
The objection
Ask an antitrust lawyer whether their client should map competition risks and you will often get a cautious answer. The reasoning goes like this. Competition authorities conduct unannounced inspections. They can seize any document relevant to the investigation. A risk map is a document written by the company about its own exposure to cartels, information exchange or abuse of dominance. If the inspectors find it, you have handed them a roadmap.
I hear this everywhere, and most often in France, for reasons explained below. It is the logic of any litigator who thinks about a case file first and a compliance system second.
What I never hear is the same objection about anti-corruption. The same lawyers, advising the same groups, treat the corruption risk map as a given. In France the AFA audits it, can sanction its absence, and can refer findings to the prosecutor. Nobody argues that a corruption risk map should not exist. One map is imposed by law, article 17 of loi Sapin II, and the other is only recommended. When a tool is optional, every residual risk becomes a reason not to use it.
The real problem: a misconception of the exercise
The fear of seizure assumes that a risk map contains something an inspector would want. That assumption reveals a misunderstanding of what the map is and what it is for.
A competition risk map starts from objective elements. Which sectors does the company operate in, and how concentrated are they? Does it hold a strong position anywhere? Where do its people meet competitors: trade associations, standardisation bodies, joint ventures, supplier-customer relationships with rivals? How are prices set, and who sees what? Does it respond to public tenders? Does it operate in sectors with a history of enforcement?
From those elements, the map builds scenarios. "Sales managers attend quarterly trade association meetings where pricing trends are discussed." "Regional subsidiaries respond to the same tenders as a company in which the group holds a minority stake." Each scenario gets a probability, an impact, and a list of existing controls.
None of this is an admission. "Our people meet competitors monthly" is a fact about the industry. "Therefore information exchange risk is high" is a judgment about exposure. To sanction a company, an authority needs evidence of an agreement, an exchange or an abuse. A map of where such things could happen is not that evidence. If anything, it shows the company identified the scenario and acted on it.
The purpose follows from the content. A risk map exists to decide where controls, training and monitoring should go. It is a management tool for allocating compliance effort. It is not an audit of past conduct, not a confession, and not a file for litigation. A lawyer who fears the map is usually picturing a different document: a Word file drafted after twenty free-form interviews, with raw allegations written into the risk descriptions. That document is a liability. It is also not a risk map. It is an unstructured investigation file with a risk map's title.
The map and the investigation are two different registers
This is the structural point that resolves the objection.
A risk map operates at scenario level. An internal investigation operates at fact level. They are different documents, held by different people, under different rules.
Interviews are part of building a map. Sometimes an interview surfaces something concrete: a conversation that went too far, an email that should not have been sent, a habit at a trade body that nobody questioned. That signal does not go into the map. It leaves the mapping exercise and enters the internal alert and investigation procedure, which the EU Whistleblowing Directive makes mandatory for companies above 50 employees, and which authorities treat as a separate pillar. The French framework separates control, audit and alert mechanisms from the follow-up procedure when infringements are discovered. The CNMC evaluates the risk map and the complaint-handling procedure as two distinct criteria. The DOJ asks how a company decides which red flags merit investigation and whether investigations are independent and properly documented.

Where the fear comes from, and why it is loudest in France
Once the misconception is set aside, what remains of the fear is a confidentiality question. It is real, and it deserves to be stated properly, but it is secondary.
Under EU law, since Akzo, communications with in-house counsel do not benefit from legal privilege in Commission investigations. Several Member States follow the same line. France went furthest: until 2026, in-house lawyers had no confidentiality at all.
The French Autorité's 2022 document-cadre recommends managing competition law through risk by using a risk map, a concept borrowed from loi Sapin II, and says nothing about privilege.
The OECD reports a German case where the Bundeskartellamt seized summaries of interviews a law firm had held with management during a compliance audit (not a risk map exercise); the Bonn court held that privilege covered only the entity that had instructed the firm for its defence.
In British Sugar, the Commission increased the fine by 75% for aggravating circumstances. The Commission argued that British Sugar had acted contrary to the clear wording of its own competition compliance programme. The programme, adopted in December 1986, expressly prohibited price coordination and the exchange of pricing information with competitors. British Sugar had presented it to the Commission and obtained a significant fine reduction for it in the 1988 Napier Brown decision. It then kept meeting Tate & Lyle and the sugar merchants to coordinate prices until July 1990.
