Banking Law And Regulatory Reporting Obligations Spain .
Banking Law and Regulatory Reporting Obligations in Spain
1. Introduction
Regulatory reporting obligations in Spanish banking law are the duties imposed on banks and other regulated financial institutions to provide financial, prudential, statistical, resolution, governance and compliance information to competent authorities.
For Spanish banks, reporting is not governed by one statute. It operates through an integrated Spanish and European Union framework, particularly because Spain participates in the EU Banking Union and Single Supervisory Mechanism (SSM).
Important authorities include:
- Banco de España;
- European Central Bank (ECB);
- European Banking Authority (EBA);
- Single Resolution Board (SRB);
- FROB, Spain's national resolution authority;
- CNMV, where securities-market reporting is involved; and
- SEPBLAC, particularly for AML/CFT matters.
The central principle is:
A bank must provide regulators with accurate, complete, consistent and timely information sufficient to assess its financial condition, risks and regulatory compliance.
2. Main legal framework
Spanish regulatory reporting requirements derive from several levels of legislation.
Spanish law
A central statute is Law 10/2014 on the regulation, supervision and solvency of credit institutions.
It establishes the broader legal framework for:
- Authorization;
- Prudential supervision;
- Governance;
- Capital;
- Supervisory powers;
- Reporting and information;
- Inspections; and
- Sanctions.
EU law
Important European instruments include:
- Capital Requirements Regulation (CRR);
- Capital Requirements Directive (CRD);
- EBA implementing technical standards;
- ECB supervisory regulations;
- Bank Recovery and Resolution Directive (BRRD);
- Single Resolution Mechanism framework.
Consequently, regulatory reporting by a Spanish bank is substantially harmonized at EU level.
3. Why banks must report
Banking supervision cannot function effectively if supervisors only receive information after a bank fails.
Regulatory reporting allows supervisors to identify:
- Falling capital;
- Liquidity shortages;
- Concentrated exposures;
- Deteriorating loan portfolios;
- Excessive leverage;
- Operational problems;
- Governance weaknesses;
- Financial-crime risks.
Reporting therefore functions as an early-warning mechanism.
4. FINREP
One major reporting framework is FINREP — Financial Reporting.
FINREP provides standardized financial information to supervisors.
Reports can contain information concerning:
- Assets;
- Liabilities;
- Equity;
- Income;
- Expenses;
- Loans;
- Deposits;
- Derivatives;
- Impairment;
- Non-performing exposures.
IFRS-based accounting information is particularly important for relevant banking groups.
The purpose is to allow supervisors to compare financial information across institutions using standardized definitions.
5. COREP
Another major framework is COREP — Common Reporting.
COREP focuses principally on prudential requirements.
It covers matters such as:
- Own funds;
- Capital ratios;
- Credit risk;
- Market risk;
- Operational risk;
- Leverage;
- Large exposures;
- Liquidity.
A simplified example is:
Bank capital: €15 billion
Risk-weighted assets: €100 billion
Supervisors use regulatory reports to assess whether required prudential ratios are satisfied.
6. Capital reporting
Banks must provide information allowing supervisors to calculate and verify capital requirements.
Relevant information can include:
- CET1 capital;
- Additional Tier 1 capital;
- Tier 2 capital;
- Regulatory deductions;
- Risk-weighted assets.
Incorrect classification can materially distort a bank's apparent solvency.
For example, incorrectly treating an instrument as eligible regulatory capital could make a bank appear better capitalized than it actually is.
7. Liquidity reporting
Banks also report liquidity information.
Important measures include:
Liquidity Coverage Ratio — LCR
Designed to ensure that banks maintain sufficient high-quality liquid assets to withstand a short-term liquidity stress scenario.
Net Stable Funding Ratio — NSFR
Addresses the stability of funding over a longer horizon.
Supervisors need reliable information concerning:
- Liquid assets;
- Deposits;
- Wholesale funding;
- Cash flows;
- Maturity profiles.
