1Control de versiones
| Compañía | doValue Spain Servicing, S.A.U. |
|---|---|
| Título | Política de Cumplimiento Penal |
| Versión | V.6.2 |
| Documento | Política 1 |
| Elaborado por | Compliance Officer |
| Fecha Aprobación | 24/09/2026 |
| Responsable de la aprobación | Compliance Officer |
| Fecha ratificación | 11/2026 |
| Responsable ratificación | Consejo de Administración de DVSP |
| Política o normas modificadas / derogadas | Política de Cumplimiento Penal v.6.1 |
| Modificaciones de la versión | Inclusión expresa de TEAM 4 COLLECTION AND CONSULTING, S.L.U. en el alcance de la política. |
| Fecha última actualización | 24/09/2026 |
Histórico de versiones
| Versión | Causa del Cambio | Responsable | Fecha aprobación | Fecha ratificación |
|---|---|---|---|---|
| 1.0 | Versión Inicial | 18/09/2018 | 20/09/2018 | NA |
| Comité Cumplimiento | Consejo Altamira Asset Management | NA | ||
| 2.0 | Versión 2 | 15/01/2019 | 16/01/2019 | NA |
| Comité Cumplimiento | Consejo Altamira Asset Management | NA | ||
| 3.0 | Versión 3 (Introducción de cambios en el ámbito de aplicación) | Cumplimiento Normativo | 07/10/2020 | NA |
| Comité Control | NA | |||
| 4.0 | Versión 4 (Cambio de denominación social y actualización de nuevas políticas y procedimientos) | Cumplimiento Normativo | 07/10/2020 | NA |
| Comité Control | NA | |||
| 5.0 | Versión 5 (Cambio en la referencia al Modelo de Cumplimiento por Marco de Cumplimiento e incorporación de un párrafo en el punto 5) | Cumplimiento Normativo | 10/03/2025 | NA |
| Comité Control | NA | |||
| 6.0 | Actualización integral de la Política para su alineación con UNE 19601, adecuación al Sistema Integrado de Gestión, revisión del ámbito de aplicación, actualización de la gobernanza del sistema de compliance penal y adaptación a la Política del Sistema Interno de Información | Compliance Officer | 31/07/2026 | NA |
| Compliance Officer | NA | |||
| 6.1 | Actualización apartado control de versiones con corrección de typos | Compliance Officer | 04/08/2026 | 09/2026 |
| Compliance Officer | Consejo Administración DVSP | |||
| 6.2 | Inclusión expresa de TEAM 4 COLLECTION AND CONSULTING, S.L.U. en el alcance de la política | Compliance Officer | 24/09/2026 | 11/2026 |
| Compliance Officer | Consejo Administración DVSP |
2Introducción
Mediante la presente Política de Cumplimiento Penal de DOVALUE SPAIN SERVICING, S.A.U. (en adelante, "doValue" o "DVSP" o "DOVALUE") y sus filiales incluidas en el alcance del SIG y, en concreto, su filial en España, TEAM 4 COLLECTION AND CONSULTING, S.L.U. (en adelante, "Team4" o "T4"), manifiestan su compromiso con el desarrollo de una cultura de cumplimiento, integridad y ética empresarial que inspire la actuación de todos los integrantes de la Organización y de aquellas personas que actúen en su nombre o representación.
A los efectos de la presente Política, se entenderá por "la Organización" o "la Compañía" el conjunto formado por doValue y por las demás sociedades que se encuentren incluidas en el alcance del Sistema. A la fecha de aprobación de la presente Política, dicho perímetro está integrado por doValue Spain Servicing, S.A.U. y Team 4 Collection and Consulting, S.L.U. Cualquier referencia en la presente Política a "las filiales" o "sus filiales" se entenderá realizada exclusivamente a las sociedades filiales de doValue incluidas en el alcance del Sistema.
El cumplimiento normativo y la prevención de delitos constituyen elementos esenciales del modelo de gobierno y control de la Organización. En este sentido, la Organización ha implantado su propio Sistema Integrado de Gestión (en adelante, SIG o Sistema), que incorpora los principios, controles y mecanismos necesarios para prevenir, detectar y gestionar los riesgos penales derivados de sus actividades, alineándose con la normativa vigente en materia de responsabilidad penal de las personas jurídicas, así como con los requisitos de la Norma UNE 19601: Sistemas de Gestión de Compliance Penal.
La Dirección y el Consejo de Administración de la Organización asumen un compromiso expreso con la promoción de una cultura de cumplimiento basada en el respeto a la legalidad, la tolerancia cero frente a la comisión de ilícitos y la mejora continua de los sistemas de control interno.
