Banking Law And Operations Management Spain .
Banking Law and Operations Management in Spain
1. Introduction
Operations management in Spanish banking law concerns the legal and organisational framework through which a bank conducts its day-to-day activities safely, efficiently and in compliance with banking regulation.
It covers much more than ordinary administration. It includes:
- governance and decision-making;
- internal controls;
- risk management;
- credit and lending operations;
- liquidity management;
- payment operations;
- accounting and reporting;
- outsourcing;
- IT and cybersecurity;
- customer operations;
- compliance and AML controls;
- business continuity;
- internal audit;
- remuneration and staff management;
- crisis management and resolution.
The principal Spanish statute is Law 10/2014 of 26 June on the organisation, supervision and solvency of credit institutions (Ley 10/2014). Article 29 requires credit institutions to maintain sound corporate-governance procedures, clear responsibility lines, effective risk identification and management, internal controls, and appropriate accounting and administrative procedures. It also places important governance responsibilities directly on the board of directors.
Spanish banking operations are also regulated within the EU Single Supervisory Mechanism (SSM). Since 4 November 2014, Spanish banks in the euro area have been supervised within the SSM, involving the ECB and Banco de España.
2. Meaning of Operations Management in Banking
Operations management may be defined as:
The organisation, control and supervision of the processes, people, technology and resources through which a bank performs its regulated activities and delivers banking services while controlling operational, financial, legal and compliance risks.
A bank's operations can therefore be represented as:
Customers
↓
Banking products and services
↓
Operational processes
↓
Risk and internal controls
↓
Compliance and reporting
↓
Supervisory oversight
The legal objective is not simply efficiency. A bank must achieve efficiency without compromising solvency, customer protection, market integrity or financial stability.
Banco de España explains that banking supervision focuses on solvency, compliance and prudent management and control of business and risks.
3. Principal Legal Framework
Spanish banking operations are governed by a combination of Spanish and EU law.
| Legal instrument | Main operational significance |
|---|---|
| Law 10/2014 | Governance, supervision, solvency and internal organisation |
| Royal Decree 84/2015 | Development of Law 10/2014 |
| CRR – Regulation 575/2013 | Capital, liquidity and prudential requirements |
| CRD framework | Governance, risk management and prudential supervision |
| DORA – Regulation 2022/2554 | ICT and digital operational resilience |
| PSD2 / Spanish RDL 19/2018 | Payment operations and security |
| AML Law 10/2010 | Prevention of money laundering and terrorist financing |
| GDPR | Personal-data protection |
| BRRD / Law 11/2015 | Recovery and resolution of failing banks |
| ECB/SSM rules | Prudential supervision |
| Banco de España regulations and guidance | National supervisory implementation |
Banco de España states that its supervisory powers are based, among other things, on the SSM Regulation, Law 13/1994 and Spanish banking legislation.
4. Corporate Governance as the Foundation of Operations Management
The most important provision is Article 29 of Law 10/2014.
Banks must establish:
- a clear organisational structure;
- defined lines of responsibility;
- effective procedures for identifying risks;
- risk-management procedures;
- risk-control procedures;
- risk-communication procedures;
- appropriate internal controls;
- proper administrative and accounting procedures;
- remuneration policies compatible with effective risk management.
Legal significance
Operations management is therefore legally connected to corporate governance.
A bank cannot operate as an ordinary commercial company where management has unrestricted discretion. Because banks manage public deposits and perform an essential intermediary function, the law imposes enhanced governance obligations.
5. Board of Directors
The board has a central role.
Under Article 29, the board must establish a governance system that ensures:
- sound and prudent management;
- appropriate allocation of responsibilities;
- prevention of conflicts of interest;
- effective supervision of the governance system.
Certain functions are expressly non-delegable, including monitoring and evaluating the effectiveness of the governance system and assuming responsibility for the administration and management of the institution.
Practical consequence
The board cannot simply delegate operational responsibility and then disregard what happens inside the bank.
For example:
Poor credit controls → excessive bad loans → inadequate risk reporting
The board's governance responsibilities may become relevant if the deficiencies reflect failures in the bank's governance and control system.
6. Internal Control
Internal control is an essential part of banking operations management.
It covers:
- authorisation procedures;
- segregation of duties;
- accounting controls;
- fraud prevention;
- transaction monitoring;
- reconciliation;
- access controls;
- risk reporting;
- internal audit.
The objective is to ensure that one employee or department cannot exercise unchecked control over an entire transaction.
Example
A sound lending operation could involve:
Credit officer
→ assesses borrower
Risk department
→ independently assesses risk
Approval committee
→ authorises loan
Operations department
→ executes documentation/disbursement
Internal audit
→ tests compliance
This creates operational separation.
