Logo AZ - 35 Años entregando soluciones legales

Compliance in Chile: From Regulatory Obligation to Strategic Management

Sep 11, 2026

We are sharing an interview with Yoab Bitran, director of our Compliance Group, for Compliance Latam, in which he provided an overview of the Chilean landscape in this area and progress toward an ethical culture.

In recent years, compliance in Chile has evolved beyond being viewed solely as a response to obligations related to corporate criminal liability. It has gradually established itself as a broader discipline, linked to comprehensive risk management, ethical culture, and organizations’ ability to anticipate corruption, money laundering, cybersecurity, data protection, and artificial intelligence. However, the challenge no longer lies solely in designing policies and controls, but in ensuring that these are known, utilized, and capable of effectively influencing behavior and decision-making.

In this interview, we spoke with Yoab Bitran, director of the Compliance Group at az—a firm representing ComplianceLatam in Chile—a lawyer from the University of Chile and a specialist in compliance, regulation, corporate governance, and business. With 15 years of experience in the field, Bitran has advised companies of various sizes and across different industries on the design, implementation, and evaluation of compliance programs, in addition to leading cultural transformation processes in organizations that have faced corruption cases.

His work has positioned him as an active advocate for ethical leadership and best practices in Chile and Latin America.

Based on your experience, what has been the most complex challenge you’ve faced in the area of compliance, and what lessons did you learn from it?

Working with companies that were emerging from compliance scandals. That taught me that, when it comes to compliance and ethical culture, changes are often gradual and long-term. If an in-house compliance leader comes in with the idea of making abrupt, substantive changes, they are very likely to end up losing support and being viewed by their peers as a disruptive threat to the business. It’s about evolution, not revolution. To lead substantive change, you have to build trust, forge alliances, cultivate political capital, and—very importantly—know which battles to fight.

You currently lead the compliance department at az. How would you define the role that a compliance professional should play within organizations?

Although it may sound obvious and is often repeated, a compliance professional must first and foremost be a strategic partner to the business. The moment they begin to be perceived as a “sheriff,” their effectiveness is negatively impacted. If people start avoiding or bypassing the compliance leader, it will be impossible to have a seat at the tables where relevant decisions are made.

How do you assess the maturity of compliance in Chile today, more than fifteen years after Law 20.393? What has truly changed in the market?

I think the main change is that compliance—albeit slowly—has begun to be understood as it is in more developed countries in this area. That is, it goes beyond the Economic Crimes Act and is viewed as a comprehensive and holistic discipline that allows for the management and mitigation of risks ranging from what we might call “traditional” risks—such as corruption or money laundering—to risks linked to the digital economy, such as cybersecurity or AI.

What would you say is the main weakness of compliance programs in Chile today?

In general, the main weakness is the very aspect that local and international regulations emphasize most: effectiveness. We still see many compliance documents that virtually no one in the company is familiar with, let alone uses. Many training sessions are conducted merely to check a box and have no impact on actual behavior. Many reporting channels that no one trusts. And here lies a duty for boards of directors, linked to their duty of care or diligence. Of course, they cannot be involved in day-to-day operations, but they must be able to rest assured that the organization has an effective compliance program in place.

If a company seriously wants to strengthen its compliance culture, where should it start?

The first step is to measure. To understand where we stand. Today, there are very robust tools and frameworks that allow us to measure ethical culture by combining quantitative and qualitative aspects. Then, based on the results, targeted strategies are defined and prioritized. One example that’s always important is the incentive structure. It’s key to reward both the “what” and the “how.”

New Risks and Challenges

In addition to compliance, you’ve developed solid expertise in data protection and cybersecurity. Why do you think these areas are becoming increasingly interconnected?

Because they share management tools: policies, procedures, training, due diligence, and so on. And, even more importantly, they share a common goal: to build and sustain an ethical culture that helps mitigate various risks. A culture of data protection, cybersecurity, and the prevention of corruption and money laundering—a culture free of harassment and more.

Chile has sectors with very specific risk exposures, such as mining, lithium, and concession-based infrastructure. What are the main compliance challenges in those sectors today?

The main challenges today are linked to third parties and the supply chain. First, there is the European Union’s recent regulation on the matter. This is especially relevant for subsidiaries of European companies in Latin America, as well as Latin American companies with a presence in Europe. Then there is the U.S. Department of Justice’s (DOJ) focus on cartels and their designation as terrorist organizations. And finally, Chile’s Economic Crimes Act itself establishes criminal liability for companies for crimes committed by third parties managing the organization’s affairs.

Personal data protection is undergoing significant regulatory changes in the region. What challenges do you foresee for companies in the coming years?

The main challenges are not technical in nature. It is not difficult to acquire or license systems and technologies that provide better protection. In this area, the weakest link in the chain continues to be the human factor. The vast majority of data breaches occur due to human error—for example, because someone negligently shared sensitive information, was irresponsible with a password, or clicked on a phishing link. Therefore, the main challenge is raising awareness and fostering a cultural shift regarding personal data protection.

What role is artificial intelligence playing in compliance programs, and what compliance risks are you seeing associated with its use?

From a compliance perspective, AI has this dual nature. On the one hand, using it (responsibly) in a compliance program is essential for improving effectiveness and efficiency. I would say that failing to use it in certain processes and controls actually undermines the effectiveness of the model. Take, for example, compliance due diligence processes—no one would imagine doing without tools and solutions that would set us back many years, to a time when everything was done manually.

On the other hand, there are risks associated with using AI without governance. We know there are significant risks related to bias, data protection, intellectual property, opacity, and lack of traceability (“black box”), among others.

The key lies in moving forward with strategy, governance, and human oversight, mitigating risks without hindering or squandering the enormous opportunities that AI offers.

What value does a digital platform and regional network like ComplianceLatam bring in a context where risks, regulations, and challenges transcend national borders?

ComplianceLatam enables leaders in legal and compliance departments across the region, the U.S., and Spain to access top-tier content, share best practices, learn from peers and thought leaders, and contribute ideas, opinions, and expertise toward a very noble cause.

Source: Compliance Latam, August 18. [See here]

Te podría interesar