Banking Law And Operations Management Spain .

Banking Law and Operations Management in Spain

1. Introduction

Operations management in Spanish banking law concerns the legal and organisational framework through which a bank conducts its day-to-day activities safely, efficiently and in compliance with banking regulation.

It covers much more than ordinary administration. It includes:

  • governance and decision-making;
  • internal controls;
  • risk management;
  • credit and lending operations;
  • liquidity management;
  • payment operations;
  • accounting and reporting;
  • outsourcing;
  • IT and cybersecurity;
  • customer operations;
  • compliance and AML controls;
  • business continuity;
  • internal audit;
  • remuneration and staff management;
  • crisis management and resolution.

The principal Spanish statute is Law 10/2014 of 26 June on the organisation, supervision and solvency of credit institutions (Ley 10/2014). Article 29 requires credit institutions to maintain sound corporate-governance procedures, clear responsibility lines, effective risk identification and management, internal controls, and appropriate accounting and administrative procedures. It also places important governance responsibilities directly on the board of directors.

Spanish banking operations are also regulated within the EU Single Supervisory Mechanism (SSM). Since 4 November 2014, Spanish banks in the euro area have been supervised within the SSM, involving the ECB and Banco de España.

2. Meaning of Operations Management in Banking

Operations management may be defined as:

The organisation, control and supervision of the processes, people, technology and resources through which a bank performs its regulated activities and delivers banking services while controlling operational, financial, legal and compliance risks.

A bank's operations can therefore be represented as:

Customers

↓

Banking products and services

↓

Operational processes

↓

Risk and internal controls

↓

Compliance and reporting

↓

Supervisory oversight

The legal objective is not simply efficiency. A bank must achieve efficiency without compromising solvency, customer protection, market integrity or financial stability.

Banco de España explains that banking supervision focuses on solvency, compliance and prudent management and control of business and risks.

3. Principal Legal Framework

Spanish banking operations are governed by a combination of Spanish and EU law.

Legal instrumentMain operational significance
Law 10/2014Governance, supervision, solvency and internal organisation
Royal Decree 84/2015Development of Law 10/2014
CRR – Regulation 575/2013Capital, liquidity and prudential requirements
CRD frameworkGovernance, risk management and prudential supervision
DORA – Regulation 2022/2554ICT and digital operational resilience
PSD2 / Spanish RDL 19/2018Payment operations and security
AML Law 10/2010Prevention of money laundering and terrorist financing
GDPRPersonal-data protection
BRRD / Law 11/2015Recovery and resolution of failing banks
ECB/SSM rulesPrudential supervision
Banco de España regulations and guidanceNational supervisory implementation

Banco de España states that its supervisory powers are based, among other things, on the SSM Regulation, Law 13/1994 and Spanish banking legislation.

4. Corporate Governance as the Foundation of Operations Management

The most important provision is Article 29 of Law 10/2014.

Banks must establish:

  1. a clear organisational structure;
  2. defined lines of responsibility;
  3. effective procedures for identifying risks;
  4. risk-management procedures;
  5. risk-control procedures;
  6. risk-communication procedures;
  7. appropriate internal controls;
  8. proper administrative and accounting procedures;
  9. remuneration policies compatible with effective risk management.

 

Legal significance

Operations management is therefore legally connected to corporate governance.

A bank cannot operate as an ordinary commercial company where management has unrestricted discretion. Because banks manage public deposits and perform an essential intermediary function, the law imposes enhanced governance obligations.

5. Board of Directors

The board has a central role.

Under Article 29, the board must establish a governance system that ensures:

  • sound and prudent management;
  • appropriate allocation of responsibilities;
  • prevention of conflicts of interest;
  • effective supervision of the governance system.

Certain functions are expressly non-delegable, including monitoring and evaluating the effectiveness of the governance system and assuming responsibility for the administration and management of the institution.

Practical consequence

The board cannot simply delegate operational responsibility and then disregard what happens inside the bank.

