Article

Compliance And Esg

October 02, 2026

Ethics in Artificial Intelligence and ESG in Brazilian corporate practices

Ethics in Artificial Intelligence and ESG in Brazilian Corporate Practices

Fabiane Baltruchaitis Figueiredo; João Valsecchi Ribeiro de Souza

DOI: 10.22167/2675-6528-202602881

Article derived from a Final Course Work (TCC), with content based on the student’s original work and adapted to the editorial format of the E&S Magazine with the support of the ResumeAI tool, an artificial intelligence solution developed by the Pecege Institute for textual synthesis and organization.

Abstract

The growing adoption of artificial intelligence in the corporate environment has amplified ethical, social, and environmental challenges, demanding the incorporation of practices aligned with governance and sustainability. A lack of clarity was identified regarding the maturity level of artificial intelligence ethical practices in publicly traded Brazilian companies. The study analyzed, in an intentional sample of eight publicly traded Brazilian companies, how artificial intelligence ethical governance guidelines and practices are evidenced in public documents and compared their level of documentary maturity. An exploratory and descriptive research was conducted, with a predominantly qualitative approach and a complementary quantitative component, using a multiple case study design. The methodology was based on the comparative analysis of institutional reports and corporate policies of eight companies listed on B3, from various economic sectors. The data were systematized through a comparative matrix, based on international theoretical and normative references on artificial intelligence ethics. The results showed a heterogeneous adoption of ethical practices among sectors, with greater maturity in organizations under greater regulatory pressure. Gaps persisted in dimensions such as transparency, explainability, and mitigation of algorithmic biases. The observed initiatives were largely reactive, indicating a dissociation between technological advancement and ethical governance. The analysis demonstrated that artificial intelligence ethics remains in a consolidation process in the Brazilian corporate context, demanding more integrated, proactive approaches aligned with ESG principles.

Keywords: Compliance; ESG; Ethics in artificial intelligence; Technological governance; Responsible AI.

1. Introduction

The growing adoption of Artificial Intelligence (AI) technologies has transformed the existing social order, improving business processes in various areas and promoting innovation, efficiency gains, and competitiveness. Data from the 2024 Semestral Innovation Survey (Pintec Semestral) by the Brazilian Institute of Geography and Statistics (IBGE) indicated that the technology whose use grew the most was artificial intelligence, with an increase of 16.9% compared to 2022, and that a significant percentage, 41.9%, of the 10,167 companies investigated used AI in their activities.

However, the intensive use of these technologies also generates social, ethical, and environmental externalities, which go beyond financial results. Among some of these consequences, as observed by Huang et al. (2023), are: algorithmic biases, impact on the number of available jobs in the labor market due to the replacement of human labor, lack of transparency in decision-making processes, risks related to confidentiality, privacy, and data security, increased energy consumption and carbon footprint of computational systems, as well as impacts on human physical and mental health and the violation of copyrights, human rights, and the rule of law itself, when viewed from the perspective of the legal system. These side effects represent real risks to corporate sustainability practices, pressuring organizations to incorporate governance, transparency, and risk mitigation mechanisms aligned with Compliance and ESG (Environmental, Social and Governance) frameworks.

With the intensification of pressures from investors, consumers, regulatory bodies, and civil society, organizations increasingly need to align their technological development with ethical values, human rights, and environmental goals. However, many companies still have gaps in their management programs for the non-financial impacts of AI, whether due to the absence of technological compliance structures or the lack of clear indicators reflecting the social and environmental effects of their digital operations. Thus, the research problem identified was the lack of clarity regarding the maturity level of ethical practices related to artificial intelligence in Brazilian publicly traded companies.

Thus, understanding the risks arising from the business use of AI that can affect companies’ ESG indicators is essential for the advancement of responsible and sustainable corporate practices, as the adoption of ethical practices and adherence to ESG guidelines can mitigate these risks, improving the response of organizations seeking to balance innovation, sustainability, and business ethics to these challenges and contributing to the strengthening of a model in ethical governance. The relevance of this study is supported both by the timeliness of the topic and by the emergent and still little-consolidated nature of applied research that addresses the connection between AI, ESG, and Compliance. By addressing this intersection, it is intended to support companies in formulating responsible, sustainable, and transparent corporate policies, especially regarding ethics in Artificial Intelligence. For the purposes of this study, AI governance is understood as the set of formal and informal mechanisms that guide the development, implementation, and monitoring of algorithmic systems, according to the literature on AI ethics and technological governance.

