CESCOM Exam Preparation Course for Compliance Professionals
Get this this CPD‑Accredited programme now. Be secure with a SSL-secured payment backed up by a 14‑day money‑back guarantee.
Overview
The CESCOM syllabus is broad, technical, and difficult to navigate. Without structure, revision becomes slow, fragmented, and overwhelming. This course gives learners a clear path forward.
Learners study all twenty CESCOM syllabus areas. Topics include ethics, governance, risk, AML, and data protection. Each module turns complex requirements into practical, manageable learning.
Structured lessons support focused revision and stronger knowledge retention. Self-paced access fits study around demanding professional schedules. Learners build clearer understanding across the complete CESCOM syllabus.
Learning Outcomes
Certification Information
Curriculum
1
Module 1: General Concepts of Compliance
- What Compliance is and the historical evolution of the function.
- Compliance as a function and as a culture; difference between legal counsel and internal control.
- Compliance models and "superstructures"; international reference models.
- Main standards and frameworks: UNE-ISO 37301, UNE-ISO 37001, COSO, and the three lines of defense model.
- Role, mandate, position, and independence of the Compliance Officer.
- Anchors: UNE-ISO 37301, COSO, IIA Three Lines.
- Case study – NovaTerra: Code of Ethics groundwork.
2
Module 2: Corporate Ethics
- Introduction and origins of corporate ethics; history and regulation.
- Difference between law and ethics.
- Ethics applied to the company: ethical dilemmas and codes of conduct.
- Ethics as a factor for value creation and reputation.
- The Compliance Officer as the guarantor of corporate values.
- Case study – NovaTerra: Code of Ethics.
3
Module 3: Essential Elements of a Compliance Programme
- Concept and purpose of a Compliance programme.
- Generally accepted compliance principles.
- Essential components: governance, risks, policies, controls, training, reporting channel, and oversight.
- Documentation of the model.
- Review cycle and continuous improvement.
- Effectiveness of the programme and its accreditation (proof of effectiveness).
- Case study – NovaTerra: compliance-programme blueprint.
4
Module 4: Compliance Management Systems: UNE-ISO 37301
- From UNE-ISO 19600 (guidelines) to UNE-ISO 37301 (certifiable requirements).
- Object and scope of application.
- High-Level Structure (Annex SL): context, leadership, planning, support, operation, performance evaluation, and improvement.
- Key definitions and Compliance obligations.
- The Compliance body and the compliance function.
- Certification of the management system.
- Anchors: UNE-ISO 37301 (related to UNE 19601, see Module 12).
5
Module 5: Leadership and Compliance Culture
- Compliance culture: definition and how it is measured.
- Tone from the top and responsibilities of the administrative body and senior management.
- Human behavior and biases applied to Compliance.
- Levers to build and sustain a compliance culture.
- Case study – NovaTerra: culture diagnostic.
6
Module 6: Corporate Social Responsibility and Good Governance
- Concepts of corporate governance and corporate social responsibility (CSR).
- The rationale behind corporate governance: ownership, management, and stakeholders; economic impact and value creation.
- Origin and evolution of good governance: from soft law to legal entrenchment; "comply or explain" principle; Anglo-Saxon and European influence.
- Current regulatory framework and its extension to unlisted companies.
- Protection of business discretion: Business Judgment Rule.
- Corporate governance instruments and the Annual Corporate Governance Report.
- Sector specialisations: financial and insurance entities.
- (Update) Link with sustainability and ESG criteria.
- Anchors: Código de Buen Gobierno CNMV, Ley de Sociedades de Capital.
7
Module 7: Compliance Risk Management
- Definition of Compliance risk.
- Risk management process according to UNE-ISO 31000.
- Communication and consultation; establishing the context.
- Risk assessment: identification, analysis, and evaluation.
- Inherent risk, residual risk, and risk appetite.
- Treatment of risks.
- Monitoring, review, and recording of the process.
- Development of the risk map.
- Case study – NovaTerra: risk map.
8
Module 8: Compliance Policies
- Concept and function of Compliance policies.
- Policy tree and internal regulatory hierarchy.
- High-level policies: code of ethics and Compliance policy.
- Specific policies by subject matter.
- Drafting, approval, dissemination, and version control.
- Case study – NovaTerra: full policy (gifts and hospitality).
9
Module 9: Communication, Training, and Awareness
- Compliance communication plan (internal and external).
- Design of training programmes.
- Awareness and sensitisation.
- Measuring training effectiveness; channels and frequency.
- Case study – NovaTerra: training and communication plan.
10
Module 10: Supervision, Monitoring, and Reporting
- The three lines of defense control model.
- Compliance monitoring: concept and types.
- Design of the monitoring plan.
