Evaluación Inicial de Cumplimiento Ley 21.595 | Anguita Osorio

Diagnóstico legal para identificar brechas regulatorias, riesgos penales y estructuras de control efectivas

Compliance service

Initial Compliance Assessment under Law 21.595

The initial assessment is the first methodological step in determining an organization's current state of regulatory compliance against the requirements of Law 21.595. This technical analysis identifies regulatory gaps, evaluates specific risk exposures and establishes a frame of reference for the implementation of appropriate controls.

Last updated:

This page walks through how a compliance diagnosis works, in four parts: the risk-management framework and the process it follows, the dimensions of analysis a technical assessment covers, the components of an effective evaluation and what it delivers, and the inherent-residual methodology behind the risk matrix. At the close are the frequently asked questions.

Compliance Risk Management

Systematic assessment of regulatory risk in accordance with international standards

Conceptual Framework for Risk Management

Compliance risk assessment requires a systematic approach that identifies, evaluates and prioritizes specific regulatory exposures. International standards such as ISO 37301:2021 and ISO 31000:2018 provide recognized methodological frameworks for the comprehensive management of compliance risk, integrating context assessment, threat identification and the design of appropriate controls.

On that framework, the diagnosis advances through three sequential stages.

  1. Risk Identification and Context

    Assessment of the organizational context, identification of sources of regulatory risk and analysis of the compliance environment. Determination of the universe of applicable risks according to business activity and sector exposures.

  2. Risk Analysis and Evaluation

    Analysis of the likelihood and impact of identified risks, evaluation of existing controls and determination of residual risk. Prioritization according to criteria of materiality and regulatory exposure.

  3. Treatment and Monitoring

    Evaluation of risk treatment options, analysis of control gaps and recommendations for the effective management of residual risk. Establishment of continuous monitoring metrics.

That process is applied across several dimensions, each with its own checkpoints.

Dimensions of Compliance Analysis

Fundamental components that require consideration in a comprehensive technical assessment

Organizational Structure

  • Clear definition of governance roles and responsibilities
  • Effective autonomy of the prevention officer
  • Independent reporting lines and direct communication
  • Appropriate allocation of resources for compliance

Risk Management

  • Systematic identification of regulatory exposures
  • Risk mapping against the taxonomy of economic crimes
  • Consideration of sector-specific risks
  • Materiality analysis and historical patterns

Internal Regulatory Framework

  • Policies that are current and appropriate to identified risks
  • Specific prevention and detection procedures
  • Investigation and incident response protocols
  • Adequate documentation of controls and processes

Organizational Culture and Conduct

  • Appropriate and effective training programs
  • Accessible and independent whistleblowing channels
  • Visible leadership commitment to ethics
  • Consistent and proportionate disciplinary systems

Sector Regulatory Framework

  • Specific financial supervision requirements (CMF)
  • Energy and utilities regulations (CNE, SEC)
  • Health and laboratory regulations (ISP, SEREMI)
  • Agricultural and food safety standards (SAG, ACHIPIA)
  • Environmental and forestry framework (CONAF, SMA)
  • Telecommunications regulation (SUBTEL)

Across those dimensions, a rigorous assessment produces a defined set of components.

Components of an Effective Technical Assessment

International best practice frameworks establish essential components for a rigorous technical assessment of compliance systems

Regulatory Compliance Analysis

Technical assessment against the specific requirements of Article 4 of Law No. 20.393 and the applicable taxonomy of economic crimes

Risk Exposure Matrix

Systematic identification and classification of regulatory risks by likelihood, impact and level of existing control

Regulatory Gap Assessment

Analysis of deficiencies between the current state and regulatory requirements, considering applicable sector standards

Technical Recommendations Framework

Identification of required regulatory elements: policies, procedures and controls in line with regulatory best practices

Compliance Governance Structure

Evaluation of lines of responsibility, autonomy of the prevention officer and reporting structure in accordance with legal requirements

Control Architecture

Analysis of preventive, detective and corrective controls appropriate to the identified organizational risk profile

The risk matrix at the center of those components rests on a widely used methodology.

Example: Inherent-Residual Methodology

One of the most widely used methodologies in risk management. Frameworks such as ISO 31000 and COSO exemplify this systematic approach, although multiple valid methodologies exist depending on the organizational context

  1. Step 1
    1. Inherent Risk

    The organization's natural exposure without considering existing controls. Calculated as Likelihood × Impact according to business activity and sector exposures.

  2. Step 2
    2. Control Evaluation

    Analysis of the effectiveness of existing policies, procedures and mitigation mechanisms. Includes preventive, detective and corrective controls according to the identified risk.

  3. Step 3
    3. Residual Risk

    The exposure that remains after considering the effectiveness of existing controls. It forms the basis for decisions on additional risk treatment and the prioritization of resources.

Methodological Diversity:

There are multiple valid approaches to risk assessment, including asset-based methodologies, situational analysis, threat assessment, and quantitative versus qualitative models. The inherent-residual methodology is one of the most widely used approaches in regulatory environments, but the selection of the appropriate approach must consider the organizational context, the sector of activity and the specific objectives of the assessment.

The questions below cover the most common points about scope, timing and outputs.

Frequently asked questions

What is a compliance diagnosis?

A compliance diagnosis is an initial technical assessment that compares the current state of an organization's controls, policies and governance with the requirements of Law 20.393 and Law 21.595, identifying regulatory gaps, residual risks and remediation priorities. It is delivered as a findings matrix with a roadmap prioritized by materiality and exposure.

When should a diagnosis be conducted?

At least four moments warrant it: before implementing a prevention model for the first time; after a new predicate offense enters into force (as happened with Law 21.595); after a significant change in operations or corporate perimeter (M&A, sector expansion); and as a recommended periodic review every 18 to 24 months.

What methodology is used?

The diagnosis is structured on recognized international standards (ISO 37301:2021 on compliance management systems, ISO 31000:2018 on risk management and the U.S. Department of Justice guidance on Evaluation of Corporate Compliance Programs) adapted to the Chilean legal framework and the organization's risk profile.

What does the diagnosis produce?

The final deliverable is a technical report containing: a risk matrix per predicate offense; a gap analysis against Law 20.393 and Law 21.595; an evaluation of organizational structure, controls and compliance culture; and a remediation roadmap prioritized by materiality, with effort estimates and proposed milestones.

How long does a diagnosis take?

A standard diagnosis for a mid-sized company takes between four and six weeks, depending on scope, number of business units and the availability of documentation and counterparts. Larger engagements (corporate groups, multi-country presence or regulated sectors) extend the timeline accordingly.

Transform Your Legal Challenges into Competitive Advantages

Discover how our innovative approach can drive your business

© 2026 AnguitaOsorio, all rights reserved.
Chile

Contact

Contáctanos

Phone:

+56 2 2760 4512

Location:

Cerro el Plomo 5420, office 1306, Las Condes, Metropolitan Region.