La Organización ha logrado una posición de liderazgo y referencia en el mercado. Para ello ha sido y es fundamental el comportamiento ético y responsable de los miembros del órgano de administración, directivos, empleados, colaboradores y demás personas sujetas a la presente Política (en adelante, el "Personal"), persiguiendo la implantación de un SIG robusto y promoviendo una cultura de cumplimiento en toda la organización. Por ello, esta Política de Cumplimiento Penal constituye el marco de referencia del Sistema, que es conocido y de obligado cumplimiento por todo el Personal e impulsado por la Dirección.
3Ámbito de aplicación
La presente Política es de aplicación a los miembros del órgano de administración, directivos, empleados, trabajadores cedidos, becarios, personal en formación y, en general, a todas las personas que desarrollen su actividad profesional para doValue y sus filiales, con independencia de la naturaleza, duración o modalidad de su relación con la Organización.
Asimismo, esta Política resulta de aplicación a aquellas personas físicas o jurídicas que actúen en nombre o en representación de doValue y/o sus filiales, así como a quienes ejerzan funciones de administración, dirección, gestión, supervisión o control dentro de la Organización o de las entidades que formen parte de su grupo.
La Organización promoverá igualmente el conocimiento y observancia de los principios contenidos en esta Política por parte de sus socios de negocio, proveedores, contratistas, colaboradores externos, asesores y demás terceros con los que mantenga relaciones profesionales o comerciales, cuando así resulte aplicable de conformidad con la normativa vigente, las obligaciones contractuales asumidas o los sistemas internos de control y cumplimiento de la Organización.
4Finalidad y objetivos
La presente Política de Cumplimiento Penal tiene como finalidad promover y consolidar una cultura de cumplimiento, integridad y comportamiento ético en el seno de doValue y sus filiales, reforzando el compromiso de la Organización con la prevención, detección y gestión de los riesgos penales derivados del desarrollo de su actividad.
Asimismo, esta Política manifiesta el compromiso de tolerancia cero frente a la comisión de cualquier conducta ilícita o contraria a la normativa aplicable, al Código Ético o a los principios que inspiran el Sistema Integrado de Gestión, sin que en ningún caso la obtención de un beneficio económico, operativo o estratégico pueda justificar un incumplimiento normativo.
Para la consecución de dicha finalidad, la presente Política persigue los siguientes objetivos:
- Establecer los principios generales que rigen el Sistema Integrado de Gestión de Compliance Penal de la Organización.
- Fomentar una actuación profesional diligente, íntegra y respetuosa con la legalidad por parte de todas las personas sujetas a esta Política.
- Promover la prevención, detección temprana y gestión adecuada de los riesgos penales.
- Facilitar el conocimiento de las obligaciones, responsabilidades, controles y procedimientos que conforman el Sistema Integrado de Gestión de Compliance Penal.
- Reforzar la cultura de comunicación y consulta ante dudas o posibles incumplimientos, favoreciendo el uso de los canales habilitados por la Organización.
- Contribuir a la mejora continua del Sistema Integrado de Gestión de Compliance Penal y a la protección de la reputación, sostenibilidad y buen gobierno de la Organización.
5Principios generales de actuación
El Sistema Integrado de Gestión de doValue y sus filiales se inspira en los siguientes principios generales, que constituyen la base fundamental, tanto de la normativa interna de doValue y sus filiales, como de la actuación del Personal:
Tolerancia cero ante la comisión de delitos
doValue y sus filiales prohíben a todas las personas recogidas en el apartado 3 de esta Política la comisión de hechos delictivos y les obliga a informar sobre estos o cualquier otra conducta sospechosa susceptible de constituir una infracción penal a través de los canales establecidos para estos fines.
Prevención y gestión de riesgos penales
A estos efectos, y atendiendo a la naturaleza de la actividad de doValue y sus filiales —centrada en la gestión y asesoramiento de carteras de activos financieros (incluyendo NPLs y REOs), la recuperación y gestión de crédito, y la gestión y comercialización de activos inmobiliarios—, se identifican como ámbitos de especial atención los siguientes: la gestión y negociación con deudores y terceros en procesos de recobro; la contratación y relación con proveedores, intermediarios y socios de negocio; la valoración, adquisición y transmisión de activos financieros e inmobiliarios; o la gestión de información confidencial y datos de carácter personal. Dichas actividades son objeto de análisis y evaluación periódica de riesgos penales en el marco del Sistema Integrado de Gestión, cuyos resultados se recogen en el correspondiente mapa de riesgos penales. Todo ello acorde con los estándares, principios, valores y fines establecidos en materia de compliance penal y con el objetivo de minimizar la exposición de doValue y sus filiales a los riesgos penales.
Compromiso de legalidad
La Organización, y especialmente su Consejo de Administración y la Dirección, se comprometen a cumplir con la normativa penal vigente que resulte de aplicación, así como con los requisitos establecidos en el Sistema Integrado de Gestión de Compliance Penal y Calidad. A tal efecto, actuarán y exigirán que se actúe en todo momento conforme a lo dispuesto en dicha normativa y en el Sistema, y que en todo caso se cumpla con los requisitos de esta Política.
