← Back to all posts

Corporate Criminal Law: The New Landscape for Dominican Companies Under Law No. 74-25

Dominican Republic Law No. 74-25 reshapes the corporate criminal landscape by expanding companies’ exposure to liability and underscoring the need for robust compliance and risk-management programs.
September 21, 2026
David Zavala

On August 3, 2026,Law No. 74-25 entered into force in the Dominican Republic, establishing thenew Penal Code and replacing the criminal law system that, with its amendments,had been in place for over a century.

 For Dominicancompanies, this reform represents much more than the addition of new crimes andnew penalties. One of its most significant changes is the establishment of ageneral regime of criminal liability for legal entities, which introduces a newdimension to the management of companies’ legal risks. Legal entities may beheld criminally liable, under the conditions set forth by law, for certainoffenses committed by individuals acting on their behalf or within theirstructure, such as their representatives, managers, directors, administrators,agents, or subordinates.

 And this is wherea conversation begins that every company should have: A crime is no longerjust a problem for the person who commits it. Article 8 of Law No. 74-25establishes the conditions under which a legal entity may be held criminallyliable for offenses committed through punishable acts or omissions by itsgoverning bodies, representatives, or subordinates, when they act on behalf ofor in representation of the company and the conditions set forth in the Codeare met.

 This represents ashift in perspective. A company cannot simply claim that it is unaware of whatits employees, managers, representatives, or collaborators are doing. Thequestion posed by the new Code is much more demanding: Did the company havereasonable mechanisms in place to prevent, detect, and respond to the risk? Andthe answer can have significant consequences.

 Where mightcriminal risk arise within a company?

 The new Codecovers a broad range of conduct that may be relevant to the businessenvironment. Among these, depending on the circumstances and the specificrequirements of each criminal offense, are acts related to fraud, embezzlement,bankruptcy, extortion, blackmail, misrepresentation, and certain violationslinked to business activities, among others.

This isparticularly relevant because many of these situations can arise from acompany’s day-to-day operations: hiring employees or suppliers, sales, documenthandling, resource management, financial transactions, customer relations,participation in public procurement processes, or interactions withauthorities. For example, an irregularity in a document used to close atransaction, improper conduct by a representative toward a third party, afinancial transaction handled without adequate controls, or misconduct by anemployee can become criminally relevant situations, depending on the specificcircumstances of the case.

Corporate criminalrisk does not necessarily arise in a courtroom. It can begin with an internalprocess that no one reviewed in a timely manner. Therefore, prevention muststart by identifying where these risks may exist within the company’sday-to-day operations and determining whether adequate mechanisms are in placeto prevent, detect, and respond to them.

Here lies one ofthe most interesting aspects of the new Code. Law No. 74-25 does not merelyestablish liability; it also expressly recognizes the value of prevention andregulatory compliance. Article 8 provides that a legal entity’s criminalliability may be mitigated or that it may be subject to certain alternativeremedies when it has verifiable and measurable policies and programs forregulatory compliance and the prevention of violations that could be attributedto it.

But the Code goeseven further. Under certain circumstances, a legal entity may demonstrate thatits duties of management, control, and supervision were fulfilled if it hasobjectively adopted and implemented a compliance program that was circumventedthrough fraudulent schemes and, furthermore, the other conditions set forth bylaw are met.

This completelychanges the conversation. Compliance is no longer just a matter of corporatereputation. It can become evidence that the company took concrete steps tofulfill its duties of management, control, and supervision.

But having amanual tucked away in a drawer is not compliance. A compliance program must bereflected in the company’s day-to-day operations. If there is a policy forhiring suppliers, there must be a procedure to verify that the policy is beingfollowed. If certain payments require authorization, there must be a mechanismto document it. If an employee detects an irregularity, they must know whom toreport it to, and the company must have established procedures for how torespond.

In other words, itis not enough to have written policies; it must be possible to demonstrate thatthey were communicated, implemented, monitored, and updated. The Code offerssome very clear guidelines on what is expected of a true prevention program:

  • the identification of areas where criminal risks     exist or may exist;
  • a body or department with autonomy to oversee the     program’s implementation;
  • protocols for responding to detected risks,     including disciplinary mechanisms; and
  • periodic review of the framework and its     modification as the organization’s circumstances change.

