Califix Compliance · Crime Prevention Model PRO
The Crime Prevention Model. Managed end to end.
Califix lets Compliance teams manage the full lifecycle of the Crime Prevention Model: risks, controls, owners, activities, evidence, incidents, action plans, and continuous improvement.
A continuous, traceable, risk-based compliance operation.
Prevention. Operated. Monitored. Evidenced.
Prevention Model
Example
Prevention Model
Model statusOperating
- Operating controls
- 92%
- Material risks
- 14
- Active controls
- 37
- Open actions
- 8
Material risks
- Favoritism in procurementCritical
- Improper paymentsHigh
- Third party without due diligenceMedium
Controls
Monitoring
- Critical third-party reviewIn progress
- Quarterly risk matrixScheduled
- Evidence validationDue soon
- Findings
- 4
- Evidence
- 96%
- Incidents
- 2
- Owners
- 18
A prevention model does not end when it is implemented.
The real challenge starts after implementation.
Compliance has to keep the risk map current, test controls, run activities, manage owners, monitor results, document evidence, administer findings, and show that the model is working over time.
Califix turns the Crime Prevention Model into a continuous operation.
Designing the model is only the start. Operating it creates traceability.
The full lifecycle of the model. On one platform.
01
Design
Scope, structure, processes, and components of the model.
02
Identify
Mapping of processes, activities, third parties, and relevant scenarios.
03
Assess
Risk assessment and prioritization.
04
Control
Definition and management of preventive and detective controls.
05
Operate
Execution of activities, reviews, tasks, and monitoring.
06
Evidence
Recording and centralization of evidence.
07
Detect
Management of alerts, findings, and incidents.
08
Correct
Action plans, owners, dates, and follow-up.
09
Improve
Periodic review and update of the model.
The model evolves with the organization.
Design → Identify → Assess → Control → Operate → Evidence → Detect → Correct → Improve
It starts by knowing where the risks are.
Identify, assess, and prioritize compliance risks so resources go where they are actually needed.
Risk matrix
Probability
- Procurement
- Commercial
- Logistics
- Finance
- People
| Process | Risk | Probability | Impact | Level | Residual | Owner | Status |
|---|---|---|---|---|---|---|---|
| Procurement | Supplier favoritism | High | High | Critical | Medium | J. Morales | Open |
| Commercial | Improper payments | Medium | High | High | Low | A. Ruiz | Controlled |
| Logistics | Third party without due diligence | Medium | Medium | Medium | Low | C. Vega | In review |
| Finance | Irregular accounting record | Low | High | Medium | Low | L. Soto | Controlled |
- Critical
Procurement
Supplier favoritism
High · High · Medium · J. Morales · Open
- High
Commercial
Improper payments
Medium · High · Low · A. Ruiz · Controlled
- Medium
Logistics
Third party without due diligence
Medium · Medium · Low · C. Vega · In review
- Medium
Finance
Irregular accounting record
Low · High · Low · L. Soto · Controlled
Turn risks into controls you can manage.
- Risk
- Control
- Owner
- Activity
- Evidence
- Result
Due diligence on critical third parties
- Objective
- Verify critical third parties before contracting.
- Owner
- Prevention Officer
- Frequency
- Monthly
- Status
- Executed
- Evidence
- Report DD-041
- Result
- Conforming
- Last run
- 12 Mar
- Next run
- 12 Apr
A control is not valuable because it exists in a policy. It is valuable when it can be executed, monitored, and evidenced.
The model lives in daily operations.
Califix turns model obligations into concrete activities that can be assigned, executed, and monitored.
Execute control
M. Peña18 MarClosedConformingDD-041
Review process
A. Ruiz21 MarIn progressPartialREV-12
Validate evidence
C. Vega22 MarPending—To upload
Update matrix
J. Morales28 MarScheduled——
Review third party
L. Soto02 AprIn progressNotedTER-088
Analyze finding
M. Peña04 AprOpenIn analysisHAL-019
Manage action plan
A. Ruiz18 AprIn follow-upOn timePA-007
Run monitoring
C. Vega30 AprScheduled——
Document result
L. Soto02 MayPending—To record
Is the model actually working?
Keep a continuous view of the model and see, in time, where it needs attention.
Controls executed
128
This quarter
Overdue controls
6
Need execution
Pending activities
11
Assigned
Critical risks
3
Under follow-up
Open findings
4
With an owner
Corrective actions
8
2 critical
Evolution
+6 pts
Versus prior quarter
When something happens, the model has to respond.