In this context, the study aimed to analyze, in an intentional sample of eight publicly traded Brazilian companies, how ethical artificial intelligence governance guidelines and practices are evidenced in public documents and to compare the degree of documentary maturity of these practices among the selected organizations and sectors.

2. Material and Methods

This study was characterized as an exploratory and descriptive research, with a multiple case study design and applied character. The methodological approach adopted was predominantly qualitative, based on documentary analysis and content interpretation, seeking to identify contextual evidence. A complementary quantitative component was employed to synthesize frequencies and compare patterns, resulting from the ordinal coding of evidence in a comparative matrix.

The unit of analysis consisted of the ethical artificial intelligence governance guidelines and practices, as evidenced in public corporate documents. The sample was intentional and comprised eight publicly traded Brazilian companies, listed on the B3 and belonging to various economic sectors. The selection of these organizations considered criteria such as size, economic relevance, sectoral diversity, and maturity in the use of artificial intelligence, in addition to the publication of annual reports and the adoption of structured practices for governance, risk management, and compliance.

The inclusion criteria for the documentary corpus were: (i) to be an official and publicly accessible document; (ii) to be the current institutional publication or the most recent one located until April 2026; (iii) to present explicit content about AI or documents related to governance, risks, data, human rights, sustainability, security, ethics, or compliance potentially related to the framework’s dimensions; and (iv) to allow comparison between companies. Promotional materials without normative or governance content, third-party news, and documents with no identifiable institutional authorship were excluded.

The public corporate documents analyzed included integrated reports, sustainability reports, information and cyber security policies, artificial intelligence risk management policies, data ethics guidance documents, codes of ethics and conduct, global human rights policies, and human rights commitment statements. Specifically, documents from B3, Bradesco, Itaú Unibanco, TOTVS, Vale, Petrobras, Magazine Luiza, and Natura &Co were examined, all available for consultation until April 2026.

Data collection was carried out by systematically reading the institutional documents of the eight selected companies. Evidence associated with each dimension of the proposed framework, which served as the basis for the analysis, was identified. The process involved searching for explicit references to artificial intelligence, algorithmic systems, or automated decisions, as well as describing applicable mechanisms, rules, responsibilities, controls, or procedures.

For the comparative analysis, a matrix based on international theoretical and normative references on ethics in artificial intelligence was used. This matrix was inspired by the panorama outlined by Huang et al. (2023) and the guidelines of the “Recommendation on the Ethics of Artificial Intelligence” and “Brazil: artificial intelligence ethics readiness assessment report”, both from UNESCO. The systematization of the dimensions aimed to ensure conceptual clarity and consistency in data interpretation.

The data analysis technique involved the comparative qualitative categorization of evidence. Each dimension was evaluated and classified as “Present” when the document made explicit reference to AI and described at least one applicable mechanism, rule, responsibility, control, or procedure. The “Partial” classification was assigned when the evidence appeared in a generic or indirect way, without explicit linkage to AI, or when AI was mentioned without detailing an operational mechanism. It was classified as “Absent” when no relevant documentary evidence for the dimension was found in the analyzed corpus. This ordinal classification aided in comparing patterns across companies and dimensions.

In the interpretation of the data, a distinction was made between direct evidence of ethical AI governance, which expressly mentions AI, algorithms, models, or automated decisions and establishes principles, responsibilities, controls, supervision, risk assessment, or accountability mechanisms applicable to these systems. Contextual evidence corresponded to general ESG practices, human rights, diversity, privacy, information security, sustainability, and compliance that, although they could support responsible governance, did not, in isolation, demonstrate their direct application to AI. This distinction was crucial to avoid erroneous inferences about AI ethics maturity.

During the study preparation phase, ChatGPT was used as a support tool in the search for papers for the literature review, in the alignment of the methodology for data collection and analysis, and in the systematization of the consulted institutional reports and policies. The author reviewed and edited the generated content, assuming full responsibility for the published material.

The structuring of the analyzed dimensions in the comparative matrix was essential to provide theoretical and methodological support to the study. This approach sought to reduce ambiguities, standardize evaluation criteria, and strengthen the validity of the proposed framework, contributing to methodological transparency and research replicability. The dimensions were defined based on the literature on AI ethics and technological governance.

