BPM for government turns every procedure into a traceable electronic circuit — registry, processing, signature, notification and archive — without replacing the case-file manager: it orchestrates them. It delivers what Spain's Law 39/2015 already requires: an electronic case file with a numbered index (art. 70), electronic notification (art. 41) and a default decision deadline of three months (art. 21.3).
What BPM for government adds (and what it is not)
It adds the one thing almost no administration has in machine-readable form: the executable definition of the procedure. Who does what, in which order, against which deadline, which document enters or leaves at each step, and what evidence remains. The case-file manager custodies the file; the registry records what comes in and goes out; the signing portal signs; the notification platform notifies. None of them knows that the technical report has been sitting untouched for forty days, or whose job it is to chase it. A BPM does, because the procedure lives modelled inside it rather than in the head of the case officer. The conceptual groundwork is in what BPM is and in the BPMN 2.0 guide, the notation these circuits are drawn in.
What a BPM is not, and it pays to settle this before anyone drafts a specification:
- It is not a new case-file manager. If the body already runs one that produces an electronic index and archives to the interoperability scheme, the BPM connects to it. Replacing it is a different, far more expensive project.
- It is not a citizen portal. The portal is the front door; the BPM is what happens once the application crosses it.
- It is not RPA. A robot imitates clicks on screens; a BPM defines the process and calls systems through connectors. RPA without BPM automates the mess. We unpack the difference in RPA and BPM.
The sentence that summarises this article: digitising a procedure is not scanning it, it is modelling its circuit. The first produces PDFs; the second produces deadlines met and case files that survive an appeal.
What the law already requires: the EU layer and the Spanish layer
You do not have to invent requirements for a public sector BPM: they are already written down, and a tender that quotes them is far harder to argue with than one that lists features. Two layers stack up. The first applies to every EU administration.
| EU instrument | What it requires | What it asks of the BPM |
|---|---|---|
| eIDAS (Regulation 910/2014) and eIDAS 2 (Regulation 2024/1183) | A qualified electronic signature has the legal effect of a handwritten one across the Union (art. 25.2); qualified seals and time stamps authenticate what an organisation issues. eIDAS 2 adds the European digital identity wallet — we cover it in what changes with eIDAS2. | A signing portal with advanced and qualified signature, time stamping and a verification code the citizen can check; identification of the applicant through the national scheme and, in time, through the EUDI wallet. |
| Single Digital Gateway (Regulation (EU) 2018/1724) | Key procedures must be available fully online to cross-border users, and article 14 sets up the once-only technical system so that evidence held by one administration can be requested from another instead of from the citizen. | Steps that fetch evidence from other bodies as part of the flow, not as an offline errand, and procedures that can be completed end to end without a physical visit. |
| AI Act (Regulation (EU) 2024/1689) | Annex III classifies as high risk the systems public authorities use to evaluate eligibility for essential public benefits and services, or to grant, reduce or withdraw them, plus uses in public employment, migration, law enforcement and justice. | AI as a step inside the process with a human control point, an activity log and a record of what the model proposed and what the officer changed. Detail in the AI section below. |
| NIS2 (Directive (EU) 2022/2555) | Public administration entities of central government are listed among the sectors of high criticality in Annex I, with risk-management measures and incident reporting duties, as transposed by each member state. | A supplier that can evidence its own security controls and support incident notification timelines. Background in our guide to the NIS2 directive. |
The second layer is national. Spain's is worth reading even if you work elsewhere, because it spells out in statute what most e-government programmes only describe in slide decks: the electronic case file, automated administrative action, the security framework and the interoperability framework. This is the table to have open while writing the technical specification.
