Back to Insights
    A Practical Guide to the DOJ’s Evaluation of Corporate Compliance Programs
    reference· 7 min read

    A Practical Guide to the DOJ’s Evaluation of Corporate Compliance Programs

    This guide translates the U.S. Department of Justice’s (DOJ) guidance on evaluating corporate compliance programs into actionable insights for HR leaders. It breaks down the key questions prosecutors ask and outlines the evidence required to demonstrate an “effective in practice” compliance program.

    The Department of Justice does not certify compliance programs. It evaluates them — after something has gone wrong. That distinction matters more than most HR and compliance leaders account for, because the questions a prosecutor asks are not the questions an internal audit asks. The DOJ's Evaluation of Corporate Compliance Programs (U.S. Department of Justice, 2020) is the closest thing to a published answer key, and read carefully it is less a checklist than a demand for evidence: proof that a program is not simply documented, but working.

    What is the ECCP, and why should HR leaders read it?

    The ECCP is guidance for federal prosecutors deciding how much credit a company deserves for its compliance program — at charging, at resolution, and at sentencing. It is not a mandate, and there is no template to fill in. But because so much of what it examines lives inside the HR function — training, reporting channels, investigations, discipline, incentives, promotion decisions — HR leaders are, in practice, the custodians of most of the evidence a prosecutor will eventually ask for. The guidance organizes that inquiry around three questions: whether the program is well designed, whether it is applied earnestly and in good faith with real resources and authority, and whether it actually works in practice.

    Is the program well designed?

    Design, in the DOJ's reading, means tailored — not comprehensive. Prosecutors ask how the company identified, assessed, and defined its risk profile, what methodology it used to prioritize those risks, and how it keeps that picture current. The evidence that satisfies this is documented risk assessment that accounts for geography, industry, third-party relationships, and regulatory environment; a visible line from those findings into the design of policies, controls, and training; and a process for revising the assessment when the business changes. A program built on generic risk is a program that will read as untailored.

    Policies and procedures are examined the same way. The questions are how new policies are designed and implemented, and how they were communicated to employees and relevant third parties. What holds up is a code of conduct written to be understood rather than to be defensible, genuine accessibility, and a documented review cycle that shows the policies have been revisited rather than archived.

    Training draws the sharpest inquiry, and it is where HR is most exposed. Prosecutors want to know what training employees actually received, whether it addressed the risks the company itself identified, and — critically — how the company measures whether it worked. Completion data alone answers none of that. What answers it is role-specific and risk-specific training, delivery that allows employees to ask questions and be answered, and evidence of retention and behavior change that feeds back into the next revision of the program. On this point the ECCP and the behavioral research converge: see why compliance training doesn't change behavior.

    Is the program applied earnestly and in good faith?

    This is the resourcing and authority question, and it is largely a question about leadership behavior. Prosecutors look at what senior leaders and middle managers have specifically done to demonstrate commitment, and at how compliance personnel are compensated and promoted. The evidence is documentary and behavioral: communications from leadership that treat ethics as operational rather than ceremonial, leadership participation in the program itself, and — most persuasively — compliance factored into performance evaluation, compensation, and promotion for everyone, not only the compliance function. Incentives are read as the honest statement of what an organization values.

    Autonomy is assessed through structure. To whom does the compliance function report, and has it been given the resources to do the job? A reporting line with direct access to the board and senior management, independent of the business units it oversees; staffing and expertise proportionate to the risk profile; and a dedicated budget covering training, technology, and outside expertise where needed. A compliance function that must ask permission of the people it monitors is a design flaw, not a staffing issue.

    Does the program work in practice?

    This is the question that decides outcomes, and the one the other two exist to serve. Prosecutors begin with reporting: how employees and third parties can raise concerns, and how the company assesses seriousness once they do. The evidence is multiple well-publicized channels including anonymous options, clearly communicated and observably honored non-retaliation protection, and data — hotline volume, complaint categories, trends over time — showing the channels are used and the traffic is analyzed rather than logged.

    Investigations are next. Prosecutors ask how they are documented and how allegations are escalated and resolved. What holds up is documentation showing prompt, objective, thorough work; investigators with real training and appropriate independence; and confidentiality procedures that protect everyone involved. An investigation that cannot be reconstructed from its record did not, for these purposes, happen.

    Then remediation and discipline, where most programs are actually tested. The question prosecutors ask is whether disciplinary action is consistent and proportionate across all levels of the company — the emphasis on all levels is deliberate. A record showing that seniority attracted leniency undermines every other piece of evidence a company has assembled. Alongside consistency, the DOJ looks for root cause analysis rather than incident closure, and for evidence that findings changed the program: revised policies, new controls, redesigned training.

    What this means for HR leaders

    Read as a whole, the ECCP is an evidentiary standard, not a compliance standard. Every question it poses resolves into a demand for proof that the program produced an effect. That is not a documentation exercise — it is a governance posture, and the evidence has to be generated continuously, because it cannot be assembled retroactively once an investigation is underway. HR leaders who treat the ECCP's three questions as an ongoing internal audit rather than a defense brief are doing the only version of this work that survives contact with a prosecutor.

    For the broader framework this sits inside, see what human risk governance is, or read the flagship analysis on why conduct risk originates below the level most programs measure.

    Sources

    • U.S. Department of Justice. (2020, June). [Evaluation of Corporate Compliance Programs](https://www.justice.gov/criminal-fraud/page/file/937501/download).