3. Results and Discussion

The analysis of public documents from eight Brazilian publicly traded companies revealed a heterogeneous panorama regarding the maturity of ethical practices related to artificial intelligence. The findings indicated that the formalization of ethical guidelines and governance mechanisms for AI is in different stages of development across economic sectors, reflecting the complexity of the subject and the diversity of regulatory and market pressures. This variation suggests that the incorporation of ethics in AI is still in a consolidation process within the Brazilian corporate environment, as pointed out by the literature (Huang et al., 2023).

The results showed that the adoption of formal governance, control, and risk mitigation mechanisms associated with AI occurred unevenly across sectors. Companies in more regulated segments with greater technological dependence, such as banking and technology, demonstrated greater progress. In contrast, organizations in sectors like mining, energy, and consumer goods, despite strong ESG performance, presented less explicit detail on AI ethics, addressing it more indirectly within broader corporate policies.

For the interpretation of the results, it was fundamental to distinguish between direct and contextual evidence. Direct evidence refers to explicit mentions of AI, algorithms, or automated decisions, accompanied by specific principles, responsibilities, or controls. Contextual evidence, on the other hand, corresponds to general ESG practices, human rights, privacy, or information security that, although relevant, do not demonstrate their direct application to AI. This distinction was crucial to avoid overestimating ethical maturity in AI based solely on robust corporate ESG or data protection frameworks.

In general, the dimensions of privacy, data protection and security, as well as risk management and impact assessment, showed the greatest adherence among the analyzed companies. This scenario can be attributed to the influence of regulatory frameworks such as the General Data Protection Law (LGPD) and the consolidation of risk management practices within corporate governance. However, more complex dimensions, such as algorithmic transparency and fairness, remained at intermediate or incipient levels, indicating gaps in the operationalization of abstract ethical principles into technical and measurable practices.

Governance, accountability and regulation

The governance, accountability, and regulation dimension has proven to be one of the most developed, especially in financial institutions and technology companies. The presence of formal control and accountability structures was observed, notably Bradesco, which has a specific AI Risk Management Policy, and Itaú Unibanco, with its Data Ethics Guidelines Guide. These initiatives reflect an emerging concern with specific AI governance, driven by the strong regulation of the financial system and the criticality of automated decisions in its operations.

The governance of artificial intelligence, according to Floridi et al. (2018), requires not only regulatory compliance but also internal mechanisms that ensure supervision and auditing throughout the entire lifecycle of the systems. Although financial and technology companies such as TOTVS and B3 present a “Present” level in this dimension, others like Vale, Petrobras, Magazine Luiza, and Natura &Co were classified as “Partial”. This indicates that, in the latter, governance guidelines are more generic, without explicit and detailed linkage to AI, which may limit the effectiveness of accountability.

Transparency, explainability, and contestability

Transparency, explainability, and contestability in artificial intelligence systems showed intermediate levels of development in most companies. Only Itaú, Bradesco, TOTVS, B3, and Magazine Luiza were classified as “Partial”, while Vale, Petrobras, and Natura &Co were considered “Absent”. Although some companies, such as B3 and TOTVS, have shown progress in communicating their processes and control mechanisms, most organizations have not yet provided sufficient detail on the functioning of automated systems.

The absence of mechanisms that allow users or stakeholders to contest algorithmic decisions is a significant gap. Explainability, according to Doshi-Velez and Kim (2017), is fundamental to ensure trust and allow for critical evaluation of systems, and its indirect mention in institutional reports has not translated into clear evidence of operationalization. This scenario suggests that companies still face challenges in translating abstract principles of transparency into technical and measurable practices, which can compromise the legitimacy and social acceptance of AI.

Privacy, data protection and security

Privacy, data protection, and security were the dimensions with the highest adherence among companies, with Itaú, Bradesco, TOTVS, B3, Magazine Luiza, and Natura &Co classified as “Present”. Vale and Petrobras were classified as “Partial”. This result reflects the strong influence of regulatory frameworks such as the General Data Protection Law (LGPD) and the consolidation of risk management practices within corporate governance. Financial institutions, in particular, demonstrated robust information security and privacy policies, evidencing adherence to legal and regulatory requirements.