| Spanish rule | What it requires | What it asks of the BPM |
|---|---|---|
| Law 39/2015, common administrative procedure | Mandatory electronic dealings for legal persons, professional-body members and public employees (art. 14.2); a general electronic registry (art. 16); a six-month cap on decision deadlines and three months where the rule is silent (arts. 21.2 and 21.3); positive silence by default (art. 24); electronic notification, deemed rejected after ten calendar days without access (arts. 41 and 43.2); an electronic case file with a numbered index (art. 70); simplified processing in thirty days (art. 96). | A deadline clock per case file with alerts before expiry; integration with the registry; generation of the electronic index; dispatch and access control for notifications; a trace of every action. |
| Law 40/2015, legal regime of the public sector | Automated administrative action with a defined responsible body (art. 41); electronic seal and secure verification code for anything automated (art. 42); staff signature using the system each administration establishes (art. 43); the security and interoperability frameworks as binding (art. 156); reuse of applications between administrations (art. 157). | Automated steps flagged as such and sealed or given a verification code; human steps signed with the public employee certificate; procedures exportable so another body can reuse them. |
| ENI (RD 4/2010), national interoperability framework | Electronic documents and case files with minimum metadata, a signed and paginated electronic index, and exchange formats between administrations. | Every document generated in the flow is born with its metadata; the case file can be handed to another body or to the archive in the ENI exchange format. |
| ENS (RD 311/2022), national security framework | Applies to the whole public sector and to private suppliers providing it with services or solutions (art. 2). Basic, Medium or High category depending on the impact on availability, authenticity, integrity, confidentiality and traceability (art. 40 and annex I). Basic: self-assessment and declaration of conformity; Medium and High: audit and certification (art. 38), with an ordinary audit at least every two years (art. 31). | The supplier must evidence the category the body has set for the system, with a statement of applicability and controls; data and audit logs inside the scope. |
| RD 203/2021, e-government implementing regulation | Develops the portal, registry, notification, archive and automated action provisions of the two laws above. | The text to cite in the tender alongside the statutes: it turns the principles into functional requirements. |
One detail separates a good specification from a bad one: art. 70.4 of Law 39/2015 keeps notes, drafts, opinions and internal communications out of the case file. The BPM has to distinguish between what belongs to the file (and goes into the index) and what is internal working material (and does not). A system that dumps everything into the same folder produces case files that cannot survive a party's right of access under art. 53.
Procedure by procedure: where it jams and what a BPM automates
The bottlenecks repeat across administrations of every size, and they are almost never inside one system — they sit between systems: the report you have to request from another department, the datum you have to look up at another administration, the signature waiting in a tray. Six common procedures, the usual jam and what a BPM automates without touching the case-file manager.
| Procedure | Usual bottleneck | What a BPM automates |
|---|---|---|
| Grants and subsidies (Law 38/2003) | Hundreds of applications with incomplete paperwork; requests to correct them typed by hand; the six-month cap to decide and notify (art. 25.4) burned on checking documents; the justification stage (art. 30) starts from zero all over again. | Validation of the application against the call, an automatic correction request with its own deadline, tax and social-security status looked up through the inter-administration data service, scoring in a table, a draft decision for the committee, and a justification circuit with the same traceability. |
| Permits and licences (building, activity, street occupation) | Technical and legal reports run in series when they could run in parallel; nobody knows how much of the deadline is left, and administrative silence — positive by default under art. 24 of Law 39/2015 — arrives without warning. | Parallel reports with an internal deadline each, a traffic light of days remaining per file, an alert to the head of unit before silence bites, and a decision signed in the signing portal and notified from within the flow. |
| Public procurement (Law 9/2017) | The procurement file (art. 116) is assembled from loose documents: needs report (art. 28), specifications, reports, financial control; in minor contracts (art. 118) the needs report goes missing and nobody tracks the annual accumulation per supplier. | A needs → specifications → financial control → approval → publication circuit with mandatory stages, control of accumulated value by supplier and subject matter, and a complete file ready for the procurement platform and for the audit body. |
| HR and workforce (public employee statute) | Leave, holidays, secondments and time records for civil servants living on paper forms or emails that end up in a spreadsheet on the HR drive. | Requests from the portal or the phone, approval by the line manager under the statutory and collective-agreement rules, an up-to-date balance and an exportable time record, all filed in the personal record. |
| Citizen services and registry | Generic applications that someone has to read one by one to work out which unit they belong to; "how is my file going?" enquiries that art. 53.1.a) obliges you to answer and that eat half the front-office day. | Classification of the application and routing to the right unit, automatic acknowledgement, file status visible in the citizen folder, and electronic notification with access control and the ten-day clock. |
| Penalty procedures (traffic, planning, consumer) | Chained deadlines — initiation, submissions, proposal, decision, appeal — that lapse; the early-payment reduction (art. 85 of Law 39/2015) applied wrongly; tickets that never reach a decision. | A state machine with every deadline and its expiry, calculation of reductions, proposal and decision generated from templates, signature and notification with evidence of access or refusal. |
The pattern repeats: the BPM decides nothing the law reserves to a public employee; it prepares, watches deadlines, fetches data, moves the file and leaves a trail. The decision is signed, and the signature stays in the file.
