Skip to main content
Category: Compliance Programs

Evaluation of Corporate Compliance Programs

Also known as: ECCP, DOJ ECCP, Evaluation of Corporate Compliance Programs guidance
Simply put

The Evaluation of Corporate Compliance Programs (ECCP) is guidance issued by the U.S. Department of Justice that helps its prosecutors decide whether a company's compliance program was actually effective. It informs decisions about whether to charge a company with misconduct and how any resolution should be structured. Many companies also use it informally as a reference to help build or assess their own compliance programs.

Formal definition

The ECCP is a set of non-binding guiding principles published by the U.S. Department of Justice to assist prosecutors in making informed decisions about whether, and to what extent, a corporation's compliance program was effective at the time of alleged misconduct and at the time of a charging or resolution decision. It functions as a decision framework tied to DOJ charging decisions, resolutions, and expectations, rather than as a statute, regulation, or mandatory certification standard. Although directed at DOJ prosecutors, practitioners commonly apply the document as a reference for designing, benchmarking, or remediating corporate ethics and compliance programs; its application depends on the facts of a given matter and does not by itself impose independent legal obligations on companies.

Why it matters

The ECCP matters because it offers a window into how U.S. Department of Justice prosecutors think about compliance program effectiveness when they weigh whether, and to what extent, to charge a company or how to structure a resolution. Because these decisions can carry significant consequences for an organization, understanding the criteria prosecutors apply helps boards, general counsel, and compliance officers anticipate how their program might be judged if misconduct surfaces. The guidance reframes compliance not as a paper exercise but as something assessed for whether it was actually working at the time of alleged wrongdoing and at the time of the charging or resolution decision.

Although the ECCP is directed at prosecutors and is non-binding on companies, many practitioners treat it as a practical reference for designing, benchmarking, or remediating their own ethics and compliance programs. It effectively signals the questions a company may need to answer if its program is ever scrutinized, which is why some describe it as the DOJ's framework for evaluating corporate compliance. Using it proactively can help an organization identify gaps before, rather than after, a problem arises.

It is important to keep the document's limits in view. The ECCP does not by itself impose independent legal obligations, and it is not a statute, regulation, or certification standard. How it is applied depends on the specific facts of a given matter and on prosecutorial judgment, so the presence of a program that maps to the ECCP does not guarantee any particular outcome. Entities in regulated sectors or outside the United States should also recognize that other frameworks and authorities may apply alongside or instead of the ECCP.

Who it's relevant to

Chief Compliance Officers and Compliance Teams
Compliance leaders commonly use the ECCP as a reference to build, benchmark, and remediate their programs, since it reflects the questions a DOJ prosecutor might ask about whether a program was effective in practice. It helps them focus not only on program design but also on evidence that controls are resourced and operating, though the document does not certify a program or guarantee any regulatory outcome.
General Counsel and Legal Advisors
General counsel and outside advisors draw on the ECCP to understand how prosecutors may evaluate a program when a charging or resolution decision is on the table. It informs remediation strategy and negotiation posture, but because it is non-binding and fact-dependent, applying it requires case-specific legal judgment rather than mechanical application.
Boards and Audit or Compliance Committees
Boards and their committees exercise oversight of the compliance program rather than running it day to day. The ECCP can help directors frame the questions they ask management about whether the program is effective and adequately resourced, supporting informed oversight without shifting operational responsibility onto the board.
Internal Audit and Assurance Functions
Assurance functions can use the areas of inquiry reflected in the ECCP to test whether a compliance program's controls are not merely designed but operating as intended. This supports independent evaluation of program effectiveness, distinct from the compliance function that owns and operates the program.
Senior Management Responsible for the Program
Management is accountable for implementing and resourcing the compliance program on the ground. The ECCP signals the kinds of practical evidence, such as commitment of resources and functioning processes, that prosecutors may look for, helping management prioritize investments even though the guidance imposes no independent legal obligation.

Inside ECCP

Program Design and Comprehensiveness
An assessment of whether the compliance program is well-designed to identify, prevent, and detect misconduct relevant to the entity's specific risk profile. This typically examines whether the program reflects a considered risk assessment rather than an off-the-shelf template, and whether policies and procedures address the particular risks the organization faces given its industry, geography, and business model.
Risk Assessment Foundation
The extent to which the program is grounded in a periodic, evidence-based assessment of the risks the organization actually faces. Evaluations generally consider whether resources and controls are prioritized toward higher-risk areas rather than allocated uniformly, and whether the risk assessment is refreshed over time.
Genuine Empowerment and Resourcing
Whether the program is adequately funded, staffed, and positioned with sufficient authority, autonomy, and access to relevant data. This element distinguishes a program that exists on paper from one that operates effectively in practice, and it considers the standing of the compliance function relative to management and the board.
Effective Operation in Practice
Whether the program works in practice, not merely how it is designed. This typically looks at control operating effectiveness, testing and monitoring, incident response, remediation of identified issues, and whether the organization learns from prior conduct. Design and operating effectiveness are distinct dimensions and are generally assessed separately.
Culture, Tone, and Incentives
Consideration of leadership commitment, tone at the top and middle, and whether compensation, promotion, and disciplinary systems reinforce or undermine compliant conduct. Evaluations often weigh whether employees can raise concerns without fear of retaliation and whether reporting channels are used and trusted.
Roles, Accountability, and Assurance
How responsibility is allocated among management (which owns and operates the program), the board or a committee (which oversees it), and independent assurance functions (which provide objective evaluation). The distinction between operational ownership and oversight is central to how program accountability is understood.

