Certificación del modelo de prevención de delitos y evaluación de tercero independiente (Ley 20.393), Anguita Osorio
Requisito de la Ley 20.393 para programas de compliance efectivos en Chile
Crime Prevention Model Certification: the Independent Third-Party Assessment
Following the reform introduced by Law 21.595, Article 4° N°4 of Law 20.393 requires that the Crime Prevention Model be subject to periodic assessments conducted by independent third parties. Without that review, the model loses its exculpatory value at trial, however sophisticated its documentary design may be.
Last updated:
This page walks through the independent third-party evaluation of the crime-prevention model: the legal reference and context under Law 20.393, what the review examines and how it is carried out, how it intersects with cybersecurity, data and sectoral duties, two contrasting cases, and the frequently asked questions.
Article 4° N°4 - Law N°20.393
"Provision for periodic assessments by independent third parties and improvement or update mechanisms based on such assessments."
Legal implication: Without periodic independent assessment, the Prevention Model cannot be invoked as an exemption from corporate criminal liability, regardless of its design or implementation.
Regulatory Context: Expansion and Normative Convergence
The starting point is what the evaluation implies for the company relative to the previous regime.
The catalog of offenses applicable to legal entities was multiplied by Law 21.595. A Prevention Model designed three years ago and never revisited is unlikely to cover today's criminal risks stemming from the 21.663 Cybersecurity Framework Law, the reform to Law 19.628 on personal data, or the new economic and environmental offenses. Independent assessment is the mechanism through which an organization demonstrates —before the Public Prosecutor's Office and the courts— that its risk matrix and its controls are kept current with this expanding regulatory landscape.
Constitutive Element of the CPM
Without evidence of external review, the model is deemed incomplete. Prosecutors and courts have refused to treat as an exemption programs that were never audited by a third party with verifiable independence.
Substantive Effectiveness Standard
The 'serious organizational failure' doctrine set by the Corpesca ruling requires distinguishing unused manuals from systems with documented operation. The evaluator must verify records, interview the prevention officer, and review actions taken in response to real alerts.
Transversal Regulatory Integration
Recent practice requires the evaluator to examine how the model articulates with sectoral obligations already under supervision —CMF, ANCI, SMA, FNE— so that a single incident does not catch the organization in two regulatory jurisdictions with misaligned defenses.
With that context set, the review follows a defined method and a set of guiding questions.
Assessment Standards: International Convergence and Local Practice
Chilean regulatory practice has progressively adopted international assessment criteria
International Reference Frameworks
Multiple recognized frameworks exist for compliance program assessment. The U.S. Department of Justice (DOJ) provides an example of criteria that distinguish between formal compliance and substantive effectiveness. Other frameworks include ISO 37001 (anti-bribery systems), ISO 37301 (compliance management systems), and OECD guidelines. Chilean jurisprudence has progressively adopted these international standards, as evidenced by the Corpesca case where a merely formal model was rejected.
Design adequacy for specific risks
Considering sectoral risk profile and applicable crime matrix
Autonomy and independence of the Prevention Officer
Critical element recognized in national jurisprudence as determinant of effectiveness
Empirical evidence of operation
Demonstration of effective operation beyond formal documentation
Strategic Implications of Independent Assessment
Assessment transcends formal compliance to constitute a corporate governance tool
Intersection with Specific Regulatory Frameworks
Independent assessment must consider the growing complexity of the Chilean regulatory environment. The prevention model operates at the intersection of multiple regulatory obligations that require integrated analysis:
Cybersecurity and Computer Crimes
Convergence between Law 21.595 (cybercrimes) and Law 21.663 (cybersecurity framework). Essential Services face dual obligations requiring coordinated assessment.
Personal Data Protection
Integration with Law 19.628 and future reform. Improper data processing can constitute both administrative infractions and crimes underlying criminal liability.
Sectoral Regulations
Coordination with specific frameworks: CMF for financial sector, SEC for energy, CNE, CEN, SMA for environment, DGA for water, SUBTEL for telecommunications, UAF for money laundering, SII, DT, FNE for antitrust, among others.
Independence and Technical Competence Criteria
Evaluator independence is not merely formal. It requires absence of conflicts of interest, demonstrable technical competence, and deep understanding of the applicable regulatory framework. Jurisprudence has emphasized that assessment must be substantive, not ceremonial.
