Certificación del modelo de prevención de delitos y evaluación de tercero independiente (Ley 20.393), Anguita Osorio

Requisito de la Ley 20.393 para programas de compliance efectivos en Chile

Corporate compliance

Crime Prevention Model Certification: the Independent Third-Party Assessment

Following the reform introduced by Law 21.595, Article 4° N°4 of Law 20.393 requires that the Crime Prevention Model be subject to periodic assessments conducted by independent third parties. Without that review, the model loses its exculpatory value at trial, however sophisticated its documentary design may be.

Last updated:

This page walks through the independent third-party evaluation of the crime-prevention model: the legal reference and context under Law 20.393, what the review examines and how it is carried out, how it intersects with cybersecurity, data and sectoral duties, two contrasting cases, and the frequently asked questions.

Article 4° N°4 - Law N°20.393

"Provision for periodic assessments by independent third parties and improvement or update mechanisms based on such assessments."

Legal implication: Without periodic independent assessment, the Prevention Model cannot be invoked as an exemption from corporate criminal liability, regardless of its design or implementation.

Regulatory Context: Expansion and Normative Convergence

The starting point is what the evaluation implies for the company relative to the previous regime.

The catalog of offenses applicable to legal entities was multiplied by Law 21.595. A Prevention Model designed three years ago and never revisited is unlikely to cover today's criminal risks stemming from the 21.663 Cybersecurity Framework Law, the reform to Law 19.628 on personal data, or the new economic and environmental offenses. Independent assessment is the mechanism through which an organization demonstrates —before the Public Prosecutor's Office and the courts— that its risk matrix and its controls are kept current with this expanding regulatory landscape.

Constitutive Element of the CPM

Without evidence of external review, the model is deemed incomplete. Prosecutors and courts have refused to treat as an exemption programs that were never audited by a third party with verifiable independence.

Substantive Effectiveness Standard

The 'serious organizational failure' doctrine set by the Corpesca ruling requires distinguishing unused manuals from systems with documented operation. The evaluator must verify records, interview the prevention officer, and review actions taken in response to real alerts.

Transversal Regulatory Integration

Recent practice requires the evaluator to examine how the model articulates with sectoral obligations already under supervision —CMF, ANCI, SMA, FNE— so that a single incident does not catch the organization in two regulatory jurisdictions with misaligned defenses.

With that context set, the review follows a defined method and a set of guiding questions.

Assessment Standards: International Convergence and Local Practice

Chilean regulatory practice has progressively adopted international assessment criteria

International Reference Frameworks

Multiple recognized frameworks exist for compliance program assessment. The U.S. Department of Justice (DOJ) provides an example of criteria that distinguish between formal compliance and substantive effectiveness. Other frameworks include ISO 37001 (anti-bribery systems), ISO 37301 (compliance management systems), and OECD guidelines. Chilean jurisprudence has progressively adopted these international standards, as evidenced by the Corpesca case where a merely formal model was rejected.

Design adequacy for specific risks

Considering sectoral risk profile and applicable crime matrix

Autonomy and independence of the Prevention Officer

Critical element recognized in national jurisprudence as determinant of effectiveness

Empirical evidence of operation

Demonstration of effective operation beyond formal documentation

Strategic Implications of Independent Assessment

Assessment transcends formal compliance to constitute a corporate governance tool

Intersection with Specific Regulatory Frameworks

Independent assessment must consider the growing complexity of the Chilean regulatory environment. The prevention model operates at the intersection of multiple regulatory obligations that require integrated analysis:

Cybersecurity and Computer Crimes

Convergence between Law 21.595 (cybercrimes) and Law 21.663 (cybersecurity framework). Essential Services face dual obligations requiring coordinated assessment.

Personal Data Protection

Integration with Law 19.628 and future reform. Improper data processing can constitute both administrative infractions and crimes underlying criminal liability.