8. Large exposures
A bank that concentrates too much lending on one customer or connected group creates concentration risk.
Regulatory reports therefore identify large exposures.
Example:
Bank capital base: €4 billion
Exposure to corporate group: €900 million.
Supervisors need to determine whether the exposure complies with applicable CRR limits.
Banks must also identify when apparently separate borrowers form a group of connected clients.
9. Credit-risk reporting
Spanish banks report extensive information regarding credit portfolios.
This may cover:
- Mortgages;
- Corporate loans;
- SME loans;
- Consumer credit;
- Public-sector exposures;
- Defaulted exposures;
- Collateral.
Regulators can use the information to determine whether credit deterioration is being recognized appropriately.
10. Non-performing exposures
Following the European banking crises, reporting of non-performing loans and exposures (NPL/NPE) became especially important.
Banks need systems capable of distinguishing:
Performing exposure
from
Non-performing exposure.
Incorrectly keeping troubled loans classified as performing can distort:
- Profit;
- Provisions;
- Capital;
- Asset quality.
Supervisors therefore scrutinize classification and provisioning data.
11. AnaCredit
Spanish institutions can also have reporting obligations under AnaCredit, the ECB's analytical credit dataset.
AnaCredit provides detailed information about individual bank credit exposures.
Its purpose includes supporting:
- Monetary analysis;
- Financial-stability analysis;
- Banking supervision;
- Risk assessment.
This illustrates how modern regulatory reporting increasingly operates at granular loan level, rather than only through aggregate balance-sheet figures.
12. Banco de España's Central Credit Register
Spain also operates the Central de Información de Riesgos (CIR) through Banco de España.
Credit institutions report specified credit-risk information.
The system assists with:
- Credit-risk analysis;
- Supervision;
- Understanding borrower indebtedness.
Because the data can affect lending decisions and individuals or companies, accuracy is particularly important.
13. Statistical reporting
Banco de España and the Eurosystem require statistical information for monetary and economic purposes.
Banks can therefore report data concerning:
- Deposits;
- Loans;
- Interest rates;
- Securities;
- Cross-border positions;
- Balance sheets.
These reports support both banking supervision and monetary-policy analysis.
14. Supervisory reporting to the ECB
Under the SSM, significant Spanish banks are directly supervised by the ECB.
Reporting can therefore flow through a supervisory structure involving:
Spanish bank
↓
Banco de España / supervisory reporting infrastructure
↓
ECB
The exact reporting channel depends on the relevant dataset and regulatory framework.
15. SREP information
Regulatory reporting also supports the Supervisory Review and Evaluation Process (SREP).
Supervisors assess:
- Business model;
- Governance;
- Capital;
- Liquidity;
- Credit risk;
- Market risk;
- Operational risk.
Reported information can influence supervisory requirements, including institution-specific capital expectations and measures.
16. ICAAP reporting
Banks maintain an Internal Capital Adequacy Assessment Process (ICAAP).
The institution evaluates whether its capital is sufficient for its risks.
Relevant information can concern:
- Risk appetite;
- Stress testing;
- Capital planning;
- Credit risk;
- Concentration risk;
- Interest-rate risk;
- Operational risk.
ICAAP should not simply be a reporting exercise. Supervisors expect it to reflect genuine risk management.
17. ILAAP
Similarly, the Internal Liquidity Adequacy Assessment Process (ILAAP) addresses liquidity and funding.
It examines:
- Liquidity buffers;
- Funding structure;
- Stress scenarios;
- Contingency funding;
- Intraday liquidity.
ICAAP and ILAAP therefore connect internal risk governance with external supervision.
18. Resolution reporting
Banks also provide information for resolution planning.
Under the BRRD/SRM framework, authorities need information concerning:
- Legal entities;
- Critical functions;
- Liabilities;
- Capital instruments;
- Eligible liabilities;
- Intragroup exposures;
- Operational dependencies.
This allows resolution authorities to answer:
If this bank fails, how can it be resolved without uncontrolled disruption to the financial system?