How this plays out in practice can be seen by contrasting two cases.
Practical Application in Chile
DOJ methodology is already reflected in Chilean jurisprudence and regulatory practice
Successful Case: Antitrust - Supermarkets
In the supermarket collusion case, TDLC applied a fine reduction to Walmart, recognizing that its compliance program was 'comparatively very superior' and represented 'a very relevant advance'.
Lesson: A demonstrable investment in a robust and operational program has tangible benefits, being recognized by Chilean authorities.
Ineffective Program: Corruption - Corpesca Case
First legal entity convicted in oral trial in Chile. Despite having a CPM, the court qualified it as ineffective due to 'serious organizational defect'. The Prevention Officer had no autonomy to supervise senior management.
Lesson: The mere existence of manuals and nominal officer is irrelevant without genuine compliance culture and commitment from the highest level.
The questions that come up most often about scope, timing and independence are answered below.
Frequently asked questions
What is independent third-party evaluation?
It is the objective review of the crime-prevention model by an external evaluator, under Article 4 of Law 20.393. It verifies that the implemented model is suitable and operates effectively. After the Law 21.595 reform, the former certification regime was discontinued: what the law now contemplates is this periodic third-party evaluation, which provides evidence of the preventive diligence of the board and management.
Is there a crime prevention model certificate?
Not as an official document anymore. Law 21.595 eliminated the certification regime for crime prevention models. Its functional equivalent today is the independent third-party evaluation report: it evidences before prosecutors and courts that the model is suitable and operates effectively. That report, together with its findings and improvement plan, is the evidence the company presents to support its preventive diligence.
Is it mandatory?
It is not mandatory. Law 20.393 does not require it, but contemplates it as a way to evidence effective implementation of the model. In practice, companies facing significant regulatory exposure, operating in regulated sectors or participating in public procurement use it to reinforce their defense in possible indictments.
Who can perform the evaluation?
A party independent from the design and implementation of the model. The evaluator's autonomy and independence is essential: the same firm that designs or implements the model should not evaluate it, in order to preserve the objectivity of the judgment and its value as evidence of diligence.
What is evaluated?
The evaluation covers four axes: autonomy and resources of the prevention officer; consistency between the documented model and effective operations; coverage of the model against the applicable predicate-offense catalogue (including those incorporated by Law 21.595); and traceability of monitoring, training and reporting channels.
How much does it cost and how long does it take?
Cost and duration depend on company size, number of business units and prior model maturity. Typical engagements run six to twelve weeks and involve fieldwork, document review and interviews with key areas. Subsequent periodic evaluation benefits from the documentation generated in the first cycle.
Strategic Considerations for the Board
Independent assessment under Article 4° N°4 of Law 20.393 constitutes more than a legal requirement: it represents an opportunity to strengthen corporate governance and demonstrate genuine commitment to business integrity. In a context of growing regulatory complexity and expansion of the crime catalog, independent assessment becomes a critical risk management tool.
- Observed periodicity: Recommended practice suggests biennial assessments with annual follow-up, balancing the need for periodic review with operational continuity. The scope should consider intersection with specific sectoral obligations according to organizational risk profile.
Related services
Explore complementary practice areas and regulatory analysis from our team.
Corporate compliance
Prevention models, internal investigations and regulatory compliance.
Compliance diagnosis
Prioritized gaps against the obligations applicable to your business.
Labor compliance
Ley Karin programs, working time and Labor Directorate readiness.
Tax compliance
Tax obligations, the anti-avoidance rule and tax governance.
Corporate criminal liability
When the company is criminally liable, which penalties it faces and how it defends itself.
Law 20.393
What Law 20.393 is, which offenses it covers and how the company is exempted.
Economic Crimes Law (21.595)
Offense catalog, penalties and their impact on corporate liability.
Ley Karin (Law 21.643)
Prevention, investigation and sanction of sexual harassment, workplace harassment and violence.
Reconstruction Law
What the approved law contains: three time-limited windows, tax cuts and new operating rules.
Transform Your Legal Challenges into Competitive Advantages
Discover how our innovative approach can drive your business