The Problem / Why This Matters Now
You've seen the headlines. The U.S. Supreme Court ended Chevron deference, narrowed federal bribery law, and restricted the SEC's enforcement toolkit. Legal scholars are debating the implications, and regulatory agencies are recalibrating their strategies.
Your board wants to know: can we dial back compliance now?
The answer is no. The rulings in SEC v. Jarkesy, Snyder v. United States, and Loper Bright Enterprises v. Raimondo fundamentally altered enforcement procedures and judicial oversight, but they didn't touch the underlying conduct that gets companies into trouble. Your anti-corruption controls, financial reporting standards, and third-party due diligence protocols remain as critical as they were before the court issued its opinions.
This guide walks you through maintaining program effectiveness when the legal landscape shifts.
What You Need Before Starting
Before briefing your executive team or adjusting program documentation, assemble the following:
Documentation inventory:
- Current anti-corruption policy and training materials
- Risk assessment methodology and most recent assessment
- Compliance program charter referencing U.S. Sentencing Guidelines and DOJ Evaluation of Corporate Compliance Programs
- Records of recent regulatory filings (SEC, OSHA, EPA, or other relevant agencies)
- Inventory of state and local government touchpoints (permits, licenses, inspections)
Stakeholder access:
- Direct line to General Counsel for legal interpretation
- Business unit leaders who interact with government officials
- Internal Audit for validation of control effectiveness
- Board Audit Committee or Compliance Committee chair for governance alignment
Reference materials:
- Foreign Corrupt Practices Act compliance guidance
- Anti-Kickback Statute provisions (if healthcare-related)
- U.K. Bribery Act requirements (if you operate internationally)
- Relevant state anti-corruption statutes for your operating jurisdictions
- DOJ's Evaluation of Corporate Compliance Programs (updated guidance)
You don't need new legal frameworks. You need clarity on what hasn't changed.
Step-by-Step Implementation
Step 1: Conduct a Gap Analysis Against Existing Requirements
Review your compliance program against the DOJ's three fundamental questions: Is the program well designed? Is it being applied earnestly and in good faith? Does it work?
Action: Document which requirements stem from which legal authority. Create a matrix:
- Column 1: Control or requirement
- Column 2: Legal/regulatory basis
- Column 3: Impact from recent rulings (most will show "none")
For example, your FCPA training requirement isn't affected by Snyder, which only addressed Title 18, Section 666 of the U.S. Criminal Code governing payments to state and local officials. Your insider trading policy isn't affected by Jarkesy, which changed where the SEC brings enforcement actions, not what constitutes insider trading.
Step 2: Reaffirm Your Anti-Corruption Standards
The Snyder ruling created a distinction between pre-act bribes (illegal) and post-act gratuities to state and local officials (potentially legal under federal law). This is irrelevant to your compliance program.
Action: Update your anti-corruption policy preamble to state clearly: "This organization prohibits all improper payments to government officials, regardless of timing, jurisdiction, or legal technicalities in specific statutes."
Do not train employees on the difference between bribes and gratuities. Train them that corruption is prohibited, period. If your existing training splits hairs among the FCPA, Anti-Kickback Statute, and Section 666, consolidate it into a single principles-based standard.
Configuration note: If you use a learning management system, tag all anti-corruption modules with a completion requirement. Don't make any module optional based on employee location or government interaction frequency. The risk of selective training outweighs any efficiency gain.
Step 3: Validate Your Regulatory Compliance Scope
Loper Bright ended judicial deference to agency interpretations of ambiguous statutes. This introduces uncertainty about future regulations, not current ones.
Action: Inventory every regulation your organization currently follows. For each:
- Identify the underlying statute
- Confirm whether compliance is based on explicit statutory language or agency interpretation
- Assess litigation risk if a court were to overturn the agency's interpretation
Do not reduce compliance activities based on this assessment. Instead, flag high-uncertainty regulations for legal monitoring. If a court invalidates a rule you've been following, you'll have advance notice and can adjust with General Counsel's guidance.
