CESCOM Exam Preparation Course for Compliance Professionals

Structured CESCOM exam preparation covering all twenty compliance modules.

56
July 2026
  • Trust badge
  • Trust badge

Get this this CPD‑Accredited programme now. Be secure with a SSL-secured payment backed up by a 14‑day money‑back guarantee.

Overview

The CESCOM syllabus is broad, technical, and difficult to navigate. Without structure, revision becomes slow, fragmented, and overwhelming. This course gives learners a clear path forward.

Learners study all twenty CESCOM syllabus areas. Topics include ethics, governance, risk, AML, and data protection. Each module turns complex requirements into practical, manageable learning.

Structured lessons support focused revision and stronger knowledge retention. Self-paced access fits study around demanding professional schedules. Learners build clearer understanding across the complete CESCOM syllabus.

Learning Outcomes

By completing this course, learners will be able to:

  • Explain core Compliance concepts, frameworks, terminology, and governance principles.
  • Interpret the Compliance Officer’s mandate, responsibilities, positioning, and independence.
  • Identify relevant Spanish and EU laws, standards, and regulatory authorities.
  • Analyse Compliance risks using structured identification, evaluation, and treatment methods.
  • Apply appropriate procedures for whistleblowing, investigations, data protection, and reporting.
  • Evaluate anti-bribery, AML/CFT, market-abuse, and corporate Compliance controls within practical scenarios.

Certification Information

Certification Information

After completing the course, learners will receive a Certificate of Completion from Spanish Compliance Institute.

It demonstrates structured CESCOM knowledge and professional development. It does not grant official CESCOM certification. 

Curriculum

1

Module 1: General Concepts of Compliance

2 Hours

  • What Compliance is and the historical evolution of the function.
  • Compliance as a function and as a culture; difference between legal counsel and internal control.
  • Compliance models and "superstructures"; international reference models.
  • Main standards and frameworks: UNE-ISO 37301, UNE-ISO 37001, COSO, and the three lines of defense model.
  • Role, mandate, position, and independence of the Compliance Officer.
  • Anchors: UNE-ISO 37301, COSO, IIA Three Lines.
  • Case study – NovaTerra: Code of Ethics groundwork.
2

Module 2: Corporate Ethics

2 Hours

  • Introduction and origins of corporate ethics; history and regulation.
  • Difference between law and ethics.
  • Ethics applied to the company: ethical dilemmas and codes of conduct.
  • Ethics as a factor for value creation and reputation.
  • The Compliance Officer as the guarantor of corporate values.
  • Case study – NovaTerra: Code of Ethics.
3

Module 3: Essential Elements of a Compliance Programme

2 Hours

  • Concept and purpose of a Compliance programme.
  • Generally accepted compliance principles.
  • Essential components: governance, risks, policies, controls, training, reporting channel, and oversight.
  • Documentation of the model.
  • Review cycle and continuous improvement.
  • Effectiveness of the programme and its accreditation (proof of effectiveness).
  • Case study – NovaTerra: compliance-programme blueprint.
4

Module 4: Compliance Management Systems: UNE-ISO 37301

2 Hours

  • From UNE-ISO 19600 (guidelines) to UNE-ISO 37301 (certifiable requirements).
  • Object and scope of application.
  • High-Level Structure (Annex SL): context, leadership, planning, support, operation, performance evaluation, and improvement.
  • Key definitions and Compliance obligations.
  • The Compliance body and the compliance function.
  • Certification of the management system.
  • Anchors: UNE-ISO 37301 (related to UNE 19601, see Module 12).
5

Module 5: Leadership and Compliance Culture

2 Hours

  • Compliance culture: definition and how it is measured.
  • Tone from the top and responsibilities of the administrative body and senior management.
  • Human behavior and biases applied to Compliance.
  • Levers to build and sustain a compliance culture.
  • Case study – NovaTerra: culture diagnostic.
6