How it differs from BPM in a private company
In two ways that change everything: the process is designed by law rather than by the organisation, and the software is bought through a tender. A BPM built for companies optimises for changing the flow every week; in an administration the flow is fixed by a rule, what changes is the volume, and what gets judged is the evidence. Six differences that should drive the choice:
| Dimension | Private company | Public administration |
|---|---|---|
| Traceability | Desirable for internal audit and quality. | Mandatory and evidential: every action has to be reconstructable before an appeal, an audit body or an ombudsman. Traceability is also one of the ENS security dimensions. |
| Deadlines | Service targets the company sets and can change. | Statutory deadlines with consequences: administrative silence, lapse of a penalty procedure, liability. The BPM has to count working days and calendar days as the rule defines them, not as the office calendar does. |
| Interoperability | API integrations with your own ERP and CRM. | Exchange with other administrations through national platforms and EU once-only channels, in prescribed formats. Art. 28.2 of Law 39/2015 forbids asking citizens for documents the administration already holds: you look them up, you do not request them. |
| Buying the software itself | You trial it, negotiate and sign. | You tender it under Law 9/2017: minor contract up to EUR 15,000 in services (art. 118), abbreviated simplified open procedure up to EUR 60,000 (art. 159.6), simplified open up to the harmonised threshold (art. 159), open above it. Technical specifications cannot name a brand without "or equivalent" (art. 126.6). |
| Data and security | GDPR and, by sector, ISO 27001 or NIS2. | GDPR plus the ENS category the body has set; the tender may require where the servers sit and submission to European data protection law (art. 122.2 of Law 9/2017). Data in the EU and, for many bodies, an on-premise option. |
| Identity and signature | Corporate account and a signature level matched to the document's risk. | Public employee certificate and the signature system the administration has established (art. 43 of Law 40/2015); electronic seal and verification code for automated action (art. 42); citizens identified through the national scheme or a certificate. |
What is identical in both worlds: a process you do not measure will not improve. A well-implemented public BPM produces the number almost nobody has today — the average number of days each procedure takes, the stage where time is lost and how many files expire each month.
AI in case processing: what the EU AI Act and Law 40/2015 allow
AI can be used in an administration to prepare the public employee's work; what is regulated is using it to decide about people. Regulation (EU) 2024/1689 puts in annex III, as high risk, the systems public authorities use to evaluate whether a person is eligible for essential public benefits and services, or to grant, reduce or withdraw them, alongside uses in public employment, migration control, law enforcement and the administration of justice. Those systems require risk management, logging, effective human oversight (art. 26) and, where the deployer is a body governed by public law, a fundamental rights impact assessment before use (art. 27).
The calendar moved this summer. Regulation (EU) 2026/1744, the digital omnibus on AI published in the Official Journal on 24 July 2026, pushed the annex III high-risk obligations from 2 August 2026 to 2 December 2027 (and the annex I ones to 2 August 2028). Still in force: the art. 5 prohibitions, the art. 4 AI literacy duty and the art. 50 transparency obligations for conversational assistants. Our article on the EU AI Act and process automation walks through the risk tiers in detail.
