Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

Simple Fine

← Back to Glossary
By NHI Mgmt Group Updated September 30, 2026 Domain: Governance, Ownership & Risk

A monetary penalty calculated from a base value and then adjusted for aggravating and mitigating circumstances. Under the ANPD regulation, the final amount is also constrained by minimum and maximum limits, including the value of any unlawful advantage and the statutory cap tied to revenue. It is the core pecuniary sanction under the framework.

How a simple fine is calculated

A simple fine is not a flat figure. It starts from a base amount and is then adjusted by aggravating and mitigating factors, which means the final sanction reflects both the seriousness of the conduct and the surrounding circumstances.

That structure matters because it gives the regulator a repeatable way to scale punishment without turning every case into an arbitrary one-off decision. In practice, the calculation is designed to separate the starting point from the final outcome, so the legal reasoning remains visible.

Factors that can increase or reduce the amount

The adjustment step is where the penalty becomes case-specific. Aggravating circumstances can raise the amount when conduct is more harmful, more deliberate, or more difficult to contain, while mitigating circumstances can reduce it when the facts show lower culpability or stronger cooperation.

Because the calculation is meant to be structured, those factors should be tied to the legal or factual record rather than used as a vague sense of severity. The value of the adjustment is that it explains why two breaches with the same base value can still end up with different totals.

Minimums, maximums, and statutory caps

Under the ANPD framework, the result is not unlimited. The final amount is constrained by minimum and maximum limits, and it must also fit within broader statutory boundaries such as the value of any unlawful advantage and the cap tied to revenue.

This is important because the ceiling and floor prevent the adjustment formula from producing a number that is detached from the legal framework. The cap also links the penalty to the regulated entity’s economic scale, which makes the sanction more proportionate to the offender’s capacity and the framework’s deterrence goal.

Why the simple fine matters in the sanctioning model

The simple fine is the core pecuniary sanction under the framework, so it is more than a bookkeeping term. It is the main monetary outcome that translates legal findings into an enforceable financial consequence, and it often becomes the reference point for explaining the rest of the penalty regime.

For that reason, understanding how the amount is built is essential to understanding the sanction itself. The base amount, the adjustments, and the statutory constraints all work together to turn a regulatory violation into a final number that can be defended, reviewed, and applied consistently.

Risk and Threat Considerations

Although this is a legal sanction, the risk dimension is practical: if the calculation logic is misunderstood or applied inconsistently, organisations may underestimate exposure, misstate reserves, or misjudge settlement posture. The severity of the final amount depends on how the aggravating and mitigating facts are documented and weighed.

Failure mechanism: Weak fact gathering, poor internal escalation, or unclear treatment of aggravating and mitigating circumstances can distort the calculated base and lead to an inaccurate final penalty expectation.

Impact: The organisation may face avoidable financial exposure, delayed decision-making, and weaker leverage when assessing remediation, defence, or negotiation strategy.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.31 — Legal, statutory, regulatory and contractual requirementsSimple fines arise from regulatory enforcement and legal penalty rules.
Recommendation — Map sanction exposure to legal obligations and maintain evidence needed to support regulatory defence.
NIST CSF 2.0GV.RM-01 — Risk Management StrategyPenalty calculation affects organizational risk treatment, reserves, and response decisions.
Recommendation — Incorporate regulatory fine exposure into enterprise risk treatment and response planning.
SOC 2 (AICPA)CC1.3 — Establish Structure, Authority, and ResponsibilityPenalty outcomes depend on accountable ownership for compliance facts and escalation.
Recommendation — Assign clear ownership for regulatory response, evidence preservation, and penalty assessment.

Practitioner Guidance

Governance implication: Treat the simple-fine calculation as a controlled legal-financial process, not an after-the-fact estimate. Teams responsible for incident response, compliance, and legal review should preserve the factual record that supports aggravating or mitigating arguments, because that record can materially affect the final amount.

Practitioner takeaway: When the penalty model is formula-based, the quality of the underlying facts often matters as much as the violation itself.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org