Skip to main content
DOJ Revises Compliance Evaluation StandardsEthics and Conduct
4 min readFor Compliance Officers

DOJ Revises Compliance Evaluation Standards

The Justice Department has updated its guidance for evaluating corporate compliance programs, introducing three critical assessment areas that will shape prosecutorial decisions: AI-enabled risk controls, speak-up culture mechanisms, and compliance team access to enterprise data. Nicole Argentieri, head of the Criminal Division, announced these changes at the Society of Corporate Compliance & Ethics' annual conference.

For compliance officers, these updates represent a significant shift in regulatory expectations. The DOJ is demanding that compliance functions operate with the same analytical rigor and resource allocation as revenue-generating business units.

Key Changes in Compliance Evaluation

The updated guidance introduces specific evaluation criteria across three domains:

AI Risk Management: Prosecutors will assess whether your organization has implemented controls to detect and prevent AI-generated fraud, including false documentation, impersonation schemes, and manipulated approvals. The guidance explicitly asks whether you've deployed tools to verify the accuracy of data used in business operations.

Speak-Up Culture Assessment: The DOJ will evaluate not just your reporting channels, but whether employees actually feel comfortable using them. New questions probe whether your organization trains employees on external whistleblower protections and regulatory reporting options, not just internal hotlines.

Data Access Parity: Prosecutors will compare the resources allocated to compliance analytics against those dedicated to business development. The guidance asks whether impediments limit compliance teams' access to relevant data sources and whether technology investments favor growth over risk detection.

Implications of the New Guidance

Speak-Up Metrics Require Cultural Depth

The guidance moves beyond measuring hotline volume. It asks: "How does the company assess employees' willingness to report misconduct?" and "Does the company use practices that tend to chill such reporting?" You'll need quantitative and qualitative measures. Consider pulse surveys that gauge psychological safety, exit interview analysis for patterns of unreported concerns, and comparative discipline data showing whether internal reporters receive harsher treatment than non-reporters involved in the same misconduct.

AI Due Diligence Needs Independent Verification

The DOJ expects you to anticipate scenarios where third parties use AI to fabricate credentials, compliance certifications, or financial statements. Your current vendor onboarding questionnaires won't suffice. You need cross-reference capabilities: access to independent databases that can validate supplier certifications, multi-source verification for high-risk transactions, and challenge controls that flag documentation inconsistencies. If your due diligence process accepts submitted documents at face value, you're exposed.

Resource Allocation Reflects Strategic Priorities

The guidance includes a pointed question: "Is there an imbalance between the technology and resources used by the company to identify and capture market opportunities and the technology and resources used to detect and mitigate risks?" This isn't about absolute spending levels. It's about proportionality. If your sales team has predictive analytics and your compliance team has spreadsheets, prosecutors will interpret that gap as evidence that leadership treats compliance as a cost center rather than a strategic function.

External Reporting Awareness is Mandatory

The DOJ will assess whether you train employees on external whistleblower programs and regulatory regimes, not just internal channels. This represents a significant expectation shift. You must now affirmatively inform employees about SEC whistleblower provisions, state-level protections, and industry-specific reporting mechanisms. Document this training specifically; generic ethics sessions won't demonstrate compliance with this criterion.

Business Email Compromise Defenses Need Authentication Layers

The guidance specifically mentions AI-enabled impersonation schemes. Your payment authorization policies must incorporate multi-factor authentication and independent confirmation requirements. Review whether any single executive, including your CEO, can authorize large wire transfers without secondary verification. If your current process allows unilateral payment approvals above materiality thresholds, you're vulnerable to both fraud and prosecutorial scrutiny.

Strategic Adjustments for Compliance Teams

You're now accountable for demonstrating that compliance functions with the same analytical sophistication as your commercial operations. This requires three shifts:

First, your compliance program must incorporate predictive and detective analytics, not just reactive investigation tools. If your business intelligence team uses machine learning to forecast market opportunities, your compliance team needs equivalent technology to identify emerging risks.

Second, you need documented methodologies for measuring culture. Anecdotal assessments won't satisfy prosecutors. Develop repeatable metrics: survey response rates segmented by business unit, time-to-resolution for reported concerns, and comparative analysis of discipline decisions.

Third, your training curriculum must explicitly cover external reporting options. Employees need to understand their legal protections under federal and state whistleblower statutes, and you need attendance records proving they received this information.

Action Items by Priority

Immediate (Next 30 Days)

Audit your current training materials to verify they include external whistleblower protections and regulatory reporting channels. If they don't, schedule curriculum revisions and document the gap you're addressing.

Inventory your compliance team's data access. List every system where compliance personnel lack real-time visibility and every approval layer that delays access. Present this inventory to your CFO and general counsel with specific requests to eliminate barriers.

Near-Term (Next 90 Days)

Implement multi-factor authentication for all payment authorizations above your materiality threshold. Revise payment policies to require independent confirmation for wire transfers, regardless of the requesting executive's seniority.

Deploy a culture assessment mechanism. This could be quarterly pulse surveys, focus groups facilitated by external consultants, or exit interview protocols that specifically probe whether departing employees felt comfortable reporting concerns.

Strategic (Next 12 Months)

Develop AI-specific due diligence protocols. Identify which third-party relationships are most vulnerable to documentation fraud and implement verification layers using independent data sources.

Conduct a resource allocation analysis comparing compliance technology investments to business development spending. Present findings to your board's audit committee with specific requests to close capability gaps.

Build challenge controls into your document verification processes. This might include optical character recognition tools that detect AI-generated signatures, database cross-checks for supplier certifications, or anomaly detection algorithms that flag suspicious documentation patterns.

DOJ Evaluation of Corporate Compliance Programs

You Might Also Like