INTERVIEW

Jairo Higuita Naranjo: “We want to leverage the international network to consolidate the firm both nationally and internationally.”

INTERVIEW

Juan Francisco Torres Landa, from Hogan Lovells Cadwalader: “What distinguishes a good advisor is the ability to give calm, well-founded and strategic advice”

Guillermo Larrea: “The most frequent blind spot is continuing to enter certain business decisions too late”

By Heidi Maldonado

Guillermo Larrea, partner at Hogan Lovells Cadwalader and CEO of ELTEMATE LATAM, has spent over a decade building what Chambers ranks as Mexico’s most recognized compliance practice. He now leads the firm’s Latin American Compliance Committee following the merger with Cadwalader. For Larrea, the true fundamental shift in compliance lies in the ability to demonstrate that policies modify decisions before risk materializes, going beyond their mere existence on paper. This idea permeates the designation of cartels as terrorist organizations, which redefines the risk perimeter even for legitimate businesses; the most common pattern of fraud in the region, channeled through third parties without up-to-date due diligence; and the mistake of drafting AI governance without first defining a usage strategy. and crisis management, where the most costly mistake is dividing the problem into separate fronts instead of a single command structure.

This same criterion of real effectiveness is the central theme that Larrea will bring to the Foro Gerencias Legales México 2026, where he will participate this year: “I believe the challenge for legal management is to be much closer to operations. Not to control all decisions, but to identify risk before it becomes a legal problem.”

You joined Hogan Lovells in January 2025 from Jones Day, and a year and a half later you are now part of Hogan Lovells Cadwalader following the largest merger in the history of the legal sector. How would you describe the scope of your compliance, cybersecurity, and AI practice within this new combined platform today?

Today, it’s a broader and more integrated practice, and that’s the result of combining strengths. When I arrived at Hogan Lovells Cadwalader with my team, the firm already had talent in the area of Compliance, and what we did was integrate it under common leadership. We created a Compliance Committee, which I lead for the Latin American region, that now brings together five partners and ten associates and professionals, combining backgrounds, specializations, and relationships that were previously scattered, to build a strong, integrated, and differentiated practice in investigations.

Our practice is divided into two main segments: Business Integrity Compliance, which addresses investigations and compliance in anti-corruption, fraud, money laundering, and sanctions (especially relevant in the context of the Trump era), and Digital Compliance, which addresses issues of privacy, cybersecurity, data protection, and artificial intelligence. In practice, the boundaries between these areas have become increasingly blurred: an investigation may involve reviewing enormous volumes of information using AI tools; a cyber incident may generate regulatory issues, litigation, sanctions, or an internal investigation; and an AI adoption project may raise privacy or liability questions.

The merger with Cadwalader brought a portfolio of clients in the financial sector and specialists in financial regulation, investigations, and disputes, particularly in the United States and the United Kingdom. This is very relevant for us because many of the matters we handle from Mexico and Latin America have a global dimension, and we now have a strengthened financial arm to support our clients in each of these jurisdictions, without losing the close relationships and local knowledge we have built over the years in the region.

Chambers has recognized you as the leading compliance partner in Mexico for 11 consecutive years. What type of client and mandate has changed the most in the last decade, compared to when you began building this practice?

When Chambers first recognized us in 2015, the practice was heavily focused on the Foreign Corrupt Practices Act and money laundering prevention. Today, the practice has grown in subject matter (e.g., the designation of Foreign Terrorist Organizations), the depth of regulation and soft law, and the tools available. Geopolitics and technology have transformed our practice.

Previously, the starting point was almost always reactive: a specific problem of corruption or fraud that had to be investigated and resolved. Today, clients are proactive with risk assessments where the primary concern is ensuring that no part of their operation or supply chain is affected, directly or indirectly, by compliance risks—for example, dealing with suppliers linked to criminal organizations, now potentially terrorist groups. This is complemented by reviews of the origin of funds, who they contract with, the traceability of their supply chain, and their response to executive orders from President Donald Trump’s administration.

