This site uses technical and third-party cookies to improve your browsing experience. Learn more

    Prerequisites

    The entity may be held liable only for offences expressly listed in the decree, according to a catalogue that is exhaustive but progressively expanded by the legislator.

    The Prerequisites of 231 Liability

    1. Predicate offence

    The entity may be held liable only for offences expressly listed in the decree, according to a catalogue that is exhaustive but progressively expanded by the legislator.

    The main categories include:

    • offences against the Public Administration (corruption, extortion)
    • corporate offences (false corporate communications, obstruction of supervision)
    • tax offences
    • insolvency and business crisis offences
    • environmental offences
    • health and safety at work offences
    • money laundering and self-laundering
    • cybercrime
    • offences against industry and trade

    The typicality of the predicate offence constitutes the first legality filter of the 231 system.

    2. Qualification of the offender

    The offence must be committed:

    • by senior persons, i.e. persons holding functions of representation, administration or management of the entity, or who de facto exercise its management
    • or by persons subject to the direction or supervision of one of the aforementioned persons

    The entity's liability is based on the functional relationship between the offender and the organisational structure.

    3. Interest or benefit of the entity

    The offence must have been committed:

    • in the interest of the entity, assessed ex ante in relation to the purpose of the conduct
    • or to the benefit of the entity, assessed ex post based on the effects actually derived

    The entity is not liable when the offender acted exclusively in their own interest or that of third parties, without any benefit to the organisation.

    4. Organisational fault

    The central and autonomous element of the system is the so-called organisational fault. The entity is liable when the offence is the expression of an organisational structure that is inadequate in relation to the specific risks of the activity carried out, i.e. when there is no system capable of preventing offences of the type that occurred.

    It is on this ground — that of the adequacy and effective implementation of the organisational model — that the most relevant defence strategy in proceedings under Legislative Decree 231/2001 is concentrated.

    Frequently asked questions about Administrative Liability of Entities – Legislative Decree 231/2001

    What is corporate administrative liability under Legislative Decree 231/2001?
    Legislative Decree 231/2001 introduces an autonomous imputation framework alongside individual criminal liability: a company may be held liable for offences committed in its interest or for its benefit by senior management or subordinates. Sanctions include financial penalties, interdictory measures and confiscation, with direct effects on business continuity.
    How is the adequacy of an Organisational Model 231 assessed?
    The Organisational, Management and Control Model (MOG) is the exculpatory tool provided by Legislative Decree 231/2001. Its adequacy requires an effective mapping of crime risks, adequate control protocols, an autonomous Supervisory Board, and ongoing training. Adequacy is not measured on paper but on the model's substantial ability to prevent predicate offences.
    What interdictory precautionary measures can affect an entity?
    In 231 proceedings, a company may be subject to interdictory precautionary measures such as suspension of activities, prohibition from contracting with public authorities, exclusion from public subsidies and financing, and prohibition from advertising goods and services. The defence verifies the existence of serious indicia of liability and the concrete risk of reoffending.
    How is the Supervisory Board structured and what are its requirements?
    The Supervisory Board (OdV) must have autonomy, independence, professional competence and continuity of action. It may be single-member or collegial; in SMEs, it may coincide with the board of statutory auditors. The OdV supervises the effectiveness of the Model, receives reports, proposes updates and reports to corporate bodies. Its composition and functioning directly affect the exculpatory defence under Legislative Decree 231/2001.
    Does the Model 231 also protect small and medium enterprises?
    Legislative Decree 231/2001 applies to all entities — including SMEs — that have legal personality or are otherwise endowed with autonomous assets. For SMEs, a simplified OdV structure (even single-member) is permitted, and a Model proportionate to the size and operational complexity of the entity is acceptable. A poorly calibrated or merely formal Model may not produce the exculpatory effect, exposing the company to sanctions.

    Request a confidential consultation

    Every request is handled with the utmost discretion and professional confidentiality.

    All expertise areas