7. Risk Management
Banking operations must be organised around risk management.
Important risks include:
Credit risk
Borrower fails to repay.
Market risk
Losses arise from movements in:
- interest rates;
- foreign exchange;
- securities prices.
Liquidity risk
The bank cannot meet its obligations when due.
Operational risk
Loss resulting from failures in:
- processes;
- people;
- systems;
- external events.
Legal risk
Loss resulting from legal disputes or regulatory non-compliance.
Cyber/ICT risk
Loss caused by technological disruption, cyberattack or system failure.
The Spanish supervisory model specifically includes review of models used to calculate capital requirements for credit, counterparty, market and operational risks.
8. Credit Operations Management
Credit is one of the principal banking operations.
A legally sound credit-management process generally involves:
Customer identification
↓
Credit assessment
↓
Income/financial analysis
↓
Collateral assessment
↓
Risk classification
↓
Approval
↓
Documentation
↓
Disbursement
↓
Monitoring
↓
Recovery, restructuring or enforcement
The bank must ensure that credit decisions are consistent with its risk strategy.
Poor credit operations can produce:
- non-performing loans;
- capital losses;
- liquidity pressure;
- provisioning requirements;
- regulatory intervention.
9. Liquidity Management
Liquidity management is another central operational function.
Banks must maintain sufficient liquidity to meet:
- withdrawals;
- payment obligations;
- settlement obligations;
- debt repayments;
- collateral requirements.
The problem is particularly serious because banks generally transform:
short-term liabilities → longer-term assets
For example:
A customer can withdraw a deposit relatively quickly, whereas a mortgage asset may remain outstanding for many years.
Therefore, effective treasury and liquidity operations are legally significant.
10. Payment Operations
Banks operate large payment systems involving:
- credit transfers;
- direct debits;
- card transactions;
- instant payments;
- cross-border payments;
- electronic transfers.
These activities are governed by payment-services legislation as well as prudential rules.
Operational management must ensure:
- authentication;
- transaction accuracy;
- fraud detection;
- settlement;
- customer information;
- transaction records;
- incident management.
11. Digital Banking Operations
Modern Spanish banks increasingly operate through:
- mobile applications;
- internet banking;
- APIs;
- automated systems;
- cloud infrastructure;
- electronic authentication.
This has transformed operations management.
The bank must now manage both:
traditional operational risk
and
digital operational risk.
This is one reason DORA is important.
12. DORA and Banking Operations
The Digital Operational Resilience Act (DORA) has applied since 17 January 2025.
It establishes requirements concerning:
- ICT-risk management;
- ICT incident management;
- resilience testing;
- business continuity;
- ICT third-party risk;
- cyber resilience;
- contractual arrangements with technology providers.
Thus, IT operations are now directly connected to banking regulatory compliance.
Example
Suppose a Spanish bank outsources its mobile-banking platform to a cloud provider.
The bank cannot treat the arrangement merely as a commercial IT contract.
It must consider:
- operational risk;
- concentration risk;
- security;
- continuity;
- incident response;
- contractual rights;
- recovery;
- regulatory requirements.
13. Outsourcing Management
Banks frequently outsource:
- IT;
- data processing;
- call centres;
- payment processing;
- cloud computing;
- cybersecurity;
- document storage.
Outsourcing can improve efficiency but can also create dependency.
Therefore, the bank must maintain sufficient oversight.
Important principle
Outsourcing an operational function does not mean outsourcing regulatory responsibility.
The bank remains responsible for ensuring that outsourced activities do not undermine its governance, risk management or compliance framework.
14. Operational Resilience
Operations management overlaps closely with operational resilience.
The bank should be capable of continuing critical functions despite:
- cyberattacks;
- power outages;
- software failures;
- natural disasters;
- telecommunications failures;
- third-party failures;
- internal fraud.
The Spanish supervisory system uses both continuing off-site supervision and on-site inspections, while also employing stress testing and review of internal risk models.
15. AML and Operations Management
Bank operations must incorporate anti-money-laundering controls.
Operational procedures commonly include:
- customer identification;
- beneficial-owner identification;
- customer due diligence;
- transaction monitoring;
- suspicious-transaction reporting;
- record retention;
- sanctions screening.
Therefore, AML compliance is not simply a legal department function.
It must be embedded into everyday banking operations.
16. Customer-Service Operations
Banks also have operational obligations toward customers.
These include:
- transparency;
- appropriate information;
- complaint handling;
- execution of transactions;
- protection of customer data;
- appropriate treatment of vulnerable customers;
- compliance with applicable consumer and conduct requirements.