- Detection
- Record
- Classification
- Investigation
- Action
- Evidence
- Closure
- Incident type
- Control finding
- Date
- 04 Mar
- Process
- Procurement
- Related risk
- Supplier favoritism
- Owner
- Prevention Officer
- Severity
- High
- Status
- Under review
- Measures taken
- Process paused and action plan opened
- Evidence
- ACT-118
- History
- 3 recorded events
Centralize incidents, findings, and corrective actions without losing traceability.
Every finding has to become an action.
Follow through until each action is actually resolved.
- 01
Finding
Due diligence control executed after its due date.
- 02
Corrective action
Rerun the review and adjust the frequency.
- 03
Owner
Compliance leadership
- 04
Target date
30 Apr
- 05
Evidence
Pending upload
- 06
Validation
Open
- 07
Closure
In follow-up
Show that the model works.
Compliance has to show not only that a prevention model exists, but how it is managed, which controls run, which findings are identified, and which actions are taken.
01
Control executed
Due diligence
02
Owner
M. Peña
03
Date
18 Mar
04
Result
Conforming
05
Evidence
Report DD-041
06
Validation
Validated
Every activity leaves a trace.
Your model has to evolve with your organization.
When the business changes, risk exposure changes. Califix keeps the model current and traceable.
Processes
A digital sales channel is added to the model scope.
Risks
New exposure in commercial intermediaries.
Controls
A quarterly review of critical third parties is added.
Owners
Matrix ownership moves to Risk Management.
Third parties
A logistics operator is added to the risk map.
Internal policy
The code of ethics and its current version are updated.
Organization
A new regional leadership team enters scope.
The entire compliance operation, in one view.
Prevention Model
Example
- Operating controls
- 92%
- Material risks
- 14
- Active controls
- 37
- Open actions
- 8
- Evidence available
- 96%
- Open findings
- 4
Risk Exposure
- Procurement86
- Commercial72
- Logistics54
- Finance41
- People28
Control Effectiveness
92%
Evidence Coverage
96%
Evolution over Time
Monitoring Status
- Executed82%
- In progress11%
- Overdue7%
Open Actions
- Adjust third-party frequency30 Apr
- Close procurement finding18 Apr
- Reassign regional control02 May
In seconds, I know the state of the model.
Operational information for Compliance. Executive information for leadership.
Turn model operations into information that decision-makers can use.
Compliance
Detail on risks, controls, activities, findings, and evidence.
- Risks on the map
- 14 material
- Controls with an owner
- 37
- Activities this month
- 11 open
- Findings with evidence
- 4
Management
A summary for people who decide.
- Principal risks
- 3 critical
- Model status
- Operating
- Exposures
- Procurement and third parties
- Findings
- 4 open
- Critical actions
- 2
- Evolution
- +6 pts this quarter
The prevention model should not live on its own.
One platform for the risks and obligations that affect the organization.
- Prevention Model
- Risk Management
- Third Parties
- Conflict of Interest
- Data Protection
- Evidence
- Compliance
Built for Compliance teams that need real control.
Designed for organizations where the model must stay operational, current, and demonstrable across its full lifecycle.
Crime Prevention Officers
Operate the model, assign controls, and show they were executed.
Chief Compliance Officers
See the state of the model and prioritize exposures.
Legal leadership
Follow findings, actions, and the evidence attached to them.
Internal Audit
Reconstruct what ran, who did it, and what supports it.
Risk Management
Connect risks, controls, and residual risk on one map.
Boards and management
Receive the state of the model without the operational detail.
More than a documented model. An operating model.
Traditional management
- Documents
- Spreadsheets
- Meetings
- Manual follow-up
- Scattered evidence
- Periodic reviews
Califix
- Risk Management
- Controls
- Workflows
- Monitoring
- Evidence
- Audit Trail
- Action Plans
- Executive Dashboard
The difference is not having a model. It is being able to run it.
A platform to professionalize compliance operations.
Technology so Compliance moves from administering documents to running an operation.
01
Platform
Technology to centralize the entire operation.
02
Risk
Prioritization and a view of the main exposures.
03
Operations
Workflows, activities, owners, and follow-up.
04
Evidence
Traceability of the work and support for the activities performed.
Your prevention model cannot stay in a document.
Take it into operations with Califix and manage risks, controls, monitoring, evidence, and continuous improvement from one platform.
Califix Compliance
Crime Prevention Model PRO
Prevention. Operated. Monitored. Evidenced.