Look closely at these two cases. In Bonn, what was seized and used was interview material from an internal investigation, in other words facts. In British Sugar, what aggravated the fine was conduct that contradicted the undertakings the company had given to the Commission and the compliance programme it had adopted, both of which the Commission had already counted as mitigating factors when fixing the fine in Napier Brown. Neither case involved a scenario-level risk map. They confirm the point above: the exposure sits in the investigation register and in the gap between what a company says and what it does, not in the map.
The confidentiality gap is narrowing anyway
In France, loi n° 2026-122 of 23 February 2026 makes in-house legal consultations confidential; confidentiality cannot be invoked in criminal or tax proceedings but can be in civil, commercial and administrative matters. The Conseil constitutionnel validated the law on 18 February 2026, and it enters into force on a date set by decree, at the latest on the first day of the twelfth month after promulgation. France was the outlier among OECD countries on this point. The outlier is being corrected.
Two limits remain. The French law preserves the control powers of EU authorities, so confidentiality will not be opposable to Commission inspectors, consistent with Akzo. And the Conseil constitutionnel's reservations let administrative authorities, including the Autorité de la concurrence, challenge confidentiality before the JLD under any statutory right of communication.
In any jurisdiction, the map itself is a management document and not a legal opinion. The legal analysis attached to it, assessing residual risk and recommending controls, can be privileged.
The authorities asked for it
An authority that publishes a methodology and then treats its use as a confession would undermine its own policy. The French framework says an effective programme must prevent infringement risks, provide the means to detect and handle infringements that could not be avoided, and plan for updates, including when a company becomes dominant after gaining share. The ICC Antitrust Compliance Toolkit places risk identification and assessment right after culture and organisation. The DOJ's guidance expects periodic risk assessment under an oversight body.
Detection is the point, and detection is rewarded
The mapping exercise that finds a real problem is not the company's worst day. It is the company's best chance.
A company that discovers a problem through its own compliance work can apply for leniency before anyone else does. The company that avoided looking gets raided, and then learns a competitor filed first. There is no version of that race a company wins by not knowing.
Several authorities make the reward explicit. In Spain, the CNMC's guide allows fine mitigation under article 64.3 LDC when the company has cooperated actively or ended the infringement, provided those actions are verifiably linked to the compliance programme. In Italy, the AGCM granted reductions in 13 of 18 compliance-based requests between 2015 and March 2021, from 5% to 15%. In the US, the DOJ asks what role the compliance programme played in uncovering the violation. The European Commission and the French Autorité grant no reduction for the mere existence of a programme, but a functioning programme still improves the company's position.
Not mapping is the riskier choice
Consider the company that chose not to map. Its training is generic. Its controls are generic. When a raid comes, it cannot show which scenarios it had identified or what it did about them. If the raid uncovers conduct that a basic map would have flagged, the absence of risk work does not look prudent. It looks like a company that preferred not to know.
The map is the evidence of diligence. The absence of a map is the evidence of negligence.
Rules for a risk map that protects the company
- Keep the map at scenario level. Describe exposures, controls and residual risk. Never record individual conduct.
- Route facts out immediately. Anything factual that emerges in an interview goes into the alert and investigation procedure, under the rules that apply there.
- If you need a legal analysis have it issued as a privileged opinion. Where in-house privilege exists, mark it. Where it does not, or not yet, route the opinion through outside counsel.
- No names of third parties. Competitor contact details, customer employees and association officials have no place in a risk map.
Building a map this way is not simple. It requires market knowledge, process knowledge and legal judgment, and the first version is usually harder than the updates. It is also not only legal work. A risk map is a risk management exercise: it rests on judgment about likelihood and impact, on decisions about which controls answer which scenarios, and on traceability that shows those controls exist, are implemented and are effective. That traceability is what an authority, an auditor or a board will look at.
How Naltilia keeps the registers separate
Naltilia structures competition risk maps around scenario libraries with controlled vocabulary, so the map stays at the level of exposure by construction. Interview inputs are captured separately from scenario ratings. When an interview surfaces something that needs investigation, the compliance officer or counsel decides to take it out of the mapping flow and into the alert workflow, with its own access rights. The platform makes that separation possible and keeps it traceable; it does not make the decision. Deciding what is a scenario and what is a fact requires human judgment, and that judgment stays with the people responsible for the programme. The resulting map is auditable, versioned and defensible, and it shares its architecture with our Sapin II mapping, which is why the two programmes can share a backbone without sharing a file.
Book a 30-minute conversation about your competition risk map

