of MiCA is required.

There is one piece of practical relief for migrating firms. In authorising a former registrant, the CNMV may take the honourability requirements in Articles 62(2)(g) and (h) of MiCA, and the internal control, policies and procedures requirement in Article 62(2)(i) — including the AML/CFT risk elements — as satisfied without the applicant having to supply evidence; and the Banco de España will supply the CNMV, on request and for a specific entity, information on that entity’s compliance and any relevant incident during its time on the register.

6. FAQ

Are crypto-asset advisers caught as obliged subjects?

No. The definition inserted into Article 1(6) of Ley 10/2010 excludes the provision of advice on crypto-assets under Article 3(1)(16)(h) of Regulation (EU) 2023/1114. The carve-out covers advice only — a firm that also executes, custodies, exchanges or operates a platform is inside.

Does the SEPBLAC report bind the CNMV?

The bill does not say so, and Article 80(1) of Ley 39/2015 makes reports non-binding unless a provision expressly states otherwise. What is mandatory is that the supervisor requests it. In practice a negative view from the financial intelligence unit on the adequacy of internal control measures is not something an applicant should plan around.

How long can the authorisation be delayed?

Requesting a preceptive report allows the maximum period to resolve to be suspended for the time between the request and its receipt, under Article 22(1)(d) of Ley 39/2015. That suspension cannot exceed three months, and if the report has not been received by then the procedure continues.

Does any of this apply to a payment institution with no crypto business?

Yes, in two places. The amended Article 52(5) classifies breaches of Articles 4 to 24 and 26 of Regulation (EU) 2023/1113 by payment service providers as serious infringements. And the rewritten Article 13 expressly brings payment institutions inside the correspondent-relationship definition.

What does the Banco de España additional provision add?

It mirrors the CNMV duty for MiCA procedures within Banco de España competence, so the SEPBLAC report requirement follows the supervisory split rather than attaching only to CASP authorisations.

Is this in force?

No. It is a bill before the Cortes, processed under the urgent procedure, with the amendment window closing on 9 September 2026 and a Senado stage after the Congreso. Its commencement clause is twenty days after publication in the Boletín Oficial del Estado.

7. What to do, today

  • If you are filing a Spanish crypto authorisation, front-load the internal-control file. Article 45(4)(l) points SEPBLAC at the adequacy of internal control measures specifically, and the report is the step most likely to move your grant date.
  • Re-run your correspondent inventory against the widened definition. The test is now function, not label, and it expressly reaches payment institutions and crypto-asset transfer relationships. Non-EU counterparties providing equivalent crypto services need an authorisation-or-registration check and a refresh trigger, not a one-off onboarding record.
  • Write down your exit decisions. Ending a correspondent relationship for AML/CFT reasons becomes a documented, recorded act — which also means the absence of a record becomes a finding.
  • Treat transfer-information data quality as a compliance metric. Articles 4 to 24 and 26 of Regulation (EU) 2023/1113 carry a serious-infringement classification for PSPs, not only for crypto firms.

And diarise mid-September: the amendment window closes on 9 September 2026, and every article number above is a number in a bill, not in a statute.

Related: CASP authorisation in Spain under MiCA · the MiCA travel rule · What is SEPBLAC? · information accompanying transfers of funds

Related reads.