• via Alberto da Giussano, 26, 20145 Milano
  • +39 02 8295 4969
  • info@studiolegalebianucci.it
Avv. Marco Bianucci
Avv. Marco Bianucci

Criminal Lawyer

Model 231 is a prevention tool, not a document to be filed away. If you manage a company, association or other entity, the practical doubt often concerns the gap between a model approved on paper and a system that actually works: what risks it must cover, who supervises, what should happen when a procedure is violated and when the model can help exclude the entity's liability.

I want to help you distinguish essential requirements from generic formulas. We will see why the model must start from the activities actually carried out, what role the supervisory body plays, and why delegations, controls, information flows and reports must correspond to the real organisation. The first useful distinction is this: adopting the model and implementing it effectively are two different things.

When corporate liability may arise

The entity is not liable for every crime committed by those who work there. Legislative Decree 231/2001 links the entity's liability to specific predicate offences and requires the act to be committed in its interest or to its advantage. Article 5 considers both those who perform functions of representation, administration or management, even on a de facto basis, and persons subject to the direction or supervision of others. The regulatory reference is Legislative Decree no. 231 of 8 June 2001 published on Normattiva.

Interest and advantage indicate two different checks. Interest concerns the purpose pursued by the person acting at the time of the act; advantage, on the other hand, concerns the utility that the entity has obtained or could have obtained. They are not interchangeable words. Conduct may be aimed at favouring the entity even if the hoped-for result is not achieved; conversely, an utility obtained by the entity may assume relevance even if it was not the author's sole purpose.

Exclusive personal benefit can break the connection with the entity. Article 5 excludes liability when the person has acted in their own exclusive interest or that of third parties. However, it is not sufficient to classify conduct as an individual initiative: what counts are the concrete reasons for the transaction, the role held, the effects produced and any utility for the organisation.

The model does not replace the assessment of the crime. The liability of the individual and that of the entity remain distinct. The model intervenes at the level of preventive organisation: it can assume an exempting effect under the conditions set out in Articles 6 and 7 of the decree, but it does not automatically cancel a fact, nor does it transform every internal irregularity into a 231 offence.

The model must start from the organisation's concrete risks

A useful model identifies where risk can form. Article 6 requires the identification of activities within the scope of which relevant crimes may be committed. This mapping does not coincide with an abstract list of all crimes provided for by the decree. It must link the relevant offences to the entity's real processes: for example, relations with public entities, the awarding of consultancies, purchases, payments, safety management, relations with intermediaries or corporate information, when such activities actually exist.

Each sensitive area requires recognisable operational rules. Protocols must regulate how decisions are formed and implemented in processes exposed to risk. A concrete procedure indicates who can propose a transaction, who approves it, what controls precede execution, what documents must remain available and how anomalies or derogations are managed. A simple ban on committing offences does not yet describe an organisational safeguard.

Traceability serves to make choices controllable. It does not mean adding empty signatures. It means being able to understand, after a transaction, who proposed it, what information it was based on, who had the power to authorise it and what control was planned. If actual powers diverge from written delegations, or if authorisations are given without knowing the recipient, subject and economic reason of the transaction, the control risks being merely apparent.

Financial resources require their own safeguards. Article 6 includes among the contents of the model methods for managing financial resources suitable for preventing the commission of crimes. In concrete terms, the separation between those who request, authorise and execute a payment, the consistency between contract, service and consideration, and the documentation of activities carried out by consultants, agents or other third parties assume relevance. The point is not to multiply steps, but to make the process proportionate to the risk.

The disciplinary system makes internal rules enforceable. The model must provide for measures suitable for penalising failure to comply with provisions. This does not authorise automatic or disproportionate responses: the consequence must be compatible with the applicable relationship and the role of the person involved. Without a system for disciplining violations, protocols and codes of ethics risk remaining ineffective indications.

The exempting effect also depends on who commits the act

For senior management, the law requires particularly rigorous conditions. If the crime is committed by a person in a senior position, Article 6 links the exemption of the entity to the proof that the governing body had adopted and effectively implemented the model before the fact, that it had entrusted supervision to a body endowed with autonomous powers of initiative and control, and that the offender had fraudulently circumvented the model, and that supervision by the Supervisory Body was neither omitted nor insufficient.

Fraudulent circumvention does not coincide with mere non-observance. Violating a procedure is not enough, on its own, to demonstrate that it was bypassed in a fraudulent manner. It is necessary to consider the content of the safeguard, its suitability with respect to the risk, the way in which it was bypassed and the presence of controls capable of intercepting anomalies. The supervision of the Supervisory Body also becomes an essential part of this check.

For subordinates, the failure of direction or supervision counts. Article 7 concerns crimes committed by persons subject to the direction or supervision of others. The entity is liable if the commission of the crime was made possible by the non-observance of management or supervisory obligations. The model can exclude liability if it had been adopted and effectively implemented before the fact and was suitable for preventing its commission.

Updating is part of implementation. For subordinate subjects, Article 7 refers to periodic checks and modifications of the model when significant violations or changes in the organisation or activity emerge. Reorganisation, new delegations, entry into a different market or the outsourcing of a delicate phase can change risks and make a protocol that was previously consistent insufficient.

