ARGO INVESTIGATIONS

Legislative Decree 231/2001

Corporate Investigations: Administrative Liability of Entities

Legislative Decree 231/01 — the administrative liability of entities for crimes committed by employees in the interest or to the advantage of the entities themselves — and the adoption of effective behavioral models to avoid incurring this type of liability.

 

What is meant by administrative liability of entities, and what is the scope of application of the regulation?

The topics of corporate compliance and the administrative liability of companies have long belonged to the Anglo-Saxon economic culture, while only recently have they become part of political and media debates, and later of the Italian legal system. The growing phenomenon of economic crime, increasingly recorded since the 1970s, prompted European community institutions to introduce measures against entities that benefited from crimes committed by their employees.

Attention to these issues grew because the phenomenon no longer affected only illegal enterprises, those with criminal purposes, but also organizations and institutions that, although pursuing legitimate goals, committed offenses to achieve their corporate objectives. This led EU legislators to encourage member states to issue laws directly sanctioning companies or entities behaving in such a manner.

On these grounds, Italy passed Delegation Law No. 300/2000, which introduced into the Italian legal system the concept of entity liability for offenses arising from crimes. This Copernican revolution was the result of a long doctrinal debate, largely developed outside Italy, and took concrete form thanks to the push of supranational bodies and institutions on national lawmakers. This law marked a historic turning point in the Italian legal system, which had always been reluctant to accept the principle of corporate liability, based on the ancient maxim “societas delinquere non potest” (“a company cannot commit crimes”).

By overcoming this traditional principle excluding the direct liability of legal persons, the legislature established the administrative liability of entities as autonomous and independent from that of the natural person acting in the entity’s name and interest. Legislative Decree 231/2001 specifically introduced the possibility for companies to adopt organizational, management, and control models to prevent the commission of the crimes covered by the decree. In other words, the legislature provided that an entity could be exempt from liability if it adopted an organizational, management, and control system capable of preventing crimes by its employees.

The scope of Legislative Decree 231/01 extends to crimes committed in the interest or to the advantage of entities with legal personality, companies with legal personality, and associations even without legal personality. The State, territorial public entities, and entities performing functions of constitutional importance are excluded from this regulation.

An entity is also exempt from liability if the individual committed the crime solely for personal gain or for the benefit of third parties. In particular, regarding crimes committed in the interest or to the advantage of entities, the regulation applies both to ordinary employees and to individuals holding positions of representation, administration, or management of the entity or one of its financially and functionally autonomous units, or exercising, even de facto, management and control (Art. 5(a)), as well as persons under their supervision or direction (Art. 5(b)). For these latter subjects, Legislative Decree 231/01 establishes the administrative liability of the entity for crimes committed in its interest or to its advantage.

 

The essential nature of organizational, management, and control models for crime prevention within companies

Under current law, the entity bears the burden of proving that the alleged crimes are not attributable to it. To do so, it must demonstrate that, before the offense occurred, it had adopted and effectively implemented organizational, management, and control models capable of preventing the commission of such crimes, and that it constantly monitored their proper application.

Specifically, achieving this goal requires establishing within the company an autonomous supervisory body with oversight powers. The adoption of valid models therefore constitutes grounds for exemption from liability. Article 6 provides that if the crime was committed by individuals in senior positions (Art. 5(a)), the entity must prove that it had nonetheless adopted organizational, management, and control models suitable for preventing such crimes.

In such cases, the entity must show that management committed the offense fraudulently evading the preventive protocols, and that the supervisory body was neither negligent nor derelict in its duties. Article 7 specifies that if the crime was committed by an employee, proof of fraudulent evasion of protocols is not required, though the other proofs remain necessary.

The entity must therefore have an organizational, management, and control model characterized by efficiency, practicality, and functionality, reasonably capable of reducing the likelihood of crimes within the company’s risk areas. It must also have an internal body (supervisory body) responsible for monitoring and initiating control measures, with full autonomy in supervision and disciplinary powers. This model must:

  1. Identify activities within which crimes may be committed;
  2. Establish specific protocols governing decision-making processes related to crime prevention;
  3. Define financial management procedures designed to prevent criminal acts;
  4. Include information obligations toward the supervisory body, introduce a disciplinary system sanctioning noncompliance with the model’s measures, and assign responsibility for monitoring its functioning to an independent internal body.

 

Identifying risk-prone activities and formalizing them in an effective control system aims to:

  1. Make everyone operating on behalf of the entity aware of the risks of committing offenses punishable by criminal or administrative sanctions, both personally and for the company;
  2. Reinforce that such illicit behavior is strongly condemned by the entity as contrary not only to law but also to the ethical and social principles guiding its mission;
  3. Enable the company, through risk-area monitoring, to intervene promptly to prevent or counter the commission of such crimes.

 

One goal of the Model is thus to instill among employees, corporate bodies, external collaborators, and partners operating on behalf of or in the interest of the entity in risk-prone areas, the importance of respecting roles, procedures, protocols, and the adopted organizational model. For these provisions to be effective, they must not be generic or abstract but must include practical measures consistent with their objectives.

Ultimately, it is up to the criminal judge to assess whether an entity’s behavioral codes meet the criteria in Art. 6(2) of Legislative Decree 231. The design and implementation of the Model must therefore effectively fulfill the preventive purpose envisioned by the law.

The Model must thus constitute a structured and coherent system of procedures and controls—both preventive and corrective—aimed at reducing the risk of crimes under the Decree. These control programs must be continuously monitored, reviewed, and updated in response to new business areas or related activities. Legislative Decree 231/2001 therefore aims to assign economic operators a “guarantor” role, promoting ethical and lawful business conduct to prevent economic crimes.

