A case management system is the system a public authority uses to handle its procedures: it receives the application, examines it, generates decisions, issues notifications and archives the file. Under Spain’s administrative procedure law, Law 39/2015 (Ley 39/2015), all of that must be electronic, and under the National Interoperability Framework (Esquema Nacional de Interoperabilidad, ENI), all of it must be capable of being exchanged with other public authorities without being keyed in again. The problem with many electronic case management systems is not that they fail to handle procedures, but that they produce case files that are not ENI case files, serve notifications through channels other than the legally prescribed ones, or do not talk to the registry (the official record of documents received and sent) or the archive. This guide sets out, law by law, what a case management system must comply with, how that translates into technical requirements and how to write it into the tender specifications when you opt for custom development. CEDESA has built platforms for processing and managing case files for provincial councils (Diputaciones) and local councils, and these are the requirements that cannot be left out.
The legislation that sets the requirements
- Law 39/2015 on the common administrative procedure: it defines the electronic document (Article 26), the electronic case file as an ordered aggregation of documents with a signed index (Article 70), the general electronic registry (Article 16), the single electronic archive (Article 17), electronic notifications (Articles 41 to 43), the right not to submit documents already held by the public sector (Article 28) and who is obliged to deal with public authorities electronically (Article 14).
- Law 40/2015 on the legal regime of the public sector (Ley 40/2015): automated administrative action (Article 41), signature systems and the body’s electronic seal, or sello de órgano (Articles 40 to 46), and the obligations on interoperability and data transmission between public authorities (Articles 155 to 158).
- Royal Decree 203/2021, the Regulation on the action and operation of the public sector by electronic means (Real Decreto 203/2021), in force since 2 April 2021: it sets out the detailed rules on the e-office (sede electrónica), the registry, identification and signature, notifications, automated action and the archive.
- National Interoperability Framework (Royal Decree 4/2010, Real Decreto 4/2010) and its Technical Interoperability Standards (Normas Técnicas de Interoperabilidad): electronic document, electronic case file, digitisation, authentic copying and conversion, signature and seal policy, document management policy, catalogue of standards, data model for the exchange of registry entries (SICRES), data intermediation protocols and reuse.
- National Security Framework (Esquema Nacional de Seguridad, ENS), governed by Royal Decree 311/2022 (Real Decreto 311/2022): the case management system is one of the public body’s information systems and must be categorised and protected, and its supplier must demonstrate conformity, as we explain in what the ENS is.
- Data protection and accessibility: the GDPR and the LOPDGDD (Spain’s data protection act) for interested parties’ data, and accessibility of the e-office and its forms in accordance with Royal Decree 1112/2018 (Real Decreto 1112/2018).
The requirements the case management system must meet
1. ENI-compliant documents and case files
Every document must be generated with the minimum mandatory metadata required by the Technical Standard on the electronic document (identifier, body, capture date, origin, document status, document type, format, signature), and every case file with its signed or sealed electronic index, which guarantees the integrity and the order of the documents it contains. The exchange format is the one set by the Technical Standard on the electronic case file; a system that cannot export a complete ENI case file cannot send it to a court, to another public authority or to the archive. Authentic copies and digitised paper documents must follow their own technical standards and be marked as such.
2. Electronic registry and interconnection
The system receives applications from the general electronic registry and from the in-person assistance offices, and sends the outgoing entries back to it. It must be integrated with the public body’s registry and with the Registry Interconnection System (Sistema de Interconexión de Registros), so that it can receive entries from other public authorities and send entries to them in the SICRES format, without anything that has already been registered being keyed in again.
3. Identification and signature
Interested parties are identified using the accepted systems (electronic certificate, the Cl@ve shared identification system and any others the public body approves); public employees sign with a public employee certificate and automated acts are signed with the body’s electronic seal, in accordance with the ENI’s signature and seal policy and with validation through the services of central government (Administración General del Estado) or equivalent services.
4. Electronic notifications
Notifications are served through the e-office and at the Single Enabled Electronic Address (Dirección Electrónica Habilitada única or DEHú, the single national inbox for official notifications), with the access deadlines and the alerts provided for in Articles 41 to 43 of Law 39/2015, and with a record of the notification being made available, accessed or rejected. The system must generate the notification from the case file, send it through the notification services of central government or of the autonomous community (region), and store the acknowledgement of receipt in the case file itself.
5. Data intermediation: not asking for what the public sector already holds
Article 28 of Law 39/2015 recognises the right not to submit documents that public authorities already hold. The system must query the services of the Data Intermediation Platform (Plataforma de Intermediación de Datos) – identity, residence, tax and social security status, qualifications and benefits, among others – with the consent of the interested party or subject to their right to object, as applicable, and keep evidence of each query in the case file.
6. Automated administrative action
When the system issues acts without human intervention (acknowledgements of receipt, requests to remedy defects in an application, non-discretionary decisions), Article 41 of Law 40/2015 requires a prior decision identifying the system, the body responsible and the audit mechanism, together with the use of the body’s electronic seal. The system must record which acts are automated and under which rules, so that they can be audited.
