Our Compliance Group Director, Yoab Bitran, spoke with Diario Financiero about companies’ growing focus on managing risks associated with suppliers and contractors.
The focus of business risks is shifting toward the supply chain, where suppliers and contractors have become a critical component for regulatory compliance, operational continuity, and corporate reputation.
Yoab Bitran, director of az’s compliance group, explains that this is a global trend and, by way of example, notes that in Europe today there are regulations requiring companies to assess risks, conduct due diligence, and monitor and report potential negative impacts on their value chains. “This regulatory framework may apply to companies in Chile, either because they are subsidiaries of European companies, have a presence in the European Union, or export products to the European Union,” he notes.
In Chile, Mariángela Pontigo—a lawyer, partner, and founder of C+Board—states that the amendment to Law 20,393 highlighted the importance within the business ecosystem of having in-depth knowledge of those who will provide services to a company, especially when they may act on its behalf. “Due diligence processes, which were previously focused mainly on preventing money laundering and terrorist financing, now play a cross-cutting role in business relationships,” Pontigo states. For this reason, she argues that risk management with third parties must be in place “before, during, and after,” as it is key to understanding the risks assumed by the client companies.
According to Héctor Juan Hernández, a partner at Compliance Metrics, this shift is not solely a response to stricter legal requirements. “We’ve also observed genuine maturity in the Chilean market regarding these matters,” he says, explaining that companies today prioritize working with suppliers and contractors who align with their ethical standards, have adequate controls in place, and—above all—will not become a potential reputational risk in the future. However, he notes that one of the most common mistakes is overconfidence.
Comprehensive Assessment
Ramón Montero, operations manager at BH Compliance, says that the most significant development is the shift from “onboarding” due diligence to continuous monitoring. “Today, suppliers are required to contractually adhere to codes of ethics, anti-corruption policies, crime prevention models, reporting and investigation obligations, and rules regarding confidentiality and data protection,” the executive explains. Among the most commonly used tools, he mentions third-party management platforms, open reporting channels, and periodic assessment systems based on risk indicators.
Pedro Trevisán, a forensic partner at Deloitte, agrees that companies are adopting a more structured approach in this area. Among the key practices they have adopted, he highlights the identification of critical suppliers, classifications by profile and risk category, the establishment of due diligence processes supported by open-source intelligence, databases, and public information, and the implementation of contractual control mechanisms.
“When it comes to data protection and cybersecurity, in many cases we are including an annex to the contract that governs the processing of personal data and its security,” adds Bitran.