Banco de España describes conduct supervision as aimed not merely at detecting breaches but at encouraging banking business models and organisational structures that produce appropriate market practices.
17. Accounting and Reporting
Banking operations generate enormous quantities of regulatory information.
Banks must maintain appropriate:
- accounting systems;
- financial records;
- risk reports;
- prudential reports;
- transaction records;
- regulatory submissions.
Article 29 of Law 10/2014 expressly includes correct administrative and accounting procedures among the internal-control requirements.
Incorrect reporting can therefore become both an operational and regulatory problem.
18. Internal Audit
Internal audit provides an independent assessment of whether the bank's operational systems are working.
It may examine:
- credit approvals;
- treasury;
- IT systems;
- AML controls;
- accounting;
- regulatory reporting;
- outsourcing;
- branch operations;
- cybersecurity.
Internal audit should identify weaknesses before they become major losses.
19. Three Lines of Defence
A useful model is:
First line — Business operations
Employees and business units directly manage risks.
Second line — Risk and compliance
Independent control functions monitor and challenge the first line.
Third line — Internal audit
Provides independent assurance to the board.
This model creates organisational separation and reduces the possibility that operational errors remain undetected.
20. Banco de España's Supervisory Role
Banco de España's role is particularly important.
Its supervisory model contains:
- prudential regulation;
- continuous supervision;
- corrective measures;
- disciplinary and sanctioning powers.
For significant euro-area banks, supervision takes place through the Single Supervisory Mechanism, with Joint Supervisory Teams involving ECB and national supervisory staff.
21. Off-Site and On-Site Supervision
Off-site supervision
Authorities analyse:
- financial information;
- risk reports;
- capital;
- liquidity;
- governance;
- regulatory submissions.
On-site supervision
Authorities can inspect:
- internal systems;
- documents;
- controls;
- governance;
- risk models;
- specific operations.
Banco de España expressly describes these as complementary components of Spanish banking supervision.
22. Stress Testing
Stress testing examines how a bank would perform under adverse circumstances.
Possible scenarios include:
- recession;
- unemployment;
- property-price decline;
- interest-rate shocks;
- market volatility;
- liquidity stress.
Stress tests are therefore an important operational-management tool because they connect strategic planning with risk management.
Banco de España states that supervisory activities are complemented by periodic stress tests.
23. Corrective Measures
If deficiencies are identified, supervisory authorities may use measures such as:
- requirements;
- recommendations;
- remediation plans;
- restrictions;
- intervention;
- replacement of administrators;
- sanctions.
Banco de España expressly identifies corrective measures and, where appropriate, intervention or replacement of administrators as components of its supervisory model.
24. Operations Management and Bank Resolution
Operations management also becomes important when a bank is failing.
The authorities need to preserve:
- deposits;
- payment services;
- critical IT systems;
- essential customer services;
- key operational personnel;
- critical outsourcing arrangements.
Spanish and EU resolution law therefore forms an important part of the broader operational-management framework.
25. Case Law
There is no single Spanish Supreme Court doctrine called "banking operations management law." Instead, the relevant case law comes from Spanish courts and the CJEU, covering governance, banking operations, customer protection, payment services and bank resolution.
Case 1 — Banco Popular / SRB, C-410/20 P
The Banco Popular resolution is one of the most significant Spanish banking cases.
Banco Popular was resolved in June 2017, with its capital instruments written down and the bank transferred to Banco Santander.
The litigation concerned the legality and consequences of the resolution process.
Importance for operations management
The case demonstrates that banking operations must be capable of continuing during an institutional crisis.
Operational management therefore includes:
- continuity of critical services;
- preservation of essential infrastructure;
- transfer of operations;
- treatment of liabilities;
- continuity of customer relationships.
26. Case 2 — Banco Santander (Resolution of Banco Popular II)
Joined Cases C-775/22, C-779/22 and C-794/22, judgment of 5 September 2024.
These cases originated from the Spanish Tribunal Supremo and concerned the consequences of Banco Popular's resolution, including bail-in, protection of shareholders and creditors, and claims arising from allegedly defective information in the prospectus.
Principle
Resolution law can modify the legal position of investors and creditors in order to make the resolution mechanism effective.
Operations-management relevance
A bank's operations must be organised so that records, contracts, customer relationships and liabilities can be identified and managed even during resolution.
This requires strong:
- documentation;
- accounting;
- data management;
- legal records;
- operational continuity.
27. Case 3 — Banco Santander (Resolution of Banco Popular III), C-687/23
This is particularly important because it is a 2025 judgment.
