SAGRILAFT implementation: risk matrix, manual and procedures
Implementing a SAGRILAFT is not delivering a manual. It is building a system the board can approve, the staff can actually run, and that leaves a documentary trail for the day the authority asks. We diagnose the real risk factors of the business, document the matrix, draft the manual on your operation rather than on a template, put the due diligence procedures to work and train your people with attendance records.
Implementing is not handing over a manual
The manual is the last piece of the work, not the first. What the authority looks at is not the cover page but whether there is a risk matrix built on the real operation, whether there are procedures someone actually runs, and whether there is a trail showing they were run. A manual downloaded from the internet and approved in a minute leaves the company exactly as exposed as before, with the added problem that there is now a signed document promising things nobody does.
Diagnosing the risk factors
We start by understanding the business, not by opening a template. The risk factors set out in the regime mean different things in a commodity trader, a construction company and an exporter.
- Counterparties. Customers, suppliers, partners, employees and other third parties the company deals with, grouped by type.
- Products and services. Which lend themselves to misuse and which do not, with the reasoning behind each rating.
- Distribution channels. Direct sales, distributors, platforms, intermediaries and the means of payment accepted.
- Jurisdictions. Where it buys, where it sells, where payments come from and where funds are sent.
The risk matrix
This is the document that holds everything else up. We document the four stages —identification, measurement, control and monitoring— recording the criterion used to rate each risk and who owns each control. That traceability, not the length of the document, is what makes the programme defensible. We also record the level of risk the company is prepared to accept, because without that definition later decisions have nothing to be measured against.
The pieces that get adopted
- The SAGRILAFT manual drafted on the company's operation, together with the approving body's minute.
- Due diligence procedures: what is requested, from whom, at which point in the commercial process and who may authorise an exception.
- Red flags specific to the sector and the business, with the internal route to analyse them and document the decision.
- Escalation and reporting: who analyses, who decides and how the decision to report or not to report is recorded.
- Record retention and access rules for the information collected.
- Working forms so the sales and procurement teams can comply without consulting legal on every case.
Training and going live
A programme nobody explains is a programme nobody applies. We run separate sessions: one for staff in contact with customers and suppliers, who request the documents and see the flags first; one for management, who authorise exceptions; and one for the board or the highest corporate body, which approves the programme and answers for supervising it. Each session leaves materials and an attendance record, because training that cannot be evidenced, for practical purposes, did not happen.
We then support the first operating cycles: the first onboardings run under the new procedure, the first alert that has to be analysed, the first compliance officer report. That is where it becomes clear which part of the design needs adjusting, and it gets adjusted.
What the client receives
- The risk factor diagnosis and the documented matrix, with criteria and owners.
- The manual and policies, with the approval minute and evidence of internal circulation.
- The due diligence procedures and forms, ready to operate.
- The training delivered, with materials and attendance records.
- The programme's compliance calendar and the evidence file showing it exists and is applied.
Who this is for
- Companies that have just confirmed they are covered and have nothing in place.
- Companies with a generic manual and no procedure behind it.
- Groups that need a common standard and separate programmes per subsidiary.
- Companies asked by a third party to evidence the programme, who found they had nothing to show.
Let's solve your legal matter
Every case starts with an honest conversation. Book 30 minutes, no commitment.
Start my SAGRILAFT →