Our Compliance Group Director, Yoab Bitran, spoke with Diario Financiero about the evolution and impact of the Economic Crimes Act on companies three years after its enactment.
Three years ago, the enactment of the Economic Crimes Act tightened the regulations governing economic crimes and introduced changes to the criminal liability of legal entities, which took effect in September 2024. The new landscape prompted companies to review their prevention models and strengthen risk management, including risks associated with suppliers, contractors, and other third parties.
“There are greater incentives to adopt crime prevention models, especially since the amended text expressly states that the existence of an effective and implemented system exempts legal entities from criminal liability,” says Ximena Marcazzolo, a research professor at the Center for Regulatory and Business Law at the University of Desarrollo Law School.
The process is in full swing, driven primarily by commercial rather than criminal implications, says Ricardo Ibáñez, the founding attorney of Grupo Defensa.cl. “Companies have gotten their processes in order when a bank asked them for their prevention model to renew a line of credit, when a major client included it in the terms of a bid, when it came up in a due diligence review, or when an insurer inquired about corporate governance before quoting a directors’ liability policy,” he says, which explains why progress has been so uneven.
For Rebeca Zamora, a partner at HD Compliance, reputation remains a decisive intangible in Chile, and the law has added an economic incentive: “The forfeiture of profits and daily fines are designed to ensure that committing a crime is never a better business decision than operating within the legal framework. That awareness is most acute among those who have already experienced a crisis due to noncompliance that was both penalized and publicly exposed.”
For her part, Sara Huerta, a partner at HD Compliance, notes that new controls are being implemented for third parties to prevent a supplier from exposing the company to criminal liability: “This means hours of work on due diligence processes that didn’t exist before or were less rigorous, and platforms that automate risk analysis based on public information,” in addition to more training for boards of directors to “understand the criminal and civil liability associated with their role.”
For Yoab Bitran, director of az’s Compliance Group, most due diligence processes incorporate compliance aspects aimed at safeguarding the legal entity from potential liability. “Furthermore, today’s technology greatly facilitates these tasks. The same applies to contractual clauses that require counterparties to adopt certain standards and make compliance declarations,” he says.
What’s Next
Despite the progress, there are still challenges in integrating prevention models into day-to-day practices in a way that drives changes in decisions and behavior, says attorney Paulo García Huidobro, legal director at Cultura Compliance. “That requires a genuine commitment from the board of directors and senior management,” he emphasizes.
A common mistake is to delegate this entire aspect to the compliance officer and continue making commercial, financial, or operational decisions without considering the criminal risk: “It’s also key that reporting channels inspire real trust, and that training goes beyond simply explaining the law,” he notes.
Bitran adds that there are underestimated risks, such as those involving third parties related to cybersecurity, data protection, and the use of AI: “Beyond the likely postponement of the Data Protection Law’s effective date, the reputational risk cannot be postponed.”