Module 6: Corporate Social Responsibility and Good Governance

2 Hours

  • Concepts of corporate governance and corporate social responsibility (CSR).
  • The rationale behind corporate governance: ownership, management, and stakeholders; economic impact and value creation.
  • Origin and evolution of good governance: from soft law to legal entrenchment; "comply or explain" principle; Anglo-Saxon and European influence.
  • Current regulatory framework and its extension to unlisted companies.
  • Protection of business discretion: Business Judgment Rule.
  • Corporate governance instruments and the Annual Corporate Governance Report.
  • Sector specialisations: financial and insurance entities.
  • (Update) Link with sustainability and ESG criteria.
  • Anchors: Código de Buen Gobierno CNMV, Ley de Sociedades de Capital.
7

Module 7: Compliance Risk Management

2 Hours

  • Definition of Compliance risk.
  • Risk management process according to UNE-ISO 31000.
  • Communication and consultation; establishing the context.
  • Risk assessment: identification, analysis, and evaluation.
  • Inherent risk, residual risk, and risk appetite.
  • Treatment of risks.
  • Monitoring, review, and recording of the process.
  • Development of the risk map.
  • Case study – NovaTerra: risk map.
8

Module 8: Compliance Policies

2 Hours

  • Concept and function of Compliance policies.
  • Policy tree and internal regulatory hierarchy.
  • High-level policies: code of ethics and Compliance policy.
  • Specific policies by subject matter.
  • Drafting, approval, dissemination, and version control.
  • Case study – NovaTerra: full policy (gifts and hospitality).
9

Module 9: Communication, Training, and Awareness

2 Hours

  • Compliance communication plan (internal and external).
  • Design of training programmes.
  • Awareness and sensitisation.
  • Measuring training effectiveness; channels and frequency.
  • Case study – NovaTerra: training and communication plan.
10

Module 10: Supervision, Monitoring, and Reporting

2 Hours

  • The three lines of defense control model.
  • Compliance monitoring: concept and types.
  • Design of the monitoring plan.
  • Execution of monitoring and control testing.
  • Indicators (KRI/KPI).
  • Information and reporting to the administrative body.
  • Case study – NovaTerra: monitoring and reporting cadence (feeds the risk map).
11

Module 11: Reporting Channels, Investigations, Disciplinary Measures, and Incentives

2 Hours

  • The whistleblowing channel and the Internal Information System: Ley 2/2023 and EU Directive 2019/1937.
  • Requirements, guarantees, and protection of the informant; the Independent Authority for Informant Protection (A.A.I.).
  • Threshold of 50 workers and other obliged entities.
  • Management and processing of reports.
  • Internal investigations: rights of the person under investigation, evidence, confidentiality, and data protection.
  • Disciplinary measures and incentives.
  • Case study – NovaTerra: whistleblowing procedure and investigation protocol.
12

Module 12: Corporate Compliance: Prevention of Criminal Risk for Legal Entities

2 Hours

  • Background and evolution of the criminal liability of legal entities.
  • Regulatory scope in the Criminal Code: Art. 31 bis and related provisions.
  • Criteria for imputation and exemption from liability.
  • Catalog of offenses attributable to legal entities.
  • Penalties applicable to legal entities.
  • Design and implementation of an effective organisation and management model (crime prevention model).
  • The compliance body.
  • The UNE 19601 standard (management system for criminal Compliance).
  • Doctrine of the State Attorney General's Office (Circular 1/2016).
  • Case study – NovaTerra: Criminal Prevention Model outline.
13

Module 13: Prevention of Bribery and Corruption

2 Hours

  • Framework and context: understanding the organisation and its stakeholders.
  • Corruption risk assessment.
  • Commitment of senior management.
  • Anti-fraud and anti-corruption policy; procedures for employees.
  • Training and awareness; whistleblowing channels.
  • Records and documentation.
  • Due diligence on third parties and business partners.
  • Financial and non-financial controls.
  • Anti-corruption contractual clauses.
  • Gifts, hospitality, and facilitation payments; sponsorships and patronage.
  • Anti-corruption systems in group companies; supervision and control.
14

Module 14: Prevention of Money Laundering and Terrorist Financing (AML/CFT)

2 Hours

  • Origin, concept, and stages of money laundering.
  • Applicable regulations: Ley 10/2010 and its regulatory development.
  • Connection between the LPBC (AML Law) and the Criminal Code.
  • Obliged entities; formal and material requirements.
  • Due diligence (KYC) and risk-based approach.
  • Main control and prevention elements.
  • Reporting and communication obligations; SEPBLAC.
  • Retention of documentation.
  • Infractions and penalties (Ley 10/2010).
  • Institutional organisation.
15