Deber de comunicación
La Organización promueve el deber de comunicar, a través del Sistema Interno de Información (SII), cualquier conducta irregular o potencial incumplimiento de la normativa aplicable o de la normativa interna de la Organización del que se tenga conocimiento o sospecha razonable. La Organización garantiza la confidencialidad de las comunicaciones, la protección de la identidad del informante y la prohibición de represalias o conductas perjudiciales en los términos previstos en la normativa aplicable y en la Política del Sistema Interno de Información.
Régimen disciplinario
doValue y sus filiales difunden entre todo el Personal el régimen disciplinario aplicable en caso de incumplimiento del Sistema Integrado de Gestión o de la normativa interna de aplicación, o en el supuesto de comisión de hechos o conductas que pudieran ser calificadas de delictivas, en virtud de lo establecido en los convenios colectivos de aplicación.
Marco para la consecución de objetivos
doValue y sus filiales establecen, supervisan y revisan periódicamente los objetivos del Sistema Integrado de Gestión de Compliance Penal, asegurando su alineación con los riesgos penales identificados y con la estrategia de la organización. A tal efecto, se dotan de los recursos financieros, humanos y tecnológicos necesarios para su adecuada consecución y seguimiento.
Difusión y acceso
El Sistema es difundido correctamente y de forma continua entre todo el Personal. Asimismo, los principios y normas que lo componen estarán a disposición de todos los miembros de la organización. Esta Política se pone a disposición de todos los interesados a través de los canales internos de comunicación y de la web corporativa.
Órgano de Compliance Penal
La función de cumplimiento penal, ejercida por el Compliance Officer, se encarga de supervisar, gestionar y mantener actualizado el Sistema Integrado de Gestión, velando por su eficacia. Esta función se desempeña con autonomía e independencia, y con plenas competencias y autoridad para el ejercicio de su rol. El Compliance Officer reporta directamente al Consejo de Administración, informándole periódicamente sobre el estado del Sistema, y dispone de acceso directo al mismo, con independencia de la línea jerárquica, cuando las circunstancias lo requieran. Esta estructura de reporte garantiza su independencia funcional respecto de las áreas de negocio y de cualquier órgano o persona sujeta a su supervisión.
Mejora continua
El Sistema Integrado de Gestión es objeto de revisión periódica y mejora continua, informando al Órgano de Dirección y al Órgano de Gobierno (Consejo de Administración), de forma recurrente, de sus actividades de supervisión y seguimiento, de los cambios estructurales y normativos que hayan podido producirse, así como de las mediciones del desempeño del compliance penal y de los resultados de su evaluación.
6Normas que configuran el marco de compliance penal
doValue y sus filiales disponen de una serie de normas fundamentales, aplicables a todo el Personal, sobre las que se estructura y desarrolla el Sistema Integrado de Gestión:
- Código Ético: constituye el marco de referencia y orientación de carácter general en el desarrollo de las actividades de doValue y sus filiales. El mismo contiene, con base a los principios de negocio de doValue y sus filiales, los principios éticos que han de presidir el comportamiento de todos los empleados. El conocimiento de este documento es obligatorio para todos los miembros y colaboradores externos de doValue y sus filiales.
- Manual del Sistema Integrado de Gestión: establece las pautas de actuación de doValue y sus filiales para cumplir con el ejercicio del control debido y del deber de vigilancia sobre su actividad empresarial, cumpliendo de este modo con las exigencias legales del Código Penal español y con los deberes de control de riesgos impuestos por la Ley de Sociedades de Capital (RD 1/2010).
- Política del Sistema Interno de Información: doValue y sus filiales ponen a disposición un Canal de Comunicación o Canal Ético, en donde los empleados o terceros que tengan relación con doValue y sus filiales pueden informar sobre infracciones o sospechas relativas al incumplimiento legal dentro de la actividad empresarial de doValue y sus filiales. De este modo, se potencia la transparencia y el control del correcto cumplimiento de las leyes y el Código Ético.
- Procedimiento Corporativo de Gestión del Sistema Interno de Información: establece las directrices de actuación para aquellos casos en que llegue a constatarse que, en el seno de doValue y sus filiales, se están cometiendo conductas potencialmente constitutivas de infracciones del derecho de la Unión Europea, o infracciones penales o administrativas graves o muy graves.
- Política Global de Conflictos de Interés y Operaciones Vinculadas: establece el compromiso de doValue y sus filiales de implantar las medidas y políticas globales que permitan identificar los potenciales conflictos de intereses que pudieren surgir en el ámbito de la prestación de servicios.
