Compliance & Governance

Italian Legislative Decree 231 Compliance

Design, updating and maintenance of the Organisation, Management and Control Model required by Italian Legislative Decree 231/2001, working alongside management: predicate offence risk assessment, protocols, code of ethics, whistleblowing and support for the Supervisory Body (OdV).

What we do

Our areas of work

Predicate offence risk assessment

We map the sensitive activities in each risk area (public administration, financial reporting and corporate matters, health and safety at work, environment, tax, information systems) and assess likelihood and impact with the direct involvement of function heads.

Gap analysis and Model design

We compare existing controls with the safeguards expected under the Confindustria guidelines (the reference standard set by the Italian employers’ federation), then draft the General Part and the Special Parts of the Model, tailored to how the organisation actually works and not to off-the-shelf templates.

Code of ethics, protocols and disciplinary system

We draft the code of ethics, the decision-making protocols for high-risk areas and the disciplinary system, aligning them with delegated authorities, powers of attorney, ISO procedures and internal rules already in use across the company.

Support for the Supervisory Body

We support the OdV on its audit plan, information flows and reporting to the board; on request we provide an external member, kept separate from those who drafted the Model in order to safeguard the Body’s independence, or we run its technical secretariat.

Whistleblowing and reporting channels

We design the internal channel required by Italian Legislative Decree 24/2023 and by the guidelines issued by ANAC (the Italian anti-corruption authority): platform or procedure, an independent and trained case handler, trade union consultation, confidentiality for the whistleblower, handling of reports and links to the OdV and the disciplinary system.

Training and ongoing updates

We train the board, managers and operational staff with role-specific content, and update the Model whenever the predicate offences, the organisation or the business processes change.

The regulatory framework

Italian Legislative Decree 231/2001 introduced the administrative liability of entities for offences committed, in their interest or to their advantage, by persons holding functions of representation, administration or management, including on a de facto basis, or by those subject to their direction or supervision (Article 5). The company is liable in its own right, alongside the individual, facing financial penalties calculated by quotas and disqualification penalties that directly affect day-to-day operations: suspension of authorisations, a ban on contracting with the public administration, exclusion from grants and public funding and, at the extreme, disqualification from carrying on the business.

The catalogue of predicate offences has widened over the years and today covers, among others, areas that touch every business: offences against the public administration and bribery (Articles 24 and 25), computer crime (Article 24-bis), corporate offences (Article 25-ter), involuntary manslaughter and serious or very serious negligent injury committed in breach of health and safety at work legislation (Article 25-septies), receiving stolen goods, money laundering and self-laundering (Article 25-octies), offences relating to non-cash means of payment (Article 25-octies.1), environmental offences (Article 25-undecies), the employment of third-country nationals staying irregularly (Article 25-duodecies), tax offences (Article 25-quinquiesdecies), smuggling (Article 25-sexiesdecies) and offences against cultural heritage (Article 25-septiesdecies).

Articles 6 and 7 set out the route to excluding liability: having adopted and effectively implemented, before the event, an Organisation, Management and Control Model capable of preventing the offences, and having given a Supervisory Body (Organismo di Vigilanza, OdV) vested with autonomous powers the task of overseeing how the Model works and whether it is complied with. Linked to this framework are Italian Legislative Decree 81/2008 (Article 30) on health and safety at work and Italian Legislative Decree 24/2023 on whistleblowing, which requires internal reporting channels in entities that had an average of at least fifty employees in the past year, in those operating in sectors regulated by European Union law (financial services, anti-money laundering, transport safety, environmental protection) and in those that adopt a 231 Model.

Our approach

A Model works as a defence only if it describes safeguards that genuinely exist and that are actually checked. We therefore start with the processes, not the documents: we meet the function heads, reconstruct how decisions are taken in sensitive areas (procurement, sales to the public administration, personnel management, environment, tax, information systems) and measure the risk of each offence against the controls already in operation.

The gap analysis identifies what is missing against the requirements of the Confindustria guidelines and of case law. Only then do we write the General Part, the Special Parts, the code of ethics and the protocols, reusing what the company already has: ISO procedures, delegated authorities and powers of attorney, internal rules, GDPR measures. The result is a single control system, not a stack of parallel documents.

After adoption we support the Supervisory Body through the most delicate stage: implementation. Over time we maintain the audit plan, the information flows, the handling of reports and role-based training, with a point of contact who has known the system from the outset; where we provide a member of the OdV, that person is kept separate from those who drafted the Model. We update the Model whenever the predicate offences or the organisation change.