For example:

Poor credit controls → excessive bad loans → inadequate risk reporting

The board's governance responsibilities may become relevant if the deficiencies reflect failures in the bank's governance and control system.

6. Internal Control

Internal control is an essential part of banking operations management.

It covers:

  • authorisation procedures;
  • segregation of duties;
  • accounting controls;
  • fraud prevention;
  • transaction monitoring;
  • reconciliation;
  • access controls;
  • risk reporting;
  • internal audit.

The objective is to ensure that one employee or department cannot exercise unchecked control over an entire transaction.

Example

A sound lending operation could involve:

Credit officer

→ assesses borrower

Risk department

→ independently assesses risk

Approval committee

→ authorises loan

Operations department

→ executes documentation/disbursement

Internal audit

→ tests compliance

This creates operational separation.

7. Risk Management

Banking operations must be organised around risk management.

Important risks include:

Credit risk

Borrower fails to repay.

Market risk

Losses arise from movements in:

  • interest rates;
  • foreign exchange;
  • securities prices.

Liquidity risk

The bank cannot meet its obligations when due.

Operational risk

Loss resulting from failures in:

  • processes;
  • people;
  • systems;
  • external events.

Legal risk

Loss resulting from legal disputes or regulatory non-compliance.

Cyber/ICT risk

Loss caused by technological disruption, cyberattack or system failure.

The Spanish supervisory model specifically includes review of models used to calculate capital requirements for credit, counterparty, market and operational risks.

8. Credit Operations Management

Credit is one of the principal banking operations.

A legally sound credit-management process generally involves:

Customer identification

↓

Credit assessment

↓

Income/financial analysis

↓

Collateral assessment

↓

Risk classification

↓

Approval

↓

Documentation

↓

Disbursement

↓

Monitoring

↓

Recovery, restructuring or enforcement

The bank must ensure that credit decisions are consistent with its risk strategy.

Poor credit operations can produce:

  • non-performing loans;
  • capital losses;
  • liquidity pressure;
  • provisioning requirements;
  • regulatory intervention.

9. Liquidity Management

Liquidity management is another central operational function.

Banks must maintain sufficient liquidity to meet:

  • withdrawals;
  • payment obligations;
  • settlement obligations;
  • debt repayments;
  • collateral requirements.

The problem is particularly serious because banks generally transform:

short-term liabilities → longer-term assets

For example:

A customer can withdraw a deposit relatively quickly, whereas a mortgage asset may remain outstanding for many years.

Therefore, effective treasury and liquidity operations are legally significant.

10. Payment Operations

Banks operate large payment systems involving:

  • credit transfers;
  • direct debits;
  • card transactions;
  • instant payments;
  • cross-border payments;
  • electronic transfers.

These activities are governed by payment-services legislation as well as prudential rules.

Operational management must ensure:

  • authentication;
  • transaction accuracy;
  • fraud detection;
  • settlement;
  • customer information;
  • transaction records;
  • incident management.

11. Digital Banking Operations

Modern Spanish banks increasingly operate through:

  • mobile applications;
  • internet banking;
  • APIs;
  • automated systems;
  • cloud infrastructure;
  • electronic authentication.

This has transformed operations management.

The bank must now manage both:

traditional operational risk

and

digital operational risk.

This is one reason DORA is important.

12. DORA and Banking Operations

The Digital Operational Resilience Act (DORA) has applied since 17 January 2025.

It establishes requirements concerning:

  • ICT-risk management;
  • ICT incident management;
  • resilience testing;
  • business continuity;
  • ICT third-party risk;
  • cyber resilience;
  • contractual arrangements with technology providers.

Thus, IT operations are now directly connected to banking regulatory compliance.

Example

Suppose a Spanish bank outsources its mobile-banking platform to a cloud provider.

The bank cannot treat the arrangement merely as a commercial IT contract.

