Does an Israeli company need an internal compliance and enforcement program?
Israeli corporate criminal liability attaches to a company through the acts of the individuals who direct it, so the state can prosecute the company itself for conduct by senior employees. The regulators built the internal enforcement concept on that foundation: a program that is documented, funded, led by a named officer, and actually applied can reduce or avoid an administrative penalty, while a policy that sits unread does not. The Competition Authority looks for risk mapping, training, reporting channels, and periodic audit, and the Securities Authority applies comparable criteria to reporting companies. The Companies Law never names compliance programs, but the duty of care in Section 252 is measured against what a reasonable director in the same position would have done.
For a foreign group with an Israeli subsidiary, the common mistake is assuming the parent’s global program already covers it. It rarely does without adaptation, because Israeli competition, privacy, and employment rules diverge from their US and EU equivalents and because regulators expect Hebrew-language materials and a locally reachable officer. Budget for a risk assessment, a written policy approved by the Israeli board, annual training, and a reporting channel that works with the Protection of Employees (Disclosure of Offences) Law 5757-1997. Minute the board approval, because that record is what evidences the directors’ diligence if a regulator asks years later. Our guide to directors’ duties and corporate governance in Israel sets out the wider board obligations.
- Governing law: Sections 252 and 253, Companies Law 5759-1999; corporate criminal liability under the Penal Law 5737-1977
- Competent authorities: Israel Competition Authority (Reshut HaTacharut) and Israel Securities Authority (Reshut Niyarot Erech), each publishing internal-enforcement criteria
- Sector duties: compliance officer under the Prohibition on Money Laundering Law 5760-2000 for financial institutions; data protection officer under Amendment 13 to the Privacy Protection Law 5741-1981, in force since August 2025
- Costs: external risk mapping and program design for a mid-size Israeli company typically runs NIS 40,000 to NIS 120,000 (2026)
- What regulators look for: a named officer, a board-approved policy, risk mapping, documented training, a reporting channel, and periodic audit
- Review cycle: programs are normally reviewed annually; regulators discount a program that has never been tested or updated
From the full guide: Corporate Governance in Israel: Directors' Duties
Related Questions
Get a Free Consultation with Adv. Eli ShimonyPrepared under the direction of Adv. Eli Shimony, Eli Shimony Law Office · Editorial policy