What sets our service apart

  • Real safeguards, not boilerplate: the Model is built on interviews with process owners and on the controls already in operation, with a review of delegated authorities and signing powers; every protocol describes a safeguard that genuinely exists and that the OdV can verify.
  • Integration: a single control system linking the 231 Model, GDPR, health and safety at work and the ISO 9001, 14001, 45001, 37001 and 37301 systems, with one audit calendar.
  • Continuity: we do not stop when the Model is delivered; we continue to support the OdV and to look after training, whistleblowing and updates as legislation, predicate offences and the organisation change.
  • Knowledge of regulated sectors: energy, telecommunications and services to the public administration involve specific sensitive activities that we know how to identify and bring under control.

Our method

How we work

  1. Kick-off and scope

    We meet the board and the key functions, collect the organisation chart, delegated authorities, procedures and existing certifications, and define the scope, timescales and points of contact for the project.

  2. Mapping and risk assessment

    Structured interviews with process owners to identify sensitive activities, the offences that could in principle arise, the controls in place and the residual risk in each area.

  3. Gap analysis and action plan

    A report setting out the shortfalls against the expected safeguards, ranked by priority, and an agreed action plan with responsibilities and deadlines for building or updating the Model.

  4. Drafting and adoption

    We write the Model, the code of ethics, the protocols and the disciplinary system, validate them with the functions involved and support the board in the resolution adopting the Model and in appointing the OdV.

  5. Implementation and oversight

    Training, launch of the information flows and of the whistleblowing channel, the OdV audit plan and periodic updates as legislation, predicate offences and the organisation change.

Benefits

What the business gains

  • A Model that can be defended in court, built on real and documented safeguards rather than on boilerplate
  • Protection of assets and business continuity against financial and disqualification penalties
  • A scoring advantage in public tenders and for the legality rating, often required in the supplier qualification processes of major clients
  • Controls integrated with GDPR, health and safety at work and ISO systems, with no duplication of procedures or audits
  • A single point of contact for the board, the OdV and operational functions on every corporate liability matter

Deliverables

What we deliver

  • Map of sensitive activities and risk assessment matrix by predicate offence
  • Gap analysis report with a prioritised action plan
  • Organisation, Management and Control Model: General Part and Special Parts
  • Code of ethics and disciplinary system aligned with the applicable Italian national collective labour agreement (CCNL)
  • Protocols and procedures for high-risk areas, with a review of delegated authorities and signing powers
  • OdV charter, audit plan and map of information flows
  • Whistleblowing procedure and configuration of the internal reporting channel
  • Training plan with materials, knowledge tests and attendance records

Frequently asked questions

Answers to the questions we hear most often

Is a 231 Model mandatory?

As a general rule no: the decree does not make it compulsory, although some regional and sector rules do require it (healthcare accreditation in certain Italian regions, for example). Without a Model the entity is liable for offences committed in its interest or to its advantage, facing financial and disqualification penalties. The Model can exclude liability (Articles 6 and 7) only if it was adopted before the event, effectively implemented and overseen by an autonomous OdV; for offences committed by senior management it must also be proven that the perpetrators fraudulently circumvented it.

We are an SME: does a 231 Model make sense at our size?

Yes, if the company operates in exposed areas: dealings with the public administration, public contracts, construction sites, waste, complex tax matters. The decree allows proportionate solutions: in small entities the management body may perform the duties of the OdV directly (Article 6(4)). We tailor the Model to the actual exposure, without oversized structures.

Who can sit on the Supervisory Body?

People who meet the requirements of autonomy, independence, professionalism and continuity of action: external professionals, internal members with no operational duties in high-risk areas or, in companies with share capital, the board of statutory auditors (Article 6(4-bis)). The Body may be made up of a single member or of several. On request we can provide an external member or support the OdV with its technical secretariat.

We adopted a Model years ago: is updating it enough?

It depends on the state it is in. Since then, new predicate offences have entered the catalogue (tax, smuggling, cultural heritage), whistleblowing has changed with Italian Legislative Decree 24/2023 and the organisation is often no longer the same. A focused assessment tells us whether additions will suffice or whether the Model needs rewriting: a document that has not been kept up to date risks not standing up as a defence.

How long does the project take and how much of our people’s time does it require?

It depends on the size of the company, on the number of sensitive areas and on the documentation already available. For an SME with a single site and straightforward processes, mapping, gap analysis and drafting generally take a few months; groups with several companies or complex operations take longer. Internal effort is concentrated in the interviews with function heads and in validating the protocols: timescales and points of contact are set out in the initial proposal.

Let’s talk

Together, let’s build your tomorrow.

Tell us your business priorities: in a first meeting with no obligation we look at your context and propose a concrete way forward, with clear timescales and measurable results.