Sectoral Regulations

Coordination with specific frameworks: CMF for financial sector, SEC for energy, CNE, CEN, SMA for environment, DGA for water, SUBTEL for telecommunications, UAF for money laundering, SII, DT, FNE for antitrust, among others.

Independence and Technical Competence Criteria

Evaluator independence is not merely formal. It requires absence of conflicts of interest, demonstrable technical competence, and deep understanding of the applicable regulatory framework. Jurisprudence has emphasized that assessment must be substantive, not ceremonial.

How this plays out in practice can be seen by contrasting two cases.

Practical Application in Chile

DOJ methodology is already reflected in Chilean jurisprudence and regulatory practice

Successful Case: Antitrust - Supermarkets

In the supermarket collusion case, TDLC applied a fine reduction to Walmart, recognizing that its compliance program was 'comparatively very superior' and represented 'a very relevant advance'.

Lesson: A demonstrable investment in a robust and operational program has tangible benefits, being recognized by Chilean authorities.

Ineffective Program: Corruption - Corpesca Case

First legal entity convicted in oral trial in Chile. Despite having a CPM, the court qualified it as ineffective due to 'serious organizational defect'. The Prevention Officer had no autonomy to supervise senior management.

Lesson: The mere existence of manuals and nominal officer is irrelevant without genuine compliance culture and commitment from the highest level.

The questions that come up most often about scope, timing and independence are answered below.

Frequently asked questions

What is independent third-party evaluation?

It is the objective review of the crime-prevention model by an external evaluator, under Article 4 of Law 20.393. It verifies that the implemented model is suitable and operates effectively. After the Law 21.595 reform, the former certification regime was discontinued: what the law now contemplates is this periodic third-party evaluation, which provides evidence of the preventive diligence of the board and management.

Is there a crime prevention model certificate?

Not as an official document anymore. Law 21.595 eliminated the certification regime for crime prevention models. Its functional equivalent today is the independent third-party evaluation report: it evidences before prosecutors and courts that the model is suitable and operates effectively. That report, together with its findings and improvement plan, is the evidence the company presents to support its preventive diligence.

Is it mandatory?

It is not mandatory. Law 20.393 does not require it, but contemplates it as a way to evidence effective implementation of the model. In practice, companies facing significant regulatory exposure, operating in regulated sectors or participating in public procurement use it to reinforce their defense in possible indictments.

Who can perform the evaluation?

A party independent from the design and implementation of the model. The evaluator's autonomy and independence is essential: the same firm that designs or implements the model should not evaluate it, in order to preserve the objectivity of the judgment and its value as evidence of diligence.

What is evaluated?

The evaluation covers four axes: autonomy and resources of the prevention officer; consistency between the documented model and effective operations; coverage of the model against the applicable predicate-offense catalogue (including those incorporated by Law 21.595); and traceability of monitoring, training and reporting channels.

How much does it cost and how long does it take?

Cost and duration depend on company size, number of business units and prior model maturity. Typical engagements run six to twelve weeks and involve fieldwork, document review and interviews with key areas. Subsequent periodic evaluation benefits from the documentation generated in the first cycle.

Strategic Considerations for the Board

Independent assessment under Article 4° N°4 of Law 20.393 constitutes more than a legal requirement: it represents an opportunity to strengthen corporate governance and demonstrate genuine commitment to business integrity. In a context of growing regulatory complexity and expansion of the crime catalog, independent assessment becomes a critical risk management tool.

  • Observed periodicity: Recommended practice suggests biennial assessments with annual follow-up, balancing the need for periodic review with operational continuity. The scope should consider intersection with specific sectoral obligations according to organizational risk profile.

Transform Your Legal Challenges into Competitive Advantages

Discover how our innovative approach can drive your business

© 2026 AnguitaOsorio, all rights reserved.
Chile

Contact

Contáctanos

Phone:

+56 2 2760 4512

Location:

Cerro el Plomo 5420, office 1306, Las Condes, Metropolitan Region.