Third-party risk management: lessons from Chile’s expanding corporate criminal regime
Matías Gatica Van de Velde
Carey, Santiago
mgatica@carey.cl
Introduction
Compliance programmes have traditionally focused on preventing and detecting crimes committed by individuals within the organisation. This approach is understandable, as companies naturally exercise greater control over their directors, officers and employees than over external parties.
Over the last two decades, companies have increasingly recognised that significant legal and compliance risks originate outside their organisational boundaries. As businesses outsource functions that fall beyond their core activities, consultants, agents, contractors, distributors and other third parties have become integral to day-to-day operations. Consequently, managing third-party risk has become one of the central challenges of modern compliance.
Chile has followed this global trend. Until recently, however, Chilean corporate criminal liability remained largely confined to misconduct committed by individuals within the company. That changed in 2023 with the enactment of the Economic Crimes Act (Law No 21,595),[1] which significantly expanded corporate criminal liability by allowing companies to be held criminally liable for offences committed by certain external third parties.
This reform raises several practical questions. Which third parties fall within the scope of the new regime? Should companies apply the same level of due diligence to every supplier, contractor and intermediary they have dealings with? Or should compliance efforts instead be allocated according to the level of criminal exposure each third party creates?
This article argues that the new legislation calls for the adoption of a genuinely risk-based approach to third-party compliance. Rather than treating all third parties alike, companies should distinguish between those capable of generating corporate criminal liability and those presenting a lower degree of criminal exposure. This distinction has significant implications for the design of due diligence procedures, contractual safeguards and ongoing monitoring throughout the commercial relationship.
The evolution of third-party due diligence in Chile
Chile’s regulation of third-party risk did not originate in corporate criminal law. It developed through different regulatory regimes, each responding to a distinct source of risk. The first significant duties emerged in the field of anti-money laundering, where financial institutions were progressively required to know their customers, verify their identity and monitor their transactions. What began as regulatory recommendations evolved into a comprehensive framework of statutory customer due diligence and ongoing monitoring obligations. A similar evolution occurred in labour law: as outsourcing became increasingly common, the legal framework gradually imposed broader supervisory duties on the principal company, requiring it to implement preventive measures and actively oversee compliance throughout the subcontracting chain. Although these regimes apply only in specific contexts, they introduced into Chilean law the idea that organisations bear responsibility not only for their own conduct, but also for understanding and managing the risks posed by those with whom they do business.
Criminal law remained largely detached from this broader regulatory trend. While companies were expected to supervise customers in regard to anti-money laundering matters and contractors in regard to labour and occupational safety matters, no equivalent expectation existed regarding third parties capable of exposing the company to criminal liability. As a general rule, offences committed by independent consultants, intermediaries or other external service providers did not trigger corporate criminal liability unless someone within the company had personally participated in or directed the criminal conduct.
This distinction was particularly evident in corruption cases. A company engaging an external consultant or lobbyist to obtain permits or authorisations could face significant reputational and commercial consequences if that consultant bribed a public official. Yet, from a criminal law perspective, liability ordinarily rested with the individual who committed the offence. Unless a director, officer or employee of the company had authorised, instructed or otherwise participated in the bribery, the company itself could not be held criminally liable.
The Economic Crimes Act has fundamentally altered this landscape. For the first time, Chilean corporate criminal law expressly recognises that, in certain circumstances, misconduct committed by external third parties may be attributed to the company itself. The reform represents the convergence of two previously separate regulatory developments: the expansion of corporate oversight over third parties and the evolution of corporate criminal liability.
The new paradigm: corporate criminal liability for third-party misconduct
The Economic Crimes Act has substantially expanded the scope of corporate criminal liability in Chile. Among its many reforms, one of the most significant from a compliance perspective is the extension of liability to certain offences committed by external third parties.
Prior to the reform, corporate criminal liability was generally limited to offences committed by individuals acting within the company’s organisational structure. Directors, officers, employees and other persons performing functions on behalf of the company could expose the legal entity to criminal liability, provided the statutory requirements were met. Independent third parties, by contrast, ordinarily fell outside that framework.