In conclusion, for a company to be deemed unrelated to offenses committed by an employee, it must not only demonstrate that it adopted serious and effective models capable of preventing crimes, but also that it exercised proper oversight to prevent illicit acts.

 

The importance of relying on professionals, such as a certified investigative agency, in drafting organizational, management, and control models

A company equipped with a solid compliance model gains a dominant value both in the market and ethically: its adherence to the law encourages other companies to do the same and serves as a positive example to society. A strong compliance culture also fosters positive employee attitudes at all organizational levels.

Engaging an investigative agency such as Argo allows your company to rely on qualified professionals with proven experience in developing such models—now essential for modern enterprises. Below are the guidelines we follow in designing these models:

  • Definition of principles and rules for creating a Corporate Code of Ethics
  • Process and Risk Assessment Analysis and Development: Argo’s consulting activity begins with an assessment process through which, together with the client, a corporate check-up identifies crime-risk areas and plans the necessary actions consistent with corporate goals.
  • Crisis & Risk Management Evaluations: After auditing analysis, behavioral and assessment protocols are developed to manage risks and prevent crises, including workplace safety, environmental, health, and IT risks.
  • Identification, appointment, and activation of an autonomous and independent supervisory body: Through the establishment of an internal Supervisory Body, constant monitoring of employee compliance with designed models is ensured, including periodic evaluations and reporting on program effectiveness and ethics compliance.
  • Communication of the model, employee training, continuous optimization, and updating: Argo identifies the best methods to communicate and train employees at all organizational levels—including senior management—on model provisions. Procedures are updated periodically.

 

Finally, Argo’s approach emphasizes the company’s awareness and obligation, after detecting offenses, to adopt reasonable measures to respond appropriately and prevent similar behavior in the future, revising the program if necessary to improve compliance. In essence, this operational method enables companies to avoid incurring liability for employee misconduct.

In conclusion, the Argo investigative agency knows how to draft measures capable of preventing, detecting, and sanctioning unlawful conduct by employees against the company, thus protecting it from liability arising from disloyal staff.

 

Notes

[1] The Italian legislator, in defining the type of liability incurred by the entity, referred to it as a “tertium genus.” This means a form of liability that is neither purely administrative—since it presupposes the commission of a crime (criminal in nature)—nor purely criminal, because the sanction imposed on the entity, although punitive in nature, lacks the typical rehabilitative function that characterizes criminal penalties.

[2] The Supervisory Body (so-called OdV)
The primary function of the OdV is to oversee the implementation and proper application of the adopted Model, ensuring its updating and any necessary or useful adjustments. Essentially, the body must verify the consistency between the company’s actual behavior and the established Model, analyzing its soundness and functionality and ensuring its suitability to prevent risk situations, including newly emerging ones. It must also periodically monitor the individual areas identified as “sensitive,” the correct application of protocols, and the proper maintenance of the documents required by them.

Therefore, the OdV must be constantly informed of everything that happens within the company and of any other relevant managerial or operational matters (internal reporting, relevant documentation, notes from the governing body, internal/external communications related to any type of offense covered by the Model, etc.).

The OdV must have “autonomous powers of initiative and control,” remain free from any interference or pressure from management not involved in operational activities, and refrain from participating in management decisions. It must also be able to set its own procedural and behavioral rules and independently manage an adequate budget of resources approved in advance by the company (this requirement, though not explicitly stated in Legislative Decree 231, is considered essential to ensure independence from the company and its management).

Moreover, according to the Explanatory Report accompanying the Decree, the OdV must be “internal” to the company (to avoid using compliant external bodies and to establish genuine entity accountability) and specifically dedicated to these tasks. The OdV must therefore be a third, independent body positioned at the top of the organizational hierarchy, whose decisions are not subject to review.

Finally, the OdV must be professionally competent and reliable, possessing multidisciplinary expertise (corporate, criminal, procedural, civil, and administrative law) and the technical knowledge necessary to ensure the proper and effective performance of its duties. Specifically, it holds several powers, including:

  • Power of self-regulation: the ability to determine its own procedures for meetings, decision-making, communication, direct interaction with all corporate functions, and acquisition of information and documentation;
  • Inspection power: exercised through mandatory audits of significant corporate operations/processes, primarily financial management and treasury operations, as well as coordination with the board of auditors, external auditors (or audit firms), etc.;
  • Sanctioning power: involving the initiation of disciplinary proceedings against those who fail to comply with the adopted Models.

 

In the event of a report or complaint of a violation, the OdV must conduct the necessary checks and promptly report to the designated corporate bodies. If the violation is confirmed—after hearing the offender and regardless of any criminal proceedings—the OdV must officially notify the administrative and supervisory bodies and propose the disciplinary measure provided by the entity’s internal system.

[3] Article 6 provides that: “organizational and control models may be adopted (…) on the basis of codes of conduct drawn up by the representative associations of entities and communicated to the Ministry of Justice.” For this purpose, in March 2002, the “Guidelines for the Construction of Organizational, Management and Control Models under Legislative Decree 231/01” were issued, and the main trade associations became actively involved in their implementation.

[4] This final point clarifies the establishment within the entity of a specific figure designated as the guarantor of the overall effectiveness of the compliance program and as the supervisor of those responsible for its daily application.

Contact details

Take a few minutes and send us your requests, we will come back with a solution

Contact us