Contact us

une19601

Criminal Compliance: From Having a Model to Proving It Works

Does your company have a criminal prevention model that actually works in practice, or a document that no one has opened since it was approved?

The difference matters. Article 31 bis of the Penal Code requires that the policy have been adopted and effectively implemented before the crime is committed. Adopting policies is only the beginning: they must be applied in day-to-day operations and kept up to date.

Why Implement a Criminal Compliance System

A well-established system helps identify risks, establish controls, assign responsibilities, and detect irregularities. It also helps respond when something goes wrong: investigate what happened, decide what measures to take, and correct any deficiencies that are identified.

If the company faces an investigation, it will need to demonstrate what measures it had taken and how it implemented them. An approved policy alone does not prove that employees received training, that controls were implemented, or that alerts were addressed.

UNE 19601 and ISO 37301: Two Complementary Frameworks

UNE 19601 establishes requirements specifically for managing criminal compliance. ISO 37301 provides a broader framework for managing an organization’s compliance obligations. Together, they make it possible to integrate criminal prevention into a management system that is consistent with the company’s other obligations.

Standards provide structure and evaluation criteria. Certification may serve as an additional factor in evaluating the system, but it does not replace an analysis of how the system functions in a specific case, nor does it guarantee exemption from criminal liability.

From Model to Operations

A dynamic system identifies risks, assigns controls and responsible parties, trains the people involved, monitors implementation, manages alerts, and reviews results. When the company’s operations change or a deficiency is detected, the model must also be revised.

Let’s consider a possible irregularity in the hiring of a third party. The procedure describes what should happen. An operational system makes it possible to verify what actually happened: who received the alert, when it was reviewed, what decision was made, and what actions were taken.

Proof that it works

Training records, control reviews, incidents, decisions, and improvement actions make it possible to track the system’s activity. This traceability helps monitor the system and, if necessary, demonstrate how the organization responded.

Criminal compliance doesn’t end when the policy is approved. It begins when the company incorporates it into its operations.

Delivering is important. Being able to show how you deliver, when it counts, is important too.

At ithikios, we work to make that process easier: connecting risks, controls, alerts, decisions, and evidence within a single workflow, without having to reconstruct later what each person did.

Related articles

How many hours will a compliance job that currently requires 40 hours take in five years? If the answer is 20, 10, or even 5, the challenge facing many consulting...

For years, compliance has been built around regulations, policies, procedures, and audits. Organizations would identify the obligations that applied to them, prepare the necessary documentation, and periodically review their compliance....

Do you want to try our whistleblower channel?

Do it from here for 15 days, without commitment, without cards,…

Want to see how ithikios can help you?

Get started today. Be compliant within hours. And when you grow up, ithikiosis with you.