The new legislation significantly broadens this approach. Under Article 3 of Law No 20,393, as amended by the Economic Crimes Act, a company may now incur criminal liability for offences committed by third parties that provide services by managing the company’s affairs before other persons, ‘with or without its representation’.[2] Liability no longer depends on the offender being formally integrated into the organisation, nor on the existence of a power of attorney or other legal authority.
The reference to acting with or without representation reflects an evident legislative purpose. Had liability depended upon the existence of a formal mandate, companies could easily have avoided the rule simply by structuring their commercial relationships differently. In practice, many consultants, intermediaries and lobbyists perform precisely these functions without holding formal powers of representation. The legislation focuses on the substance of the relationship rather than on its legal form.
The Chilean rule moves the country closer to the position under the United Kingdom’s Bribery Act 2010, which exposes companies to liability for bribery committed by ‘associated persons’, broadly defined as anyone who performs services for or on behalf of the organisation, whatever their formal capacity.[3] It likewise echoes the long-standing exposure under the United States Foreign Corrupt Practices Act (FCPA) for corrupt payments made through agents and other intermediaries.[4] Chile’s formulation is, nonetheless, narrower in one important respect: it does not capture every person performing services for the company, but only those who manage the company’s affairs with third parties.
Determining which third parties actually manage a company’s affairs with others is not always straightforward. Third-party relationships can usefully be placed on a spectrum. At one end are situations that appear relatively clear: a consultant retained to negotiate with a regulator or a lobbyist engaged to obtain a governmental permit would ordinarily fall within the scope of the provision. At the opposite end, suppliers of goods or providers of purely internal services, such as cleaning or maintenance contractors, do not ordinarily manage the company’s affairs with third parties and, therefore, appear to fall outside the rule. Between these two extremes lies a broad category of relationships whose legal treatment remains uncertain: outsourced sales forces, logistics providers, transport companies and numerous other service providers interact directly with customers, authorities or other external stakeholders, while simultaneously performing functions closely connected to the company’s business. Whether misconduct committed by these actors may trigger corporate criminal liability will often depend on how broadly the statutory concept is interpreted.
This has immediate consequences for compliance programmes. Companies cannot assume that every third party presents the same degree of criminal exposure. Nor can they simply conclude that only consultants or lobbyists require enhanced scrutiny. The new legislation instead requires a more nuanced assessment of third-party relationships based on the specific level of criminal risk that each category of external actor creates.
Not all third parties are equal: a risk-based approach
The uncertainty surrounding the scope of the new regime should not lead companies to adopt a one-size-fits-all approach to third-party compliance. On the contrary, the reform reinforces the need for the adoption of a genuinely risk-based methodology.
Not every third party creates the same level of criminal exposure. A consultant retained to obtain environmental permits or a customs broker representing the company before public authorities presents a substantially different risk profile from that of a supplier delivering office equipment or a contractor providing cleaning services. Although all of these relationships may deserve some degree of due diligence, there is little justification for subjecting them to identical compliance measures.
The first step, therefore, should be to classify third parties along the spectrum described above, according to the criminal exposure each relationship generates. Third parties presenting a higher degree of criminal exposure should ordinarily be subject to more robust due diligence, enhanced contractual safeguards and closer monitoring throughout the commercial relationship. Conversely, where the possibility of generating corporate criminal liability is remote, more proportionate compliance measures may be appropriate.
That said, criminal exposure should not be the only factor informing this assessment. Companies routinely engage third parties whose strategic importance justifies enhanced scrutiny even if they fall outside the scope of the corporate liability regime. Long-term suppliers, providers of critical goods or services or business partners whose replacement would significantly disrupt operations may warrant more intensive due diligence because of their operational significance rather than their capacity to trigger criminal liability.
The appropriate level of oversight should be determined through a combination of legal and commercial considerations. The likelihood that a third party could expose the company to criminal liability is undoubtedly relevant, but so too are factors such as the strategic importance of the relationship, the duration of the engagement, the ease with which the third party could be replaced and the broader reputational risks associated with its activities.
Ultimately, the Economic Crimes Act should not be understood as requiring companies to apply identical compliance controls to every external relationship. Rather, it encourages a more sophisticated allocation of compliance resources, allowing companies to concentrate their efforts where the legal and operational risks are greatest.