Mandates have also changed in how we execute them. Today, we use artificial intelligence to analyze large volumes of documents and communications, identifying risks much faster and more accurately. Through Eltemate, Hogan Lovells Cadwalader’s legal-tech company, we can provide our clients with AI tools, forensic technology, background checks, and predictive data analytics to strengthen our legal and regulatory analysis from a legal perspective.

You have investigated cases under Mexico’s National Anti-Corruption System, the US FCPA, and the UK Bribery Act. In Mexico’s current regulatory environment, what kind of compliance risk do you see being underestimated by multinational companies operating in the country?

Many multinational corporations continue to operate with an “umbrella compliance” program—a generic program designed at headquarters and replicated identically in Mexico, Colombia, or Brazil, without local adaptation. This is especially true for companies of Spanish and Latin American origin. The cost is often very high when faced with investigations by North American and European authorities.

Exposure to local authorities through friendly or close relationships is also underestimated.

Finally, today, with the designation of cartels as terrorist groups in countries like Mexico, Ecuador, Colombia, Venezuela, and Brazil, the most relevant risk is the indirect or direct association with these criminal groups that operate with legitimate networks in legitimate businesses, but whose mere connection has lethal consequences.

Without identifying clients, can you describe the most common pattern you have seen in recent investigations of corporate fraud or corruption in the region, and what internal structural failure typically explains it?

The most common pattern we have seen in recent investigations is that of improper payments channeled through third parties: agents, distributors, or consultants who act as intermediaries to create a layer of distance that makes it difficult to trace the origin and destination of the payment.

The structural flaw that almost always explains this is twofold. First, weak or superficial third-party due diligence, conducted only once at the time of contracting and never updated, which fails to delve into who the intermediary really is, how they generate value, or why their commission is reasonable in relation to the service provided. Second, and perhaps more importantly, controls that exist at the corporate level but never truly trickle down to the local operation: well-designed policies at headquarters that the subsidiary formally applies, without the local team having the knowledge, authority, or incentives to make them effective on a daily basis. When these two flaws coincide, the third becomes the perfect blind spot.

You advise companies on AI ethics and governance. What is the most common mistake a company makes when designing its AI governance framework, and how prepared are companies in Latin America really for this?

The most common mistake is to start by writing a policy before understanding how the company is using AI and defining its own AI strategy.

The first thing a company should do is understand its strategy, what tools are being used, who is using them, for what purpose, with what information, and what decisions might be affected. The risk varies considerably depending on the use case.

Then come the rules: what uses need authorization, when there should be human supervision, what information can be shared with a tool, how suppliers are reviewed, and what happens when the system makes a mistake.

AI governance shouldn’t be a document that’s approved once and then filed away. It needs to function like any other risk management system: identifying risk, measuring it, establishing controls, and constantly reviewing it, but above all, it must reflect the company’s strategy.

Large corporations in Latin America still face a significant challenge in this area. What we see is that they continue to discuss the use of tools, but lack defined AI strategies.

Part of your practice includes advising Chinese technology companies expanding in Latin America on compliance with regional data protection laws. How different is this compliance process compared to that of a Western multinational, and what fundamental challenge does a Chinese company face today that wants to operate effectively in the region in this area?

One aspect remains the same: a Chinese company entering Latin America must comply with the same local regulations as any other company. What does change is the context. Many of these companies operate with technology, infrastructure, and information flows distributed across multiple jurisdictions.

So a seemingly local decision can have regulatory consequences in China, the United States, or Europe.

This requires a very careful review of where the data is located, who can access it, what technology is used, which providers are involved, and whether there are restrictions related to sanctions, export controls, or information security.

The challenge is to allow the company to maintain an efficient global model without creating regulatory problems in the markets where it wants to operate.

On the other hand, Chinese companies are fundamentally pragmatic. They want to understand how to do things, understanding their legality and risks. Sometimes that means testing the model to its limits.