Practical example: If you've implemented the SEC's recently adopted climate disclosure rules (currently under legal challenge), continue implementation while monitoring the litigation. Stopping mid-stream creates operational disruption and signals poor judgment to stakeholders who expect climate transparency regardless of regulatory mandates.
Step 4: Address the SEC Enforcement Question
Jarkesy found that the SEC cannot impose civil penalties through in-house administrative judges. For most corporate matters, the SEC already files in federal court.
Action: Review your securities law compliance program. Confirm that controls address the underlying conduct (accurate financial reporting, insider trading prevention, FCPA compliance), not the enforcement mechanism.
Update your risk assessment to note: "SEC enforcement procedures have changed, but violations remain violations. Our program focuses on preventing misconduct, not gaming enforcement processes."
Step 5: Prepare Your Board Communication
Your Audit Committee or Board will ask what these rulings mean for the organization.
Action: Draft a one-page memo structured as follows:
- Summary of the three rulings (two sentences each)
- Impact on our compliance obligations (one sentence: "No change to underlying requirements")
- Impact on our compliance program (one sentence: "Program design remains aligned with DOJ and Sentencing Guidelines expectations")
- Risks to monitor (regulatory uncertainty from Loper; potential future challenges to specific rules)
- Recommended action (continue current program; monitor legal developments; maintain audit readiness)
Don't oversell stability and don't catastrophize uncertainty. State facts.
Validation: How to Verify It Works
Immediate Validation
Within 30 days of completing the implementation steps, conduct these checks:
Policy acknowledgment audit: Pull reports from your policy management system showing employee acknowledgment rates for your anti-corruption policy. Target: 100% of employees with government touchpoints, 95%+ of all employees.
Training completion: Verify that anti-corruption training completion rates haven't dropped. If business leaders are citing Snyder as a reason to deprioritize training, escalate immediately.
Control testing: Select five transactions involving government officials (permit applications, regulatory filings, government contracts). Verify that approval workflows, documentation requirements, and payment controls functioned as designed.
Quarterly Validation
Regulatory monitoring log: Maintain a tracking document of legal challenges to regulations affecting your industry. Review quarterly with General Counsel. If a court invalidates a rule you've been following, document the decision and your response.
Compliance metrics review: Compare your key program metrics (hotline reports, policy violations, training completion, audit findings) quarter-over-quarter. Stability or improvement indicates the program is functioning despite legal uncertainty.
Annual Validation
Program effectiveness assessment: Use the DOJ's Evaluation of Corporate Compliance Programs as your assessment framework. Document how your program addresses each element. If you can't demonstrate effectiveness independent of enforcement mechanisms, you have a design flaw.
Maintenance / Ongoing Tasks
Monthly
- Review legal developments affecting regulations in your compliance scope
- Monitor industry enforcement actions (even if procedures have changed, the conduct triggering enforcement hasn't)
- Track compliance metrics and flag anomalies
Quarterly
- Brief senior leadership on regulatory landscape changes
- Update risk assessment if new legal interpretations create uncertainty in specific areas
- Validate that training content remains current and doesn't reference outdated enforcement procedures
Annually
- Conduct full compliance program assessment against DOJ guidelines and Sentencing Guidelines
- Update board on program effectiveness and legal landscape
- Refresh policies to remove references to specific enforcement mechanisms; focus on prohibited conduct
As Needed
- When a court invalidates a regulation you follow, convene General Counsel, Compliance, and relevant business leaders to determine response
- When enforcement agencies issue new guidance post-Loper, assess whether it affects your program scope
- When employees cite legal rulings as justification for non-compliance, escalate and retrain immediately
The legal landscape will continue shifting. Your compliance program's job is to prevent misconduct regardless of which courthouse hears the case or which judge reviews the regulation. Build for resilience, not for loopholes.



