Technology

Criminal compliance and regulatory compliance: two programmes that are now one

Nextica Law & Tax builds the technology company's compliance programme in both halves, which until recently ran separately. The criminal half: the organisation and control model under art. 31 bis of the Criminal Code, with the risk map of a business that bills by subscription and processes other people's data, plus the internal reporting channel under Law 2/2023. And the regulatory half, which is the one its clients now demand by contract: risk classification and technical documentation under Regulation (EU) 2024/1689 on artificial intelligence where the product embeds AI, and readiness for the cybersecurity risk-management measures of Directive (EU) 2022/2555, NIS2, which reach the small company through its financial and industrial clients' supply chain even where it is not itself designated an essential entity.

The corporate client no longer asks for a certificate: it asks for evidence, and it asks in the contract.

What's included

1. A risk map for a business that bills by subscription and processes other people's data

procurement fraud, contractual breach with regulated clients, third-party intellectual property in the code, and misuse of information.

2. An organisation and control model with the supervisory measures the Criminal Code requires for exemption, and a compliance body with real autonomy in a thirty-person company, which is where it usually fails.

3. An internal reporting channel under Law 2/2023

platform, system owner, acknowledgement and response deadlines, and confidentiality guaranteed against the management team itself.

4. An inventory of the product's AI systems and risk classification under Regulation (EU) 2024/1689, separating what is developed in-house from what is integrated from third parties.

5. Technical documentation, a decision log and traceability of training data, so the classification can be evidenced when a client asks.

6. Readiness for the cybersecurity risk-management measures of Directive (EU) 2022/2555 at the level that arrives through the supply chain: risk analysis, incident handling, continuity and supplier security.

7. Corporate governance that holds all of the above

the board's competences, minutes documenting compliance decisions, and an annual review of the programme.

TWO COMPLIANCE TRACKS THAT CAN NO LONGER RUN SEPARATELY

The criminal one answers to a judge; the regulatory one, to the client renewing the contract. Both ask for the same thing: evidence, not declarations.

A compliance programme approved and never executed

the legal entity's exemption requires a model with supervisory and control measures effectively implemented, and a manual with no training, no incident log and no periodic review is hard to evidence when it matters.

art. 31 bis of the Criminal Code

A reporting channel without real confidentiality guarantees

the law requires a system owner with autonomy, acknowledgement and response deadlines, and protection against retaliation. In a small company, a channel run by someone who could be reported does not comply — and does not get used either.

Law 2/2023 on whistleblower protection

Integrating a third party's AI system assuming the obligations belong to whoever developed it: putting your own name on a third party's system, or substantially modifying its intended purpose, can mean being treated as a provider, with the documentation and classification duties that brings.

Regulation (EU) 2024/1689 on artificial intelligence

MOST COMMON CRIMES IN THE BUSINESS FIELD

CrimeCP PreceptSectors with the highest exposure
Crimes against the Public Treasury and Social SecurityArt. 305-310 bisAll sectors
Money launderingArt. 301-304Financial services, real estate, jewelry, casino
Corruption between individuals (bribery)Art. 286 bisPharmaceutical, food, construction, distribution
Fraud and misappropriationArt. 248-254Services, technology, finance
Crimes against worker safetyArt. 316-317Construction, industry, logistics
Environmental crimesArt. 325-331Chemical industry, food, agriculture
Cyber crimesArt. 197 bis et seq.Technology, digital services, telecommunications

Crimes against the Public Treasury and Social Security

CP PreceptArt. 305-310 bis
Sectors with the highest exposureAll sectors

Money laundering

CP PreceptArt. 301-304
Sectors with the highest exposureFinancial services, real estate, jewelry, casino

Corruption between individuals (bribery)

CP PreceptArt. 286 bis
Sectors with the highest exposurePharmaceutical, food, construction, distribution

Fraud and misappropriation

CP PreceptArt. 248-254
Sectors with the highest exposureServices, technology, finance

Crimes against worker safety

CP PreceptArt. 316-317
Sectors with the highest exposureConstruction, industry, logistics

Environmental crimes

CP PreceptArt. 325-331
Sectors with the highest exposureChemical industry, food, agriculture

Cyber crimes

CP PreceptArt. 197 bis et seq.
Sectors with the highest exposureTechnology, digital services, telecommunications

Frequently asked questions

We are 30 people and not on the NIS2 essential entities list. Does it affect us?

Directly, perhaps not; by contract, almost certainly. Directive (EU) 2022/2555 requires essential and important entities to manage their supply chain risk, and the practical way they do it is by passing requirements down to suppliers in the clauses: minimum technical measures, incident notification within short deadlines, audit rights and periodic evidence. If you sell software to a bank, an insurer or a large manufacturer, those clauses are already arriving in your renewal contracts. Preparing for them beforehand is cheaper than negotiating them with the contract on the table.

We embed a third party's AI model. Are we a provider or a deployer?

It depends on what you do with it, and the answer changes the obligations entirely. Regulation (EU) 2024/1689 distinguishes whoever develops and places an AI system on the market from whoever uses it under their own authority, and adds that putting your name on a third party's system, or substantially modifying its intended purpose, can make you be treated as a provider. So the analysis starts with the same thing as the product sheet: what the system does, what it is marketed for and what has been changed. From that come the risk classification and the technical documentation you must be able to show.

Results, not names

Cases we have worked on

  • tecnologia

    Pacto de socios que desbloqueó la entrada de un inversor

Equipo Nextica

Content reviewed by

Equipo Nextica

Dirección

Meet the team

Let's talk about your company.

Tell us your situation and we'll reply within 24 working hours.

Step 1 of 2

Your data is processed according to our privacy policy.