|
Law 10/2014 and Royal Decree 84/2015 on Credit InstitutionsSpanish Government and BdE
|
Credit institutions operating within the Spanish prudential regime |
Governance, risk management, internal controls, remuneration, supervisory reporting, recovery and accountable management. |
|
Source
|
|
Circular 2/2016 on Supervision and SolvencyBdE
|
Credit institutions within the circular’s scope |
Risk governance, capital and liquidity controls, internal processes, reporting, supervisory review and remediation evidence. |
|
Source
|
|
Good Governance Code of Listed CompaniesCNMV
|
Spanish listed companies on a comply-or-explain basis |
Board risk oversight, control functions, audit committees, internal audit, reporting and governance accountability. |
|
Source
|
|
Digital Operational Resilience ActEuropean Union and Spanish financial supervisors
|
Financial entities and ICT third-party providers within DORA’s scope |
ICT risk governance, major incident reporting, resilience testing, third-party controls, recovery and management-body oversight. |
|
Source
|
|
GDPR Personal Data Breach NotificationAEPD
|
Controllers and processors handling personal data within the GDPR’s scope |
Incident documentation, risk assessment, 72-hour notification where required, affected-person communication and corrective actions. |
|
Source
|