Maëlle Vautrin
Paris, France
Oct 5, 2026

Spain’s securities regulator has identified a gap between broadly adequate anti-money-laundering reporting and the evidence needed to demonstrate that firms understand and control their risks. For crypto-asset service providers, the implications extend beyond correcting a regulatory return: risk assessments, transaction monitoring and management oversight need to tell a consistent story.

In its review of initial confidential AML/CFT statements, dated 14 September 2026, the Comisión Nacional del Mercado de Valores assessed BCFT1 submissions from crypto-asset service providers, investment management companies and broker-dealers under its 2026 Activity Plan. It considered the overall quality adequate, while identifying recurring weaknesses, including contradictory information and insufficiently developed internal risk frameworks.

That is a qualified assessment of reporting quality, not a clean bill of health for every firm’s controls. Nor does the identification of a weakness, by itself, establish a legal breach. The material supervisory message is narrower and more useful: firms must be able to explain how the risks they report translate into the controls they operate.

From risk ratings to operational decisions

For crypto-asset service providers, or CASPs, the review emphasises documented methodologies for assessing both inherent and residual money-laundering and terrorist-financing risk. Inherent risk is the exposure before mitigating controls are considered; residual risk is what remains after those controls are taken into account.

The distinction matters because a single overall rating can conceal substantial differences within a business. Customer profiles, products, geographical exposure and transaction channels can create different vulnerabilities. A credible methodology should explain how those factors are assessed and why particular controls are expected to reduce the resulting exposure.

The operational consequence is straightforward. A customer group classified as higher risk should not disappear into a monitoring framework that treats all customers identically. Equally, a firm should not assume that a control reduces risk simply because it exists in a policy manual. The assessment needs a defensible connection to what the control actually does.

The CNMV’s findings place particular weight on transaction-monitoring parameters calibrated to counterparty risk and transaction size. That does not mean every firm should adopt the same thresholds. It means firms should be able to justify their settings against their own activities and risk profile.

In practice, that calls for evidence of why parameters were selected, how their performance is assessed and who approves changes. Alert volumes alone cannot establish effectiveness: a system can generate many alerts without reliably identifying suspicious activity. Investigation quality, escalation decisions and the handling of unresolved concerns are also relevant to understanding whether monitoring works.

Reporting inconsistencies can expose governance weaknesses

Contradictory data in a BCFT1 statement may begin as a reporting problem, but it can also reveal a fragmented internal view of the business. If compliance, operations and management use different definitions or reporting periods, the resulting submission may be difficult to reconcile even where each underlying dataset appears plausible.

The practical response is therefore more than editing a return. Firms need to reconcile reported information with their risk assessments and operational records, identify the causes of discrepancies and establish responsibility for resolving them.

For supervisors, consistent reporting makes it easier to distinguish a data-quality issue from a substantive control weakness. For firms, it reduces the risk that management decisions are based on an incomplete or misleading account of exposure.

Existing obligations, not a new AML regime

The review also highlights representation arrangements with Sepblac, Spain’s financial intelligence unit, and external examination of AML/CFT compliance. These should not be treated simply as new expectations created by the CNMV’s publication.

Spain’s Law 10/2010 on preventing money laundering and terrorist financing already establishes internal-control, representative and external-examination requirements for obliged entities, subject to the applicable scope and exceptions. Its external-expert framework is more specific than a generic recommendation to commission an annual compliance audit, including provision for follow-up reports in the two years after an examination.

The distinction is important for proportional supervision. Firms need to know whether a finding concerns an existing legal obligation, the regulator’s interpretation of adequate implementation, or an improvement in reporting practice. Those categories can require different responses and should not be blurred.

Crypto firms also operate under the separate EU Transfer of Funds Regulation, Regulation (EU) 2023/1113, whose crypto-transfer provisions have applied since 30 December 2024. The regulation’s information requirements—the crypto “travel rule”—are not the same as the CNMV’s assessment of BCFT1 reporting. Compliance with one does not establish compliance with the other.

The review’s broader significance is an emphasis on traceability rather than paperwork alone. External scrutiny can challenge a firm’s assumptions, but responsibility remains with its leadership. Findings need owners, remediation needs tracking, and claimed improvements need supporting evidence.

For Spain’s supervised crypto firms, the immediate priority is to make the chain visible: the risk identified, the control selected, the operational result and the information reported to the regulator. Credible supervision depends on that chain being demonstrable—and on regulatory expectations remaining clear enough for firms to act before weaknesses become enforcement cases.