In Spanish law the rule is older and simpler: any automated administrative action — an act issued without the direct intervention of a public employee — requires you to define in advance the body competent for the specifications, programming, supervision and audit of the system, and the body answerable for challenges (art. 41 of Law 40/2015). With those two texts side by side, the map of uses looks like this:
| Use of AI in the procedure | Where it lands legally | Condition for doing it properly |
|---|---|---|
| Summarising the file, classifying an incoming application, extracting data from a submitted document | Support to the case officer; it does not decide about the person. Outside high risk. | The output is shown as an editable proposal; the employee validates it; the system records what the AI proposed and what was changed. |
| Checking that an application is complete and issuing the request to correct it | Automated administrative action (art. 41 of Law 40/2015) if issued without human intervention; signed with a seal or verification code (art. 42). | Responsible body named in the instrument that approves the use; deterministic rules rather than probabilistic ones; the citizen can ask for review. |
| Scoring grant applications or deciding the award | High risk, annex III of the AI Act (access to public benefits). Obligations apply from 2 December 2027. | Fundamental rights impact assessment, human oversight with a real ability to override, activity logging and an explanation to the affected person (art. 86). |
| A conversational assistant on the portal guiding citizens through procedures | Transparency obligation (art. 50): tell people they are talking to an AI. Applicable since 2 August 2026. | Answers grounded in the body's own rules, never inventing deadlines; escalation to a human; no processing of file data without identification. |
The safe way to fit AI into a procedure is to have it live inside the BPM as one more step, with its input, its output and its human control point — not as a separate tool the case officer consults in another tab. That is the model behind governed AI agents: the AI proposes, the process decides who validates, and everything stays in the file.
Common mistakes when digitising procedures
E-government projects that stall halfway almost always fail for the same six reasons, and none of them is technological.
- Digitising the paper instead of the circuit. Replacing the printed form with a fillable PDF and carrying on printing it to sign. The file stays hybrid and art. 70 stays unmet.
- Starting with the most complex procedure. Procurement and urban planning have dozens of variants. Start with something high-volume and low-exception — a minor building permit, staff leave, one grant call — and teach the team on that.
- Modelling the real flow instead of the legal one. If today's circuit has three signatures where the rule requires one, the BPM should not copy them. The redesign happens with the secretariat and the legal service before the first diagram is drawn.
- Asking citizens for what the administration already holds. Every document you could look up through the inter-administration data service and still demand is a breach of art. 28.2 of Law 39/2015 and an avoidable correction round.
- Buying without requiring connectors. A BPM with no integration to the registry, the signing portal and the notification platforms forces people to retype data between systems. That was the thing you were trying to remove.
- Forgetting the archive. A closed file has to be transferable to the electronic archive in the interoperability format with its signed index. If the system only "exports a ZIP", the problem shows up five years later.
And one more, a quiet one: not measuring. Without the days-per-stage baseline taken before you start, nobody will be able to demonstrate the improvement when the contract comes up for renewal.
Procurement checklist: what to ask for in a BPM tender
Twelve requirements worth carrying into the technical specification, written as verifiable functions rather than product names. The first six are compliance; the last six are what makes the thing usable.
- Interoperable electronic case file. Generation of documents and files with minimum metadata, a signed and paginated electronic index, exportable in the ENI exchange format.
- ENS category of the system. State the category the body has assigned and require the matching evidence: declaration of conformity for Basic, certification of conformity for Medium or High (art. 38 of RD 311/2022), with the statement of applicability of controls.
- Signature and seal. A signing portal with eIDAS advanced and qualified signature for public employees, electronic seal and verification code for automated action, time stamping, and verification of the code from the public portal.
- Interoperability. Connectors for the registry, notification, inter-administration data lookup and identity platforms your body uses — national, regional or the EU once-only channel.
- Data location and data protection. Servers in the EU, an art. 28 GDPR processor agreement and submission to national and European law (art. 122.2 of Law 9/2017). An on-premise option where the body needs it.
