SEPBLAC software: automate AML reporting without losing traceability
Any fintech, payment institution or e-money institution operating in Spain is an obliged entity under Law 10/2010 on the prevention of money laundering. That means reporting to SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010).Read more → SEPBLAC with enforceable deadlines, format and traceability. Manual reporting does not scale with volume, and a shared spreadsheet does not survive an inspection. Well-designed SEPBLAC software automates the repetitive work without sacrificing the audit trail or human control over what reaches the regulator.
What SEPBLAC requires from an obliged entity
Law 10/2010 and Royal Decree 304/2014 set out four operational obligations a system must sustain:
| Obligation | What it means |
|---|---|
| Special examination | Analyse in detail every complex, unusual operation with no apparent economic purpose before deciding whether to report. |
| Suspicion-based reporting | Report to SEPBLAC any operation linked, by indication or certainty, to money laundering, with its supporting documentation. |
| Systematic reporting | Periodically report operations subject to declaration even with no indication of suspicion. |
| Record retention | Keep documentation for ten years, retrievable and with demonstrable integrity. |
Each one produces a case file. Without a system, that file lives scattered across emails, spreadsheets and folders, and the decision chain goes unrecorded.
Why manual reporting does not scale
The problem is not only time. It is defensibility under an inspection.
| Problem | Impact |
|---|---|
| Latency | Weeks between detection and reporting, when the deadline is tight. |
| Transcription errors | Data hand-copied from five different systems, with inconsistency risk. |
| Incomplete audit trail | No record of who analysed what, when and on what criteria. |
| Key-person risk | Process knowledge lives in a single head. |
In an inspection, what is examined is not only the final report: it is how it was reached. A manual process can rarely reconstruct that chain with guarantees.
What SEPBLAC software should automate
Automating is not generating the report in one click and signing blind. The layers where software adds real value are specific:
1. Structured special examination
The system should enrich each alert with a 360° KYC (Know Your Customer) is the sector name for customer due diligence under Directive (EU) 2015/849: identifying and verifying the customer, identifying the beneficial owner, assessing the relationship's purpose and monitoring it over time. It is completed before the relationship opens, with exceptions (Article 14).Read more → KYC profile: client risk factors, jurisdiction, PEP status, transaction history. The analyst receives the case already documented, not a stray line.
2. Pre-filled case file
From the case file, the software pre-fills the F19 (form F19-1) is the template an obliged entity uses to report to SEPBLAC any act or transaction with indications or certainty of money laundering or terrorist financing, under Article 18 of Spain's Law 10/2010 and after the special examination of Article 17. Its content and audit trail are reviewed in inspections.Read more → F19 form, drafts the narrative summary in regulatory language, maps the applicable SEPBLAC indicators and builds the chronological timeline of operations. The analyst reviews and corrects, rather than transcribing.
3. Filing in a valid format
Reporting to SEPBLAC has a defined format and fields. The software validates the structure before submission, so an incomplete case file is never filed by mistake.
Guiding principle: the software proposes, the person decides
Automation must never report to the regulator without human approval. The four-eyes principle (segregation of duties) guarantees that every high-risk filing requires validation by two distinct people. It is enforceable, not optional.
Traceability is not an add-on
This is where most generic solutions fail. Serious SEPBLAC software must record every state transition of the case file immutably: who opened it, who analysed it, who approved the filing and when. Without that audit trail, automation solves speed but leaves the defence before the regulator exposed.
Ten-year retention demands the same: keeping the final PDF is not enough. You must be able to prove the integrity of the case file from the moment it was opened. A cryptographically sealed audit log turns "trust our archive" into "verify the integrity".
Data sovereignty when AI is involved
If the software uses AI for triage or drafting, it processes specially protected information: full names, national IDs, banking data, transaction patterns. Sending that data to third-party APIs only relocates the problem:
| Risk | Description |
|---|---|
| Data sovereignty | Information leaves your jurisdiction with no effective control. |
| The GDPR (General Data Protection Regulation) is Regulation (EU) 2016/679 on data protection, applicable since 25 May 2018. It reaches every entity established in the EU and anyone outside it offering goods or services to people in the Union or monitoring their behavior. Fines run up to 20,000,000 EUR or 4%.Read more → GDPR Art. 28 | The AI provider becomes a data processor. |
| The AI Act is Regulation (EU) 2024/1689, the European risk-based framework for AI: it bans unacceptable uses, regulates high-risk systems and requires transparency from general-purpose models. Its high-risk regime covers credit scoring and life and health insurance pricing from 2 December 2027 (Reg. 2026/1744).Read more → AI Act | High-risk AI systems require transparency and governance. |
The alternative is sovereign processing: models that run on your own infrastructure, so the case-file data never leaves the controlled perimeter.
How BlueUPALM approaches SEPBLAC reporting
| Capability | Implementation |
|---|---|
| Special examination | 360° KYC profile with configurable risk factors. |
| Indicators | Mapping of SEPBLAC indicators onto each alert. |
| Four-eyes | Segregation of duties with dual approval on filings. |
| Reporting | F19 pre-fill with narrative summary and timeline. |
| Audit trail | Immutable record of every case-file state transition. |
| Sovereign AI | Local processing: data never leaves the perimeter. |
Related reading
- AML automation with AI: from manual screening to intelligent triage — The AI layer that feeds the special examination.
- DORA 2026: a practical guide for financial entities — The other regulatory framework that shares traceability demands.
- DORA Calculator — Assess your DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.Read more → DORA maturity in minutes.
Want to see SEPBLAC reporting automated?
We will walk you through the BlueUPALM AML engine with synthetic data from your sector, including the special-examination flow and filing with an audit trail.