The Justice Department's National Fraud Division has published its prosecution criteria. While the Corporate Enforcement Policy remains unchanged, the memo clarifies which fraud schemes will attract federal attention. If your compliance program involves government contracts, healthcare reimbursements, or tax reporting, it's time to align your controls with these ten factors.
Why This Matters
Colin McDonald, assistant attorney general for the National Fraud Division, outlined criteria prosecutors will use to decide on corporate fraud charges. The focus on senior management involvement, multi-district schemes, and concealment from government agencies creates pressure points for your compliance program.
Self-disclosure, cooperation, and remediation still offer a path to declination under the Corporate Enforcement Policy. However, you now know which fraud patterns will trigger scrutiny. This allows you to build controls and escalation procedures that match enforcement priorities before issues arise.
What You Need Before Starting
Before revising your fraud risk assessment, gather these components:
Documentation of current controls:
- Your existing fraud risk universe
- Transaction monitoring thresholds and sampling methodologies
- Escalation procedures for suspected misconduct
- Hotline intake and case management workflows
- Cross-functional communication protocols between offices or business units
Access to systems and data:
- Transaction databases across all business units and geographic locations
- Contract management systems for government-funded programs
- Financial reporting systems that track program-specific revenue
- Whistleblower hotline records for the past 36 months
- Senior management approval logs for high-value transactions
Stakeholder alignment:
- Legal team availability to review disclosure protocols
- Internal audit's current fraud testing procedures
- Finance team's understanding of program-specific accounting
- IT's ability to query transactions across multiple systems
- Business unit leaders who can explain operational variations between offices
Step-by-Step Implementation
Step 1: Map your fraud exposure against the ten factors
Review each of McDonald's criteria and identify where your organization has material exposure. Focus on these high-priority areas:
- Senior management involvement: Document which approvals require C-suite or board authorization. If fraud occurred in these workflows, would you detect it?
- Multi-district operations: List every U.S. attorney district where you have physical offices, remote employees, or significant contract performance. Can you correlate transactions across these locations?
- Government program concentration: Identify every taxpayer-funded program your company supports. Do you have program-specific controls or just enterprise-wide procedures?
Create a matrix that cross-references your business activities against each factor. Mark any cell where you lack sufficient detective controls.
Step 2: Strengthen transaction analysis capabilities
If McDonald's memo highlights multi-district fraud, your transaction monitoring can't stop at individual office boundaries.
Build queries that identify:
- Similar transaction patterns across different offices
- Vendors or counterparties that appear in multiple districts
- Approval chains that bypass standard procedures
- Invoice amounts just below review thresholds
- Timing patterns that suggest coordinated behavior
If you're using an IRM platform, configure dashboards that aggregate risk indicators across business units. If you're working in spreadsheets, establish monthly procedures to consolidate transaction samples from each location.
Step 3: Revise your hotline intake procedures
Multiple hotline calls describing similar misconduct in different offices might indicate a multi-district scheme. Update your case management workflow:
- Tag every complaint with geographic location and business unit
- Flag cases that share common elements (vendor names, transaction types, approval processes)
- Establish weekly review meetings where compliance reviews new cases alongside open investigations
- Create alerts when new complaints match keywords or parties from existing cases
Document this process so investigators can demonstrate you had procedures to detect widespread schemes.
Step 4: Update escalation thresholds
The memo identifies financial losses over $25 million and schemes affecting 25 or more victims as prosecution factors. Review your escalation procedures:
If your current threshold for legal review is $50 million, lower it to $20 million to ensure you're escalating before you cross McDonald's line. If you don't track victim counts, add that field to your case intake form.
For schemes lasting three years or more, establish lookback procedures. When you discover potential fraud, don't just investigate the current fiscal year. Query the same transaction types, vendors, or approval chains for the previous 36 months.
Step 5: Strengthen concealment detection
The division prioritizes cases where companies hid misconduct from government agencies or auditors. Build controls that detect concealment attempts:
- Monitor for deleted or modified audit trail records
- Flag communications that reference audits, government reviews, or compliance inquiries
- Review who has access to modify transaction records after they're initially entered
- Track failed login attempts to financial systems during audit periods
If you discover fraud, immediately preserve all related communications and system logs. Concealment evidence matters as much as the underlying scheme.
Validation: How to Verify It Works
Test your revised controls before you need them:
Run a tabletop exercise where you simulate discovering a $30 million fraud scheme that involves three different offices. Walk through your escalation procedures, transaction analysis capabilities, and disclosure decision-making. Time how long it takes to gather the information legal counsel will need.
Audit your cross-office visibility by selecting a random vendor and querying all transactions with that counterparty across your entire organization. If you can't produce comprehensive results within 48 hours, your transaction monitoring isn't ready for a multi-district investigation.
Review your last 20 hotline cases and retroactively apply geographic and keyword tagging. Would you have identified any patterns you missed the first time?
Test your data retention by requesting audit logs from 36 months ago. If you can't produce them, you can't demonstrate whether misconduct was concealed.
Maintenance and Ongoing Tasks
Monthly: Review new hotline cases against open investigations to identify potential patterns across offices.
Quarterly: Run transaction queries that test for multi-district schemes, even if you haven't received any specific allegations. Look for statistical outliers or approval bypasses.
Annually: Update your fraud risk universe to reflect new government programs, new office locations, or changes in senior management approval authorities.
After organizational changes: When you acquire a new business unit, open a new office, or win a new government contract, immediately map it against McDonald's ten factors and extend your controls accordingly.
The Corporate Enforcement Policy still rewards self-disclosure, but you can't disclose what you can't detect. These controls give you the visibility to find multi-district fraud before prosecutors do.