- Execution of monitoring and control testing.
- Indicators (KRI/KPI).
- Information and reporting to the administrative body.
- Case study – NovaTerra: monitoring and reporting cadence (feeds the risk map).
11
Module 11: Reporting Channels, Investigations, Disciplinary Measures, and Incentives
- The whistleblowing channel and the Internal Information System: Ley 2/2023 and EU Directive 2019/1937.
- Requirements, guarantees, and protection of the informant; the Independent Authority for Informant Protection (A.A.I.).
- Threshold of 50 workers and other obliged entities.
- Management and processing of reports.
- Internal investigations: rights of the person under investigation, evidence, confidentiality, and data protection.
- Disciplinary measures and incentives.
- Case study – NovaTerra: whistleblowing procedure and investigation protocol.
12
Module 12: Corporate Compliance: Prevention of Criminal Risk for Legal Entities
- Background and evolution of the criminal liability of legal entities.
- Regulatory scope in the Criminal Code: Art. 31 bis and related provisions.
- Criteria for imputation and exemption from liability.
- Catalog of offenses attributable to legal entities.
- Penalties applicable to legal entities.
- Design and implementation of an effective organisation and management model (crime prevention model).
- The compliance body.
- The UNE 19601 standard (management system for criminal Compliance).
- Doctrine of the State Attorney General's Office (Circular 1/2016).
- Case study – NovaTerra: Criminal Prevention Model outline.
13
Module 13: Prevention of Bribery and Corruption
- Framework and context: understanding the organisation and its stakeholders.
- Corruption risk assessment.
- Commitment of senior management.
- Anti-fraud and anti-corruption policy; procedures for employees.
- Training and awareness; whistleblowing channels.
- Records and documentation.
- Due diligence on third parties and business partners.
- Financial and non-financial controls.
- Anti-corruption contractual clauses.
- Gifts, hospitality, and facilitation payments; sponsorships and patronage.
- Anti-corruption systems in group companies; supervision and control.
14
Module 14: Prevention of Money Laundering and Terrorist Financing (AML/CFT)
- Origin, concept, and stages of money laundering.
- Applicable regulations: Ley 10/2010 and its regulatory development.
- Connection between the LPBC (AML Law) and the Criminal Code.
- Obliged entities; formal and material requirements.
- Due diligence (KYC) and risk-based approach.
- Main control and prevention elements.
- Reporting and communication obligations; SEPBLAC.
- Retention of documentation.
- Infractions and penalties (Ley 10/2010).
- Institutional organisation.
15
Module 15: Defense of Competition
- Introduction to competition law (national and EU).
- Restrictive practices: collusive agreements and abuse of dominant position.
- Merger control regime.
- State Aid.
- Consequences of infractions: the CNMC, sanctions, and leniency.
- Why and how to establish a Competition Compliance Programme.
16
Module 16: Prevention of Market Abuse
- Rationale of the regulation (MAR).
- Concept and types of market abuse.
- Inside information and its control.
- Reporting of suspicious transactions.
- Management of news and rumors.
- Internal Code of Conduct.
- Applicable regulatory framework.
17
Module 17: Personal Data Protection and Information Privacy
- Applicable regulation: GDPR and LOPDGDD (LO 3/2018).
- General concepts and roles: data controller, data processor, Data Protection Officer (DPO).
- Data protection principles and bases of lawfulness.
- Data communications and data processing assignments.
- International data transfers.
- The Spanish Data Protection Agency (AEPD).
- Security breach management; data subject rights.
18
Module 18: Due Diligence Procedures and Prevention of Conflicts of Interest
- Due diligence procedures: customers, suppliers, and third parties.
- Diligence levels and risk-based approach.
- Identification and management of conflicts of interest.
- Declaration, registration, and mitigation measures.
19
Module 19: Consumer Protection
- Compliance perspective in consumer and user regulations.
- Consumer rights: information, withdrawal, and warranties.
- Investor protection in the field of financial services.
- Management of complaints and claims.
20
Module 20: Compliance and New Technologies
- Corporate website and legal obligations (LSSI-CE).
- E-commerce and electronic contracting.
- Electronic signature.
- Cybersecurity.
- Use of ICT resources in the workplace: monitoring and digital rights.
- Other relevant ICT regulations.
- (Update) The EU AI Act and its impact on Compliance.
21
Final Exam
Requirements
This Course Includes
Why Choose Us
Career Opportunities
Corporate Compliance Essentials: Governance, Ethics, Risk and Practice
A comprehensive bilingual English–Spanish guide covering corporate compliance foundations, ethics, management systems, risk, policies, whistleblowing, monitoring and governance. It includes 10 structured modules, workplace-based case examples and 100 assessment questions to support professional development and certification preparation