Banking Law And Regulatory Reporting Standards Spain .
Banking Law and Regulatory Reporting Standards in Spain
1. Introduction
Regulatory reporting standards in Spanish banking law are the legal and supervisory requirements under which banks and other regulated financial institutions must provide financial, prudential, risk, statistical, resolution, AML and other information to competent authorities.
Spain's reporting framework is not purely domestic. Spanish banks operate within a multi-level European regulatory system involving:
- the Banco de España;
- the European Central Bank (ECB) within the Single Supervisory Mechanism (SSM);
- the European Banking Authority (EBA);
- the Single Resolution Board (SRB) and Spanish resolution authorities;
- SEPBLAC for AML/CFT matters;
- other authorities where securities, accounting, data-protection or market-conduct requirements apply.
The core principle is:
Banks must provide accurate, complete, timely and sufficiently granular regulatory information so supervisors can assess their financial condition and risks.
Failure to report correctly can lead to supervisory measures and, where the statutory conditions are satisfied, administrative sanctions.
2. Principal Spanish Legal Framework
Important domestic sources include Law 10/2014 of 26 June on the organization, supervision and solvency of credit institutions and its implementing legislation.
Law 10/2014 establishes the basic Spanish framework governing:
- authorization;
- solvency;
- supervision;
- governance;
- information obligations;
- inspections;
- infringements and sanctions.
The Banco de España also issues circulars dealing with accounting, supervisory and reporting matters.
For Spanish banks, however, these domestic requirements must be read together with directly applicable EU banking legislation.
3. EU Prudential Reporting Framework
A substantial part of Spanish regulatory reporting originates at EU level.
Important sources include the Capital Requirements Regulation (CRR) and the regulatory/implementing framework developed under EU banking legislation.
This creates harmonized reporting obligations across the European banking sector.
The objective is to make supervisory information sufficiently comparable across:
- Spain;
- France;
- Germany;
- Italy;
- other EU/EEA banking markets covered by the relevant rules.
A Spanish bank therefore cannot understand its reporting obligations solely by examining Spanish legislation.
4. FINREP
FINREP — Financial Reporting provides standardized supervisory financial information.
Depending on the institution and applicable reporting perimeter, information can concern:
- balance-sheet assets;
- liabilities;
- equity;
- income and expenses;
- loans;
- impairment;
- financial instruments;
- collateral;
- non-performing exposures.
FINREP improves comparability between institutions.
For example, supervisors can compare how different banks classify and report deteriorated credit exposures.
5. COREP
COREP — Common Reporting concerns prudential information.
Important areas include:
- own funds;
- capital requirements;
- credit risk;
- market risk;
- operational risk;
- leverage;
- large exposures;
- liquidity-related prudential information.
COREP allows supervisors to determine whether a bank is satisfying applicable prudential requirements.
A bank cannot simply calculate its own capital ratio using whatever methodology it prefers. Regulatory calculations and reporting must follow the legally applicable framework.
6. Capital Reporting
Banks must provide sufficient information for supervisors to understand their capital position.
Relevant information can include:
- Common Equity Tier 1;
- Additional Tier 1;
- Tier 2;
- deductions;
- risk-weighted assets;
- capital ratios;
- regulatory adjustments.
Errors can be significant.
For example:
Bank reports CET1 ratio = 14%.
After correcting improperly reported risk-weighted assets:
actual CET1 ratio = 11.8%.
This is not merely an accounting difference. It can affect supervisory assessment, capital planning and potentially compliance with prudential requirements.
7. Liquidity Reporting
Liquidity reporting is another major component.
Banks may be required to provide information concerning matters such as:
- high-quality liquid assets;
- cash outflows;
- cash inflows;
- funding sources;
- maturity structure;
- liquidity coverage;
- funding concentration.
The purpose is to determine whether a bank could continue satisfying obligations during periods of financial stress.
Reporting therefore forms part of the early-warning system for financial instability.
8. Large Exposure Reporting
Concentration risk is particularly important.
Banks must identify significant exposures to:
- individual borrowers;
- groups of connected clients;
- financial institutions;
- corporate groups.