- Política de Regalos: establece la prohibición expresa de realizar o recibir cualquier tipo de regalo o comisión económica con la intención de obtener cualquier tipo de provecho que beneficie a la organización.
- Política Anticorrupción: recoge el compromiso de doValue y sus filiales con la tolerancia cero frente a cualquier forma de corrupción, tanto en el sector público como en el privado, incluyendo el cohecho, el soborno, el tráfico de influencias y cualquier otra práctica corrupta.
- Formación en materia de compliance y prevención de riesgos penales: se establece anualmente un plan de formación, comunicación, sensibilización y difusión donde se detallan los aspectos prácticos sobre la prevención de delitos para que todos los miembros de doValue y sus filiales sean conocedores de sus derechos y obligaciones en relación al compliance penal.
- Régimen disciplinario: el cual será de aplicación en caso de incumplimiento del Sistema Integrado de Gestión o de la normativa interna de aplicación, así como en los supuestos de comisión de hechos o conductas irregulares, conforme al régimen de faltas y sanciones previstas en los Convenios Colectivos aplicables a doValue y sus filiales, en el Estatuto de los Trabajadores y en cualesquiera otras normas laborales o internas que sean de aplicación. En los supuestos en que los hechos pudieran ser constitutivos de infracción penal, doValue y sus filiales podrán proceder a su comunicación a las autoridades competentes, sin perjuicio de los supuestos en que dicha comunicación resulte legalmente obligatoria. Las consecuencias del régimen disciplinario serán de aplicación a todo el Personal sujeto a esta Política, con independencia de su cargo o nivel jerárquico, incluyendo consejeros y directivos, conforme a la normativa laboral, mercantil o contractual que en cada caso resulte de aplicación. Todo ello sin perjuicio de lo establecido en el apartado 8 de la presente Política.
7Compromiso del Consejo de Administración y del Órgano de Dirección
Los Consejos de Administración y los Órganos de Dirección de doValue y sus filiales reafirman mediante la presente Política su compromiso con la ética, la integridad, el cumplimiento normativo y la prevención de delitos, promoviendo una cultura de cumplimiento que forme parte de los valores y de la actividad diaria de la Organización.
El Consejo de Administración, como órgano de gobierno de la Organización, asume un liderazgo visible, activo y efectivo en relación con el Sistema Integrado de Gestión de Compliance Penal, impulsando su implantación, supervisando su funcionamiento y promoviendo su mejora continua. Asimismo, aprueba la presente Política y vela por que el Sistema disponga de los recursos humanos, tecnológicos y financieros necesarios para alcanzar sus objetivos.
Por su parte, el Órgano de Dirección es responsable de promover la aplicación efectiva de los principios y requisitos establecidos en el Sistema Integrado de Gestión, fomentando comportamientos coherentes con la cultura de cumplimiento e integrando los objetivos de compliance penal en la gestión ordinaria de la Organización.
El Consejo de Administración y el Órgano de Dirección apoyan expresamente el ejercicio independiente de la función de Compliance Penal, encomendada al Compliance Officer, garantizando su autonomía, autoridad, acceso a la información necesaria para el desempeño de sus funciones y acceso directo a los órganos de gobierno cuando las circunstancias así lo requieran.
Asimismo, ambos órganos promueven la comunicación, difusión y conocimiento de esta Política, así como del resto de elementos que integran el Sistema Integrado de Gestión de Compliance Penal, impulsando la formación, sensibilización y concienciación de todas las personas sujetas a la misma.
8Comunicación de irregularidades
Todas las personas sujetas a la presente Política tienen la obligación de comunicar cualquier incumplimiento o sospecha razonable de incumplimiento de la normativa aplicable, del Código Ético, de la presente Política o del resto de normas que integran el Sistema Integrado de Gestión, de los que tengan conocimiento en el ejercicio de sus actividades profesionales.
A estos efectos, la Organización dispone de un Sistema Interno de Información (SII) gestionado de conformidad con la Política del Sistema Interno de Información y el Procedimiento Corporativo de Gestión del Sistema Interno de Información, garantizando la confidencialidad de la información comunicada, la protección de la identidad del informante y la prohibición de represalias en los términos previstos en la normativa aplicable.
El Sistema Interno de Información es supervisado por el Comité del Sistema Interno de Información (CSII), designado por el Consejo de Administración como Responsable del Sistema.
Las comunicaciones podrán realizarse a través de los canales habilitados por la Organización, accesibles a través de los siguientes enlaces:
- doValue: https://dovalue.whistlelink.com/
- TEAM4: https://team4.canalhelas.com/home
Todo lo relativo al funcionamiento del Sistema Interno de Información, las modalidades de comunicación, las garantías aplicables a los informantes, personas afectadas y terceros relacionados, así como la tramitación de las comunicaciones recibidas, se regula en la Política del Sistema Interno de Información y en el Procedimiento de Gestión del Sistema Interno de Información.