Common questions

Answers to the questions practitioners most commonly ask about ECCP.

Does the 'Evaluation of Corporate Compliance Programs' guidance function as a mandatory checklist that, if followed, guarantees a favorable outcome?
No. The guidance is generally understood as a set of considerations used by prosecutors to inform their exercise of discretion, not a binding checklist or a scoring rubric. It is typically framed around open-ended questions, such as whether a program is well designed, adequately resourced and empowered to function effectively, and whether it works in practice, rather than a pass/fail test. Following it does not guarantee any particular charging decision, resolution, or reduction in exposure, because outcomes depend on the specific facts, the conduct at issue, and the judgment of the reviewing authority. Entities should treat it as an educational reference point rather than a safe harbor, and consult qualified counsel about its application to their circumstances.
Is having compliance policies and a code of conduct on paper enough to demonstrate an effective program under this type of evaluation?
Generally, no. A recurring theme in this kind of evaluation is the distinction between a program that exists on paper and one that operates effectively in practice. Reviewers typically look beyond the design of policies to whether controls are actually implemented, understood, resourced, and enforced, for example, whether training reaches the right people, whether the compliance function is empowered and has access to leadership, and whether the program adapts based on lessons learned. Documentation of design is relevant, but evidence of operating effectiveness is usually what distinguishes a program considered genuinely effective from a 'paper program.'
How can an organization gather evidence to show its compliance program works in practice rather than only on paper?
Organizations typically build a body of evidence that demonstrates operation over time rather than a single snapshot. This can include records of risk assessments and how they informed program priorities, training completion and comprehension data, metrics on how issues are identified and escalated, records of internal investigations and their outcomes, evidence of consistent discipline and remediation, and documentation of periodic testing or auditing of key controls. The aim is generally to show both control design and operating effectiveness, and to trace how findings led to updates. What evidence is appropriate depends on the organization's size, sector, and risk profile, and reflects professional judgment rather than a fixed list. This is educational information, not audit or legal advice.
Who within the organization should own the different activities examined in such an evaluation?
Accountability is typically distributed across functions rather than resting in one place. Management usually owns the design and day-to-day operation of controls and the resourcing and empowerment of the compliance function. The compliance function generally owns monitoring, advising, training, and program administration, and is often positioned to report to senior leadership and, in many structures, to a board committee. The board or a designated committee typically holds oversight responsibility, satisfying itself that a program exists, is appropriately resourced, and is functioning, without taking on operational execution. Internal audit or another assurance function may provide independent testing. The precise allocation varies by entity type, size, and governance structure.
How should the results of this kind of evaluation feed into program improvement?
The evaluation is generally most useful when treated as an input to a continuous improvement cycle rather than a one-time exercise. Findings, whether from self-assessment, internal audit, an investigation, or external review, are typically fed back into the risk assessment, used to reprioritize resources, and translated into specific remediation actions with ownership and timelines. Many frameworks emphasize the ability to show that a program evolves in response to lessons learned. Tracking whether remediation was completed and whether it addressed the underlying cause, rather than only the symptom, is usually part of demonstrating an effective, adaptive program.
How often should an organization assess its compliance program, and does timing depend on circumstances?
There is generally no single mandated frequency; the appropriate cadence typically depends on the organization's risk profile, size, sector, regulatory environment, and history. Many organizations conduct periodic assessments, often on a recurring cycle, supplemented by event-driven reviews triggered by changes such as a significant incident, an acquisition, entry into a new market, a material change in regulation, or the identification of a control weakness. The underlying principle in many frameworks is that assessment should be proportionate to risk and responsive to change rather than purely calendar-driven. Determining the right approach is a matter of professional judgment for the organization and its advisers.

Common misconceptions

A documented compliance program with written policies is sufficient to demonstrate effectiveness.
Design and documentation are only one dimension. Evaluations generally place significant weight on whether the program operates effectively in practice, including whether controls function as intended, issues are remediated, and the program is genuinely resourced and empowered. A well-drafted policy that is not implemented or monitored typically carries limited weight.
A standardized, off-the-shelf program applied uniformly across the organization is a strong program.
A program is generally expected to be tailored to the entity's specific risk profile, informed by a periodic risk assessment. Uniform allocation of controls without prioritizing higher-risk areas is often viewed as a weakness rather than a strength, because it may leave material risks under-addressed.
Compliance program evaluation is essentially the same as enterprise risk management or internal audit.
These are related but distinct disciplines. Compliance monitoring, enterprise risk management, and independent assurance sit in different functions with different accountability. A compliance program evaluation focuses on the design, resourcing, and operation of the compliance function, whereas risk management and assurance play separate, though complementary, roles.

Best practices

Ground the program in a documented, periodic risk assessment and direct resources and controls toward the organization's highest-priority risks rather than applying uniform coverage.
Assess design effectiveness and operating effectiveness separately, gathering evidence that controls not only exist but function as intended and that identified issues are remediated and tracked to closure.
Clarify accountability so that management owns and operates the program, the board or a designated committee oversees it, and independent assurance provides objective evaluation, avoiding overlap or gaps between these roles.
Evaluate whether the compliance function has genuine autonomy, adequate funding and staffing, and sufficient access to data and senior leadership to act on findings.
Test whether reporting and whistleblowing channels are trusted and used, and whether the organization protects those who raise concerns from retaliation.
Examine whether incentives, compensation, discipline, and tone at the top and middle reinforce compliant conduct, and confirm that the program is refreshed as the organization's risks evolve.