Caso destacadoFeatured case

Autoevaluación del riesgo de blanqueo de capitales

Money-laundering risk self-assessment

Diseñé y lideré el risk assessment anual en materia de financial crime —y el plan de controles que lo sustenta— en un contexto fintech de pagos B2B: el ejercicio que convierte la realidad operativa del negocio en una visión estructurada y fundamentada de su perfil de riesgo. I designed and led the annual financial-crime risk assessment — and the control plan behind it — for a B2B payments fintech: the exercise that turns the business's operating reality into a structured, well-founded view of its risk profile.

4
Categorías de riesgo ponderadasWeighted risk categories · 15 variables
3
Áreas de controlControl areas · 35 controles evaluados· 35 controls tested
2025 Periodo de referencia anualReference period
RolRole Dirección del risk assessmentRisk-assessment lead
SectorSector Pagos B2B y divisas (FX)B2B payments & FX
MarcoFrameworks Ley 10/2010 · RD 304/2014 · SEPBLAC
En resumenIn short

Antes de decidir qué controlar, es imprescindible comprender qué se quiere proteger y de qué amenazas. El Risk Assessment aporta ese conocimiento y se convierte en el fundamento sobre el que se construye todo el sistema de control interno. Before deciding what to control, you must first understand what you're protecting and from which threats. The risk assessment provides that knowledge and becomes the foundation on which the entire internal-control system is built.

01

El problemaThe problem

La normativa —el artículo 7 de la Ley 10/2010 y el artículo 32 del RD 304/2014— exige fundamentar el control interno en un análisis de riesgo previo y documentado. Regulation — article 7 of Law 10/2010 and article 32 of Royal Decree 304/2014 — requires internal controls to rest on a prior, documented risk analysis.

El reto no es rellenar un formulario. Es construir una representación fiel del riesgo de blanqueo de capitales, financiación del terrorismo y sanciones internacionales, basada en un conocimiento profundo del negocio y sustentada en criterios consistentes, ponderados y auditables. The challenge isn't filling in a template. It's building a faithful representation of money-laundering, terrorist-financing and sanctions risk, grounded in a deep understanding of the business and underpinned by consistent, weighted and auditable criteria.

ProductoProduct ClienteClient CanalChannel Fondos y geografíaFunds & geography
02

El enfoqueThe approach

Estructuré el ejercicio en cuatro fases y una escala común de cinco niveles, de modo que cada categoría se evaluara con el mismo criterio y un peso explícito según su relevancia en el negocio. I structured the exercise in four phases and a shared five-level scale, so every category was judged by the same yardstick — with an explicit weight reflecting its relevance to the business.

01 Identificación de categoríasIdentify categories Delimitar las categorías de riesgo y sus variables.Define the risk categories and their variables.
02 Tratamiento de datosData processing Recopilar, depurar y preparar los datos de cada categoría, priorizando la integridad, precisión y relevancia.Collect, clean and prepare the data for each category, prioritising integrity, accuracy and relevance.
03 Análisis integralIntegral analysis Lectura cuantitativa y cualitativa: cifras, patrones, contexto y tendencias.Quantitative and qualitative reading: figures, patterns, context.
04 Calificación y ponderaciónRating & weighting Asignar nivel por categoría y ponderar hasta el riesgo global.Assign a level per category and weight up to the global risk.
BajoLow Bajo–medioLow–medium MedioMedium Medio–altoMedium–high AltoHigh
Escala común de valoración — cinco nivelesShared rating scale — five levels

De qué riesgo partimosThe risk we start from

Cada categoría de riesgo se descompone en variables observables; su lectura conjunta, ponderada, fija el riesgo inherente del que parte el ejercicio.Each risk category breaks down into observable variables; read together and weighted, they set the inherent risk the exercise starts from.

01 Tipología de clientesClient typology
35%
Riesgo alto · 7 variablesHigh risk · 7 variables
Naturaleza jurídicaLegal nature Sector de actividadSector of activity Titularidad realBeneficial ownership Personas con responsabilidad públicaPolitically exposed persons Origen de fondosSource of funds Nacionalidad / residenciaNationality / residence Duración de la relaciónRelationship duration
02 Transmisión de fondos y geografíaFund transmission & geography
30%
Riesgo medio-alto · 4 variablesMedium-high risk · 4 variables
Jurisdicciones de origen y destinoOrigin & destination jurisdictions Divisas operadasCurrencies handled Medios de transmisiónTransmission methods Volumen y frecuenciaVolume & frequency
03 Actividad, productos y serviciosActivity, products & services
25%
Riesgo alto · 2 variablesHigh risk · 2 variables
Tipo de productoProduct type Complejidad operativaOperational complexity
04 Canales de distribuciónDistribution channels
10%
Riesgo medio · 2 variablesMedium risk · 2 variables
RemotoRemote Intermediarios / agentesIntermediaries / agents
4 categorías ponderadas · 15 variables observables en total.4 weighted categories · 15 observable variables in total.
La otra mitad del enfoqueThe other half of the approach

Entorno de controlControl environment

Medir el riesgo inherente es solo la mitad del enfoque; la otra mitad es probar si los controles funcionan. Measuring inherent risk is only half the approach; the other half is proving the controls actually work.