- Traceability and audit. An immutable record of every action with author, timestamp, signature system and document version, exportable for an appeal or a financial audit.
- Statutory deadline control. Working-day and calendar-day computation per procedure, configurable alerts before expiry and a dashboard of files at risk of silence or lapse.
- Low-code modelling by the body itself. The secretariat or IT should be able to change a circuit without bespoke development, and the model should export to BPMN 2.0 so another administration can reuse it (art. 157 of Law 40/2015).
- A line between the file and internal work. Notes, drafts and internal communications outside the index (art. 70.4 of Law 39/2015) but retained for audit.
- AI with a human control point. If AI is included to summarise, classify or extract data, it must act as a proposal validated by a public employee, with a record of what was proposed and what was amended, and it must not decide on benefits.
- Citizen folder and file status. The interested party can check the processing status and obtain a copy (art. 53.1.a) without phoning the office.
- A trial before committing. The ability to evaluate the platform with a real procedure before opening the procurement file, and specifications drafted with "or equivalent" (art. 126.6).
And one award criterion that rarely appears and should: time to the first procedure in production, measured in weeks rather than months. It is best value for money (art. 145) translated into something the team will actually feel.
How Dokuflex solves it: the whole case-file circuit without changing what already works
The public sector templates from Dokuflex, the AI low-code BPM platform, were built for exactly the problem in this article: the hybrid case file nobody can follow. Against the checklist above, this is what they bring:
- An electronic case file born digital. Electronic pagination, electronic index and archiving in line with the National Interoperability Framework; the procedure moves through its stages by the rules defined, and every action stays in the file.
- An eIDAS signing portal with evidence. Advanced and qualified signature with a secure verification code and time stamping, so who signed what and when does not have to be reconstructed by hand when an appeal arrives.
- Interoperability inside the flow. Standard connectors for GEISER, ORVE, SCSP, Notific@ and Cl@ve — Spain's registry, data-exchange, notification and identity services — so registry entries, cross-administration lookups and citizen notification happen within the procedure itself.
- AI for case files, with human control. Summarisation, classification and data extraction from procedures presented as a proposal to the case officer, inside the circuit rather than in another tab.
- Workforce management on the same platform. Leave, holidays and time tracking for civil servants, with their trail in the personal record.
- Deployment matched to data sovereignty. Cloud aligned with ENS Medium with data in the EU, or on-premise on the body's own servers; the control detail lives in the Trust and Security Center.
And the point that weighs most in a tender: you can evaluate it for free with a real procedure before opening any procurement file, no card and no commitment.
Frequently asked questions
What is BPM for government and how is it different from a case-file manager? +
BPM (business process management) is the layer that defines and executes the circuit of each procedure: who does what, in which order, against which deadline and what evidence remains. The case-file manager custodies the file (documents, index, interoperability metadata) and the registry records entries and exits. A BPM does not replace them: it orchestrates them, connecting to those systems and to the signing portal, the notification platform and the data-exchange services. That is why it can be implemented without rewriting the administration.
Can a small council use a BPM without replacing its case-file manager? +
Yes, and it is the most common scenario. The BPM is deployed on top of the case-file manager and registry that already exist, starts with one or two high-volume procedures (minor building permits, grants, staff leave) and connects to the registry, notification and data-exchange platforms through standard connectors. Article 157 of Spain's Law 40/2015 also encourages the reuse of applications between administrations, which makes replicating an already-modelled procedure cheaper.
What does Law 39/2015 require for a case file to be genuinely electronic? +
Article 70 requires the file to be in electronic format, formed by adding in order all documents, evidence, reports and decisions, and to have a numbered electronic index guaranteeing integrity and allowing recovery. Notes, drafts and internal communications are excluded (art. 70.4). Notification is served by electronic means as the default (art. 41) and is deemed rejected after ten calendar days without access (art. 43.2).