9Incumplimientos de la Política de Cumplimiento Penal
El cumplimiento de la presente Política es responsabilidad de todas las personas sujetas a su ámbito de aplicación. Asimismo, el Consejo de Administración, el Órgano de Dirección y las personas que ejercen funciones de dirección o supervisión en la Organización deberán promover activamente su conocimiento, aplicación y cumplimiento en sus respectivos ámbitos de responsabilidad.
Sin perjuicio de lo anterior, corresponde al Compliance Officer, en el ejercicio de la función de Compliance Penal, supervisar la adecuada implantación, mantenimiento y eficacia del Sistema Integrado de Gestión de Compliance Penal, así como informar de su funcionamiento a los órganos de gobierno y dirección de la Organización.
El incumplimiento de lo dispuesto en la presente Política podrá dar lugar a la adopción de las medidas disciplinarias, contractuales o legales que resulten procedentes en cada caso, de conformidad con la normativa vigente, los convenios colectivos aplicables, la normativa interna de la Organización y las obligaciones contractuales asumidas.
La aplicación de dichas medidas se realizará atendiendo a la naturaleza y gravedad de los hechos, garantizando en todo caso los derechos de las personas afectadas y el respeto a los procedimientos legalmente establecidos.
10Publicación y entrada en vigor
La presente Política forma parte del Sistema de Gestión del Compliance Penal de doValue y constituye información documentada del mismo. La Política será objeto de revisión periódica y mejora continua, con el fin de garantizar su adecuación a la normativa aplicable, a la evolución de los riesgos penales de la Organización, a los cambios organizativos que puedan producirse y a las necesidades derivadas del funcionamiento del Sistema Integrado de Gestión.
Asimismo, la presente Política se pondrá a disposición de las partes interesadas a través de la página web corporativa de doValue, de las páginas web de sus filiales y de aquellos otros medios que la Organización considere adecuados para garantizar su difusión y accesibilidad.
La presente Política entrará en vigor en doValue y sus filiales en la fecha de su aprobación por el correspondiente órgano competente, permaneciendo vigente hasta que sea sustituida, modificada o derogada por una nueva versión.
1Version control
| Company | doValue Spain Servicing, S.A.U. |
|---|---|
| Title | Criminal Compliance Policy |
| Version | V.6.2 |
| Document | Policy 1 |
| Prepared by | Compliance Officer |
| Approval Date | 24/09/2026 |
| Person responsible for approval | Compliance Officer |
| Ratification date | 11/2026 |
| Person responsible for ratification | Board of Directors of DVSP |
| Policy or rules amended / repealed | Criminal Compliance Policy v.6.1 |
| Amendments to the version | Express inclusion of TEAM 4 COLLECTION AND CONSULTING, S.L.U. within the scope of the policy. |
| Date of last update | 24/09/2026 |
Version history
| Version | Reason for the Change | Owner | Approval date | Ratification date |
|---|---|---|---|---|
| 1.0 | Initial Version | 18/09/2018 | 20/09/2018 | NA |
| Compliance Committee | Altamira Asset Management Board | NA | ||
| 2.0 | Version 2 | 15/01/2019 | 16/01/2019 | NA |
| Compliance Committee | Altamira Asset Management Board | NA | ||
| 3.0 | Version 3 (Introduction of changes to the scope of application) | Regulatory Compliance | 07/10/2020 | NA |
| Control Committee | NA | |||
| 4.0 | Version 4 (Change of corporate name and update of new policies and procedures) | Regulatory Compliance | 07/10/2020 | NA |
| Control Committee | NA | |||
| 5.0 | Version 5 (Change of the reference to the Compliance Model to Compliance Framework and addition of a paragraph in point 5) | Regulatory Compliance | 10/03/2025 | NA |
| Control Committee | NA | |||
| 6.0 | Comprehensive update of the Policy to align it with UNE 19601, adapt it to the Integrated Management System, review the scope of application, update the governance of the criminal compliance system and align it with the Internal Information System Policy | Compliance Officer | 31/07/2026 | NA |
| Compliance Officer | NA | |||
| 6.1 | Update of the version control section with correction of typos | Compliance Officer | 04/08/2026 | 09/2026 |
| Compliance Officer | DVSP Board of Directors | |||
| 6.2 | Express inclusion of TEAM 4 COLLECTION AND CONSULTING, S.L.U. within the scope of the policy | Compliance Officer | 24/09/2026 | 11/2026 |
| Compliance Officer | DVSP Board of Directors |
2Introduction
By means of this Criminal Compliance Policy of DOVALUE SPAIN SERVICING, S.A.U. (hereinafter, "doValue" or "DVSP" or "DOVALUE") and its subsidiaries included in the scope of the IMS and, specifically, its subsidiary in Spain, TEAM 4 COLLECTION AND CONSULTING, S.L.U. (hereinafter, "Team4" or "T4") express their commitment to the development of a culture of compliance, integrity and business ethics that inspires the conduct of all members of the Organisation and of those persons acting in its name or on its behalf.
For the purposes of this Policy, "the Organisation" or "the Company" shall mean doValue together with the other companies included in the scope of the System. As at the date of approval of this Policy, that perimeter comprises doValue Spain Servicing, S.A.U. and Team 4 Collection and Consulting, S.L.U. Any reference in this Policy to "the subsidiaries" or "its subsidiaries" shall be understood to refer exclusively to the subsidiaries of doValue included in the scope of the System.
Regulatory compliance and the prevention of offences are essential elements of the governance and control model of the Organisation. In this regard, the Organisation has implemented its own Integrated Management System (hereinafter, the IMS or the System), which incorporates the principles, controls and mechanisms necessary to prevent, detect and manage the criminal risks arising from its activities, in line with the legislation in force on the criminal liability of legal persons, as well as with the requirements of standard UNE 19601: Criminal Compliance Management Systems.
The Management and the Board of Directors of the Organisation assume an express commitment to promoting a culture of compliance based on respect for the law, zero tolerance of the commission of unlawful acts and the continual improvement of the internal control systems.
The Organisation has achieved a position of leadership and benchmark status in the market. To that end, the ethical and responsible conduct of the members of the administrative body, managers, employees, collaborators and other persons subject to this Policy (hereinafter, the "Personnel") has been and remains fundamental, pursuing the implementation of a robust IMS and promoting a culture of compliance throughout the organisation. For this reason, this Criminal Compliance Policy constitutes the frame of reference for the System, which is known to and mandatory for all Personnel and is driven by Management.
3Scope of application
This Policy applies to the members of the administrative body, managers, employees, assigned workers, interns, trainees and, in general, to all persons who carry out their professional activity for doValue and its subsidiaries, irrespective of the nature, duration or form of their relationship with the Organisation.
Likewise, this Policy applies to those natural or legal persons who act in the name of or on behalf of doValue and/or its subsidiaries, as well as to those who perform administration, management, supervision or control functions within the Organisation or within the entities forming part of its group.
The Organisation shall likewise promote awareness and observance of the principles contained in this Policy among its business partners, suppliers, contractors, external collaborators, advisers and other third parties with which it maintains professional or commercial relationships, where this is applicable in accordance with the legislation in force, the contractual obligations assumed or the internal control and compliance systems of the Organisation.
4Purpose and objectives
The purpose of this Criminal Compliance Policy is to promote and consolidate a culture of compliance, integrity and ethical conduct within doValue and its subsidiaries, reinforcing the commitment of the Organisation to the prevention, detection and management of the criminal risks arising from the performance of its activity.
Likewise, this Policy expresses the commitment to zero tolerance of the commission of any unlawful conduct or conduct contrary to the applicable legislation, to the Code of Ethics or to the principles underpinning the Integrated Management System, and in no case may the obtaining of an economic, operational or strategic benefit justify a regulatory breach.
In order to achieve that purpose, this Policy pursues the following objectives:
- To establish the general principles governing the Criminal Compliance Integrated Management System of the Organisation.
- To foster diligent, honest and law-abiding professional conduct on the part of all persons subject to this Policy.
- To promote the prevention, early detection and proper management of criminal risks.
- To facilitate awareness of the obligations, responsibilities, controls and procedures that make up the Criminal Compliance Integrated Management System.
- To reinforce the culture of communication and consultation in the event of doubts or possible breaches, encouraging the use of the channels made available by the Organisation.
- To contribute to the continual improvement of the Criminal Compliance Integrated Management System and to the protection of the reputation, sustainability and good governance of the Organisation.
5General principles of conduct
The Integrated Management System of doValue and its subsidiaries is based on the following general principles, which constitute the fundamental basis both of the internal regulations of doValue and its subsidiaries and of the conduct of the Personnel:
Zero tolerance of the commission of offences
doValue and its subsidiaries prohibit all persons covered by section 3 of this Policy from committing criminal acts and require them to report such acts, or any other suspicious conduct liable to constitute a criminal offence, through the channels established for those purposes.
Prevention and management of criminal risks
To this end, and having regard to the nature of the activity of doValue and its subsidiaries —focused on the management of and advisory services for portfolios of financial assets (including NPLs and REOs), credit recovery and management, and the management and marketing of real estate assets— the following are identified as areas requiring particular attention: the management of, and negotiation with, debtors and third parties in debt collection processes; the contracting of, and relationship with, suppliers, intermediaries and business partners; the valuation, acquisition and transfer of financial and real estate assets; and the management of confidential information and personal data. Those activities are subject to periodic criminal risk analysis and assessment within the framework of the Integrated Management System, the results of which are recorded in the corresponding criminal risk map. All of the foregoing is in line with the standards, principles, values and purposes established in the field of criminal compliance and with the objective of minimising the exposure of doValue and its subsidiaries to criminal risks.
Commitment to legality
The Organisation, and in particular its Board of Directors and Management, undertake to comply with the criminal legislation in force that is applicable, as well as with the requirements established in the Integrated Criminal Compliance and Quality Management System. To that end, they shall act, and shall require that action be taken, at all times in accordance with the provisions of that legislation and of the System, and that the requirements of this Policy be complied with in all cases.
Duty to report
The Organisation promotes the duty to report, through the Internal Information System (IIS), any irregular conduct or potential breach of the applicable legislation or of the internal regulations of the Organisation of which the person is aware or reasonably suspects. The Organisation guarantees the confidentiality of reports, the protection of the identity of the reporting person and the prohibition of retaliation in the terms provided for in the applicable legislation and in the Internal Information System Policy.
Disciplinary regime
doValue and its subsidiaries disseminate among all Personnel the disciplinary regime applicable in the event of breach of the Integrated Management System or of the applicable internal regulations, or in the event of the commission of acts or conduct that may be classified as criminal, pursuant to the provisions of the applicable collective bargaining agreements.
Framework for the achievement of objectives
doValue and its subsidiaries establish, monitor and periodically review the objectives of the Criminal Compliance Integrated Management System, ensuring their alignment with the criminal risks identified and with the strategy of the organisation. To that end, they allocate the financial, human and technological resources necessary for their proper achievement and monitoring.
Dissemination and access
The System is disseminated properly and on an ongoing basis among all Personnel. Likewise, the principles and rules comprising it shall be made available to all members of the organisation. This Policy is made available to all interested parties through the internal communication channels and the corporate website.
Criminal Compliance Body
The criminal compliance function, performed by the Compliance Officer, is responsible for supervising, managing and keeping the Integrated Management System up to date, ensuring its effectiveness. This function is performed with autonomy and independence, and with full powers and authority for the exercise of its role. The Compliance Officer reports directly to the Board of Directors, informing it periodically of the status of the System, and has direct access to it, irrespective of the hierarchical line, where circumstances so require. This reporting structure guarantees its functional independence from the business areas and from any body or person subject to its supervision.
Continual improvement
The Integrated Management System is subject to periodic review and continual improvement, with the Management Body and the Governing Body (Board of Directors) being informed, on a recurring basis, of its supervision and monitoring activities, of the structural and regulatory changes that may have occurred, as well as of the criminal compliance performance measurements and the results of their evaluation.
6Rules that make up the criminal compliance framework
doValue and its subsidiaries have a series of fundamental rules, applicable to all Personnel, on which the Integrated Management System is structured and developed:
- Code of Ethics: constitutes the general frame of reference and guidance for the conduct of the activities of doValue and its subsidiaries. Based on the business principles of doValue and its subsidiaries, it sets out the ethical principles that must govern the conduct of all employees. Knowledge of this document is mandatory for all members and external collaborators of doValue and its subsidiaries.
- Manual of the Integrated Management System: establishes the guidelines for action of doValue and its subsidiaries in order to comply with the exercise of due control and the duty of oversight over their business activity, thereby complying with the legal requirements of the Spanish Criminal Code and with the risk control duties imposed by the Spanish Companies Act (Royal Legislative Decree 1/2010).
- Internal Information System Policy: doValue and its subsidiaries make available a Reporting Channel or Ethics Channel, through which employees or third parties having a relationship with doValue and its subsidiaries may report breaches or suspicions concerning legal non-compliance within the business activity of doValue and its subsidiaries. This enhances transparency and the monitoring of proper compliance with the law and with the Code of Ethics.
- Corporate Procedure for the Management of the Internal Information System: establishes the guidelines for action in those cases where it is established that, within doValue and its subsidiaries, conduct is being carried out that potentially constitutes breaches of European Union law, or serious or very serious criminal or administrative offences.
- Global Policy on Conflicts of Interest and Related-Party Transactions: establishes the commitment of doValue and its subsidiaries to implement the global measures and policies enabling the identification of potential conflicts of interest that may arise in the provision of services.
- Gifts Policy: establishes the express prohibition on making or receiving any type of gift or financial commission with the intention of obtaining any kind of advantage benefiting the organisation.
- Anti-Corruption Policy: sets out the commitment of doValue and its subsidiaries to zero tolerance of any form of corruption, in both the public and the private sector, including bribery, corrupt payments, influence peddling and any other corrupt practice.
- Training in compliance and the prevention of criminal risks: A training, communication, awareness and dissemination plan is established annually, setting out the practical aspects of the prevention of offences so that all members of doValue and its subsidiaries are aware of their rights and obligations in relation to criminal compliance.
- Disciplinary regime: which shall apply in the event of breach of the Integrated Management System or of the applicable internal regulations, as well as in cases of the commission of irregular acts or conduct, in accordance with the regime of infringements and sanctions provided for in the Collective Bargaining Agreements applicable to doValue and its subsidiaries, in the Workers’ Statute and in any other applicable labour or internal rules. In cases where the acts may constitute a criminal offence, doValue and its subsidiaries may report them to the competent authorities, without prejudice to those cases in which such reporting is legally mandatory. The consequences of the disciplinary regime shall apply to all Personnel subject to this Policy, irrespective of their position or hierarchical level, including directors and senior managers, in accordance with the labour, commercial or contractual rules applicable in each case. All of the foregoing is without prejudice to the provisions of section 8 of this Policy.
7Commitment of the Board of Directors and of the Management Body
The Boards of Directors and the Management Bodies of doValue and its subsidiaries reaffirm, by means of this Policy, their commitment to ethics, integrity, regulatory compliance and the prevention of offences, promoting a culture of compliance that forms part of the values and of the day-to-day activity of the Organisation.
The Board of Directors, as the governing body of the Organisation, assumes visible, active and effective leadership in relation to the Criminal Compliance Integrated Management System, driving its implementation, supervising its operation and promoting its continual improvement. It also approves this Policy and ensures that the System has the human, technological and financial resources necessary to achieve its objectives.
For its part, the Management Body is responsible for promoting the effective application of the principles and requirements established in the Integrated Management System, fostering conduct consistent with the culture of compliance and integrating the criminal compliance objectives into the ordinary management of the Organisation.
The Board of Directors and the Management Body expressly support the independent exercise of the Criminal Compliance function, entrusted to the Compliance Officer, guaranteeing its autonomy, authority, access to the information necessary for the performance of its duties and direct access to the governing bodies where circumstances so require.
Likewise, both bodies promote the communication, dissemination and awareness of this Policy, as well as of the other elements comprising the Criminal Compliance Integrated Management System, driving the training, awareness-raising and engagement of all persons subject to it.
8Reporting of irregularities
All persons subject to this Policy are obliged to report any breach or reasonable suspicion of breach of the applicable legislation, of the Code of Ethics, of this Policy or of the other rules comprising the Integrated Management System of which they become aware in the course of their professional activities.
To this end, the Organisation has an Internal Information System (IIS) managed in accordance with the Internal Information System Policy and the Corporate Procedure for the Management of the Internal Information System, guaranteeing the confidentiality of the information reported, the protection of the identity of the reporting person and the prohibition of retaliation in the terms provided for in the applicable legislation.
The Internal Information System is supervised by the Internal Information System Committee (IISC), appointed by the Board of Directors as the Person Responsible for the System.
Reports may be made through the channels made available by the Organisation, accessible via the following links:
- doValue: https://dovalue.whistlelink.com/
- TEAM4: https://team4.canalhelas.com/home
All matters relating to the operation of the Internal Information System, the methods of reporting, the safeguards applicable to reporting persons, persons concerned and related third parties, as well as the handling of the reports received, are governed by the Internal Information System Policy and the Procedure for the Management of the Internal Information System.
9Breaches of the Criminal Compliance Policy
Compliance with this Policy is the responsibility of all persons within its scope of application. Likewise, the Board of Directors, the Management Body and the persons performing management or supervisory functions in the Organisation shall actively promote awareness, application and compliance within their respective areas of responsibility.
Notwithstanding the foregoing, it is incumbent on the Compliance Officer, in the exercise of the Criminal Compliance function, to supervise the proper implementation, maintenance and effectiveness of the Criminal Compliance Integrated Management System, as well as to report on its operation to the governing and management bodies of the Organisation.
Breach of the provisions of this Policy may give rise to the adoption of such disciplinary, contractual or legal measures as may be appropriate in each case, in accordance with the legislation in force, the applicable collective bargaining agreements, the internal regulations of the Organisation and the contractual obligations assumed.
The application of such measures shall be carried out having regard to the nature and seriousness of the acts, guaranteeing in all cases the rights of the persons concerned and respect for the legally established procedures.
10Publication and entry into force
This Policy forms part of the Criminal Compliance Management System of doValue and constitutes documented information thereof. The Policy shall be subject to periodic review and continual improvement, in order to ensure its adequacy to the applicable legislation, to the evolution of the criminal risks of the Organisation, to the organisational changes that may occur and to the needs arising from the operation of the Integrated Management System.
Likewise, this Policy shall be made available to interested parties through the corporate website of doValue, the websites of its subsidiaries and such other means as the Organisation considers appropriate to ensure its dissemination and accessibility.
This Policy shall enter into force at doValue and its subsidiaries on the date of its approval by the relevant competent body, and shall remain in force until it is replaced, amended or repealed by a new version.