Por ello, se articula el Plan Anual de Controles, concebido para evaluar de forma sistemática el diseño y la eficacia operativa de cada control y determinar, con base objetiva, el riesgo residual asumido por la entidad. The Annual Control Plan was set up to systematically assess the design and operating effectiveness of each control and to determine, on an objective basis, the residual risk borne by the entity.

La estructura del planHow the plan is structured

El plan agrupa las verificaciones en tres áreas y cinco categorías de control —cada una con un propósito específico— ejecutadas con periodicidad trimestral o anual según su alcance. The plan groups its checks into three areas and five control categories — each with a specific purpose — run on a quarterly or annual cadence depending on scope.

01 Diligencia debida de clientesCustomer due diligence Trimestral + anualQuarterly + annual Concentra el mayor número de controles del plan y todas las verificaciones trimestrales.Holds the most controls in the plan and every quarterly check.
02 Operaciones sospechosasSuspicious activity AnualAnnual Identifica la actividad inusual y la reporta con rapidez.Spots unusual activity and reports it fast.
03 Control internoInternal control AnualAnnual Evalúa, ajusta y refuerza el marco de supervisión global.Assesses, adjusts and strengthens the overall oversight framework.
TrimestralQuarterly supervisión continua de la diligencia debida y el escrutinio de operaciones.continuous oversight of due diligence and transaction scrutiny.
AnualAnnual efectividad estructural de las políticas y procedimientos del entorno de control.structural effectiveness of the control environment's policies and procedures.
Por área y categoría de control.By area and control category.
PrevenciónPrevention DetecciónDetection ComunicaciónCommunication RespuestaResponse Mejora continuaContinuous improvement
Diligencia debidaDue diligence
16
Operaciones sospechosasSuspicious activity
11
Control internoInternal control
8

35 controles en total (16 · 11 · 8). Diligencia debida concentra prevención y mejora continua; el control interno, mejora continua y respuesta.35 controls in total (16 · 11 · 8). Due diligence concentrates prevention and continuous improvement; internal control, continuous improvement and response.

Desempeño por áreaPer-area performance — Customer due diligence

Los resultados se presentan desde una perspectiva analítica, permitiendo valorar tanto el equilibrio del plan de verificaciones entre áreas como la eficacia de los controles implantados.Results are presented from an analytical perspective, making it possible to weigh both the balance of the verification plan across areas and the effectiveness of the controls in place.

Estrategia de controlControl strategy 1 2 3 4 5
Plan globalOverall plan Diligencia debidaDue diligence
1 PrevenciónPrevention 2 DetecciónDetection 3 ComunicaciónCommunication 4 RespuestaResponse 5 Mejora continuaContinuous improvement

Compara el peso de cada propósito de control en el área frente al plan global.Compares the weight of each control purpose in the area against the overall plan.

Desempeño por controlControl-by-control performance
KYC & onboarding
Monitorización de operacionesTransaction monitoring
Herramienta de screeningScreening tool
RBADD · scoring de riesgoRBADD · risk scoring
RBA Payments
Alertas ex-postEx-post alerts
Screening de CPYsCounterparty screening
SatisfactorioSatisfactory Ajuste menor en cursoMinor tweak underway

Cada caja se dimensiona por la importancia relativa del control dentro del área.Each box is sized by the control's relative importance within the area.

03

El resultadoThe result

Un riesgo inherente alto, mitigado por un entorno de control satisfactorio, da como resultado un riesgo neto bajo–medio. A high inherent risk, mitigated by a satisfactory control environment, results in a low–medium net risk and a favourable trend.

Riesgo inherenteInherent risk AltoHigh
Entorno de controlControl environment SatisfactorioSatisfactory 34 de 35 controles satisfactorios (97%).34 of 35 controls satisfactory (97%).
Riesgo netoNet risk Bajo–medioLow–medium
Tendencia del riesgoRisk trend

FavorableFavourable

La tendencia del riesgo muestra la dirección esperada de su evolución, teniendo en cuenta los cambios esperados en el entorno interno y externo.The risk trend shows the expected direction of its evolution, taking into account anticipated changes in the internal and external environment.

Qué aportaThe takeaway

El informe convierte una obligación regulatoria en una herramienta de gestión: prioriza dónde reforzar controles y sustenta, con evidencia, la toma de decisiones estratégicas. The report turns a regulatory obligation into a management tool — prioritising where to strengthen controls and backing strategic anti-money-laundering decisions with evidence.

Caso destacado · PBC/FT · 2025Featured case · AML/CTF · 2025 Datos anonimizados y recursos visuales recreados para fines ilustrativos.Anonymised data and visuals recreated for illustrative purposes.