The Challenge
The Department of Justice's updated Evaluation of Corporate Compliance Programs (ECCP) guidance from September 2024 presents a new challenge: your existing risk assessment frameworks may not meet the DOJ's expectations.
The guidance emphasizes technology, mentioning it 22 times across 22 pages, with 17 of those mentions newly added. AI receives dedicated attention. The message is clear: if your risk assessment doesn't systematically account for technology and AI, it's incomplete by DOJ standards.
This update isn't a gradual change. It marks a fundamental shift in how the DOJ evaluates whether your compliance program can prevent and detect misconduct. A "risk-based approach" is inadequate if it ignores the systems that process your data, automate decisions, and mediate business relationships.
The Environment and Constraints
Many compliance officers work with risk assessment templates focused on regulatory categories like anti-bribery, trade compliance, and data privacy. Technology often appears as an afterthought.
This structure was suitable when technology was merely a support function. Now, technology is the operating environment.
The issue isn't understanding technology's importance; it's practical constraints. You might not control the technology budget, sit in procurement reviews, or know every system processing compliance-relevant data in your organization.
The DOJ's guidance anticipates this gap. It expects you to conduct a compliance-focused technology audit, mapping systems to risks and documenting how AI affects your exposure. The guidance also requires identifying "specific factors that mitigate the company's risk" and documenting whether your approach is reactive or proactive.
These are not suggestions. They are criteria prosecutors will use to assess your program's effectiveness.
The Approach Required
Begin with visibility. You can't assess technology risk without knowing which systems you're running. This requires coordination with IT, procurement, and privacy teams.
IT departments often maintain system inventories. Procurement tracks software spending and can identify vendors by billing code. Privacy teams maintain data flow maps showing how personal information moves between systems. Each function holds part of the picture you need.
Create a baseline registry with columns for system name, internal owner, business function, AI usage, and personal data processing. Focus on major systems affecting compliance-relevant activities: financial reporting, vendor payments, HR decisions, customer communications, regulatory filings.
Once you have visibility, integrate technology into your risk assessment methodology. You can either add technology as a standalone risk category or embed it within existing categories.
The embedded approach is more defensible. When assessing bribery risk, document which payment systems are in use, whether they include AI-assisted fraud detection, and how automated controls reduce exposure. For trade compliance risk, identify systems managing export classifications and sanctions screening.
AI requires separate documentation. The DOJ highlights AI because it can both create and mitigate risk in ways traditional software doesn't. An AI-assisted policy search function reduces the risk of employees not finding relevant guidance. An AI-powered resume screening tool might introduce bias. Document both dimensions.
Add a section labeled "Emerging Risks" if you don't have one. The DOJ's guidance frames emerging risk primarily around technology and AI, but it extends to proposed regulations, geopolitical shifts, and evolving enforcement priorities. The label is important because prosecutors will look for it.
Finally, document your methodology. The updated ECCP emphasizes not just completing a risk assessment, but explaining your approach and showing how it drives resource allocation. Demonstrate that "greater scrutiny applied to greater areas of risk" is a documented practice.
Results and What You'll Learn
Organizations that have integrated technology into their risk assessments report three consistent findings.
First, they discover systems they didn't know existed. Business units often procure software independently, especially SaaS tools that don't require IT infrastructure. Your marketing team might use an AI-powered customer engagement platform processing personal data and making automated decisions. You won't know until you ask.
Second, they find technology often mitigates more risk than it creates, but only when configured correctly. An accounts payable system with built-in duplicate payment detection reduces fraud risk, but only if someone validated the detection rules and monitors the alerts. Documentation forces you to verify assumptions.
Third, they realize their "proactive" risk management is more reactive than they thought. The DOJ's guidance draws this distinction deliberately. Proactive risk management means identifying the risk before an incident occurs and implementing controls in advance. Reactive means responding after a problem surfaces. Most organizations operate in reactive mode more often than they'd admit.
What to Do Differently
Don't treat the technology audit as a one-time compliance exercise. Systems change constantly. New software is deployed, vendors are acquired, AI features are enabled in products you've used for years. Build a quarterly or semi-annual refresh into your compliance calendar.
Don't delegate the AI analysis entirely to IT. Technical teams can explain how AI works, but they can't always tell you how it affects compliance risk. You need to understand the business context: what decisions the AI influences, what data it uses, who reviews its outputs, and what happens when it's wrong.
Don't assume emerging risks are always external. The DOJ's focus on technology reflects an internal emerging risk: your organization is adopting capabilities faster than your compliance program can assess them. That gap is the risk.
Takeaways for Your Team
The ECCP update isn't asking you to become a technology expert. It's requiring you to apply the same risk-based thinking you use elsewhere to the systems that increasingly run your business.
Your risk assessment must now answer: Which technologies are we using? How do they change our risk profile? Where is AI making decisions, and have we validated those decisions against compliance requirements? What emerging capabilities might create exposure we haven't planned for?
If you can't answer those questions with documentation, the DOJ has told you exactly what it will conclude: your program isn't designed to address the risks your organization actually faces.



