Skip to content
Banco de España · Spain

What is the FTF? Spain account-ownership

Fintech Passport
April 29, 2026 · 7-min read
What is the FTF? Spain account-ownership

The Fichero de Titularidades Financieras (FTF) is Spain’s centralised account-ownership register. Every Spanish-licensed credit institution, EMI and payment institution — and every Spanish branch of a foreign one — feeds it monthly with the identifying data of account holders, authorised representatives, beneficial owners and safe-deposit-box renters. Judges, prosecutors, the tax authority and police query it daily. For a fintech opening a Spanish branch, the FTF is usually the first recurring regulatory feed you have to stand up, and the one where data-quality problems surface fastest. This walkthrough covers the legal basis, the perimeter, the data model, the monthly cycle, and the mistakes that generate rejection letters.

1. What the Fichero de Titularidades Financieras is

The Fichero de Titularidades Financieras was created by Article 43 of Ley 10/2010, Spain’s AML/CFT law, and developed in detail by Real Decreto 304/2014. It is administered by SEPBLAC, the Spanish financial intelligence unit, and it answers one question for designated authorities: is this person a customer of any Spanish payment-service provider, and on which accounts?

Functionally, it is Spain’s version of the centralised bank-account registers every EU member state must operate under the AML directives (the mechanism introduced EU-wide by the fifth AML directive and carried forward in the new AML package). Spain simply ran it years before the EU obligation existed, so the FTF is a mature system with a settled technical specification and a supervisor that expects clean files.

2. Who must feed the FTF

The reporting perimeter follows the Spanish account-servicing perimeter, not the licence’s home state:

  • Banks and other credit institutions
  • Electronic-money institutions
  • Payment institutions
  • Spanish branches of foreign-licensed credit institutions, EMIs and PIs

The last bullet matters most for fintechs. If your Luxembourg or Lithuanian entity passports into Spain through a branch and issues Spanish IBANs, the branch is an obligated subject and must file — for the accounts of its Spanish customer perimeter, not for the head office’s book. Investment firms and crypto-asset service providers are not currently in the FTF perimeter, though the EU AML package points toward wider account-register coverage over time.

3. What is reported

Per account relationship, the FTF record carries:

  • Identifying data of each intervening person — name, identity document (DNI, NIE, passport or foreign ID), nationality, date of birth
  • The IBAN(s) and product type of the account
  • Authorised representatives (autorizados and apoderados) on each account
  • Beneficial owners (titulares reales) of legal-entity customers
  • Safe-deposit-box rentals, with rental dates
  • Date of opening and, where applicable, date of closure

The specification distinguishes the role each person plays on the account. Getting the role right matters: a legal entity is reported as holder, its directors or signatories as representatives, and its beneficial owners separately. Reporting a UBO as a holder — or omitting representatives entirely — is a substantive error, not a formatting one.

4. The monthly cycle and the EDITRAN channel

The FTF is delivered monthly, with a cut-off at month-end and a delivery window set in SEPBLAC’s technical specification (Especificaciones técnicas FTF). The file is a fixed-width record per accountholder relationship, transmitted over EDITRAN, the secure file-transfer rail used by Spanish regulators.

Each month’s file reports the movements of that month: openings, closures, and changes in the persons attached to each account. That makes the FTF stateful on SEPBLAC’s side — the register holds a running picture built from your monthly deltas, and inconsistencies between periods (an account closed that was never reported open, a holder whose document number changes without explanation) are detectable and queried.

5. Where files actually fail

Recurring data-quality failure modes, seen across new filers:

  • Document-type coherence. The document type code must match the document itself and its issuing country — a Spanish DNI or NIE implies Spain as issuing country; a passport requires the real issuing state. Mapping every customer to a single default document type is the classic first-file error.
  • Identifier format. Spanish NIF/NIE check digits are validated. Foreign identifiers must follow the pattern rules of the specification.
  • Cross-period consistency. A closure must reference a relationship previously reported as open, with matching identifiers.
  • Missing legal-entity fields. For companies, incorporation data and beneficial-owner records are commonly incomplete in the source CRM and must be remediated before go-live.