In other words,compliance is not simply a matter of drafting policies. There must be aconnection between the rules, the company’s actual operations, and the way itsemployees, managers, and representatives make decisions. A document that no oneis familiar with can hardly protect an organization. A protocol that is neverenforced can hardly demonstrate a genuine culture of compliance. And a policythat is never reviewed will hardly be able to address the new risks faced by aconstantly changing company.

Corporate CriminalRisk Management

Not all companiesface the same risks. A construction firm does not face exactly the same risksas a technology company. A real estate firm does not operate the same way as afinancial institution. A company that frequently contracts with the government facesdifferent scenarios than a company that sells directly to consumers.

Therefore,prevention must begin with a simple yet fundamental assessment: identifyingwhere the company’s main criminal risks lie.

1.    Risk Identification andAssessment: Determine which activities, processes, and businessrelationships may create criminal exposure.

2.    Review of internal controls: Analyze whether existing mechanisms are truly effective in preventing,detecting, and reporting irregularities.

3.    Development of policies andprotocols: Establish clear rules for employees and procedures forresponding to risky situations.

4.    Training: A policy only works when the people who must comply with it are familiarwith its content and understand their responsibilities.

5.    Reporting and InvestigationMechanisms: The company must be prepared not only to preventirregularities but also to respond appropriately when a red flag arises.

6.    Periodic Review: Risk changes as the company changes. Therefore, a compliance programshould not be a one-time project.

In small andmedium-sized enterprises, Article 8 itself provides that compliance functionsmay be assumed directly by the board of directors. This means that complianceis not exclusively for large corporations.

Consequences ofNoncompliance

The consequencesfor legal entities are significant. For very serious and serious violations,the Code provides for fines, additional penalties, and even the legaldissolution of the legal entity. Fines can range from 100 to 1,500 times thepublic-sector minimum wage for very serious violations, and from 50 to 500times the minimum wage for serious violations.

Based on the public sector minimum wage, fines for very seriousviolations would range from RD$1,000,000.00 to RD$15,000,000.00, while thosefor serious violations would range from RD$500,000.00 to RD$5,000,000.00. Forreference, these amounts are equivalent to approximately US$17,100.00 toUS$256,400.00 for very serious violations, and US$8,500.00 to US$85,500.00 forserious violations.

And theconsequences do not necessarily end with a fine. Additional penalties includeconfiscation, the permanent or temporary closure of establishments,disqualification from participating in public tenders and competitiveexaminations, and the revocation of certain licenses, permits, oradministrative authorizations.

For a company,this can mean much more than a financial penalty. It can mean losing a license,being barred from participating in certain public procurement processes,temporarily or permanently closing a facility, or losing an authorizationnecessary to conduct its business.

Prevention must begin before any problems arise. Waiting for acomplaint, audit, investigation, or subpoena to assess compliance may be toolate. By then, documents, decisions, communications, and actions that couldhave been avoided may have become evidence that the company will have tojustify. The true value of a compliance program lies in identifying andmanaging risks before they turn into violations.

And this is wherelegal guidance is essential. It is not enough to simply know the Penal Code.One must understand how the company operates, how decisions are made, who hasauthority to represent the company, what roles its executives and employeesplay, where control points exist, what regulatory obligations apply to itsoperations, and what evidence exists that preventive measures are actuallyeffective.

A lawyer shouldnot only step in once a problem has already occurred. They must be involvedearlier. They must help identify risks, translate legal requirements intoprocedures applicable to the company, and establish mechanisms that demonstratethe organization acted with due diligence.

At Mesa Abogados,we understand that the prevention of corporate criminal risk must begin with anunderstanding of each company: its business, its processes, its structure, thepeople who make decisions, its relationships with third parties, and its risks.That is why we invite companies to assess their current level of preparednessin light of the new Penal Code, identify their main risks, and determine whatmeasures they can implement to strengthen their prevention and compliancesystems.

The new Penal Codeis now in effect. Preventing corporate criminal risk begins long before anyinvestigation takes place.

← Back to all posts