It must consider:

  • operational risk;
  • concentration risk;
  • security;
  • continuity;
  • incident response;
  • contractual rights;
  • recovery;
  • regulatory requirements.

13. Outsourcing Management

Banks frequently outsource:

  • IT;
  • data processing;
  • call centres;
  • payment processing;
  • cloud computing;
  • cybersecurity;
  • document storage.

Outsourcing can improve efficiency but can also create dependency.

Therefore, the bank must maintain sufficient oversight.

Important principle

Outsourcing an operational function does not mean outsourcing regulatory responsibility.

The bank remains responsible for ensuring that outsourced activities do not undermine its governance, risk management or compliance framework.

14. Operational Resilience

Operations management overlaps closely with operational resilience.

The bank should be capable of continuing critical functions despite:

  • cyberattacks;
  • power outages;
  • software failures;
  • natural disasters;
  • telecommunications failures;
  • third-party failures;
  • internal fraud.

The Spanish supervisory system uses both continuing off-site supervision and on-site inspections, while also employing stress testing and review of internal risk models.

15. AML and Operations Management

Bank operations must incorporate anti-money-laundering controls.

Operational procedures commonly include:

  • customer identification;
  • beneficial-owner identification;
  • customer due diligence;
  • transaction monitoring;
  • suspicious-transaction reporting;
  • record retention;
  • sanctions screening.

Therefore, AML compliance is not simply a legal department function.

It must be embedded into everyday banking operations.

16. Customer-Service Operations

Banks also have operational obligations toward customers.

These include:

  • transparency;
  • appropriate information;
  • complaint handling;
  • execution of transactions;
  • protection of customer data;
  • appropriate treatment of vulnerable customers;
  • compliance with applicable consumer and conduct requirements.

Banco de España describes conduct supervision as aimed not merely at detecting breaches but at encouraging banking business models and organisational structures that produce appropriate market practices.

17. Accounting and Reporting

Banking operations generate enormous quantities of regulatory information.

Banks must maintain appropriate:

  • accounting systems;
  • financial records;
  • risk reports;
  • prudential reports;
  • transaction records;
  • regulatory submissions.

Article 29 of Law 10/2014 expressly includes correct administrative and accounting procedures among the internal-control requirements.

Incorrect reporting can therefore become both an operational and regulatory problem.

18. Internal Audit

Internal audit provides an independent assessment of whether the bank's operational systems are working.

It may examine:

  • credit approvals;
  • treasury;
  • IT systems;
  • AML controls;
  • accounting;
  • regulatory reporting;
  • outsourcing;
  • branch operations;
  • cybersecurity.

Internal audit should identify weaknesses before they become major losses.

19. Three Lines of Defence

A useful model is:

First line — Business operations

Employees and business units directly manage risks.

Second line — Risk and compliance

Independent control functions monitor and challenge the first line.

Third line — Internal audit

Provides independent assurance to the board.

This model creates organisational separation and reduces the possibility that operational errors remain undetected.

20. Banco de España's Supervisory Role

Banco de España's role is particularly important.

Its supervisory model contains:

  1. prudential regulation;
  2. continuous supervision;
  3. corrective measures;
  4. disciplinary and sanctioning powers.

 

For significant euro-area banks, supervision takes place through the Single Supervisory Mechanism, with Joint Supervisory Teams involving ECB and national supervisory staff.

21. Off-Site and On-Site Supervision

Off-site supervision

Authorities analyse:

  • financial information;
  • risk reports;
  • capital;
  • liquidity;
  • governance;
  • regulatory submissions.

On-site supervision

Authorities can inspect:

  • internal systems;
  • documents;
  • controls;
  • governance;
  • risk models;
  • specific operations.

Banco de España expressly describes these as complementary components of Spanish banking supervision.

22. Stress Testing

Stress testing examines how a bank would perform under adverse circumstances.

Possible scenarios include:

  • recession;
  • unemployment;
  • property-price decline;
  • interest-rate shocks;
  • market volatility;
  • liquidity stress.