The case concerned actions brought before Banco Popular's resolution, including claims for nullity and damages arising from allegedly defective information relating to securities.
The CJEU held that rights arising from certain actions brought before resolution could remain enforceable against Banco Santander as universal successor.
Importance
The case shows why banking operations require reliable:
- customer records;
- contractual records;
- litigation records;
- securities records;
- information systems.
A bank's operational systems must be capable of preserving legally significant information even through restructuring or resolution.
28. Case 4 — BAWAG, C-375/15
The CJEU considered whether information provided through an online banking system qualified as information communicated on a durable medium.
The Court distinguished simply making information available online from satisfying the statutory requirements for durable-medium communication.
Operations-management significance
Digital banking operations must satisfy legal requirements, not merely technological requirements.
Therefore:
A technically functioning banking system can still be legally deficient if its information and communication processes do not comply with banking law.
29. Case 5 — DenizBank, C-287/19
The case concerned contactless/NFC payment functionality and PSD2 concepts relating to payment instruments and authentication.
Operations-management significance
Banks must correctly classify and manage new payment technologies.
The case demonstrates that operations departments must understand the legal consequences of:
- contactless transactions;
- authentication;
- payment instruments;
- low-value payment exemptions.
Technology therefore cannot be separated from legal compliance.
30. Case 6 — Beobank, C-351/21
The case concerned an allegedly unauthorised payment transaction and the information that a payment service provider must provide concerning the relevant transaction.
Principle
Rules governing unauthorised transactions impose important information and liability obligations on payment-service providers.
Operations-management significance
Banks need effective operational processes for:
- transaction records;
- authentication data;
- customer complaints;
- investigation of disputed transactions;
- identification of payees;
- regulatory compliance.
Poor record management can therefore have legal consequences.
31. Case 7 — PrivatBank, C-480/18
The case concerned payment services and the application of EU payment-services law in a cross-border context.
Operations-management significance
Banks operating across EU borders must establish procedures determining:
- applicable law;
- supervisory authority;
- customer rights;
- complaint procedures;
- liability;
- cross-border service arrangements.
This illustrates why cross-border operations require more sophisticated compliance structures.
32. Case 8 — Rasool, C-568/16
The CJEU considered whether certain cash-withdrawal terminal activities constituted regulated payment services.
The Court's reasoning demonstrates that not every activity associated with payment transactions necessarily constitutes a regulated payment service.
Operations-management significance
Banks and financial businesses must correctly determine the regulatory classification of each operational activity.
This affects:
- licensing;
- compliance;
- reporting;
- consumer protection;
- supervisory obligations.
33. Case-Law Table
| Case | Main issue | Operations-management lesson |
|---|---|---|
| Banco Popular / SRB, C-410/20 P | Bank resolution | Continuity and crisis operations |
| Banco Santander, C-775/22 etc. | Resolution and creditor/investor rights | Records, liabilities and continuity |
| Banco Santander, C-687/23 | Claims surviving resolution | Legal/data continuity |
| BAWAG, C-375/15 | Digital banking information | Compliance of digital processes |
| DenizBank, C-287/19 | Contactless payments | Technology must fit legal requirements |
| Beobank, C-351/21 | Unauthorised transactions | Transaction records and customer operations |
| PrivatBank, C-480/18 | Cross-border payment services | Cross-border operational compliance |
| Rasool, C-568/16 | Definition of payment services | Correct regulatory classification |
34. Operations Management During a Banking Crisis
A bank experiencing severe operational difficulties should have a structured crisis process.
Stage 1 — Detection
Identify:
- financial deterioration;
- cyberattack;
- liquidity shortage;
- fraud;
- operational failure.
Stage 2 — Escalation
Notify:
- senior management;
- risk function;
- compliance;
- internal audit where appropriate;
- supervisory authorities where required.
Stage 3 — Containment
Prevent the problem from spreading.
Stage 4 — Continuity
Maintain critical banking functions.
Stage 5 — Recovery
Restore normal operations.
Stage 6 — Review
Identify the root cause and strengthen controls.
35. Relationship Between Efficiency and Compliance
A major issue in banking operations management is balancing:
Efficiency
with
Regulatory safety
For example, a bank might reduce costs by automating loan approvals.
But excessive automation could create:
- inappropriate lending;
- model risk;
- discrimination concerns;
- inadequate documentation;
- cybersecurity risks.
Therefore, operational efficiency must remain within the bank's risk appetite and regulatory framework.
36. Operations Management and Corporate Culture
Operations management is also affected by organisational culture.