7. Single electronic archive
Completed case files are transferred to the single electronic archive (Article 17 of Law 39/2015) with its document management policy and its retention and transfer schedule, and in formats that guarantee long-term authenticity and readability. The system must be integrated with the public body’s archive or with central government’s permanent archive service, and must not keep closed case files as though they were still live.
8. Processing, deadlines and transparency
Workflows for each procedure, with stages and tasks, and with statutory deadlines and administrative silence (silencio administrativo, the legal effect of a failure to decide in time) calculated by the system; a citizen folder (carpeta ciudadana) where people can check the status of their case; publication of case-processing data for transparency; and reporting for senior management and for the oversight bodies, especially where the procedure handles EU funds that have to be reported and justified to the IGAE (Spain’s General State Comptroller) or to Spain’s Court of Auditors (Tribunal de Cuentas).
9. Security, data and accessibility
Categorisation under the ENS and the corresponding measures, logs of access and changes, role management, a record of processing activities and accessibility of every public-facing interface.
Off-the-shelf product or custom development
A generic case-processing product meets the requirements above in a standard way, and for many public bodies that is enough. Custom development pays off when the procedures are specialised (grants with rules of their own, social services, infrastructure management, the processes of a publicly owned company), when the system has to integrate with the body’s own systems (asset management, accounting, GIS, HR systems) or when the public body wants to own the code and not depend on an annual licence. We look at this in custom software versus a generic ERP in the public sector. In either case, the nine requirements are the same: the tender specifications must require them whatever the model.
How to write it into the tender specifications
- ENI requirements set out technical standard by technical standard, not in generic terms: export of a complete ENI case file with a signed index, minimum metadata, compliant authentic copying and digitisation, and an exchange test in the bid or in the pilot.
- Mandatory integrations listed one by one: registry and registry interconnection, identification and signature, notifications, data intermediation, archive, citizen folder, e-office and those specific to the public body, each with its protocol and the person responsible for it.
- Automated action: a list of the acts that can be automated and the audit mechanism.
- ENS: the category of the system, set by the public body, and current certification held by the successful bidder, as we set out in how to check your supplier’s ENS certificate.
- Code ownership, documentation and exit: handover of the source code, the data model and the configured procedures, and a full export at the end of the contract.
- A pilot with a real procedure before the general roll-out, measured in case files processed from end to end.
- Technical capacity and financial standing criteria that do not exclude certified mid-sized companies, as we explain in large integrator or mid-sized company and in the guide on how to prepare technical specifications with ENS requirements.
CEDESA’s experience
CEDESA has developed case management systems and digital services for the Diputación de Badajoz; the Diputación de Toledo’s platform for digitalising provincial social services, financed by the PRTR (Spain’s Recovery, Transformation and Resilience Plan); the Diputación de Ourense’s administrative management software; the municipal services management platform of the Ayuntamiento de Guadalajara (local council); and the Ayuntamiento de Puerto del Rosario’s integrated system for service management and electronic processing of procedures, as well as the platform for managing competitive processes at SAREB (the company that manages the assets from Spain’s bank restructuring), which we describe in digitalising the management of competitive processes. All of them were delivered with CEDESA’s medium-category ENS certification, with the code owned by the client and with the same team handling development and maintenance. You can see how we work on our software for the public sector page.
Frequently asked questions about electronic case management systems
What is an electronic case file under Law 39/2015?
The ordered set of documents and actions that serve as the background to, and the basis for, the administrative decision, in electronic format, made up of the ordered aggregation of electronic documents with a signed or sealed electronic index that guarantees its integrity. Its structure and metadata are set by the Technical Interoperability Standard on the electronic case file.
Which integrations are mandatory in a case management system?
Electronic registry and registry interconnection, identification and signature using the accepted systems and the body’s electronic seal, electronic notifications through the e-office and at the Single Enabled Electronic Address, data intermediation so as not to ask for documents the public sector already holds, the single electronic archive and the citizen folder, as well as integrations with the public body’s own systems.
Can a case management system issue decisions automatically?
Yes, by means of automated administrative action under Article 41 of Law 40/2015: this requires a prior decision identifying the system and the body responsible, an audit mechanism and the use of the body’s electronic seal. The system must record which acts are automated and under which rules.
Does a case management system have to comply with the ENS?
Yes. It is one of the public body’s information systems, it processes personal data and it underpins acts with legal effect. It must be categorised in accordance with Royal Decree 311/2022 and apply the measures for its category, and the supplier must demonstrate conformity by holding a current certification.
When is a custom case management system a better choice than an off-the-shelf product?
When the procedures are specialised, when the system has to integrate with the public body’s own systems or when the body wants to own the code with no annual licences. The legal and interoperability requirements are the same in both cases, and the tender specifications must require them whatever the model.
Conclusion
A case management system is compliant when it produces ENI case files with a signed index, integrates with the registry, signature, notifications, data intermediation and the archive, automates acts subject to the safeguards of Article 41 and is protected in accordance with the ENS. These are requirements to be written into the tender specifications law by law, and ones that a well-planned custom development meets with the added advantage of fitting the public body’s actual procedures. If your organisation needs to define or build its own, tell us about your project via our contact page.