Stress tests are therefore an important operational-management tool because they connect strategic planning with risk management.

Banco de España states that supervisory activities are complemented by periodic stress tests.

23. Corrective Measures

If deficiencies are identified, supervisory authorities may use measures such as:

  • requirements;
  • recommendations;
  • remediation plans;
  • restrictions;
  • intervention;
  • replacement of administrators;
  • sanctions.

Banco de España expressly identifies corrective measures and, where appropriate, intervention or replacement of administrators as components of its supervisory model.

24. Operations Management and Bank Resolution

Operations management also becomes important when a bank is failing.

The authorities need to preserve:

  • deposits;
  • payment services;
  • critical IT systems;
  • essential customer services;
  • key operational personnel;
  • critical outsourcing arrangements.

Spanish and EU resolution law therefore forms an important part of the broader operational-management framework.

25. Case Law

There is no single Spanish Supreme Court doctrine called "banking operations management law." Instead, the relevant case law comes from Spanish courts and the CJEU, covering governance, banking operations, customer protection, payment services and bank resolution.

Case 1 — Banco Popular / SRB, C-410/20 P

The Banco Popular resolution is one of the most significant Spanish banking cases.

Banco Popular was resolved in June 2017, with its capital instruments written down and the bank transferred to Banco Santander.

The litigation concerned the legality and consequences of the resolution process.

Importance for operations management

The case demonstrates that banking operations must be capable of continuing during an institutional crisis.

Operational management therefore includes:

  • continuity of critical services;
  • preservation of essential infrastructure;
  • transfer of operations;
  • treatment of liabilities;
  • continuity of customer relationships.

26. Case 2 — Banco Santander (Resolution of Banco Popular II)

Joined Cases C-775/22, C-779/22 and C-794/22, judgment of 5 September 2024.

These cases originated from the Spanish Tribunal Supremo and concerned the consequences of Banco Popular's resolution, including bail-in, protection of shareholders and creditors, and claims arising from allegedly defective information in the prospectus.

Principle

Resolution law can modify the legal position of investors and creditors in order to make the resolution mechanism effective.

Operations-management relevance

A bank's operations must be organised so that records, contracts, customer relationships and liabilities can be identified and managed even during resolution.

This requires strong:

  • documentation;
  • accounting;
  • data management;
  • legal records;
  • operational continuity.

27. Case 3 — Banco Santander (Resolution of Banco Popular III), C-687/23

This is particularly important because it is a 2025 judgment.

The case concerned actions brought before Banco Popular's resolution, including claims for nullity and damages arising from allegedly defective information relating to securities.

The CJEU held that rights arising from certain actions brought before resolution could remain enforceable against Banco Santander as universal successor.

Importance

The case shows why banking operations require reliable:

  • customer records;
  • contractual records;
  • litigation records;
  • securities records;
  • information systems.

A bank's operational systems must be capable of preserving legally significant information even through restructuring or resolution.

28. Case 4 — BAWAG, C-375/15

The CJEU considered whether information provided through an online banking system qualified as information communicated on a durable medium.

The Court distinguished simply making information available online from satisfying the statutory requirements for durable-medium communication.

Operations-management significance

Digital banking operations must satisfy legal requirements, not merely technological requirements.

Therefore:

A technically functioning banking system can still be legally deficient if its information and communication processes do not comply with banking law.

29. Case 5 — DenizBank, C-287/19

The case concerned contactless/NFC payment functionality and PSD2 concepts relating to payment instruments and authentication.

Operations-management significance

Banks must correctly classify and manage new payment technologies.

The case demonstrates that operations departments must understand the legal consequences of:

  • contactless transactions;
  • authentication;
  • payment instruments;
  • low-value payment exemptions.

Technology therefore cannot be separated from legal compliance.

30. Case 6 — Beobank, C-351/21

The case concerned an allegedly unauthorised payment transaction and the information that a payment service provider must provide concerning the relevant transaction.