The protection of privacy, according to Nissenbaum (2010), must be understood within the concept of contextual integrity, respecting social expectations about the appropriate use of information. The broad identification of these practices, especially in organizational contexts that depend intensively on personal data, indicates considerable maturity in managing these aspects. However, the “Partial” classification for some companies suggests that, although general policies exist, the explicit and detailed link to AI can still be improved.

Justice, equity, and non-discrimination

The dimension of justice, equity, and non-discrimination showed more incipient development, with most companies (Itaú, Bradesco, TOTVS, B3, Petrobras, Magazine Luiza) classified as “Partial”. Only Vale and Natura &Co were classified as “Present”, mainly through diversity and inclusion policies. The findings corroborated the difficulty organizations have in translating abstract principles of algorithmic equity into concrete technical mechanisms, as highlighted by Barocas, Hardt, and Narayanan (2019).

The absence of clear evidence on the mitigation of algorithmic biases suggests that this dimension has not yet been fully incorporated into business practices. AI systems can reproduce or amplify existing inequalities when trained with biased historical data, making the adoption of bias detection and mitigation mechanisms essential. The generic approach, without explicit linkage to AI, in many of the observed policies, indicates that the operationalization of these principles is still a significant challenge in the Brazilian corporate context.

Human supervision and autonomy

Human oversight and autonomy was identified as “Present” in Itaú, Bradesco, and B3, and “Partial” in TOTVS, Petrobras, and Magazine Luiza, while Vale and Natura &Co were classified as “Absent”. The presence of human control mechanisms over automated systems was more evident in financial institutions, where the criticality of decisions demands greater human intervention. This principle is associated with the concept of “human-in-the-loop”, in which humans maintain an active role in validating and reviewing automated decisions.

AI autonomy, as proposed by the European Commission (2019), should be limited by safeguards that prevent fully independent decisions in sensitive contexts. The identification of such mechanisms in financial companies and B3 demonstrates a concern for security and responsibility. However, the “Partial” classification for other companies indicates that, although general controls exist, the specificity of human supervision regarding AI systems is not yet fully formalized or detailed in their public documents.

Social and work impacts

The dimension of social and labor impacts showed a mixed distribution, with Vale, Magazine Luiza, and Natura &Co classified as “Present”, and Itaú, Bradesco, TOTVS, B3, and Petrobras as “Partial”. Professional requalification and digital inclusion initiatives were highlighted, especially in companies like Magazine Luiza, which intensively use AI in processes related to customer experience and logistics. The adoption of AI in the organizational environment generates significant impacts on the labor market, requiring adaptation and professional requalification.

Brynjolfsson and McAfee (2014) argue that automation can increase productivity, but also deepen inequalities if not accompanied by adequate policies. The “Partial” classification for most companies suggests that, although there is recognition of the social impacts, the formalization of specific guidelines to mitigate these effects in relation to AI is still incipient. The presence in Vale, Magazine Luiza, and Natura &Co may be linked to their broader corporate social responsibility agendas.

Sustainability and environmental impacts

Sustainability and environmental impacts was a dimension with greater adherence in companies with strong ESG performance, such as Vale, Petrobras, and Natura &Co, classified as “Present”. The other companies (Itaú, Bradesco, TOTVS, B3, Magazine Luiza) were classified as “Partial”. However, even in companies classified as “Present”, the explicit connection between sustainability practices and the use of artificial intelligence was not widely detailed in the analyzed documents. This result suggests an opportunity for integration between agendas that are still treated separately.

Studies such as those by Strubell, Ganesh, and McCallum (2019) show that large-scale AI models can have significant environmental footprints, demanding that AI ethics incorporate environmental concerns. The “Partial” classification for most companies indicates that, although there is a commitment to sustainability, the specificity of how AI is managed to minimize its environmental impact is not yet fully formalized. The proactive integration of AI ethics with ESG principles is a way to promote efficient resource use and the development of more sustainable technologies.

Risk management and impact assessment

Risk management and impact assessment was a widely evidenced dimension, with Itaú, Bradesco, TOTVS, B3, Vale, and Petrobras classified as “Present”. Magazine Luiza and Natura &Co were classified as “Partial”. This result highlights the importance attributed to the identification, analysis, and mitigation of potential adverse effects arising from the use of automated systems. Impact assessment, according to the OECD framework (2019), is an essential tool for anticipating consequences and guiding responsible decisions, being a central element in compliance contexts.

