Skip to content

SEPBLAC software: automate AML reporting without losing traceability

Anti-money laundering (AML) is the prevention of money laundering and terrorist financing. In Spain, Law 10/2010 requires credit and financial institutions to apply customer due diligence and to report suspicious transactions to SEPBLAC; Regulation (EU) 2024/1624 harmonizes it from July 2027.Read more → AML & SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010).Read more → SEPBLAC · June 2026 · 6 min read

Any fintech, payment institution or e-money institution operating in Spain is an obliged entity under Law 10/2010 on the prevention of money laundering. That means reporting to SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010).Read more → SEPBLAC with enforceable deadlines, format and traceability. Manual reporting does not scale with volume, and a shared spreadsheet does not survive an inspection. Well-designed SEPBLAC software automates the repetitive work without sacrificing the audit trail or human control over what reaches the regulator.

What SEPBLAC requires from an obliged entity

Law 10/2010 and Royal Decree 304/2014 set out four operational obligations a system must sustain:

ObligationWhat it means
Special examinationAnalyse in detail every complex, unusual operation with no apparent economic purpose before deciding whether to report.
Suspicion-based reportingReport to SEPBLAC any operation linked, by indication or certainty, to money laundering, with its supporting documentation.
Systematic reportingPeriodically report operations subject to declaration even with no indication of suspicion.
Record retentionKeep documentation for ten years, retrievable and with demonstrable integrity.

Each one produces a case file. Without a system, that file lives scattered across emails, spreadsheets and folders, and the decision chain goes unrecorded.

Why manual reporting does not scale

The problem is not only time. It is defensibility under an inspection.

ProblemImpact
LatencyWeeks between detection and reporting, when the deadline is tight.
Transcription errorsData hand-copied from five different systems, with inconsistency risk.
Incomplete audit trailNo record of who analysed what, when and on what criteria.
Key-person riskProcess knowledge lives in a single head.

In an inspection, what is examined is not only the final report: it is how it was reached. A manual process can rarely reconstruct that chain with guarantees.

What SEPBLAC software should automate

Automating is not generating the report in one click and signing blind. The layers where software adds real value are specific:

1. Structured special examination

The system should enrich each alert with a 360° KYC (Know Your Customer) is the sector name for customer due diligence under Directive (EU) 2015/849: identifying and verifying the customer, identifying the beneficial owner, assessing the relationship's purpose and monitoring it over time. It is completed before the relationship opens, with exceptions (Article 14).Read more → KYC profile: client risk factors, jurisdiction, PEP status, transaction history. The analyst receives the case already documented, not a stray line.

2. Pre-filled case file

From the case file, the software pre-fills the F19 (form F19-1) is the template an obliged entity uses to report to SEPBLAC any act or transaction with indications or certainty of money laundering or terrorist financing, under Article 18 of Spain's Law 10/2010 and after the special examination of Article 17. Its content and audit trail are reviewed in inspections.Read more → F19 form, drafts the narrative summary in regulatory language, maps the applicable SEPBLAC indicators and builds the chronological timeline of operations. The analyst reviews and corrects, rather than transcribing.

3. Filing in a valid format

Reporting to SEPBLAC has a defined format and fields. The software validates the structure before submission, so an incomplete case file is never filed by mistake.

Guiding principle: the software proposes, the person decides

Automation must never report to the regulator without human approval. The four-eyes principle (segregation of duties) guarantees that every high-risk filing requires validation by two distinct people. It is enforceable, not optional.

Traceability is not an add-on

This is where most generic solutions fail. Serious SEPBLAC software must record every state transition of the case file immutably: who opened it, who analysed it, who approved the filing and when. Without that audit trail, automation solves speed but leaves the defence before the regulator exposed.

Ten-year retention demands the same: keeping the final PDF is not enough. You must be able to prove the integrity of the case file from the moment it was opened. A cryptographically sealed audit log turns "trust our archive" into "verify the integrity".

Data sovereignty when AI is involved

If the software uses AI for triage or drafting, it processes specially protected information: full names, national IDs, banking data, transaction patterns. Sending that data to third-party APIs only relocates the problem:

RiskDescription
Data sovereigntyInformation leaves your jurisdiction with no effective control.
The GDPR (General Data Protection Regulation) is Regulation (EU) 2016/679 on data protection, applicable since 25 May 2018. It reaches every entity established in the EU and anyone outside it offering goods or services to people in the Union or monitoring their behavior. Fines run up to 20,000,000 EUR or 4%.Read more → GDPR Art. 28The AI provider becomes a data processor.
The AI Act is Regulation (EU) 2024/1689, the European risk-based framework for AI: it bans unacceptable uses, regulates high-risk systems and requires transparency from general-purpose models. Its high-risk regime covers credit scoring and life and health insurance pricing from 2 December 2027 (Reg. 2026/1744).Read more → AI ActHigh-risk AI systems require transparency and governance.

The alternative is sovereign processing: models that run on your own infrastructure, so the case-file data never leaves the controlled perimeter.


How BlueUPALM approaches SEPBLAC reporting

CapabilityImplementation
Special examination360° KYC profile with configurable risk factors.
IndicatorsMapping of SEPBLAC indicators onto each alert.
Four-eyesSegregation of duties with dual approval on filings.
ReportingF19 pre-fill with narrative summary and timeline.
Audit trailImmutable record of every case-file state transition.
Sovereign AILocal processing: data never leaves the perimeter.

Want to see SEPBLAC reporting automated?

We will walk you through the BlueUPALM AML engine with synthetic data from your sector, including the special-examination flow and filing with an audit trail.

Request an AML demo


Back to the blog · See the BlueUPALM product