Principle

Rules governing unauthorised transactions impose important information and liability obligations on payment-service providers.

Operations-management significance

Banks need effective operational processes for:

  • transaction records;
  • authentication data;
  • customer complaints;
  • investigation of disputed transactions;
  • identification of payees;
  • regulatory compliance.

Poor record management can therefore have legal consequences.

31. Case 7 — PrivatBank, C-480/18

The case concerned payment services and the application of EU payment-services law in a cross-border context.

Operations-management significance

Banks operating across EU borders must establish procedures determining:

  • applicable law;
  • supervisory authority;
  • customer rights;
  • complaint procedures;
  • liability;
  • cross-border service arrangements.

This illustrates why cross-border operations require more sophisticated compliance structures.

32. Case 8 — Rasool, C-568/16

The CJEU considered whether certain cash-withdrawal terminal activities constituted regulated payment services.

The Court's reasoning demonstrates that not every activity associated with payment transactions necessarily constitutes a regulated payment service.

Operations-management significance

Banks and financial businesses must correctly determine the regulatory classification of each operational activity.

This affects:

  • licensing;
  • compliance;
  • reporting;
  • consumer protection;
  • supervisory obligations.

33. Case-Law Table

CaseMain issueOperations-management lesson
Banco Popular / SRB, C-410/20 PBank resolutionContinuity and crisis operations
Banco Santander, C-775/22 etc.Resolution and creditor/investor rightsRecords, liabilities and continuity
Banco Santander, C-687/23Claims surviving resolutionLegal/data continuity
BAWAG, C-375/15Digital banking informationCompliance of digital processes
DenizBank, C-287/19Contactless paymentsTechnology must fit legal requirements
Beobank, C-351/21Unauthorised transactionsTransaction records and customer operations
PrivatBank, C-480/18Cross-border payment servicesCross-border operational compliance
Rasool, C-568/16Definition of payment servicesCorrect regulatory classification

34. Operations Management During a Banking Crisis

A bank experiencing severe operational difficulties should have a structured crisis process.

Stage 1 — Detection

Identify:

  • financial deterioration;
  • cyberattack;
  • liquidity shortage;
  • fraud;
  • operational failure.

Stage 2 — Escalation

Notify:

  • senior management;
  • risk function;
  • compliance;
  • internal audit where appropriate;
  • supervisory authorities where required.

Stage 3 — Containment

Prevent the problem from spreading.

Stage 4 — Continuity

Maintain critical banking functions.

Stage 5 — Recovery

Restore normal operations.

Stage 6 — Review

Identify the root cause and strengthen controls.

35. Relationship Between Efficiency and Compliance

A major issue in banking operations management is balancing:

Efficiency

with

Regulatory safety

For example, a bank might reduce costs by automating loan approvals.

But excessive automation could create:

  • inappropriate lending;
  • model risk;
  • discrimination concerns;
  • inadequate documentation;
  • cybersecurity risks.

Therefore, operational efficiency must remain within the bank's risk appetite and regulatory framework.

36. Operations Management and Corporate Culture

Operations management is also affected by organisational culture.

A bank can have excellent written policies but still experience operational failures if employees:

  • ignore controls;
  • conceal mistakes;
  • bypass approval procedures;
  • manipulate records;
  • prioritise sales over risk controls.

Law 10/2014's governance framework therefore connects organisational structure, risk management, internal control and remuneration.

37. Remuneration and Operations

Remuneration can create operational and prudential risk.

For example:

Employee rewarded solely for loan volume → incentive to approve risky loans.

Therefore, banking remuneration policies must be compatible with sound and effective risk management.

This principle is expressly reflected in Article 29 of Law 10/2014.

38. Outsourcing and Vendor Management

A bank should conduct due diligence before outsourcing critical activities.

