Whistleblowers will be granted a higher level of protection under new legislation passed earlier this week in Italy.
The new provisions apply to civil servants as well as employees in the private sector. Whistleblowing protection will shield individuals who submit a good faith report concerning unlawful conduct, provided that such report is based on a reasonable belief and factual elements.
The new legislation prohibits any retaliation or other discriminatory measures against good faith whistleblowers, including termination, demotion, transfer or other organizational action.
In the private sector, the new legislation has a significant impact on organizational models adopted to prevent corporate criminal liability pursuant to Legislative Decree 231 of 2001. In fact, all organizational models will need to set up appropriate channels for the confidential reporting of criminal conduct and violations of the organizational models themselves. Measures aimed at protecting the identity of the whistleblowers and the confidentiality of the reports, as well as disciplinary sanctions against retaliatory or discriminatory measures against whistleblowers, will also need to be included in such organizational models.
The new legislation is expected to enter into force shortly, upon publication in the official gazette.
Are Companies Criminally Liable under Italian Law? Yes!
Legislative Decree no. 231/2001 (the “231 Decree”) has introduced in Italy the principle that companies are responsible for crimes committed by:
- Individuals vested with powers of company’s representation, control, direction, or management;
- Individuals subject to the authority or control by the above-mentioned individuals, including employees, consultants, non subordinate employees and whoever acts on behalf of the company.
- As a result, a company may now be considered liable for crimes committed by individuals in the interest or to the benefit of the company (while crimes committed by individuals in their exclusive interest or in the exclusive interest of third parties do not trigger company’s liability). The company’s liability is separate and distinct from the liability of the individual who committed the crime.
Which Crimes Trigger Liability? Several (not just corruption!).
The 231 Decree lists a number of crimes for which companies may be liable, which include:
- Corporate crimes;
- Crimes against public administrations;
- Crimes against the dignity of individuals;
- Conspiracies and terrorism;
- Crimes arising out of breach of laws protecting the environment and health and safety at work;
- Crimes related to criminal associations;
- Money laundering.
Which Sanctions Apply? Monetary and blacklisting sanctions.
If a company is found liable, the following sanctions may apply:
- monetary sanctions up to a maximum amount of Euro 1,549,370.69 (and precautionary seizure of the price or profit arising from the crime),
- blacklisting sanctions (applicable also as a precautionary measure), with duration between 3 to 24 months, which can consist of, inter alia, the prohibition to conduct the Business’ commercial activity, the prohibition to contract with the public administration, the prohibition to advertise goods or services, seizure, or the publication of the court’s decision (if a blacklisting sanction is applied).
Are There any Grounds of Exemption from Criminal Corporate Liability? Yes!
A company is not liable pursuant to the 231 Decree if it proves that:
- The management has adopted and effectively implemented a so-called ‘Organizational Model’ in order to prevent the commission of the criminal offences listed in the 231 Decree by subjects acting on behalf of the company;
- The company has established an internal body (‘Compliance Committee’) entrusted with the task of supervising the proper functioning and update of the Organizational Model, as well as the actual compliance by all those who must abide by it;
- Crimes were committed by individuals vested with management powers who have fraudulently avoided compliance with the Organizational Model;
- The Compliance Committee has not omitted to perform, or negligently performed its supervision duties.
- This explains why companies operating in Italy typically devote substantial resources in the setting up of an Organizational Model.
How to Set up an Organizational Model? Risk assessment, gap analysis, preventive measures.
In order to prepare an Organizational Model the following process is usually followed:
- Examination of areas of risk: on the basis of the company’s Organizational Model and relevant job descriptions, the risk of commission of each crime set forth in the 231 Decree is assessed.
- Analysis of existing procedures: all existing procedures and ethical principles are reviewed in order to identify procedures that may reduce the risk of commission of the crimes.
- Possible implementation of new measures: should the analysis of existing procedures lead to conclude that some of the risks are not properly reduced, new procedures should be implemented.
The Organizational Model must be Effective. A compliance program on paper will not help!
Once a company has adopted an Organizational Model by means of a resolution of the Board of Directors, the company must ensure that it is effectively implemented, that employees and other individuals acting on behalf of the company are duly trained on the model and that any breach of the Model is sanctioned.
In particular, the appointed Compliance Committee must actively supervise the effective functioning and adequacy of the Model on an ongoing basis and in independent fashion. The Compliance Committee is generally in charge of:
- Monitoring the activity carried out within the company and the areas considered at risk;
- Assessment of the actual implementation of, and compliance with the Organizational Model;
- Cooperation and consultation with the management as regards the application of disciplinary sanctions to employees in the event of breach of the internal procedures provided by the Organizational Model.