The strong adherence in this dimension, especially in financial institutions and regulated companies, reflects the criticality of their operations and the need to prevent operational and reputational risks. The existence of policies and procedures to manage risks, even if more broadly in some companies, demonstrates a level of maturity in corporate governance. However, the “Partial” classification for Magazine Luiza and Natura &Co suggests that, although risk management is an established practice, its specific application to the impacts of AI may still lack greater documentary detail.

Trust, perception, and social acceptance

The dimension of trust, perception, and social acceptance showed uniformly “Partial” development in all eight companies analyzed. Institutional communication focused on reputation and transparency was observed, but without sufficient detail on how trust in AI systems is built and maintained. Social acceptance of AI depends not only on its technical effectiveness but also on the transparency, responsibility, and communication of organizations, according to Mayer, Davis, and Schoorman (1995).

The absence of structured and explicit initiatives in this area may compromise the legitimacy of AI use in the long term, especially in contexts of growing public concern about privacy, discrimination, and automation. The “Partial” classification for all companies indicates that, although there is a recognition of the importance of reputation and communication, the formalization of specific strategies to foster trust and social acceptance of AI is still a challenge to be overcome, demanding more proactive and integrated approaches.

Education, training, and access to AI

Education, training, and access to AI presented a mixed scenario, with TOTVS classified as “Present”, Itaú, Bradesco, B3, Petrobras, and Magazine Luiza as “Partial”, and Vale and Natura &Co as “Absent”. Initiatives for internal training in technology and innovation were identified, especially at TOTVS, which develops digital solutions. This dimension involves the need to prepare individuals and organizations to understand, use, and critically interact with AI systems, including technical training and the development of ethical and analytical skills.

The democratization of access to AI is fundamental to ensure its equitable and sustainable use, according to UNESCO (2021). The “Partial” classification for most companies suggests that, although there are investments in technological training, the specificity of education in AI ethics and the promotion of equitable access are not yet fully formalized. The absence in Vale and Natura &Co may indicate that, for these companies, AI is not yet a central focus in their training and development strategies, or that such initiatives are not publicly disclosed.

Human rights and dignity

The dimension of human rights and dignity was classified as “Present” in Bradesco, Vale, and Natura &Co, and “Partial” in Itaú, TOTVS, B3, Petrobras, and Magazine Luiza. The practice was identified through documentary evidence in corporate policies, reports, and codes of conduct. In the case of Bradesco, the adoption of a Corporate Human Rights Policy and a Diversity, Equity, and Inclusion Policy demonstrated institutional alignment with fundamental principles of dignity, equality, and respect for individuals.

The relationship between artificial intelligence and human rights includes the guarantee that automated systems respect fundamental principles, making it necessary to incorporate them from the design stage (“by design”), as stated by the UN (2020). The “Partial” classification for most companies indicates that, although there is a general commitment to human rights, the explicit and detailed linkage of these principles to AI governance is still a challenge. Companies classified as “Present” have shown progress in formalizing these guidelines in their public documents.

Sovereignty and technological development

The dimension of sovereignty and technological development showed the lowest level of adherence, with only TOTVS classified as “Present”, while all other seven companies were classified as “Absent”. Technological sovereignty refers to an organization’s ability to develop, control, and use strategic technologies, such as artificial intelligence, autonomously and aligned with its interests. This dimension involves geopolitical, economic, and regulatory issues, including dependence on external suppliers and control over data and infrastructure.

TOTVS’s presence in this dimension can be explained by its role as a technology company, developing and providing digital solutions, which naturally positions it in a role of greater control over its technologies. Its absence in all other companies suggests that the discussion about technological sovereignty in relation to AI is still incipient in the Brazilian corporate context, or that such concerns are not formalized in public documents. According to Roberts (2024), sovereign technological development is essential to ensure security and competitiveness, and the lack of documentary evidence indicates a significant gap.