Module 15: Defense of Competition

2 Hours

  • Introduction to competition law (national and EU).
  • Restrictive practices: collusive agreements and abuse of dominant position.
  • Merger control regime.
  • State Aid.
  • Consequences of infractions: the CNMC, sanctions, and leniency.
  • Why and how to establish a Competition Compliance Programme.
16

Module 16: Prevention of Market Abuse

2 Hours

  • Rationale of the regulation (MAR).
  • Concept and types of market abuse.
  • Inside information and its control.
  • Reporting of suspicious transactions.
  • Management of news and rumors.
  • Internal Code of Conduct.
  • Applicable regulatory framework.
17

Module 17: Personal Data Protection and Information Privacy

2 Hours

  • Applicable regulation: GDPR and LOPDGDD (LO 3/2018).
  • General concepts and roles: data controller, data processor, Data Protection Officer (DPO).
  • Data protection principles and bases of lawfulness.
  • Data communications and data processing assignments.
  • International data transfers.
  • The Spanish Data Protection Agency (AEPD).
  • Security breach management; data subject rights.
18

Module 18: Due Diligence Procedures and Prevention of Conflicts of Interest

2 Hours

  • Due diligence procedures: customers, suppliers, and third parties.
  • Diligence levels and risk-based approach.
  • Identification and management of conflicts of interest.
  • Declaration, registration, and mitigation measures.
19

Module 19: Consumer Protection

2 Hours

  • Compliance perspective in consumer and user regulations.
  • Consumer rights: information, withdrawal, and warranties.
  • Investor protection in the field of financial services.
  • Management of complaints and claims.
20

Module 20: Compliance and New Technologies

2 Hours

  • Corporate website and legal obligations (LSSI-CE).
  • E-commerce and electronic contracting.
  • Electronic signature.
  • Cybersecurity.
  • Use of ICT resources in the workplace: monitoring and digital rights.
  • Other relevant ICT regulations.
  • (Update) The EU AI Act and its impact on Compliance.
21

Final Exam

100 min

Requirements

No formal compliance qualification is required. Legal, risk, or audit experience may support faster understanding.

This course suits Compliance Officers and developing compliance professionals. Lawyers, auditors, managers, and governance teams may also benefit.

Learners should have:

  • A device with internet access
  • Desktop or laptop access recommended

This Course Includes

  • Approximately 40 hours of online self-paced learning
  • Practical professional guidance
  • Regulatory and professional alignment across Spain and the EU
  • Realistic workplace examples and applied scenarios
  • Knowledge checks and assessment preparation
  • Mock exam
  • Final exam
  • Certificate of completion

Why Choose Us

Learners choose Spanish Compliance Institute because the training is:

  • Clear, structured, and easy to follow
  • Suitable for busy professionals and compliance teams
  • Focused on real Spain and EU challenges
  • Built around practical workplace application
  • Written in clear, accessible professional English
  • Designed for compliance-focused learners and employers
  • Supported by certificate-based completion

Career Opportunities

This course can support professionals working in or moving towards roles such as:

  • Compliance Officer
  • Compliance Analyst
  • Risk and Compliance Manager
  • AML/CFT Specialist
  • Corporate Governance Advisor
  • Regulatory Affairs Consultant

This course supports career development within compliance functions. It does not guarantee employment, promotion, or regulated status. Career outcomes depend on experience, qualifications, and employer requirements.

Corporate Compliance Essentials: Governance, Ethics, Risk and Practice

A comprehensive bilingual English–Spanish guide covering corporate compliance foundations, ethics, management systems, risk, policies, whistleblowing, monitoring and governance. It includes 10 structured modules, workplace-based case examples and 100 assessment questions to support professional development and certification preparation
Download

Frequently Asked Questions

It covers all twenty CESCOM syllabus modules. Mock and final exams are also included.

No. Previous legal or compliance knowledge may support faster learning.

Most learners complete it within approximately forty hours. Study remains fully self-paced.

No. It supports exam preparation but cannot guarantee success. ASCOM manages the official examination.

You receive a Certificate of Completion. Spanish Compliance Institute issues the certificate.

Yes. It supports consistent compliance knowledge across professional teams.

Share This Course