The regulatory framework
Italian Legislative Decree 231/2001 introduced the administrative liability of entities for offences committed, in their interest or to their advantage, by persons holding functions of representation, administration or management, including on a de facto basis, or by those subject to their direction or supervision (Article 5). The company is liable in its own right, alongside the individual, facing financial penalties calculated by quotas and disqualification penalties that directly affect day-to-day operations: suspension of authorisations, a ban on contracting with the public administration, exclusion from grants and public funding and, at the extreme, disqualification from carrying on the business.
The catalogue of predicate offences has widened over the years and today covers, among others, areas that touch every business: offences against the public administration and bribery (Articles 24 and 25), computer crime (Article 24-bis), corporate offences (Article 25-ter), involuntary manslaughter and serious or very serious negligent injury committed in breach of health and safety at work legislation (Article 25-septies), receiving stolen goods, money laundering and self-laundering (Article 25-octies), offences relating to non-cash means of payment (Article 25-octies.1), environmental offences (Article 25-undecies), the employment of third-country nationals staying irregularly (Article 25-duodecies), tax offences (Article 25-quinquiesdecies), smuggling (Article 25-sexiesdecies) and offences against cultural heritage (Article 25-septiesdecies).
Articles 6 and 7 set out the route to excluding liability: having adopted and effectively implemented, before the event, an Organisation, Management and Control Model capable of preventing the offences, and having given a Supervisory Body (Organismo di Vigilanza, OdV) vested with autonomous powers the task of overseeing how the Model works and whether it is complied with. Linked to this framework are Italian Legislative Decree 81/2008 (Article 30) on health and safety at work and Italian Legislative Decree 24/2023 on whistleblowing, which requires internal reporting channels in entities that had an average of at least fifty employees in the past year, in those operating in sectors regulated by European Union law (financial services, anti-money laundering, transport safety, environmental protection) and in those that adopt a 231 Model.
Our approach
A Model works as a defence only if it describes safeguards that genuinely exist and that are actually checked. We therefore start with the processes, not the documents: we meet the function heads, reconstruct how decisions are taken in sensitive areas (procurement, sales to the public administration, personnel management, environment, tax, information systems) and measure the risk of each offence against the controls already in operation.
The gap analysis identifies what is missing against the requirements of the Confindustria guidelines and of case law. Only then do we write the General Part, the Special Parts, the code of ethics and the protocols, reusing what the company already has: ISO procedures, delegated authorities and powers of attorney, internal rules, GDPR measures. The result is a single control system, not a stack of parallel documents.
After adoption we support the Supervisory Body through the most delicate stage: implementation. Over time we maintain the audit plan, the information flows, the handling of reports and role-based training, with a point of contact who has known the system from the outset; where we provide a member of the OdV, that person is kept separate from those who drafted the Model. We update the Model whenever the predicate offences or the organisation change.
What sets our service apart
- Real safeguards, not boilerplate: the Model is built on interviews with process owners and on the controls already in operation, with a review of delegated authorities and signing powers; every protocol describes a safeguard that genuinely exists and that the OdV can verify.
- Integration: a single control system linking the 231 Model, GDPR, health and safety at work and the ISO 9001, 14001, 45001, 37001 and 37301 systems, with one audit calendar.
- Continuity: we do not stop when the Model is delivered; we continue to support the OdV and to look after training, whistleblowing and updates as legislation, predicate offences and the organisation change.
- Knowledge of regulated sectors: energy, telecommunications and services to the public administration involve specific sensitive activities that we know how to identify and bring under control.