Skip to content
SEPBLAC · Spain

SEPBLAC explained — Spain’s FIU and AML supervisor, and everything you have to report to it

Fintech Passport
April 29, 2026 · 8-min read
SEPBLAC explained — Spain’s FIU and AML supervisor, and everything you have to report to it

SEPBLAC sits at the centre of every AML obligation in Spain — and is unusual in Europe in being both a financial-intelligence unit and a supervisor. If you hold a Spanish licence, run a Spanish branch, or passport into Spain on Freedom of Services at meaningful volume, this is the body you report to. The framework looks simple from the outside — one law, one authority — but it fans out into four distinct reporting tracks with different triggers, formats and delivery channels. This piece walks through what SEPBLAC is, the legal framework it operates under, the reporting streams obligated subjects must deliver, and worked examples of how the duties land on a payments firm entering Spain.

1. What SEPBLAC stands for and does

SEPBLACServicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias — translates roughly as “Executive Service of the Commission for the Prevention of Money Laundering and Monetary Offences”. It performs two functions that most EU member states split between separate agencies:

  • Financial Intelligence Unit (FIU). SEPBLAC receives, analyses and disseminates intelligence on money laundering and terrorism financing — the Spanish counterpart of FIU-Nederland, TRACFIN (France), the UIF (Italy) or the German FIU.
  • AML/CTF supervisor. Independently of any prudential supervision by Banco de España or the CNMV, SEPBLAC inspects obligated subjects for compliance with their AML duties, and breaches can be sanctioned under the law’s penalty regime.

2. The legal framework — Ley 10/2010

The backbone is Ley 10/2010, de 28 de abril, on the prevention of money laundering and terrorism financing — Spain’s transposition of the EU AML directives, refreshed over time to track the successive directive generations — together with its implementing regulation, Real Decreto 304/2014. The law defines who counts as an “obligated subject” (sujeto obligado), what the core duties are, and who supervises compliance.

Obligated subjects include:

  • Credit institutions
  • Payment institutions and electronic money institutions — including those passporting into Spain
  • Investment firms and fund managers
  • Insurance and reinsurance undertakings in scope
  • Crypto-asset service providers (CASPs)
  • Notaries, lawyers and real-estate professionals when handling regulated transactions

3. The four reporting tracks

SEPBLAC compliance breaks into four distinct data streams:

  1. Suspicious-activity reporting — the event-driven comunicación por indicio, filed when there is reasonable suspicion of money laundering or terrorism financing, plus the structured mule-account aggregated reporting for confirmed typologies. How to file a SAR in Spain.
  2. Systematic monthly reporting (DMO) — the Declaración Mensual de Operaciones: scheduled disclosure of the operation categories defined by the framework, filed monthly (or as a negative declaration where nothing is reportable). More on the DMO.
  3. Financial-ownership file feed (FTF) — the Fichero de Titularidades Financieras: a monthly feed of account openings, closures and authorised-representative changes into a central register queried by tax and law-enforcement agencies. More on the FTF.
  4. Self-assessments and inspections — periodic internal risk assessments, plus reactive responses to SEPBLAC’s requerimientos (formal information requests) and on-site inspections.
TrackTriggerFrequencyChannel
SAR (comunicación por indicio)Reasonable suspicion, case by caseEvent-driven, without delaySEPBLAC web portal
DMOOperations in the defined categoriesMonthly (negative declaration possible)EDITRAN / portal
FTFAccount and representative lifecycle eventsMonthlyEDITRAN
Requerimientos / inspectionsSEPBLAC requestAd hoc, within the stated deadlineAs specified in the request

4. How submissions are technically made

SEPBLAC operates two delivery channels for structured reporting:

  • EDITRAN — the secure file-transfer system shared with Banco de España’s reporting infrastructure, used for high-volume systematic reporting (DMO, FTF). More on EDITRAN.
  • SEPBLAC web portal — for SAR filings, ad-hoc disclosures, and the structured forms used by non-bank obligated subjects.

The split is largely historical: banks were the first obligated subjects and were plugged into existing pipes. Non-bank entrants — EMIs, PIs, CASPs — deliver the same substance through the portal and file channels, generally with less ergonomic tooling and more manual validation on their side.

5. Worked example — an EMI opens a Spanish branch

Facts: an electronic money institution licensed in another EU member state opens a branch in Spain and starts issuing accounts to Spanish residents. Volumes are expected to reach tens of thousands of customers within a year.

What the rule says: the branch is an obligated subject under Ley 10/2010 for its Spanish activity. That means designating an AML representative and notifying SEPBLAC of the appointment, standing up the FTF feed so every account opening, closure and authorised-representative change is declared monthly, filing the DMO (or its negative declaration), and filing SARs on suspicion.

