Corporate Law

Does an Israeli company need an internal compliance and enforcement program?

No single Israeli statute requires every company to run a compliance program, but several regimes make one close to mandatory in practice. The Israel Competition Authority and the Israel Securities Authority both publish criteria for an internal enforcement program (tochnit achifa penimit) and treat a genuine program as a mitigating factor when they set sanctions. Directors owe a duty of care under Sections 252 and 253 of the Companies Law 5759-1999, and failing to install controls against a foreseeable risk can breach it. Specific sectors carry hard obligations, including anti-money-laundering compliance officers and data protection officers for defined categories of company.

Israeli corporate criminal liability attaches to a company through the acts of the individuals who direct it, so the state can prosecute the company itself for conduct by senior employees. The regulators built the internal enforcement concept on that foundation: a program that is documented, funded, led by a named officer, and actually applied can reduce or avoid an administrative penalty, while a policy that sits unread does not. The Competition Authority looks for risk mapping, training, reporting channels, and periodic audit, and the Securities Authority applies comparable criteria to reporting companies. The Companies Law never names compliance programs, but the duty of care in Section 252 is measured against what a reasonable director in the same position would have done.

For a foreign group with an Israeli subsidiary, the common mistake is assuming the parent’s global program already covers it. It rarely does without adaptation, because Israeli competition, privacy, and employment rules diverge from their US and EU equivalents and because regulators expect Hebrew-language materials and a locally reachable officer. Budget for a risk assessment, a written policy approved by the Israeli board, annual training, and a reporting channel that works with the Protection of Employees (Disclosure of Offences) Law 5757-1997. Minute the board approval, because that record is what evidences the directors’ diligence if a regulator asks years later. Our guide to directors’ duties and corporate governance in Israel sets out the wider board obligations.

⚖ In Practice
  • Governing law: Sections 252 and 253, Companies Law 5759-1999; corporate criminal liability under the Penal Law 5737-1977
  • Competent authorities: Israel Competition Authority (Reshut HaTacharut) and Israel Securities Authority (Reshut Niyarot Erech), each publishing internal-enforcement criteria
  • Sector duties: compliance officer under the Prohibition on Money Laundering Law 5760-2000 for financial institutions; data protection officer under Amendment 13 to the Privacy Protection Law 5741-1981, in force since August 2025
  • Costs: external risk mapping and program design for a mid-size Israeli company typically runs NIS 40,000 to NIS 120,000 (2026)
  • What regulators look for: a named officer, a board-approved policy, risk mapping, documented training, a reporting channel, and periodic audit
  • Review cycle: programs are normally reviewed annually; regulators discount a program that has never been tested or updated

From the full guide: Corporate Governance in Israel: Directors' Duties


Related Questions

Related Guides

Need legal help with this topic?
Get a Free Consultation with Adv. Eli ShimonyPrepared under the direction of Adv. Eli Shimony, Eli Shimony Law Office · Editorial policy

← Browse all Q&A