19. MREL reporting
Banks may also have reporting obligations concerning the Minimum Requirement for Own Funds and Eligible Liabilities (MREL).
MREL helps ensure that banks have sufficient instruments capable of absorbing losses and supporting recapitalization in resolution.
Incorrect MREL reporting can undermine resolution planning.
20. AML reporting
Regulatory reporting is not limited to prudential data.
Under Spain's Law 10/2010 on the prevention of money laundering and terrorist financing, institutions have separate reporting and cooperation duties.
SEPBLAC plays a central role.
Where statutory conditions are satisfied, institutions may need to report suspicious operations and provide required information.
These reports differ fundamentally from COREP or FINREP.
21. Suspicious transaction reports
If a bank identifies circumstances giving rise to legally relevant suspicion, the matter can require reporting under AML legislation.
A typical compliance process may involve:
Transaction-monitoring alert
↓
Internal examination
↓
Compliance assessment
↓
Communication to SEPBLAC where required
Such reporting is confidential and interacts with restrictions concerning tipping off.
22. Securities-market reporting
Spanish banks participating in securities markets can also have reporting duties under legislation such as:
- MiFID II;
- MiFIR;
- Market Abuse Regulation;
- EMIR.
Depending on the activity, reporting can concern:
- Securities transactions;
- Derivatives;
- Trading;
- Market abuse;
- Positions.
The CNMV can therefore become an important authority alongside Banco de España and the ECB.
23. EMIR reporting
Banks dealing in derivatives may have obligations under EMIR.
Derivative transactions are reported to trade repositories according to the applicable framework.
The purpose includes improving transparency regarding:
- Counterparty exposure;
- Derivative concentration;
- Systemic risk.
24. Incident reporting and DORA
Digital banking has expanded reporting obligations beyond traditional financial statements.
Under the EU Digital Operational Resilience Act (DORA), applicable from 2025, financial institutions must operate within a harmonized ICT-risk framework.
Material ICT-related incidents can trigger regulatory reporting obligations.
Relevant incidents can include major:
- System failures;
- Cyber incidents;
- Data-related disruptions;
- Payment-service outages.
Thus, modern bank reporting increasingly includes technology risk.
25. Governance reporting
Supervisors may require information about:
- Directors;
- Senior managers;
- Internal controls;
- Risk committees;
- Remuneration;
- Related-party arrangements;
- Material governance changes.
Regulators need to know not merely what risks exist but who is responsible for controlling them.
26. Reporting must be accurate
Submitting a report does not satisfy the obligation if the information is materially inaccurate.
Four core qualities are:
Accuracy + completeness + consistency + timeliness.
Suppose a bank reports:
CET1 ratio = 14%
when the correct calculation is:
CET1 ratio = 10%.
The problem is potentially serious even if the report was filed before the deadline.
27. Internal reporting systems
A modern bank may obtain regulatory data from dozens of systems.
For example:
Customer systems
↓
Loan systems
↓
Trading systems
↓
Accounting ledger
↓
Risk engines
↓
Regulatory reporting platform
↓
Regulator
Errors anywhere in this chain can contaminate the final report.
Data governance is therefore a major component of regulatory compliance.
28. Management responsibility
Regulatory reporting cannot simply be delegated to junior reporting staff.
Banks require governance arrangements concerning:
- Data ownership;
- Validation;
- Reconciliation;
- Internal controls;
- Escalation;
- Sign-off.
Senior management remains responsible for ensuring an adequate regulatory-reporting framework.
29. Outsourcing
Banks increasingly outsource:
- Cloud infrastructure;
- Reporting software;
- Data processing;
- IT support.
However:
Outsourcing reporting technology does not automatically outsource regulatory responsibility.
A Spanish bank remains responsible for meeting obligations imposed upon it.
30. Reporting errors
When an institution discovers a material reporting error, appropriate action can include:
- Investigating the cause;
- Assessing materiality;
- Correcting data;
- Resubmitting where required;
- Informing the relevant supervisor where applicable;
- Remediating control weaknesses.