In summary, the research results revealed that the incorporation of ethics in artificial intelligence in the Brazilian corporate context is heterogeneous and still in the consolidation phase. Companies in more regulated and data-intensive sectors, such as finance, demonstrated greater maturity in dimensions such as governance, risk management, and data protection, driven by regulatory pressures and the criticality of their operations. However, significant gaps persist in more complex dimensions, such as transparency, explainability, algorithmic bias mitigation, and technological sovereignty, indicating the need for more integrated and proactive approaches. The analysis reinforces that, although there is growing recognition of the importance of AI ethics, the translation of abstract principles into operational and measurable practices still represents a challenge for organizations, demanding the formulation of specific and transparent policies that align technological innovation with ethical responsibility and sustainability.

4. Conclusion

This study sought to analyze how ethical artificial intelligence governance guidelines and practices are evidenced in public documents from eight publicly traded Brazilian companies, comparing the degree of documentary maturity of these practices. Heterogeneous adoption of ethical practices was observed among sectors, with greater maturity in organizations subjected to more intense regulatory pressures, such as those in the financial and technology segments. It was observed that dimensions such as privacy, data protection, security, risk management, and impact assessment showed greater formalization. However, significant gaps persisted in more complex aspects, such as transparency, explainability, algorithmic bias mitigation, and technological sovereignty, indicating that artificial intelligence ethics is still in a process of consolidation within the Brazilian corporate context. The main contribution of this work lies in the proposal of a consolidated framework that integrates various ethical dimensions of corporate artificial intelligence use, offering a diagnostic tool for compliance, risk, audit, privacy, sustainability, and technology areas, and signaling the importance of aligning technological innovation with ethical responsibility.

As a main limitation, the exclusive use of public documents was highlighted, which may not fully reflect the internal practices of the analyzed organizations, in addition to the lack of standardization in the disclosure of information about artificial intelligence, which hindered more precise comparisons. It is suggested that future studies complement the proposed framework with interviews, control tests, indicators, and operational evidence, allowing for verification of the effective incorporation of formal commitments into the life cycle of AI systems. It is also recommended that organizations prioritize topics with less documentary evidence, such as explainability, contestability, and bias mitigation, and develop more integrated and proactive approaches, aligned with ESG principles, to promote a more responsible and sustainable use of artificial intelligence.

Bibliographic References

Floridi, L.; Cowls, J.; Beltrametti, M.; Chatila, R.; Chazerand, P.; Dignum, V.; Luetge, C.; Madelin, R.; Pagallo, U.; Rossi, F.; Schafer, B.; Valcke, P.; Vayena, E. 2018. Al4People – An ethical framework for a good Al society: opportunities, risks, principles, and recommendations. Minds and Machines 28(4): 6

Huang, C.; Zhang, Z.; Mao, B.; Yao, X. 2023. An overview of artificial intelligence ethics. IEEE Transactions On Artificial Intelligence 4(4): 799-816.

Instituto Brasileiro de Geografia e Estatística [IBGE]. 2025. De 2022 a 2024, percentual de empresas industriais utilizando inteligência artificial subiu de 16,9% para 41,9%. Disponível em: <https://agenciadenoticias.ibge.gov.br/agencia-noticias/2012-agencia-de-noticias/noticias/44551-de-2022-a-2024-percentual-de-empresas-industriais-utilizando-inteligencia-artificial-subiu-de-16-9-para-41-9>. Acesso em: 30 dez. 2025.

Article originating from the Final Course Work of the Specialization in Compliance and ESG of the MBA USP/Esalq

To learn more about the course, click here and access the MBX Academy platform

You may also like

Compliance And Esg

October 05, 2026

Compliance para mitigar e prevenir furtos em canteiros de obras: Programa de integridade aplicado à construção civil

Furtos em canteiros de obras representam um desafio significativo para a construção civil, gerando impactos financeiros, operacionais e reputacionais. Nesse contexto, programas de integridade e compliance surgiram como ferramentas de gestão para fortalecer a governança e mitigar riscos. O estudo objetivou propor um programa de conformidade aplicado à construção civil, focado na prevenção e mitigação de furtos em canteiros de obras. Adotou-se uma abordagem qualitativa, com apoio quantitativo, desenvolvida em duas etapas. Primeiramente, realizou-se uma pesquisa de campo entre fevereiro e março de 2026, aplicando um questionário eletrônico a profissionais do setor. Em seguida, elaborou-se um estudo de caso fictício, baseado em experiências profissionais do autor, integrando os resultados da pesquisa a práticas de gestão de riscos e governança. Os resultados evidenciaram a importância da implementação de programas de compliance no setor e indicaram que a combinação de mecanismos de controle, processos estruturados, capacitação de equipes, canais de denúncia, monitoramento contínuo e fortalecimento da cultura ética pode reduzir vulnerabilidades. Concluiu-se que a adoção de práticas de integridade amplia a capacidade preventiva das organizações e aprimora a governança e a gestão de riscos no setor.