Third-party due diligence as a continuous process
A risk-based approach to third-party compliance is not limited to determining the level of due diligence that should be performed before entering a commercial relationship. Equally important is recognising that third-party risk evolves over time. A relationship that initially presents a low level of exposure may become significantly riskier as the third party’s activities expand, its role changes or new information becomes available.
In practice, compliance efforts often remain heavily concentrated at the outset of the relationship. Companies typically conduct background checks before onboarding a third party, negotiate contractual protections and obtain compliance representations. Once the agreement has been executed, the intensity of monitoring frequently decreases, even though many of the events capable of exposing the company to criminal liability occur during contract performance rather than at the contracting stage.
For that reason, third-party due diligence should be understood as a continuous process rather than a single event. Ongoing monitoring may include periodic risk reassessments, updates to screening procedures, requests for compliance information, audits where appropriate and regular reviews of whether the third party continues to present the level of risk originally identified.
Contractual protections also deserve particular attention. Anti-corruption clauses, audit rights and information obligations are valuable only if they can produce practical consequences. A contractual right to terminate the relationship following serious compliance breaches may prove ineffective if the relevant events have not been clearly defined or if the company’s operational dependence on the third party makes termination commercially unrealistic. Compliance programmes should anticipate not only legal responses to misconduct, but also the operational challenges that may arise when significant third parties become involved in criminal or regulatory investigations.
The end of the commercial relationship likewise deserves careful planning. Termination does not necessarily eliminate risk. Companies may still need to manage outstanding payments, preserve evidence, cooperate with regulatory authorities or respond to investigations arising from conduct that occurred during the relationship. Accordingly, the compliance lifecycle should extend beyond the duration of the contract itself.
The shift required by the Economic Crimes Act can be illustrated with a simple analogy. Traditional due diligence resembles a photograph: it captures a single moment, usually before the contract is signed. The new corporate liability regime requires something different: a moving picture. It requires a continuous view of how third-party risk develops throughout the entire commercial relationship.
Conclusion
The Economic Crimes Act has significantly altered the way Chilean companies should approach third-party risk. By extending corporate criminal liability to offences committed by certain external service providers, the reform moves beyond the traditional assumption that criminal exposure arises only from misconduct occurring within the organisation.
Companies should no longer approach third-party compliance as a uniform exercise in which every supplier, contractor or intermediary is subject to the same level of scrutiny. Instead, the new framework requires organisations to identify which third parties are capable of generating corporate criminal liability and to calibrate their compliance efforts according to the level of risk that each relationship presents.
This approach is not only more consistent with the objectives of the legislation, but also with the fundamental principles of modern compliance. Resources are always limited. Effective compliance, therefore, depends not on applying the maximum level of control to every third party, but on allocating compliance resources where they are most likely to prevent legal, operational and reputational harm.
Finally, the reform invites companies to reconsider the timing of third-party due diligence. Compliance should not be understood as an exercise performed exclusively before signing a contract. Third-party risk evolves throughout the commercial relationship, and compliance measures should evolve with it. In that sense, the new Chilean regime offers a broader lesson for compliance professionals beyond Chile’s borders: effective third-party risk management requires moving from a static to a dynamic model of due diligence, from taking a snapshot at the beginning of the relationship to maintaining a continuous view of risk throughout its entire lifecycle.
[1] Law No 21,595, which systematises economic offences and modifies various legal bodies that typify crimes against the socioeconomic order (Economic Crimes Act), published in the Chilean Official Gazette on 17 August 2023.
[2] Law No 20,393, Art 3, as amended by the Economic Crimes Act (author’s translation). The Spanish text refers to third parties who provide services to the company ‘gestionando asuntos suyos ante terceros, con o sin su representación’.
[3] UK Bribery Act 2010, sections 7–8.
[4] US Foreign Corrupt Practices Act, 15 USC section 78dd-1(a)(3). It should be noted that the FCPA requires the company to know that all or part of the money or thing of value will be used to corrupt a foreign public official. In contrast, Chilean law imposes no such knowledge requirement.