Skip to main content
Should Your Policy Governance Pass a DOJ Audit?Ethics and Conduct
5 min readFor GRC Leaders

Should Your Policy Governance Pass a DOJ Audit?

The Department of Justice's updated Evaluation of Corporate Compliance Programs guidance emphasizes that static policies pose a compliance risk. Prosecutors now scrutinize your processes for updating policies in response to lessons learned, emerging risks, and technological changes. They seek evidence of dynamic policy management, not outdated documents.

If you can't show systematic policy evolution, you're vulnerable. This checklist outlines the five core requirements the DOJ has embedded in its evaluation criteria, with specific implementation steps and clear success markers.

Prerequisites

Before you begin, confirm you have:

Policy Governance Authority: Identify who owns policy updates in your organization. This may be a compliance committee, the Chief Compliance Officer, or a cross-functional governance council. Without clear ownership, no process will be effective.

Access to Historical Data: Gather records from the past 24 months of internal investigations, disciplinary actions, and industry enforcement actions relevant to your sector. You'll need this to build your lessons-learned process.

Technology Inventory: Document what technologies your organization has adopted in the past 18 months and what's planned for the next 12 months. This forms the baseline for technology-driven policy reviews.

Current Policy Repository: Know where all compliance-related policies are stored and who can access them. If you're unsure, that's your first red flag.

Compliance Checklist

1. Establish a Lessons-Learned Policy Update Process

Requirement: The DOJ asks whether your program includes "a process for updating policies and procedures to reflect lessons learned either from the company's own prior issues or those from other companies operating in the same industry and/or geographic location."

Action Steps:

  • Create or amend your policy governance document to require quarterly reviews of internal investigation findings.
  • Assign responsibility for monitoring industry enforcement actions, such as SEC settlements and DOJ prosecutions.
  • Document a trigger mechanism: when does a finding require policy revision versus additional training?
  • Establish a review cycle: quarterly for high-risk areas, annually for lower-risk policies.

What Good Looks Like: You can produce meeting minutes showing that after your internal audit found expense report violations, you revised your T&E policy within 60 days. You can point to a competitor's FCPA settlement and show how you reviewed and strengthened your anti-corruption policy in response, even though you weren't the target.

2. Build an Emerging Risk Policy Review Protocol

Requirement: The DOJ asks, "Is there a process for updating policies and procedures to address emerging risks?"

Action Steps:

  • Link your risk assessment cycle to policy review. When your annual risk assessment identifies a new or elevated risk, trigger a policy review within 30 days.
  • Document the connection in writing. Add language to your policy governance framework: "Compliance policies shall be reviewed and updated within [X days] when the enterprise risk assessment identifies new or materially changed risks."
  • Create a tracking log that maps each identified emerging risk to the policy that addresses it.
  • Assign accountability: who reviews the risk assessment for policy gaps?

What Good Looks Like: Your 2024 risk assessment flagged supply chain cybersecurity as an emerging risk. Within 45 days, you revised your third-party due diligence policy to include cybersecurity questionnaires for vendors with access to your systems. The policy now references the risk assessment finding that prompted the change.

3. Document Technology-Driven Policy Updates

Requirement: The DOJ specifically asks about "a process for updating policies and procedures to address emerging risks relating to the use of new technologies."

Action Steps:

  • Require IT to notify compliance when deploying new technologies, such as collaboration tools, AI applications, data analytics platforms, and cloud services.
  • Create a technology impact assessment template that includes a mandatory compliance policy review section.
  • Add a provision to your policy governance document: "When the organization adopts new technologies that create compliance risk, relevant policies must be reviewed and updated within [X days] of deployment."
  • Document the review even if no policy change is needed.

What Good Looks Like: Your organization deployed a generative AI tool for customer service. Within 30 days, you reviewed and updated your data privacy policy, confidentiality policy, and intellectual property policy. You documented the review process, the risks considered, and the specific language changes made to address AI-related concerns.

4. Confirm Employee Policy Access

Requirement: The DOJ asks, "How does the company confirm that employees know how to access relevant policies?"

Action Steps:

  • Add questions to your annual ethics and compliance survey: "I know where to find my company's compliance policies" (strongly agree to strongly disagree scale).
  • Include a policy access question in training completion checks: "Do you know how to locate the [topic] policy if you need to reference it?"
  • Track policy repository login data. Are employees accessing the system? Which policies are viewed most frequently?
  • Test accessibility: ask new hires during onboarding to locate three key policies and time how long it takes.

What Good Looks Like: Your annual survey shows 87% of employees agree or strongly agree they know how to access policies. Your training completion data shows that 92% of employees correctly identified the policy repository location. You've documented these metrics and can show year-over-year improvement.

5. Integrate Policy Management into M&A Due Diligence

Requirement: The DOJ asks, "What is the company's process for implementing and/or integrating a compliance program post-transaction?" and "How are compliance policies and procedures organized?"

Action Steps:

  • Add a compliance policy integration section to your M&A integration playbook.
  • Conduct policy gap analysis within 60 days of closing: compare acquired company policies to your standards.
  • Set a timeline for policy harmonization (typically 90-180 days post-close, depending on transaction size).
  • Document which policies the acquired entity will adopt immediately versus phase in.
  • Communicate policy changes to acquired employees with clear effective dates.

What Good Looks Like: Your integration playbook includes a policy integration timeline template. After your last acquisition, you completed a policy gap analysis within 45 days, harmonized critical policies (anti-corruption, data privacy, conflicts of interest) within 90 days, and documented the entire process. Acquired employees received communication about new policies with training requirements and effective dates.

Common Mistakes

Treating Policy Updates as One-Time Events: The DOJ wants to see ongoing processes, not reactive responses. Document your review cycles and stick to them.

Failing to Document "No Change" Decisions: If you reviewed a policy in light of an emerging risk and decided no change was needed, document why. That shows deliberate consideration, not neglect.

Separating Risk Assessment from Policy Management: These functions must communicate. If your risk team doesn't trigger policy reviews, you've missed the DOJ's point.

Ignoring Industry Enforcement Actions: You're expected to learn from others' mistakes. If a competitor settles an enforcement action in your industry, document your review of whether your policies address the same risk.

Next Steps

Complete this checklist within 90 days. Then:

  • Schedule your first quarterly lessons-learned policy review.
  • Add policy governance metrics to your compliance program effectiveness reporting.
  • Update your annual compliance program assessment to include these five DOJ criteria.
  • Brief your board's audit or compliance committee on your policy governance enhancements.

The DOJ isn't asking for perfection. They're asking for proof that your policies evolve with your risks. If you can't demonstrate that evolution, you're not managing compliance; you're managing documents.

You Might Also Like