Palavras-chave: Compliance; Construção civil; Furtos; Gestão de riscos; Governança corporativa.

Compliance And Esg

October 05, 2026

A integração da Lei Geral de Proteção de Dados aos programas de Compliance nas empresas

Analisou-se a integração da Lei Geral de Proteção de Dados (Lei nº 13.709/2018) aos programas de compliance em empresas, com o objetivo de destacar seus impactos, desafios e benefícios no contexto da governança corporativa. Adotou-se uma abordagem quali-quantitativa, de caráter exploratório e descritivo, com coleta de dados por meio de questionário aplicado a profissionais de diversas áreas organizacionais. Os resultados indicaram que a integração entre LGPD e compliance ainda se encontrava em estágio inicial na maioria das organizações, sendo marcada por dificuldades estruturais, culturais e operacionais. Entre os principais desafios identificados, destacaram-se a ausência de cultura organizacional voltada à proteção de dados, a insuficiência de treinamentos, a falta de engajamento da alta administração e a indefinição de papéis e responsabilidades. Por outro lado, verificou-se que empresas que promoveram a integração entre essas áreas apresentaram maior maturidade em governança, melhor gestão de riscos e maior confiança dos stakeholders. Concluiu-se que a LGPD atuou como um elemento catalisador para o aprimoramento dos programas de compliance, exigindo das organizações uma transformação estrutural e cultural para garantir a efetividade da conformidade e a proteção dos dados pessoais.

Palavras-chave: Compliance; Gestão de riscos; Governança corporativa; Lei Geral de Proteção de Dados; Proteção de dados.

Compliance And Esg

October 05, 2026

Instituto socioambiental e os pilares ESG: integração entre biodiversidade, capital humano e governança

A crescente pressão por práticas responsáveis impulsionou a agenda ASG como estratégica para a legitimidade organizacional. Um estudo analisou como um Instituto Socioambiental (IS) autônomo, criado por uma empresa do setor de papel e celulose, operacionalizou os pilares ASG na prática. A pesquisa fundamentou-se na premissa de que a autonomia do IS transformou obrigações de compliance em um modelo de governança que gera valor compartilhado. Metodologicamente, caracterizou-se como um estudo de caso único, qualitativo, exploratório e descritivo. A coleta de dados envolveu a triangulação entre entrevista semiestruturada com a diretoria do IS, documentos públicos institucionais (processados com IRaMuTeQ) e análise de relatórios de sustentabilidade da mantenedora (2004-2024) com base em indicadores GRI. Os resultados indicaram que o IS atuou como uma unidade de inteligência técnica que transcendeu a filantropia. No pilar Ambiental, destacou-se a gestão de biodiversidade com o monitoramento de sete mil hectares de Mata Atlântica. No pilar Social, programas de educação ambiental e a implantação de bibliotecas comunitárias fortaleceram a licença social para operar. No pilar de Governança, o IS promoveu a transparência e a redução de riscos ambientais ao integrar a diretoria de sustentabilidade da mantenedora. Concluiu-se que a estrutura independente do IS superou a fragmentação histórica entre gestão econômica e ecológica, convertendo metas corporativas em ativos estratégicos e vantagem competitiva.

Palavras-chave: ASG; Educação ambiental; IRaMuTeQ; Sustentabilidade corporativa.