Does public sector software have to comply with the ENS, and in which category? +
In Spain, yes. Royal Decree 311/2022 applies to the whole public sector and to private suppliers providing it with services or solutions (art. 2). The category — Basic, Medium or High — is set by each body by assessing the impact of an incident on availability, authenticity, integrity, confidentiality and traceability (art. 40 and annex I). Basic is evidenced with self-assessment and a declaration of conformity; Medium and High require audit and certification of conformity (art. 38), with an ordinary audit at least every two years (art. 31).
Can a public administration use AI to process case files under the EU AI Act? +
It can, with two limits. Regulation (EU) 2024/1689 classifies as high risk (annex III) the systems public authorities use to evaluate access to essential public benefits and services; those require human oversight, logging and, for bodies governed by public law, a fundamental rights impact assessment (art. 27). Regulation (EU) 2026/1744 postponed those obligations to 2 December 2027. In Spanish law, any automated administrative action must have a defined responsible body (art. 41 of Law 40/2015). Summarising, classifying or extracting data from a file so that a public employee decides does not fall into high risk.
How do you procure a BPM: minor contract, simplified or open procedure? +
It depends on the estimated value of the contract under Spain's Law 9/2017. Below EUR 15,000 in services and supplies a minor contract is available (art. 118); below EUR 60,000, the abbreviated simplified open procedure (art. 159.6); up to the harmonised threshold, the simplified open procedure (art. 159); above that, the open procedure. In every case the technical specifications cannot name a brand without adding "or equivalent" (art. 126.6), and the tender may require where the servers will sit and submission to data protection law (art. 122.2).
Is a public employee's signature valid in a signing portal that is not the administration's own? +
Yes, provided it uses the signature system the administration itself has established for its staff (art. 43 of Law 40/2015) and the signature complies with eIDAS: a qualified electronic signature has the same legal effect as a handwritten one across the EU (art. 25.2 of Regulation 910/2014). For automated action, the document is authenticated with an electronic seal or a secure verification code (art. 42). What the signing portal must contribute is the evidence: who signed, when, with which certificate and time stamp, and a verification code that lets the document be checked on the public portal.
Sources
- Law 39/2015, of 1 October, on the common administrative procedure (consolidated text, in Spanish): articles 14, 16, 21, 24, 28, 41, 43, 53, 70, 85 and 96.
- Law 40/2015, of 1 October, on the legal regime of the public sector (in Spanish): articles 41, 42, 43, 156 and 157.
- Royal Decree 311/2022, of 3 May, National Security Framework (ENS, in Spanish): articles 2, 31, 38 and 40; annex I.
- Royal Decree 4/2010, of 8 January, National Interoperability Framework (ENI, in Spanish), and its technical standards on the electronic document and case file.
- Royal Decree 203/2021, of 30 March, regulation on the action and operation of the public sector by electronic means (in Spanish).
- Law 9/2017, of 8 November, on public sector contracts (in Spanish): articles 28, 116, 118, 122.2, 126.6, 145 and 159.
- Law 38/2003, of 17 November, general law on subsidies (in Spanish): articles 25.4 and 30.
- Royal Legislative Decree 5/2015, consolidated text of the basic statute of the public employee (in Spanish).
- Regulation (EU) 910/2014 (eIDAS): article 25; and Regulation (EU) 2024/1183 (eIDAS 2).
- Regulation (EU) 2018/1724, single digital gateway: article 14, technical system for the cross-border exchange of evidence (once-only).
- Directive (EU) 2022/2555 (NIS2): annex I, sectors of high criticality, including public administration entities of central government.
- Regulation (EU) 2024/1689, Artificial Intelligence Act: articles 4, 5, 26, 27, 50 and 86; annex III, point 5.
- Regulation (EU) 2026/1744, digital omnibus on AI (Official Journal of 24 July 2026): postponement of the annex III high-risk obligations to 2 December 2027.
Let the next case file be born electronic and reach a decision on time
Interoperable electronic case file, eIDAS signing portal, registry, notification and data-exchange connectors, watched deadlines and AI with a human control point. Evaluate the templates with a real procedure from your own body before opening any procurement file. Free, no card required.