Attempting to conceal a known reporting error can create much greater regulatory risk than promptly correcting it.
31. Enforcement
Failure to satisfy reporting requirements can lead to supervisory or enforcement consequences.
Depending on the provision and seriousness, consequences can include:
- Regulatory orders;
- Remediation;
- Additional supervisory requirements;
- Administrative sanctions;
- Fines;
- Governance measures;
- Restrictions on activities.
Law 10/2014 provides an important Spanish sanctioning framework for infringements involving credit institutions.
32. Case Law 1 — Banco de España v Banca Privada
Spanish Constitutional Court jurisprudence concerning banking supervision has recognized the importance of the State's powers over the fundamental framework of banking and credit regulation.
A particularly important authority is STC 96/1984, dealing with the constitutional allocation of powers in banking matters.
Reporting relevance
Regulatory information requirements are closely connected to effective banking supervision. Supervisory authority would be severely weakened if regulated institutions could refuse information necessary to monitor solvency and compliance.
33. Case Law 2 — STC 48/1988
Spanish Constitutional Court, Judgment 48/1988
The decision forms part of the important constitutional jurisprudence concerning savings banks and the distribution of regulatory powers.
Principle
Banking regulation involves both national economic interests and territorially distributed competences.
Reporting relevance
Reporting requirements form part of the broader supervisory architecture necessary to maintain effective oversight of credit institutions.
34. Case Law 3 — STC 49/1988
Spanish Constitutional Court, Judgment 49/1988
This decision also addressed the regulatory framework surrounding Spanish savings banks.
Importance
It helps explain the constitutional basis for public regulation and supervision of financial institutions.
Reporting relevance
Information gathering is an indispensable component of prudential supervision and financial regulation.
35. Case Law 4 — Spector Photo Group
CJEU, Case C-45/08, Spector Photo Group NV and Chris Van Raemdonck v CBFA, judgment of 23 December 2009.
This was a market-abuse case rather than a Spanish prudential-reporting case.
Principle
The CJEU examined the interpretation and enforcement of EU market-abuse requirements.
Reporting relevance
It illustrates the broader EU principle that financial-market transparency and regulatory information obligations must be interpreted so that EU financial regulation remains effective.
For Spanish banks active in securities markets, this broader transparency framework is relevant.
36. Case Law 5 — Altmann and Others
CJEU, Case C-140/13, Altmann and Others v BaFin, judgment of 12 November 2014.
The case concerned professional secrecy relating to information held by financial supervisors.
Principle
Information obtained through financial supervision can be subject to strong confidentiality requirements.
Spanish reporting relevance
Banks may be compelled to provide extensive confidential information to regulators, but that does not mean supervisory information becomes freely available to the public.
Regulatory reporting and supervisory confidentiality therefore operate together.
37. Case Law 6 — Baumeister
CJEU, Case C-15/16, Bundesanstalt für Finanzdienstleistungsaufsicht v Ewald Baumeister, judgment of 19 June 2018.
This is particularly important concerning supervisory confidentiality.
Principle
The CJEU considered what information obtained by competent financial authorities can constitute confidential information protected by professional secrecy.
Reporting relevance
Spanish banks routinely provide commercially sensitive information to Banco de España and the ECB. EU law establishes protections concerning the subsequent treatment of such supervisory information.
38. Case Law 7 — ECB v Crédit Agricole and Others
The EU courts have dealt with several cases involving ECB prudential supervision and sanctions following the establishment of the SSM.
These cases demonstrate that the ECB's supervisory powers over significant banks are legally enforceable and subject to judicial review.
Reporting relevance
Information supplied by banks is central to the ECB's ability to:
- Assess prudential compliance;
- Calculate supervisory requirements;
- Investigate breaches;
- Impose measures.
A significant Spanish institution therefore operates within a European supervisory environment, not merely a domestic reporting framework.
39. Case Law 8 — Landeskreditbank Baden-Württemberg v ECB
CJEU, Case C-450/17 P, judgment of 8 May 2019.
