Criminal compliance and regulatory compliance: two programmes that are now one
Nextica Law & Tax builds the technology company's compliance programme in both halves, which until recently ran separately. The criminal half: the organisation and control model under art. 31 bis of the Criminal Code, with the risk map of a business that bills by subscription and processes other people's data, plus the internal reporting channel under Law 2/2023. And the regulatory half, which is the one its clients now demand by contract: risk classification and technical documentation under Regulation (EU) 2024/1689 on artificial intelligence where the product embeds AI, and readiness for the cybersecurity risk-management measures of Directive (EU) 2022/2555, NIS2, which reach the small company through its financial and industrial clients' supply chain even where it is not itself designated an essential entity.
The corporate client no longer asks for a certificate: it asks for evidence, and it asks in the contract.
What's included
1. A risk map for a business that bills by subscription and processes other people's data
procurement fraud, contractual breach with regulated clients, third-party intellectual property in the code, and misuse of information.
2. An organisation and control model with the supervisory measures the Criminal Code requires for exemption, and a compliance body with real autonomy in a thirty-person company, which is where it usually fails.
3. An internal reporting channel under Law 2/2023
platform, system owner, acknowledgement and response deadlines, and confidentiality guaranteed against the management team itself.
4. An inventory of the product's AI systems and risk classification under Regulation (EU) 2024/1689, separating what is developed in-house from what is integrated from third parties.
5. Technical documentation, a decision log and traceability of training data, so the classification can be evidenced when a client asks.
6. Readiness for the cybersecurity risk-management measures of Directive (EU) 2022/2555 at the level that arrives through the supply chain: risk analysis, incident handling, continuity and supplier security.
7. Corporate governance that holds all of the above
the board's competences, minutes documenting compliance decisions, and an annual review of the programme.
TWO COMPLIANCE TRACKS THAT CAN NO LONGER RUN SEPARATELY
The criminal one answers to a judge; the regulatory one, to the client renewing the contract. Both ask for the same thing: evidence, not declarations.
A compliance programme approved and never executed
the legal entity's exemption requires a model with supervisory and control measures effectively implemented, and a manual with no training, no incident log and no periodic review is hard to evidence when it matters.
art. 31 bis of the Criminal CodeA reporting channel without real confidentiality guarantees
the law requires a system owner with autonomy, acknowledgement and response deadlines, and protection against retaliation. In a small company, a channel run by someone who could be reported does not comply — and does not get used either.
Law 2/2023 on whistleblower protectionIntegrating a third party's AI system assuming the obligations belong to whoever developed it: putting your own name on a third party's system, or substantially modifying its intended purpose, can mean being treated as a provider, with the documentation and classification duties that brings.
Regulation (EU) 2024/1689 on artificial intelligenceMOST COMMON CRIMES IN THE BUSINESS FIELD
| Crime | CP Precept | Sectors with the highest exposure |
|---|---|---|
| Crimes against the Public Treasury and Social Security | Art. 305-310 bis | All sectors |
| Money laundering | Art. 301-304 | Financial services, real estate, jewelry, casino |
| Corruption between individuals (bribery) | Art. 286 bis | Pharmaceutical, food, construction, distribution |
| Fraud and misappropriation | Art. 248-254 | Services, technology, finance |
| Crimes against worker safety | Art. 316-317 | Construction, industry, logistics |
| Environmental crimes | Art. 325-331 | Chemical industry, food, agriculture |
| Cyber crimes | Art. 197 bis et seq. | Technology, digital services, telecommunications |
Crimes against the Public Treasury and Social Security
Money laundering
Corruption between individuals (bribery)
Fraud and misappropriation
Crimes against worker safety
Environmental crimes
Cyber crimes
Frequently asked questions
We are 30 people and not on the NIS2 essential entities list. Does it affect us?
Directly, perhaps not; by contract, almost certainly. Directive (EU) 2022/2555 requires essential and important entities to manage their supply chain risk, and the practical way they do it is by passing requirements down to suppliers in the clauses: minimum technical measures, incident notification within short deadlines, audit rights and periodic evidence. If you sell software to a bank, an insurer or a large manufacturer, those clauses are already arriving in your renewal contracts. Preparing for them beforehand is cheaper than negotiating them with the contract on the table.
We embed a third party's AI model. Are we a provider or a deployer?
It depends on what you do with it, and the answer changes the obligations entirely. Regulation (EU) 2024/1689 distinguishes whoever develops and places an AI system on the market from whoever uses it under their own authority, and adds that putting your name on a third party's system, or substantially modifying its intended purpose, can make you be treated as a provider. So the analysis starts with the same thing as the product sheet: what the system does, what it is marketed for and what has been changed. From that come the risk classification and the technical documentation you must be able to show.
Cases we have worked on
- tecnologia
Pacto de socios que desbloqueó la entrada de un inversor
Let's talk about your company.
Tell us your situation and we'll reply within 24 working hours.