A bank can have excellent written policies but still experience operational failures if employees:
- ignore controls;
- conceal mistakes;
- bypass approval procedures;
- manipulate records;
- prioritise sales over risk controls.
Law 10/2014's governance framework therefore connects organisational structure, risk management, internal control and remuneration.
37. Remuneration and Operations
Remuneration can create operational and prudential risk.
For example:
Employee rewarded solely for loan volume → incentive to approve risky loans.
Therefore, banking remuneration policies must be compatible with sound and effective risk management.
This principle is expressly reflected in Article 29 of Law 10/2014.
38. Outsourcing and Vendor Management
A bank should conduct due diligence before outsourcing critical activities.
Important questions include:
- Is the provider financially stable?
- Where is the data stored?
- Can the bank audit the provider?
- What happens after termination?
- Is there a substitute provider?
- Can data be transferred?
- What happens during a cyberattack?
- Does the contract permit regulatory access?
DORA has significantly strengthened the regulatory importance of these questions for ICT outsourcing.
39. Data Management
Modern banking operations depend heavily on data.
A bank must ensure:
- accuracy;
- availability;
- confidentiality;
- integrity;
- traceability;
- appropriate access;
- secure retention.
This is particularly important for:
- customer accounts;
- credit histories;
- payment records;
- AML records;
- securities;
- regulatory reporting.
The Banco Popular litigation demonstrates the importance of maintaining legally reliable information through a bank's lifecycle, including resolution.
40. Banking Operations and Financial Stability
Why does the law regulate bank operations so heavily?
Because banks are interconnected.
Failure of one institution can affect:
Bank A
↓
Payment system
↓
Bank B
↓
Business customers
↓
Consumers
↓
Financial markets
Banco de España explains that banking supervision aims to safeguard financial-system stability and reduce the likelihood and cost of banking crises.
41. Supervisory Priorities
Spanish banking supervision is risk-based.
Authorities identify sectoral vulnerabilities and establish supervisory priorities each year.
The SSM uses continuing risk assessment and SREP to evaluate banks' risk profiles, capital and liquidity adequacy.
This means operations management is not static.
A bank's controls must evolve according to:
- emerging risks;
- technology;
- economic conditions;
- regulatory developments;
- business-model changes.
42. Recent Regulatory Direction
The Banco de España Supervision Report 2025, published in April 2026, continues to organise supervisory activity around governance, prudential supervision, stress testing, conduct supervision, macroprudential policy, sanctions and market infrastructure oversight.
This illustrates the modern Spanish approach: operations management is treated as part of a broader system of governance + risk + prudential supervision + conduct + resilience.
43. Key Principles
The Spanish banking operations framework can therefore be summarised through the following principles:
- Clear organisational responsibility
- Board accountability
- Sound and prudent management
- Effective internal controls
- Independent risk management
- Accurate accounting and reporting
- Customer protection
- Operational and ICT resilience
- Third-party/outsourcing control
- Regulatory supervision
- Crisis preparedness
- Orderly resolution
44. Difference Between Operations Management and Operational Resilience
| Operations Management | Operational Resilience |
|---|---|
| Day-to-day functioning | Ability to continue during disruption |
| Processes | Continuity |
| Staff | Crisis response |
| Accounting | Recovery |
| Payments | Disaster/cyber preparedness |
| Lending | Impact tolerance |
| Customer service | Critical-function preservation |
| Internal controls | Recovery and testing |
Thus, operational resilience is one component of broader banking operations management.
45. Conclusion
Banking operations management in Spain is a legally regulated management discipline, not merely an internal business function. Law 10/2014 requires banks to establish clear organisational structures, effective risk-management procedures, internal controls and proper administrative and accounting systems, while placing significant governance responsibility on the board.
The framework is reinforced by EU prudential law, the SSM, DORA, payment-services legislation, AML rules, data-protection law and bank-resolution legislation.
The case law demonstrates the same principle from different directions: BAWAG and DenizBank show how digital and payment operations must comply with legal requirements; Beobank illustrates the importance of transaction information and liability; and the Banco Popular/Santander cases demonstrate the need for reliable records, continuity and legally structured operations during bank failure and resolution.
Exam-ready conclusion
Banking operations management in Spain consists of the legally controlled organisation of a bank's people, processes, technology, finances and internal controls so that banking activities are conducted efficiently, prudently and continuously. Its principal foundations are Law 10/2014, EU prudential regulation, SSM supervision, DORA, payment-services law, AML requirements and resolution law. The ultimate objective is to ensure sound management of banking operations while protecting customers, maintaining solvency and supporting financial stability.

comments