6. Worked example — a passporting EMI’s first file

Facts: An EU-licensed EMI opens a Spanish branch and begins issuing Spanish IBANs to 12,000 retail customers, of whom 3,000 are foreign nationals resident in Spain and 400 are legal entities.

What the rule says: The branch is an obligated subject under Ley 10/2010 and must report every account relationship monthly: each retail holder with the correct document type (DNI for Spanish nationals, NIE or passport for foreigners), each legal entity with its representatives and beneficial owners, and opening dates for all accounts.

What the practitioner does: Before the first submission, run a full extract and profile it — count records with missing nationality, mismatched document types, or absent UBO data for entities. Fix the source data, not the file. A first submission built on a cleansed extract avoids opening the relationship with the FIU through a stack of error notifications.

7. Worked example — closure and representative change

Facts: In March, a corporate customer replaces its authorised signatory and, separately, a retail customer closes an account opened two years earlier under a previous core-banking system.

What the rule says: Both changes are reportable in the March file: the representative change as an update to the persons attached to the account, and the closure with its closure date — referencing the same account and holder identifiers under which the opening was originally reported.

What the practitioner does: Verify that the legacy account’s identifiers match what was historically filed. If the migration changed customer IDs or document records, reconcile before filing — a closure that does not match an open relationship in SEPBLAC’s register is exactly the kind of inconsistency that triggers a query.

8. Who queries the FTF

Access is restricted to designated authorities, and every query is logged:

AuthorityTypical use
Judges and courtsLocating accounts in criminal and civil proceedings
Public Prosecution ServiceCriminal investigations
Tax authority (AEAT)Tax investigation and enforcement
Police forces and customs surveillanceFinancial-crime and smuggling investigations
SEPBLACAML/CFT analysis and supervision

The institution does not see queries run against its data, and customers are not notified. What the institution does see is the downstream effect: information requests and account-freezing orders arrive already knowing which IBANs the person holds with you — because the authority looked them up in the FTF first.

9. FAQ

What does FTF stand for?

Fichero de Titularidades Financieras — the financial-ownership file. It is Spain’s central register of who holds accounts and safe-deposit boxes at Spanish PSPs, run by SEPBLAC.

Are EMIs and payment institutions in scope?

Yes. Credit institutions, EMIs, PIs and Spanish branches of foreign-licensed equivalents all must file for their Spanish account perimeter.

Does a passporting branch report its head office’s customers?

No. The branch reports the account relationships it services in Spain — typically the Spanish-IBAN book — not the parent entity’s customers in other countries.

Does the FTF include balances or transactions?

No. It carries identifying data only: persons, roles, IBANs, opening and closure dates. Balance and transaction data sit in other regimes.

How often is the file delivered, and how?

Monthly, via the EDITRAN secure file-transfer channel, in the fixed-width format defined in SEPBLAC’s technical specification.

Who can query the register?

Judges, prosecutors, the tax authority, police and customs forces, and SEPBLAC itself. There is no public access, and all queries are logged.

What happens if the file has errors?

SEPBLAC returns error notifications that must be corrected in subsequent submissions. Persistent quality failures are a supervisory issue under Ley 10/2010, so treat error remediation as a standing monthly control, not a one-off fix.

10. What to do, today

  • Head of Compliance: confirm whether your Spanish presence (subsidiary or branch) is an obligated subject, and put the monthly FTF cycle on the regulatory-reporting calendar with a named owner.
  • Data lead: map your customer master to the FTF specification and profile it — document types, nationalities, UBO completeness for legal entities. Fix source data before the first file.
  • IT/Operations: start the EDITRAN onboarding early — certificates and connectivity testing regularly take longer than building the file itself.
  • Project lead: plan a dry-run submission against the test environment before the first live month, and design the error-correction loop from day one.

Related: How to issue Spanish IBANs · What is SEPBLAC? · What is the DMO? · What is EDITRAN? · Registering your SEPBLAC representative

Related reads.