What the practitioner does: treats the representative designation as step zero — nothing else can be filed without it — then builds the FTF and DMO pipelines before launch, not after. Retrofitting a reporting feed onto a live account base means re-declaring history and explaining gaps to a supervisor that already holds your data.

6. Worked example — suspicion on a live account

Facts: a payment institution’s monitoring flags a consumer account, opened three months earlier, that suddenly receives a series of incoming transfers from unrelated payers and forwards the funds abroad within hours. The customer’s stated profile is a salaried employee with no business activity.

What the rule says: this is the classic mule pattern. Ley 10/2010 requires a special examination of the activity and, where suspicion is confirmed, a comunicación por indicio to SEPBLAC — distinct from, and additional to, anything the same account triggers in the systematic monthly streams. The SAR must not be disclosed to the customer (the tipping-off prohibition).

What the practitioner does: documents the special examination, files the SAR through the portal with the transaction detail SEPBLAC’s format expects, restricts the account under the firm’s own risk powers rather than citing the report, and keeps the case file for the retention period — SEPBLAC can come back with a requerimiento months later.

7. Core AML duties beyond reporting

Reporting is the visible output. Underneath sit the day-to-day obligations every obligated subject runs:

  • Customer due diligence (diligencia debida) — identification and KYC at onboarding, ongoing monitoring, enhanced due diligence for higher-risk relationships.
  • Internal control framework — written procedures manual, designated representative (representante), internal control body and training programme.
  • Risk assessment — an entity-level risk model, refreshed regularly.
  • Record retention — ten years.
  • External review of AML controls — an independent expert review of the internal control framework for most categories of obligated subject.

8. Passporting in — when SEPBLAC is your supervisor

An EMI or PI authorised in another EU member state and operating in Spain on Freedom of Services or via a branch is still an obligated subject under Ley 10/2010 for the activity carried on in Spain. Branch operations sit squarely within SEPBLAC’s supervisory perimeter; pure FoS activity is assessed more case by case but is generally caught once volume in Spain becomes meaningful. The first practical step on entering Spain is to designate a Spanish AML representative and notify SEPBLAC of the appointment through the established registration process.

9. What non-compliance looks like

Ley 10/2010 grades breaches (minor, serious, very serious) and attaches administrative sanctions that can reach the institution and, for the most serious breaches, individual managers. In practice the supervisory escalation path usually starts earlier: data-quality findings on systematic reporting, requerimientos probing specific files, then inspection. Firms that respond to requerimientos completely and on time, and that self-correct reporting errors through the established resubmission mechanisms, manage the relationship; firms that go quiet do not.

FAQ

What does SEPBLAC stand for?

Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias — the Executive Service of the Commission for the Prevention of Money Laundering and Monetary Offences. It is Spain’s combined FIU and AML supervisor.

Is SEPBLAC the same as Banco de España?

No. SEPBLAC is a separate authority, although it shares some technical infrastructure (notably EDITRAN). Banco de España handles prudential supervision; SEPBLAC handles AML/CTF.

Do EMIs and payment institutions have to report to SEPBLAC?

Yes. Ley 10/2010 lists EMIs and PIs among obligated subjects. The full set of duties — SARs, DMO, FTF, internal controls — applies whether the firm is Spanish-licensed or passporting in with Spanish activity.

What is the main law I need to know?

Ley 10/2010, de 28 de abril, on the prevention of money laundering and terrorism financing, and its implementing regulation, Real Decreto 304/2014.

What is the difference between a SAR and the DMO?

A SAR (comunicación por indicio) is event-driven and based on suspicion in a specific case. The DMO is systematic: a monthly declaration of predefined operation categories regardless of suspicion. An operation can be reportable under both tracks at once.

Where do I designate my AML representative?

Through Modelo F22 — SEPBLAC’s representative-registration form. The full process and supporting-document list is in our companion piece.

Can I tell the customer I reported them?

No. Ley 10/2010 carries a tipping-off prohibition: neither the SAR nor a related special examination may be disclosed to the customer or third parties outside the permitted channels.

What to do, today

  • MLRO: map your Spanish footprint against the four tracks — SARs, DMO, FTF, inspection readiness — and confirm each has an owner and a tested pipeline.
  • Market-entry lead: if Spain is on the roadmap, sequence the AML representative designation before launch; it gates everything else.
  • Compliance officer: verify the DMO negative-declaration discipline — a month with nothing reportable still needs its filing.
  • Operations: reconcile the FTF feed against the core account register every cycle; the register is queried by agencies that will notice gaps.
  • Everyone: keep SAR case files inspection-ready for the full ten-year retention period.

Related: How to file a SAR in Spain · What is the DMO? · What is the FTF? · What is EDITRAN?

Related reads.