Compliance And Esg

October 02, 2026

Compliance in Fixed-Odds Betting: Regulatory Challenges and Best Practices in the iGaming Market

The recent growth of the fixed-odds betting market in Brazil has highlighted the need for regulatory structures and control mechanisms capable of mitigating the financial and social risks associated with the activity. The objective was to analyze the implementation of compliance and corporate governance mechanisms in a company operating in the sector. A qualitative and applied approach was adopted, based on a case study, which included documentary analysis of internal policies, review of specialized literature, semi-structured interview with an industry expert, and observation of organizational processes. The results indicated that the analyzed company demonstrated formal adherence to regulatory requirements, with the implementation of governance structures, anti-money laundering controls, and user protection mechanisms. However, it was found that such measures presented limitations in practical effectiveness, especially in identifying risky behaviors and mitigating impacts related to problem gambling and users’ financial vulnerability. The analysis revealed a gap between formal compliance with regulatory obligations and the effective management of risks inherent to the activity in a regulatory context still under consolidation. It was concluded that the improvement of compliance programs in the sector depends on the adoption of more proactive, integrated, and data-driven approaches, aiming to strengthen governance and enhance user protection.

Keywords: Risk management; Corporate governance; Responsible gambling; Money laundering; User protection.

Compliance And Esg

October 02, 2026

Climate change and the formation of ESG professionals: an exploratory study in private companies in the socio-environmental impact sector in Brazil

Climate change has intensified the demand for professional and organizational training in ESG within the Brazilian business context. The study analyzed the perception of ESG professionals regarding their preparedness for climate change and investigated the training strategies reported by professionals from private companies with varying degrees of socio-environmental involvement or interface. The research adopted a descriptive-exploratory approach, combining quantitative and qualitative methods, through a structured questionnaire administered between January 16 and February 4, 2026, which totaled 52 valid responses. The results suggested predominantly intermediate levels of self-declared preparedness, with differences between the evaluated dimensions and familiarity with technical references, and the perception of preparedness for their practical application. Informal or ad-hoc training initiatives predominated, and open-ended responses highlighted technical, analytical, regulatory, organizational, and behavioral competencies as relevant. The findings indicated that strengthening professional action on the climate agenda involves both the development of individual competencies and organizational conditions related to training, governance, and the integration of the topic into decision-making processes.

Keywords: Professional training; Professional competencies; Organizational strategy; Climate risk management; Climate governance.

Compliance And Esg

October 02, 2026

The importance of compliance in mitigating legal risks in electronic contracts

The growing digitalization of business relationships has driven the evolution of contracts, which have moved from physical and formal instruments to more dynamic electronic models. However, such transactions are subject to new legal risks, and contractual compliance has become a fundamental element to ensure that processes, clauses, and electronic validation methods are aligned with legal norms and good governance practices. Given the existing gaps in the practical application of current regulations, the study sought to propose the creation of means to provide greater legal certainty to digital transactions. The study aimed to examine the specific legal risks of electronic contracts and present a structured compliance model to provide greater security and adherence to legal standards and requirements, and to mitigate such risks. To this end, an exploratory and qualitative methodology was adopted, supported by a bibliographic review of doctrine, legislation, jurisprudence, and policies of some large business corporations, systematically categorized to allow for comparison between them. As a result, it was found that there are recurring defects in electronic contracts, and compliance has proven to be an indispensable tool to combat them, becoming essential to ensure contractual validity and execution through the proposal of a model based on five pillars that minimizes risks and promotes safer, more transparent, and compliant digital contractual relationships.

Keywords: audit; governance; privacy; technology; transparency.

Compliance And Esg

October 02, 2026

Supplier integrity due diligence as a mechanism for mitigating reputational risks

The growing materialization of reputational risks in poorly structured commercial relationships has highlighted the relevance of supplier integrity due diligence. The study aimed to demonstrate that integrity due diligence is an essential mechanism for mitigating such risks. To this end, a single case study methodology was adopted, analyzing a winery in Rio Grande do Sul that was involved in an episode of slavery-like labor in 2023. Official documents, internal policies, and the company’s sustainability report, published between 2023 and 2025, were analyzed, and the winery’s compliance program was compared with the guidelines of the Comptroller General’s Office of the Union. The results revealed that the absence of structured due diligence procedures contributed to the hiring of a supplier with serious labor violations. However, after the reputational crisis, the winery implemented more robust governance practices, such as the creation of a Whistleblowing Channel and an Integrity Committee, although it still presented gaps, such as the lack of a specific internal policy for third-party management. The research also proposed a due diligence questionnaire for supplier evaluation. It was concluded that supplier integrity due diligence is an indispensable tool for preventing reputational damage and strengthening the integrity culture in organizations.

Keywords: Compliance; Due diligence; Third-party management; Reputational risk.