Consider:
Bank capital = €1 billion
Exposure to connected corporate group = €400 million
The supervisor needs accurate reporting to determine whether applicable concentration rules have been breached or whether significant risk exists.
Incorrect identification of connected clients can therefore produce incorrect regulatory reporting.
9. Credit-Risk Reporting
Spanish banks provide extensive information concerning their credit portfolios.
Relevant information can include:
- performing loans;
- non-performing exposures;
- defaults;
- restructurings;
- forbearance;
- collateral;
- impairment;
- provisions.
Supervisors use these data to evaluate:
- asset quality;
- expected losses;
- credit deterioration;
- concentration;
- capital adequacy.
10. Banco de España's Central Credit Register
Spain also operates the Central Credit Register (Central de Información de Riesgos — CIR) managed by the Banco de España.
Credit institutions and other entities covered by the applicable framework report specified credit-risk information.
The CIR assists with:
- supervisory analysis;
- assessment of borrower indebtedness;
- risk monitoring;
- financial stability.
The accuracy of CIR information is important because incorrect information can affect both regulatory analysis and individuals or businesses whose credit exposures are recorded.
11. Accounting and Regulatory Reporting
Regulatory reporting and financial accounting overlap but are not identical.
Spanish banks may operate under:
- EU-endorsed IFRS requirements where applicable;
- Banco de España accounting requirements;
- prudential reporting rules.
A figure can therefore be treated differently depending on whether the purpose is:
- published financial statements;
- prudential capital;
- supervisory reporting;
- statistical reporting.
This is why banks maintain specialized regulatory-reporting functions rather than simply sending ordinary financial statements to supervisors.
12. Single Supervisory Mechanism
The Single Supervisory Mechanism significantly changed Spanish banking supervision.
Under the SSM:
- the ECB directly supervises significant institutions;
- national competent authorities such as Banco de España participate in supervision;
- less significant institutions remain subject to national direct supervision within the common SSM framework, subject to ECB oversight.
Reporting information is fundamental to this structure.
The ECB needs harmonized data to compare institutions across participating Member States.
13. ECB Supervisory Reporting
Significant Spanish banks can therefore have reporting relationships extending beyond Banco de España.
Information can reach the ECB through the supervisory reporting architecture.
The ECB uses regulatory data for:
- supervisory review;
- risk assessment;
- stress testing;
- capital analysis;
- liquidity assessment;
- governance supervision;
- early intervention.
Thus, incorrect reporting in Spain can potentially affect European-level supervision.
14. EBA Reporting Standards
The European Banking Authority has played a major role in harmonizing supervisory reporting.
The EBA reporting framework promotes:
- common definitions;
- common templates;
- standardized data structures;
- validation rules;
- consistent reporting concepts.
The objective is to prevent a situation in which:
Spain reports "X," Germany reports "Y," and Italy reports "Z"
for economically equivalent exposures.
Regulatory harmonization allows supervisors to compare like with like.
15. Data Quality
Regulatory reporting is not simply about submitting a form before a deadline.
Banks need appropriate systems ensuring:
Accuracy
Figures should correctly reflect the underlying position.
Completeness
Required information should not be omitted.
Timeliness
Reports should meet regulatory deadlines.
Consistency
Different reports should not contain unexplained contradictions.
Traceability
The institution should be capable of explaining how a reported figure was produced.
These principles have become increasingly important as banking supervision becomes data-driven.
16. Governance of Regulatory Reporting
Senior management and the board cannot treat reporting purely as an IT problem.
A sound reporting framework usually requires coordination between:
- finance;
- risk management;
- compliance;
- treasury;
- accounting;
- legal;
- information technology;
- internal audit.
The governance structure should establish:
data source → calculation → validation → approval → submission → correction process.
Weak governance can produce systematic reporting errors even where no employee intentionally provides false information.
17. Regulatory Reporting and Internal Controls
Banks need controls capable of detecting reporting errors before submission.
These may include:
- automated validation;
- reconciliations;
- maker-checker processes;
- exception reports;
- management review;
- internal audit.
For example:
FINREP reports loans of €20 billion.
Another regulatory dataset shows €23 billion.
The bank should investigate the €3 billion discrepancy rather than simply transmitting both figures.
