New DOJ Guidance Says Corporate Compliance Programs are Necessary and Should Evolve

6.22.2020

On June 1, 2020, the Criminal Division of the U.S. Department of Justice (“DOJ”) issued a revision to its Guidance Document on the Evaluation of Corporate Compliance Programs.  https://www.justice.gov/criminal-fraud/page/file/937501/download.   

The Guidance Document, which was originally issued in February 2017, and updated in April 2019, is “meant to assist prosecutors in making informed decisions as to whether and to what extent, the corporation’s compliance program was effective at the time of the offense, and is effective at the time of a charging decision or resolution….”

Here are the key takeaways from the recent revisions:

  • Corporate compliance programs will not all be treated the same, but they will be evaluated based on “the company’s size, industry, geographic footprint, regulatory landscape, and other factors, both internal and external to the company’s operations, that might impact its compliance program.”
  • Risk Assessments: The Guidance Document asks whether a company has performed risk assessments and subjected those assessments to periodic reviews that are “based on continuous access to operational data and information across functions,” and have “led to updates in policies, procedures in controls,” as opposed to a simple snapshot in time. 
  • Training: Companies are urged to adopt a training program that allows employees to ask questions and allows the company to evaluate “the extent to which the training has an impact on employee behavior or operations?”
  • Compliance Hotlines: “Does the company take measures to test whether employees are aware of the [reporting] hotline and feel comfortable using it…” and “does the company periodically test the effectiveness of the hotline, for example by tracking a report from start to finish?”
  • Third Parties: What is the “business rationale for needing” a third party in a transaction; What are the risks imposed by third parties; and “Does the company engage in risk assessment of third parties throughout the lifespan of the relationship, or primarily during the onboarding process?”
  • Mergers and Acquisitions: Well-designed compliance programs should include “a process for timely and orderly integration of the acquired entity into existing compliance program structures and internal controls.” 
  • Access to Data: Do compliance and control personnel have sufficient access to relevant data sources to allow timely and effective monitoring and/or testing of policies, controls and transactions?
  • Evolving Updates: “Does the company review and adapt its compliance program based on the lessons learned from its own misconduct and/or that of other companies facing similar risks?” 

Clearly evident from these revisions is the need for a company’s compliance program to continually assess its effectiveness and to evolve in order to meet the changing needs of the company and its business environment.  Simply drafting a nice neat compliance program and then sticking it in a drawer will not win the company many points should it ever come under DOJ’s microscope.  Rather, the companies that invest the time and resources to routinely test its compliance program, and adapt it accordingly, should receive a more favorable review during a DOJ investigation.  

Butzel Long’s team of seasoned White Collar Criminal Defense and Investigations counsel are ready to assist you in crafting a new compliance program designed to meet the latest DOJ guidance or to test your current compliance program to make sure it is designed to be effective and adaptive. 

Theodore Eppel
248.258.2905
eppel@butzel.com

What's Trending

Follow us on social media

Jump to Page

Butzel Long Cookie Preference Center

Your Privacy

When you visit our website, we use cookies on your browser to collect information. The information collected might relate to you, your preferences, or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. For more information about how we use Cookies, please see our Privacy Policy.

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek