From risk to evidence: keys to social-labour compliance to meet the ITSS Strategic Plan 2025-2027

Articles31 October 2025
Raúl Rojas, partner at ECIJA, analyzes the keys for companies to adapt their labour management systems to the new regulatory scenario, where due diligence and information traceability will be essential to demonstrate compliance before the Labour Inspection.

The recent publication of the Strategic Plan of the Labour Inspection and Social Security (PEITSS) 2025–2027, approved by Resolution of September 8, 2025 (BOE September 12), has marked a turning point in the area of social-labour compliance.


It is not just about increased inspection activity as has occurred with previous plans, but rather a different approach based on creating a preventive culture against labour risk.


This new approach is mainly oriented towards greater proactivity and digitalization of Labour Inspection based on “data evidence” and focused on critical risk areas, such as job stability and fraud prevention in hiring, equality, inclusion, and harassment prevention, wage rights, or the monitoring of new labour realities generated by the ongoing digitalization process in the workplace.


The design of this strategic plan aims to respond to various challenges, such as the increase in complaints by workers for labour violations, continuous regulatory reforms, the existing legislative dispersion in labour matters, or the emergence of new labour risks arising from technological transformation.


The PEITSS, to address these challenges, structures its objectives around two main pillars: (i) the inspection activity in various risk areas and (ii) the quality, efficiency, and effectiveness of the inspection service. In addition to reinforcing classic risk areas (hiring, working hours, salary, equality, and Social Security), it promotes procedural modernization through, for example, electronic files, automation of procedures, intensive use of inter-administrative information, or a probative approach that prioritizes digital evidence obtained in an integral and verifiable manner.


It is also expected to strengthen the personal and technological resources of the ITSS, as well as specialized analysis units and forensic computing laboratories, raising the standard of proof and the likelihood of detection.


All this will result in greater demands on companies, which will need to be prepared to “evidence” at any moment their compliance with labour regulations using traceable data and records, rather than mere statements of intent or commitments without real content.


In this new scenario, the proposed social-labour compliance management system under UNE 19604:2023 enables organizations to move from “paper to practice” through the design, implementation, evaluation, and continuous improvement of their management system, standardization of their internal procedures, as well as increasing legal certainty in decision-making and managing their labour relations both internally and with third parties.


Alignment of social-labour compliance

To demonstrate this due diligence before potential inspections under the new PEITSS, social-labour compliance programs allow for complete operational alignment with regulatory compliance and risk prevention for non-compliance in the social-labour area, which could be structured at five levels:

  • Preparation of a map of social-labour risks specifically linked to the critical risk areas contemplated in the PEITSS (e.g.: causality of temporary contracts; abusive terminations during trial periods; dismissals without the legal or conventional formalities provided; reliability, integrity, and exportability of working time and attendance records; management of overtime and digital disconnection, etc.).
  • Design of specific controls for each internal process implemented to reduce or mitigate risk (e.g.: automatic verification of thresholds for collective dismissal; payroll alignment; process of updating internal policies and protocols, especially in harassment matters and investigation processes; periodic validation of contribution bases, bonuses and moulding;
  • Obtaining integral digital evidence to, if necessary, be made available to the ITSS when the company is required to do so (e.g.: digital records of working time; records of trainings provided to staff, etc.;
  • Measurement indicators for monitoring and evaluating the management system (e.g.: number of complaints filed and number of complaints investigated; % attendance in trainings, etc.); and
  • Implementation of a continuous improvement process, with periodic reports on labour regulatory compliance and review by senior management.

It is important to note that risks are not necessarily exhausted in economic fines. Non-compliant conduct or possible evidence of fraud in business actions can open the door to individual claims, nullifications of business decisions, and/or reputational damages that are sometimes difficult to reverse. For example, obstruction or the absence of reliable evidence (e.g.: inconsistent time records or audits out of touch with reality), in addition to increasing the risk of infringement (greater probability), can also aggravate the penalty (greater impact).


From the perspective of defense against an inspection review, an operational management system under UNE 19604 provides an objective plus of due diligence for the organization and facilitates proof regarding preventive measures, investigations, and corrective actions adopted.


Therefore, in light of this new scenario of increased inspection capacity, more technology, and greater evidentiary demands, the response from organizations cannot be to accumulate formal policies or those without real content. A true regulatory compliance and proven due diligence in their actions must be demonstrated through the implementation of procedures and controls that ensure not only compliance with labour regulations but also allow for a reduction in the risk of non-compliance.


A well-implemented social-labour compliance management system not only reduces the risk of receiving sanctions or litigation with workers but, above all, creates a true culture of compliance at all levels, organizes processes and internal policies, and turns risk into trust for clients, staff, investors, and verification agents such as the ITSS.


Access the full article published in Byte magazine here.

Un grupo de montañistas camina sobre un paisaje nevado en blanco y negro.

Related partners

LATEST FROM #ECIJA