Important questions include:

  • Is the provider financially stable?
  • Where is the data stored?
  • Can the bank audit the provider?
  • What happens after termination?
  • Is there a substitute provider?
  • Can data be transferred?
  • What happens during a cyberattack?
  • Does the contract permit regulatory access?

DORA has significantly strengthened the regulatory importance of these questions for ICT outsourcing.

39. Data Management

Modern banking operations depend heavily on data.

A bank must ensure:

  • accuracy;
  • availability;
  • confidentiality;
  • integrity;
  • traceability;
  • appropriate access;
  • secure retention.

This is particularly important for:

  • customer accounts;
  • credit histories;
  • payment records;
  • AML records;
  • securities;
  • regulatory reporting.

The Banco Popular litigation demonstrates the importance of maintaining legally reliable information through a bank's lifecycle, including resolution.

40. Banking Operations and Financial Stability

Why does the law regulate bank operations so heavily?

Because banks are interconnected.

Failure of one institution can affect:

Bank A

↓

Payment system

↓

Bank B

↓

Business customers

↓

Consumers

↓

Financial markets

Banco de España explains that banking supervision aims to safeguard financial-system stability and reduce the likelihood and cost of banking crises.

41. Supervisory Priorities

Spanish banking supervision is risk-based.

Authorities identify sectoral vulnerabilities and establish supervisory priorities each year.

The SSM uses continuing risk assessment and SREP to evaluate banks' risk profiles, capital and liquidity adequacy.

This means operations management is not static.

A bank's controls must evolve according to:

  • emerging risks;
  • technology;
  • economic conditions;
  • regulatory developments;
  • business-model changes.

42. Recent Regulatory Direction

The Banco de España Supervision Report 2025, published in April 2026, continues to organise supervisory activity around governance, prudential supervision, stress testing, conduct supervision, macroprudential policy, sanctions and market infrastructure oversight.

This illustrates the modern Spanish approach: operations management is treated as part of a broader system of governance + risk + prudential supervision + conduct + resilience.

43. Key Principles

The Spanish banking operations framework can therefore be summarised through the following principles:

  1. Clear organisational responsibility
  2. Board accountability
  3. Sound and prudent management
  4. Effective internal controls
  5. Independent risk management
  6. Accurate accounting and reporting
  7. Customer protection
  8. Operational and ICT resilience
  9. Third-party/outsourcing control
  10. Regulatory supervision
  11. Crisis preparedness
  12. Orderly resolution

44. Difference Between Operations Management and Operational Resilience

Operations ManagementOperational Resilience
Day-to-day functioningAbility to continue during disruption
ProcessesContinuity
StaffCrisis response
AccountingRecovery
PaymentsDisaster/cyber preparedness
LendingImpact tolerance
Customer serviceCritical-function preservation
Internal controlsRecovery and testing

Thus, operational resilience is one component of broader banking operations management.

45. Conclusion

Banking operations management in Spain is a legally regulated management discipline, not merely an internal business function. Law 10/2014 requires banks to establish clear organisational structures, effective risk-management procedures, internal controls and proper administrative and accounting systems, while placing significant governance responsibility on the board.

The framework is reinforced by EU prudential law, the SSM, DORA, payment-services legislation, AML rules, data-protection law and bank-resolution legislation.

The case law demonstrates the same principle from different directions: BAWAG and DenizBank show how digital and payment operations must comply with legal requirements; Beobank illustrates the importance of transaction information and liability; and the Banco Popular/Santander cases demonstrate the need for reliable records, continuity and legally structured operations during bank failure and resolution.

Exam-ready conclusion

Banking operations management in Spain consists of the legally controlled organisation of a bank's people, processes, technology, finances and internal controls so that banking activities are conducted efficiently, prudently and continuously. Its principal foundations are Law 10/2014, EU prudential regulation, SSM supervision, DORA, payment-services law, AML requirements and resolution law. The ultimate objective is to ensure sound management of banking operations while protecting customers, maintaining solvency and supporting financial stability.

LEAVE A COMMENT