Compliance 231

We have developed the expertise required to provide an innovative approach to compliance under Legislative Decree 231/2001.

Thanks to the experience of our professionals, we provide a wide range of services, from risk assessment aimed at identifying the main sensitive activities, to the preparation of the Organisation, Management and Control Model using legal tech tools, as well as assistance in establishing information flows between the Supervisory Body (OdV) and the company and managing whistleblowing processes. We also assist with the implementation of 231 procedures and support Supervisory Bodies in which we may participate as members. We also provide training on these matters.

What we do

  • Risk assessment and gap analysis — mapping of areas and activities at risk of criminal offences.
  • Drafting and updating of the 231 Model — general and special sections, protocols, and control measures.
  • High-risk areas — cybercrime, offences against public authorities, corporate and tax offences, environmental offences, and workplace health and safety.
  • Support for the Supervisory Body (OdV) — assistance, design of information flows, and training.
  • Integration — coordination of the Model with NIS2, AML, and data protection requirements.
  • Defence of the entity — assistance in proceedings against the entity.
  • Legislative Decree 231/2001. Establishes the administrative liability of entities for criminal offences. An adequate and effectively implemented Model, together with an effective Supervisory Body (OdV), is the basis for exemption from liability.
  • Predicate offences. An ever-expanding catalogue. Art. 24-bis (cybercrime and unlawful processing of data) is particularly relevant, with its sanctions strengthened by Law 90/2024.
  • Coordination with NIS2 — Legislative Decree 138/2024. Cybersecurity obligations have implications for 231 protocols concerning information systems. See the Cybersecurity and NIS practice.
  • Coordination with AML and data protection. Legislative Decree 231/2007 and the GDPR share processes, controls, and reporting flows to the Supervisory Body with the 231 Model.

How we work

A 231 Model is judged by how it is implemented, not by how it is written. We design it to work within the entity’s processes and remain up to date as offences and technologies evolve.

Would you like to be contacted?


Contact information