18. Reporting Corrections
Errors can occur despite controls.
A robust framework should therefore provide procedures for:
- identifying the error;
- determining affected reports;
- quantifying the impact;
- notifying the relevant authority where required;
- submitting corrected information;
- investigating root causes;
- improving controls.
Attempting to conceal a material reporting error can create much more serious regulatory consequences than promptly correcting an inadvertent mistake.
19. AML/CFT Reporting
Prudential reporting should be distinguished from anti-money-laundering reporting.
Spain's AML framework is principally established by Law 10/2010 on the prevention of money laundering and terrorist financing, together with implementing measures.
Banks and other obliged entities have duties relating to:
- customer due diligence;
- transaction monitoring;
- suspicious activity;
- record keeping;
- cooperation with competent authorities.
SEPBLAC performs a central role in Spain's AML/CFT institutional framework.
Suspicious-transaction reporting therefore serves a different objective from FINREP or COREP.
20. Resolution Reporting
Banks may also have information obligations connected with resolution planning.
Relevant authorities can require information concerning:
- liabilities;
- own funds;
- eligible liabilities;
- critical functions;
- organizational structures;
- intercompany relationships;
- operational dependencies.
This information assists authorities in determining how a failing bank could be resolved without unnecessary disruption to the financial system.
21. MREL Reporting
The Minimum Requirement for Own Funds and Eligible Liabilities (MREL) is particularly relevant to resolution.
Banks within scope must maintain and report information necessary to assess their MREL position.
The purpose is to ensure that sufficient resources are available to absorb losses and recapitalize the institution in resolution where the relevant resolution strategy requires it.
22. Statistical Reporting
Banco de España also collects statistical information for monetary and financial purposes.
Banks can therefore face reporting obligations that are:
- prudential;
- accounting;
- statistical;
- resolution-related;
- AML-related.
These categories should not be confused.
The same transaction can appear in several reporting systems for different regulatory purposes.
23. Digital Reporting and Data Standards
Modern banking reporting increasingly depends on structured digital data.
Supervisory systems can employ:
- standardized taxonomies;
- machine-readable templates;
- automated validation;
- data-quality checks;
- regulatory technology.
This reduces manual processing but introduces new risks.
For example, a mapping error in a bank's reporting software could incorrectly classify thousands of exposures.
Therefore, automation does not remove accountability.
24. Outsourcing Reporting Technology
A bank may use external technology providers to help generate regulatory reports.
However:
outsourcing production does not ordinarily outsource the regulated bank's responsibility for compliance.
Banks must therefore appropriately govern:
- data integrity;
- cybersecurity;
- provider access;
- auditability;
- business continuity;
- subcontracting.
The regulated institution remains responsible for ensuring that required information is submitted correctly.
25. Confidentiality
Regulatory reports frequently contain highly sensitive information.
Examples include:
- customer exposures;
- liquidity positions;
- capital weaknesses;
- trading positions;
- major borrowers.
Accordingly, reporting systems must provide appropriate protection against unauthorized access or disclosure.
Supervisory authorities themselves are also subject to legal confidentiality and professional-secrecy requirements.
26. Enforcement for Reporting Failures
Under the Spanish and EU supervisory framework, failures involving regulatory information can potentially trigger enforcement where the relevant statutory conditions are satisfied.
Problematic conduct may include:
- failure to submit required information;
- repeated late reporting;
- materially inaccurate reporting;
- obstruction of supervision;
- failure to provide requested information.
Possible consequences depend on the applicable provision, seriousness of the conduct, responsible person and competent authority.
They can include:
- supervisory remediation;
- administrative sanctions;
- financial penalties;
- governance consequences;
- other measures permitted by law.
27. Proportionality
Not every reporting mistake has the same legal significance.
Authorities can consider factors such as:
- seriousness;
- duration;
- negligence or intentional conduct;
- impact on supervision;
- repeated violations;
- cooperation;
- corrective action.
Thus:
minor accidental error
and
deliberate concealment of a serious capital deficiency
present fundamentally different regulatory situations.
28. Case Law 1 — CJEU, C-52/17, VTB Bank v ECB
Case C-52/17 P, VTB Bank PAO v European Central Bank forms part of the broader EU prudential-supervision jurisprudence concerning the exercise of supervisory authority.