The Supervisory Body must be able to truly supervise

The Supervisory Body supervises the functioning and observance of the model. The supervisory body does not replace directors, operational managers or corporate control bodies in their respective functions. Its task, provided for by Article 6, concerns checking the model and taking care of its updating. To carry this out, it must be able to receive relevant information, ask for clarifications and bring concrete critical issues to the entity's attention.

Autonomy is not a title assigned on paper. A Supervisory Body is autonomous when it can operate without depending, in its conclusions, on those it must supervise. Therefore, its placement in the entity's structure, access to information, availability of adequate tools and the possibility of reporting anomalies all count. A formally correct composition is not enough if the body does not receive useful news or cannot carry out significant checks.

The law does not impose a single composition. In small entities, the functions of the Supervisory Body can be performed directly by the governing body. In corporations, the decree allows these functions to also be attributed to the board of statutory auditors, the supervisory board or the management control committee. However, the choice must remain consistent with the necessary independence and continuity of control.

Information flows are the connection between model and reality. The model must provide for obligations to inform the Supervisory Body. It is not useful to indiscriminately send every corporate document; news that allows intercepting violations, anomalies in sensitive processes, relevant disciplinary measures, organisational changes and situations requiring the updating of protocols is needed.

Internal reporting and Model 231 are not the same thing

The reporting channel does not replace the supervision of the Supervisory Body. Reporting allows communicating information on violations that fall within its regulatory scope; the Supervisory Body, on the other hand, supervises the entire functioning of the model. The two functions can dialogue through coherent information flows, but they must not be confused. Establishing who receives the report, who manages it and what information can reach the Supervisory Body requires clear rules.

Not every employment conflict is a protected report. Legislative Decree 24/2023 governs the protection of those who report violations known in a work context that harm the public interest or the integrity of the entity. The same decree excludes, among other things, disputes linked exclusively to the individual employment relationship of the reporting person. The current text can be consulted in Legislative Decree no. 24 of 10 March 2023 on Normattiva.

Confidentiality and the prohibition of retaliation require effective procedures. A digital channel or a dedicated mailbox are not enough on their own. Interested parties need to know what facts they can report, how confidentiality is preserved, who manages the communication and how unfavourable behaviour connected to the report is avoided. The rules on reporting must therefore be coordinated with the disciplinary system and other flows provided for by the model.

How to recognise a merely formal model

A standardised text is not necessarily useless, but it can be insufficient. The problem arises when the document describes risks and procedures that do not correspond to the entity's activities. A model may contain abstractly correct formulas and remain inadequate if it ignores who actually makes decisions, how relations with third parties are managed, or where sensitive resources and information transit.

The proof of implementation lies in organisational behaviours. Targeted training, known procedures, carried-out controls, flows to the Supervisory Body, anomaly management and documented updates are different elements, but they must be consistent with each other. None of them alone guarantees the exempting effect. Together they show whether the model affects the way the entity operates or whether it remains separate from daily activity.

To understand what needs to be corrected, a few precise facts are needed. The activity carried out, effective delegations, applied procedures, relations with consultants and suppliers, information reaching the Supervisory Body and changes that have occurred assume relevance. The text of the model, organisational acts and relevant procedures do not count for their quantity: they serve to verify whether roles, controls and responsibilities coincide.

Frequently Asked Questions

Is Model 231 mandatory for all companies?

Legislative Decree 231/2001 does not provide for a generalised obligation of adoption for every company. The model primarily has an exempting function: when the requirements of Articles 6 or 7 are met, it allows the entity to demonstrate that it has set up a suitable preventive system. The absence of the model does not prove liability on its own, but prevents founding the exemption on that system.

Is a code of ethics enough to have an effective model?

No, the code of ethics is not enough on its own. It can express principles of behaviour and become part of the organisational setup, but the model also requires the identification of activities at risk, decision-making protocols, rules on financial resources, information flows to the Supervisory Body and a disciplinary system. It also matters that these measures are applied in practice.

Must the Supervisory Body necessarily be composed of external persons?

The law does not impose the same composition for every entity. However, it requires a body equipped with autonomous powers of initiative and control. In small entities, tasks can be performed by the governing body; in corporations, they can also be entrusted to the bodies indicated in Article 6. The decisive element remains effective autonomy.

Does the reporting channel replace the supervisory body?

No, the reporting channel and the Supervisory Body perform different functions. The former receives information on violations that fall within the applicable discipline; the Supervisory Body supervises the functioning and observance of the model as a whole. The model must regulate the coordination between the two functions, avoiding both confusing overlaps and information gaps.

When does Model 231 need to be updated?

Updating is needed when safeguards no longer correspond to real risks. Significant violations, new activities, modifications of delegations, reorganisations, acquisitions or assignments to third parties can change processes and responsibilities. Article 7 expressly recalls the modification of the model when organisation or activities change. Not every variation requires a rewrite, but every relevant change requires consistency.

The essential point

A Model 231 is effective only if it becomes part of the organisation. Risk mapping, protocols, powers, controls, the Supervisory Body, the disciplinary system and reports must describe the same reality. When one of these elements remains disconnected from the others, formal adoption may not correspond to the effective preventive capacity that the decree requires.