You are participating this year in the Foro Gerencias Legales México 2026, on September 3rd in Mexico City. What is the governance standard that companies operating in Mexico are currently demanding the most real adjustment from, beyond mere paperwork compliance?

The standard that today demands the most real adjustment is the ability to demonstrate that the controls actually work.

Many companies have policies, risk matrices, third-party procedures, whistleblowing hotlines, and training programs. The problem is that the mere existence of these elements no longer tells us much on its own.

The important question is what effect they have in practice. If a due diligence process exists, has it actually led to rejecting or conditioning relationships? If a risk assessment is conducted, has it changed resources or controls? If complaints are filed, do the investigations lead to consequences and remediation?

I think that’s the most important change: moving from demonstrating that a program exists to demonstrating that the program modifies decisions and reduces risk.

On the other hand, AI, cartel/terrorism-related risks, and cybersecurity incidents should be priority issues in every organization.

The Foro Gerencias Legales México 2026 concludes with a panel on “Operating in High-Risk Environments: Compliance Strategies and Corporate Resilience.” From your experience in crisis management and investigations, what is the most costly mistake a legal department makes when managing a compliance crisis or a cybersecurity incident in real time?

The most costly mistake is handling each aspect of the problem separately.

In a significant crisis, Legal, Compliance, IT, CISOs, Communications, and other departments must work together seamlessly. While the technical team tries to understand what happened, regulatory deadlines may be approaching, evidence may need to be preserved, sanctions analyzed, privileges protected, or decisions made about what to communicate to clients, employees, or authorities.

The problem is that these decisions often have to be made before all the facts are in. That’s why the first few hours are so important. If it’s not clear from the beginning who’s in charge, who’s making the decisions, and which fronts need to be pursued simultaneously, it’s very easy for a decision that’s correct from one perspective to create a problem from another.

With compliance, cybersecurity, and AI increasingly converging into a single corporate risk conversation, what would you say is the blind spot that most legal departments in Latin America have today, and that they are not yet aware of?

The most frequent blind spot is continuing to enter too late into certain business decisions.

Legal typically has very good visibility into contracts, litigation, and regulation, but not always into how data is being used, what technology the business is adopting, how the third-party network works, or where business decisions that may generate risk are being made.

Today, these issues are completely interconnected. A technological decision can become a problem of privacy, cybersecurity, competition, or employment. A relationship with a third party can end up being a matter of corruption, sanctions, or money laundering.

That’s why I believe the challenge for legal departments is to be much closer to operations. Not to control every decision, but to identify risk before it becomes a legal problem.

Ultimately, Larrea describes the same shift in every topic he addresses: from compliance on paper to demonstrable results. A third party becomes a risk when its due diligence is frozen at the point of contracting. An AI policy is weak from the start when it’s written before the usage strategy is defined. A crisis worsens when each department—Legal, Compliance, Technology—makes its own decisions. The underlying conclusion is the same: the legal function gains importance when it’s integrated into business operations early on, before risk escalates into litigation, sanctions, or reputational damage.

Related Articles

Editar Imagenes de Higthligths

You are not permitted to submit this form!







    Editar Imagenes de Higthligths

    You are not permitted to submit this form!

    Editar reconocimientos - Latin Lawyer

    Contenido Reconocimiento Latin Lawyer*

    Editar reconocimientos - Leaders League

    Contenido Reconocimiento Leaders League*

    Editar link equipo

    Editar Oficinas

    Editar de highlight

    Editar reconocimientos - Legal 500

    Contenido Reconocimiento Chambers*

    Editar Reconocimientos - Chamber

    Contenido Reconocimiento Chambers*

    Editar Banner

    Selecciona un Banner*

    Editar reconocimientos

    Editar reconocimientos

    Contenido Reconocimiento Interno*

    Editar resumen

    Editar sectores de actividad

    Sectores de Actividad*

    Editar áreas de practica

    Areas de practica*

    Editar tag

    Tags*

    Edita otros datos de interés

    You are not permitted to submit this form!

    Editar logo

    You are not permitted to submit this form!

    Editar datos de firma