Reporting relevance
EU banking supervision depends on accurate regulatory information and legally defined prudential requirements.
The broader lesson is that supervisory decisions must have an identifiable legal basis and remain subject to judicial review.
For Spanish significant institutions, these EU principles matter because the ECB can exercise direct supervisory powers under the SSM.
29. Case Law 2 — CJEU, C-450/17 P, Landeskreditbank Baden-Württemberg v ECB
Landeskreditbank Baden-Württemberg v ECB is one of the leading SSM cases.
The litigation concerned the allocation and exercise of supervisory competence within the Single Supervisory Mechanism.
Importance for Spain
The judgment confirms the central role of the ECB within the SSM architecture established by EU law.
For regulatory reporting, this matters because Spanish banks operate inside an integrated European supervisory structure rather than a purely domestic Banco de España system.
30. Case Law 3 — CJEU, C-64/14, Gauweiler
Gauweiler and Others primarily concerned ECB monetary-policy measures rather than regulatory reporting.
Nevertheless, it is relevant to the broader constitutional position of the ECB and the requirement that EU institutions act within powers granted by EU law.
Reporting connection
ECB requests and supervisory measures must derive from the appropriate legal framework.
The case should therefore be treated as institutional background, rather than a direct regulatory-reporting precedent.
31. Case Law 4 — CJEU, C-62/14, Peter Gauweiler and Others
The broader jurisprudential principle associated with EU institutional action is that measures must:
- possess an appropriate legal basis;
- pursue legally permitted objectives;
- respect applicable proportionality requirements.
Banking-reporting relevance
Supervisory reporting cannot simply be unlimited because information would be useful. Information requirements must operate within the statutory and regulatory powers granted to the competent authorities.
32. Case Law 5 — Spanish Supreme Court and Banco de España Supervisory Information
Spanish administrative jurisprudence concerning financial supervision generally recognizes that supervisory and sanctioning powers must comply with principles governing administrative action, including:
- legality;
- proper procedure;
- evidential sufficiency;
- proportionality.
Reporting significance
If inaccurate regulatory reporting leads to sanctions, the authority must establish the legally relevant infringement rather than merely showing that a numerical difference existed.
This distinction protects the difference between:
reporting error
and
sanctionable reporting misconduct.
33. Case Law 6 — Spanish Constitutional Court: Sanctioning Legality
Spanish Constitutional Court jurisprudence consistently applies the constitutional principle of legality to administrative sanctions.
Under Article 25 of the Spanish Constitution, sanctions require a sufficient legal foundation.
Reporting relevance
A bank or responsible individual should not be sanctioned merely because the supervisor dislikes the quality of a report.
The authority must connect the conduct to an applicable legal infringement.
This is particularly important where supervisory expectations, technical guidance and legally binding reporting requirements overlap.
34. Case Law 7 — CJEU, C-911/19, FBF v ACPR
The Fédération bancaire française (FBF) v Autorité de contrôle prudentiel et de résolution judgment is highly relevant to European banking regulation.
The case examined the legal significance and reviewability of EBA guidelines.
Importance
It demonstrates an important distinction between:
- binding EU legislation;
- supervisory guidelines;
- recommendations and other soft-law instruments.
Spanish reporting relevance
Banks must understand whether a particular EBA reporting expectation comes from:
- directly applicable legislation;
- binding technical standards;
- an EBA guideline;
- supervisory practice.
These categories do not necessarily have identical legal effects.
35. Case Law 8 — CJEU, C-219/17, Berlusconi and Fininvest
Berlusconi and Fininvest v Banca d'Italia and IVASS concerned the judicial-review structure applicable where national authorities participate in a procedure culminating in an ECB decision.
Reporting relevance
This is important because SSM supervision frequently involves cooperation between:
national competent authority → ECB.
For Spanish institutions, Banco de España may collect, analyze or transmit information within a process that ultimately supports ECB supervisory action.
The judgment illustrates the integrated character of European banking supervision and judicial review.
36. Important Case-Law Qualification
Not all of these decisions concern FINREP or COREP directly.