This important Banking Union case concerned the allocation of supervisory responsibilities within the SSM.
Principle
The Court clarified the structure of ECB and national-authority responsibilities under the SSM framework.
Spanish relevance
For Spanish banks, regulatory reporting must be understood within this integrated supervisory architecture.
The ECB has a central prudential-supervisory role, while national authorities such as Banco de España perform important functions within the system.
40. What the cases collectively establish
These cases do not all concern a bank simply filing a late COREP form. Instead, they establish the legal environment in which regulatory reporting operates.
| Case | Reporting-related principle |
|---|---|
| STC 96/1984 | Constitutional basis of banking regulation |
| STC 48/1988 | Public supervision of financial institutions |
| STC 49/1988 | Banking regulatory competence |
| C-45/08 Spector Photo | Effectiveness of EU financial regulation |
| C-140/13 Altmann | Supervisory confidentiality |
| C-15/16 Baumeister | Protection of confidential supervisory data |
| ECB supervisory cases | Enforceability of ECB supervision |
| C-450/17 P Landeskreditbank | Integrated SSM supervisory structure |
41. Practical example
Suppose a large Spanish bank reports:
CET1 ratio: 13.5%
Later, internal audit discovers that €2 billion of exposures were assigned incorrect risk weights.
The corrected ratio becomes:
CET1 ratio: 11.8%.
The bank should investigate:
Data source
Where did the incorrect data originate?
Calculation
Was the CRR methodology applied correctly?
Governance
Who approved the report?
Materiality
How significant was the error?
Correction
Must the supervisory return be resubmitted?
Notification
Does the ECB/Banco de España need immediate notification?
Remediation
What controls need improvement?
If management knew the figure was wrong but deliberately submitted it, the legal and enforcement risk would become substantially greater.
42. Main reporting categories
| Reporting category | Main purpose |
|---|---|
| FINREP | Financial position |
| COREP | Prudential requirements |
| Capital | Solvency |
| LCR/NSFR | Liquidity |
| Large exposures | Concentration risk |
| AnaCredit | Granular credit data |
| CIR | Spanish credit-risk information |
| ICAAP | Internal capital adequacy |
| ILAAP | Internal liquidity adequacy |
| MREL | Resolution capacity |
| AML reports | Financial-crime prevention |
| MiFIR/EMIR | Market/derivative transparency |
| DORA incident reports | Operational resilience |
43. Regulatory architecture
The system can be summarized as:
Spanish bank
↓
Internal accounting + risk + compliance systems
↓
Data validation and management approval
↓
FINREP / COREP / liquidity / credit / resolution / AML / ICT reporting
↓
Banco de España + ECB + SRB/FROB + SEPBLAC + CNMV, depending on the report
↓
Supervisory analysis
↓
SREP / remediation / enforcement where necessary
Conclusion
Regulatory reporting is one of the foundations of modern Spanish banking supervision. Spanish banks must provide accurate, complete, consistent and timely information concerning capital, liquidity, credit risk, large exposures, financial statements, resolution, AML/CFT, securities transactions and increasingly ICT and operational resilience.
The framework is fundamentally European as well as Spanish. Law 10/2014 provides the domestic supervisory foundation, while the CRR/CRD framework, ECB/SSM rules, BRRD/SRM regime, EBA technical standards and DORA create extensive harmonized requirements.
The case law is particularly important in three areas: the constitutional legitimacy of banking supervision, the powers of European banking supervisors, and the confidentiality of information supplied to regulators. Authorities such as STC 96/1984, STC 48/1988, STC 49/1988, Altmann (C-140/13), Baumeister (C-15/16), and Landeskreditbank (C-450/17 P) provide useful legal foundations.
For formal legal research, individual reporting obligations should always be checked against the current CRR/CRD provisions, EBA implementing technical standards, ECB requirements and Banco de España circulars, because regulatory templates, thresholds and technical reporting requirements are periodically amended.

comments