Spain's Draft Organic Law on Public Integrity introduces a requirement that will reshape how you bid on public contracts: entities seeking to contract with the public sector must implement "an appropriate organization and management model for integrity and the prevention of criminal offenses, together with effective supervision thereof." This isn't guidance, it's a gateway requirement.
If you're bidding on Spanish government contracts, you need this framework operational before the law takes effect. Here's a template you can adapt to your organization's risk profile and procurement activity.
Purpose of the Template
This compliance model template addresses the Draft's criminal compliance requirement for public procurement eligibility. It provides a documented framework that demonstrates:
- Criminal risk assessment specific to public sector interactions
- Control design for corruption prevention
- Oversight mechanisms that satisfy "effective supervision"
- Integration with your mandatory whistleblowing channel (the Draft links compliance systems to internal reporting obligations)
The template follows the structure Spanish courts have recognized in corporate liability cases: it maps risk, assigns control ownership, and creates audit trails.
Prerequisites
Before you customize this template, confirm you have:
Organizational readiness:
- Executive sponsorship (your board or equivalent must approve the compliance model)
- A designated compliance officer or function with direct reporting to senior management
- Budget allocation for training, monitoring tools, and periodic reviews
Existing documentation:
- Current organizational chart with public procurement roles identified
- List of active and planned public sector contracts
- Your existing Code of Conduct or Ethics Policy
- Your whistleblower protection policy (required under Spain's Whistleblower Protection Act)
Technical infrastructure:
- Secure internal reporting channel (email, web form, or third-party hotline)
- Document repository with access controls and version tracking
- Training delivery system (LMS or equivalent)
If you don't have a whistleblowing channel yet, the Draft makes it a prerequisite for the compliance system. Build that first.
The Template
Section 1: Compliance Model Charter
Purpose: This model establishes controls to prevent corruption and offenses against the Public Administration in all activities involving Spanish public sector entities.
Scope: All employees, contractors, and third parties acting on behalf of [Company Name] in public procurement, grant applications, licensing, inspections, or other interactions with Spanish government bodies.
Authority: Approved by [Board/Management Committee] on [Date]. Reviewed annually or upon material change to procurement activity.
Compliance Officer: [Name, Title] reports directly to [CEO/Board Committee] and has unrestricted access to all procurement documentation and communications.
Section 2: Criminal Risk Assessment
High-risk activities identified:
- Preparation and submission of public tender bids
- Contract negotiation and amendment discussions with public officials
- Invoicing and payment processing for public contracts
- Hiring of former public officials or their family members
- Gifts, hospitality, or sponsorships involving public sector personnel
- Subcontractor selection when prime contractor on public projects
Control objectives for each risk:
- Bid preparation: Prevent false certifications, collusion, or misrepresentation of qualifications
- Official interactions: Document all meetings; prohibit unauthorized commitments
- Financial transactions: Segregate duties; require dual approval for payments above €[threshold]
- Hiring: Screen for conflicts; maintain cooling-off period records
- Gifts/hospitality: Pre-approve all items above €50; maintain gift register
- Subcontracting: Due diligence on integrity; flow-down compliance obligations
Section 3: Mandatory Controls
Control 1: Conflict of Interest Declaration
All personnel involved in public procurement must execute a conflict-of-interest declaration before participating in any bid or contract activity. Update declarations annually and upon any change in circumstances.
Template declaration: "I confirm that neither I nor my immediate family members hold financial interests in, or maintain personal relationships with, any public official involved in [Procurement Reference]. I will immediately disclose any conflict that arises during this engagement."
Control 2: Dual Authorization for Public Sector Commitments
No single individual may commit the company to a public contract term, pricing structure, or deliverable modification. Require:
- Technical lead approval (confirms feasibility)
- Compliance officer approval (confirms regulatory alignment)
- Finance approval (confirms pricing integrity)
Control 3: Public Official Interaction Log
Maintain a register of all meetings, calls, and substantive email exchanges with public procurement officials. Log must capture: date, participants, topics discussed, decisions made, and any follow-up commitments.
Control 4: Third-Party Due Diligence
Before engaging consultants, subcontractors, or agents in public procurement activities, complete integrity screening:
- Beneficial ownership verification
- Sanctions and debarment list checks (Spanish and EU)
- Reputation search for corruption allegations
- Contractual flow-down of compliance obligations
Control 5: Training and Certification
Annual anti-corruption training mandatory for all public procurement participants. Training must cover:
- Prohibition on bribes, facilitation payments, and improper advantages
- Gift and hospitality limits and approval process
- Whistleblowing rights and non-retaliation protections
- Consequences of non-compliance (personal and corporate)
Maintain signed training completion certificates.
Section 4: Whistleblower Integration
Per the Draft's amendment to the Whistleblower Protection Act, your compliance model must integrate with your internal reporting system. Include in your policy:
Policy statement: "This compliance model is integrated into [Company Name]'s whistleblowing protection framework. All personnel may report suspected violations of this model through [channel description] without fear of retaliation. Reports are investigated by [function] within [timeframe]."
Escalation path: Whistleblowing reports alleging public procurement violations go directly to the Compliance Officer and [Board Committee]. No line management filter.
Section 5: Monitoring and Supervision
Quarterly compliance reviews:
- Sample 10% of public procurement transactions for control adherence
- Review conflict declarations for completeness and accuracy
- Audit gift register for items near or above thresholds
- Test dual authorization controls for override attempts
Annual effectiveness assessment:
- Interview procurement personnel about control burden and gaps
- Benchmark incident rates against prior periods
- Update risk assessment based on new contract types or jurisdictions
- Report findings and remediation plans to [Board/Committee]
Audit trail requirements:
- Retain all compliance documentation for seven years (matches the Draft's extended statute of limitations for certain offenses)
- Ensure documentation is accessible for internal audit and external investigation
Customization Tips
For small procurement teams (under 10 people):
- Simplify the dual authorization to two signatures instead of three functions
- Combine Compliance Officer role with another senior role (CFO, General Counsel)
- Use spreadsheet-based registers instead of dedicated software
For multi-entity groups:
- Cascade the model to each Spanish subsidiary with procurement authority
- Centralize Compliance Officer reporting but appoint local compliance contacts
- Standardize training content but allow local delivery
For high-volume contractors:
- Automate conflict declarations through your HR system
- Integrate gift register with expense management platform
- Schedule monthly (not quarterly) transaction sampling
For specialized sectors (construction, IT services, consulting):
- Add sector-specific risk scenarios to training (e.g., change order inflation in construction)
- Tailor due diligence questions to common subcontractor risks in your industry
- Include technical specification integrity in your control objectives
Validation Steps
Before you declare the model operational:
Executive sign-off: Present the model to your board or management committee. Document their approval in meeting minutes.
Policy publication: Post the compliance model on your intranet. Require all public procurement personnel to acknowledge receipt.
Control testing: Run a mock procurement scenario through your dual authorization and conflict declaration processes. Identify friction points.
Whistleblowing channel test: Submit an anonymous test report through your channel. Confirm it reaches the Compliance Officer without line management interception.
Training deployment: Deliver initial training to all in-scope personnel. Collect completion certificates.
Documentation audit: Verify that your retention system can retrieve compliance records by procurement reference number and date range.
External review: If you have outside counsel or auditors, have them review the model against the Draft's requirements. Address any gaps before your next bid submission.
The Draft proposes mandatory disqualification from public contracting for entities that fail to maintain adequate compliance models. That's not a fine you can budget for, it's an existential business risk. Treat this template as infrastructure, not paperwork.