Spain has extensive banking jurisprudence, but reported appellate cases specifically devoted to a bank incorrectly completing an individual modern EBA regulatory-reporting template are comparatively limited.
The relevant legal principles therefore come from several related fields:
- ECB supervisory competence;
- administrative legality;
- proportionality;
- sanctions;
- evidential standards;
- legal status of EBA instruments;
- judicial review of composite EU supervisory procedures.
It is important not to describe general SSM decisions as direct FINREP cases when they are not.
37. Practical Example
Assume a significant Spanish bank reports:
CET1 ratio: 13.5%.
An internal review discovers that certain exposures were incorrectly assigned lower risk weights.
After correction:
CET1 ratio: 11.9%.
The bank should determine:
- which regulatory reports are affected;
- which reporting periods are affected;
- whether prudential requirements were breached;
- whether Banco de España/ECB notification is required;
- whether previous public disclosures were affected;
- why internal validation failed;
- whether management or governance controls require remediation.
The issue is therefore larger than simply replacing "13.5" with "11.9."
It potentially affects prudential supervision, capital planning, governance and disclosure.
38. Regulatory Reporting Architecture
A simplified Spanish reporting structure can be represented as:
Bank's operational systems
↓
Finance / risk / treasury databases
↓
Regulatory data warehouse
↓
Validation and reconciliation
↓
Management approval
↓
Banco de España / ECB / other competent authority
↓
Supervisory analysis
↓
Corrective measures where necessary
Every stage creates potential data-quality and governance risks.
39. Principal Reporting Categories
| Reporting area | Typical supervisory purpose |
|---|---|
| FINREP | Financial condition |
| COREP | Prudential requirements |
| Own funds | Capital adequacy |
| Liquidity | Short/long-term funding resilience |
| Large exposures | Concentration risk |
| Credit risk | Asset quality |
| CIR | Credit-risk information |
| AML/CFT | Financial-crime prevention |
| Resolution reporting | Resolution planning |
| MREL | Loss-absorbing capacity |
| Statistical reporting | Monetary/financial analysis |
| Stress testing | Resilience under adverse scenarios |
40. Core Legal Principles
Spanish regulatory reporting can be summarized through eight principles.
First — Multi-level regulation: Spanish banks are governed simultaneously by Spanish and EU reporting frameworks.
Second — Harmonization: COREP, FINREP and related EU frameworks promote comparable supervisory data.
Third — Accuracy and completeness: regulatory information must reliably represent the bank's position.
Fourth — Timeliness: accurate information submitted too late can still create supervisory problems.
Fifth — Governance: responsibility for regulatory data cannot simply be delegated to the IT department.
Sixth — Accountability survives outsourcing: using an external reporting provider does not automatically eliminate the bank's regulatory responsibility.
Seventh — Proportional enforcement: sanctions must satisfy applicable legality, evidence and proportionality requirements.
Eighth — Judicial review: supervisory and sanctioning measures remain subject to review under Spanish and EU law.
41. Conclusion
Regulatory reporting standards in Spanish banking law form one of the foundations of modern prudential supervision. Spanish institutions must provide extensive information concerning their financial condition, capital, liquidity, credit risk, large exposures, AML/CFT obligations, resolution position and other regulatory matters.
The framework operates through several interconnected levels:
EU legislation and EBA standards
↓
ECB / Single Supervisory Mechanism
↓
Spanish legislation
↓
Banco de España
↓
Individual banks
Major legal sources include Law 10/2014, the EU Capital Requirements Regulation, SSM legislation, EBA technical standards, Banco de España requirements, Law 10/2010 for AML/CFT, and the EU bank-resolution framework.
Relevant jurisprudence—including Landeskreditbank v ECB, FBF v ACPR, Berlusconi and Fininvest, together with Spanish constitutional and administrative-law principles—shows that regulatory reporting exists within a broader legal framework of supervisory competence, legality, proportionality, evidence and judicial review.
The central principle is that regulatory reporting is not a clerical exercise. Accurate reporting allows the Banco de España and ECB to understand whether a bank is safe, sufficiently capitalized, liquid and properly governed. Consequently, weaknesses in reporting can become weaknesses in prudential supervision itself.

comments