Evaluación Inicial de Cumplimiento Ley 21.595 | Anguita Osorio
Diagnóstico legal para identificar brechas regulatorias, riesgos penales y estructuras de control efectivas
Initial Compliance Assessment under Law 21.595
The initial assessment is the first methodological step in determining an organization's current state of regulatory compliance against the requirements of Law 21.595. This technical analysis identifies regulatory gaps, evaluates specific risk exposures and establishes a frame of reference for the implementation of appropriate controls.
Last updated:
This page walks through how a compliance diagnosis works, in four parts: the risk-management framework and the process it follows, the dimensions of analysis a technical assessment covers, the components of an effective evaluation and what it delivers, and the inherent-residual methodology behind the risk matrix. At the close are the frequently asked questions.
Compliance Risk Management
Systematic assessment of regulatory risk in accordance with international standards
Conceptual Framework for Risk Management
Compliance risk assessment requires a systematic approach that identifies, evaluates and prioritizes specific regulatory exposures. International standards such as ISO 37301:2021 and ISO 31000:2018 provide recognized methodological frameworks for the comprehensive management of compliance risk, integrating context assessment, threat identification and the design of appropriate controls.
On that framework, the diagnosis advances through three sequential stages.
- Risk Identification and Context
Assessment of the organizational context, identification of sources of regulatory risk and analysis of the compliance environment. Determination of the universe of applicable risks according to business activity and sector exposures.
- Risk Analysis and Evaluation
Analysis of the likelihood and impact of identified risks, evaluation of existing controls and determination of residual risk. Prioritization according to criteria of materiality and regulatory exposure.
- Treatment and Monitoring
Evaluation of risk treatment options, analysis of control gaps and recommendations for the effective management of residual risk. Establishment of continuous monitoring metrics.
That process is applied across several dimensions, each with its own checkpoints.
Dimensions of Compliance Analysis
Fundamental components that require consideration in a comprehensive technical assessment
Organizational Structure
- Clear definition of governance roles and responsibilities
- Effective autonomy of the prevention officer
- Independent reporting lines and direct communication
- Appropriate allocation of resources for compliance
Risk Management
- Systematic identification of regulatory exposures
- Risk mapping against the taxonomy of economic crimes
- Consideration of sector-specific risks
- Materiality analysis and historical patterns
Internal Regulatory Framework
- Policies that are current and appropriate to identified risks
- Specific prevention and detection procedures
- Investigation and incident response protocols
- Adequate documentation of controls and processes
Organizational Culture and Conduct
- Appropriate and effective training programs
- Accessible and independent whistleblowing channels
- Visible leadership commitment to ethics
- Consistent and proportionate disciplinary systems
Sector Regulatory Framework
- Specific financial supervision requirements (CMF)
- Energy and utilities regulations (CNE, SEC)
- Health and laboratory regulations (ISP, SEREMI)
- Agricultural and food safety standards (SAG, ACHIPIA)
- Environmental and forestry framework (CONAF, SMA)
- Telecommunications regulation (SUBTEL)
Across those dimensions, a rigorous assessment produces a defined set of components.
Components of an Effective Technical Assessment
International best practice frameworks establish essential components for a rigorous technical assessment of compliance systems
Regulatory Compliance Analysis
Technical assessment against the specific requirements of Article 4 of Law No. 20.393 and the applicable taxonomy of economic crimes
Risk Exposure Matrix
Systematic identification and classification of regulatory risks by likelihood, impact and level of existing control
Regulatory Gap Assessment
Analysis of deficiencies between the current state and regulatory requirements, considering applicable sector standards
Technical Recommendations Framework
Identification of required regulatory elements: policies, procedures and controls in line with regulatory best practices
Compliance Governance Structure
Evaluation of lines of responsibility, autonomy of the prevention officer and reporting structure in accordance with legal requirements
Control Architecture
Analysis of preventive, detective and corrective controls appropriate to the identified organizational risk profile
The risk matrix at the center of those components rests on a widely used methodology.
Example: Inherent-Residual Methodology
One of the most widely used methodologies in risk management. Frameworks such as ISO 31000 and COSO exemplify this systematic approach, although multiple valid methodologies exist depending on the organizational context
- Step 11. Inherent Risk
The organization's natural exposure without considering existing controls. Calculated as Likelihood × Impact according to business activity and sector exposures.
- Step 22. Control Evaluation
Analysis of the effectiveness of existing policies, procedures and mitigation mechanisms. Includes preventive, detective and corrective controls according to the identified risk.
- Step 33. Residual Risk
The exposure that remains after considering the effectiveness of existing controls. It forms the basis for decisions on additional risk treatment and the prioritization of resources.
Methodological Diversity:
There are multiple valid approaches to risk assessment, including asset-based methodologies, situational analysis, threat assessment, and quantitative versus qualitative models. The inherent-residual methodology is one of the most widely used approaches in regulatory environments, but the selection of the appropriate approach must consider the organizational context, the sector of activity and the specific objectives of the assessment.
The questions below cover the most common points about scope, timing and outputs.
Frequently asked questions
What is a compliance diagnosis?
A compliance diagnosis is an initial technical assessment that compares the current state of an organization's controls, policies and governance with the requirements of Law 20.393 and Law 21.595, identifying regulatory gaps, residual risks and remediation priorities. It is delivered as a findings matrix with a roadmap prioritized by materiality and exposure.
When should a diagnosis be conducted?
At least four moments warrant it: before implementing a prevention model for the first time; after a new predicate offense enters into force (as happened with Law 21.595); after a significant change in operations or corporate perimeter (M&A, sector expansion); and as a recommended periodic review every 18 to 24 months.
What methodology is used?
The diagnosis is structured on recognized international standards (ISO 37301:2021 on compliance management systems, ISO 31000:2018 on risk management and the U.S. Department of Justice guidance on Evaluation of Corporate Compliance Programs) adapted to the Chilean legal framework and the organization's risk profile.
What does the diagnosis produce?
The final deliverable is a technical report containing: a risk matrix per predicate offense; a gap analysis against Law 20.393 and Law 21.595; an evaluation of organizational structure, controls and compliance culture; and a remediation roadmap prioritized by materiality, with effort estimates and proposed milestones.
How long does a diagnosis take?
A standard diagnosis for a mid-sized company takes between four and six weeks, depending on scope, number of business units and the availability of documentation and counterparts. Larger engagements (corporate groups, multi-country presence or regulated sectors) extend the timeline accordingly.
Transform Your Legal Challenges into Competitive Advantages
Discover how our innovative approach can drive your business