In March 2023, Deputy Attorney General Lisa Monaco announced significant updates to the Department of Justice's evaluation criteria for corporate compliance programs. These changes mark a fundamental shift in what prosecutors expect when assessing whether your compliance program is effective.
If you're still treating compliance as a static framework reviewed annually, you're using the wrong approach. The DoJ has made that clear.
Key Changes in DoJ Guidance
The DoJ released updated guidance on evaluating corporate compliance programs, building on memoranda from October 2021 and September 2022. The March 2023 announcement introduced several important changes:
- Standardized voluntary self-disclosures across US attorney's offices
- A three-year Pilot Program on Compensation Initiatives and Clawbacks
- Expanded expectations for data retention and device usage
- Additional resources, including 25 new prosecutors for corporate criminal enforcement
- Joint advisories with Commerce and Treasury Departments on security-related compliance
This guidance applies to any organization with US exposure. If you process transactions in US dollars or are subject to regulations like the Foreign Corrupt Practices Act, these expectations apply to you.
Timeline of Developments
June 2020: The DoJ emphasizes that compliance programs must be dynamic, not static. Programs that exist only on paper offer no protection during investigations.
October 2021: Monaco issues a memorandum outlining new prosecution guidance.
September 2022: A second memorandum reaffirms the government's commitment to corporate crime enforcement and previews compensation-focused changes.
March 2023: Monaco announces standardized self-disclosure policies, the Compensation Pilot Program, and expanded resource commitments.
Common Compliance Gaps
The DoJ updates highlight systematic gaps prosecutors have observed in corporate compliance programs:
Static risk assessment processes: Organizations conduct annual risk assessments but don't maintain continuous access to operational data. When misconduct occurs, the risk assessment hasn't been updated to reflect lessons learned.
Inaccessible policies: Compliance policies exist but aren't published in searchable formats. Companies can't demonstrate that employees access them or that linguistic barriers have been addressed for foreign subsidiaries.
One-way training programs: Training occurs, but there's no mechanism for employees to ask questions. Companies can't show how training impacts behavior or what happens when employees fail portions of the training.
Limited whistleblowing reach: Hotlines exist for employees but aren't extended to third parties. Companies haven't tested whether employees know the hotline exists or feel comfortable using it.
Weak compensation linkage: Compliance performance isn't built into bonus structures. When misconduct occurs, there's no mechanism to claw back compensation from those involved.
Incomplete M&A integration: Due diligence happens pre-acquisition, but acquired entities aren't promptly integrated into existing compliance structures.
DoJ Evaluation Criteria
The DoJ organizes its evaluation around three questions:
- Is the program well designed?
- Is it adequately resourced and empowered to function effectively?
- Does it work in practice?
For risk assessment, the guidance now explicitly asks: "Is the periodic review limited to a 'snapshot' in time or based upon continuous access to operational data and information across functions?" Companies must demonstrate they've incorporated "lessons learned either from the company's own prior issues or from those of other companies operating in the same industry and/or geographic region."
For policies and procedures, the DoJ expects you to track access: "Does the company track access to various policies and procedures to understand what policies are attracting more attention from relevant employees?"
On training, the standard has shifted toward shorter, targeted sessions with built-in feedback mechanisms. The question "Whether online or in-person, is there a process by which employees can ask questions arising out of the trainings?" is now emphasized.
For whistleblowing systems, the current guidance asks: "How is the reporting mechanism publicized to the company's employees and other third parties?" Companies must demonstrate the system is user-friendly and actually used.
The Compensation Pilot Program creates new expectations. Any company entering a corporate resolution with the Criminal Division must include compliance-promoting criteria in compensation systems. Companies that claw back compensation from individuals involved in misconduct become eligible for fine reductions.
Action Items for Your Team
Move from annual snapshots to continuous monitoring: Your risk assessment shouldn't be a document you update once a year. Build dashboards that pull real-time data from HR systems, security tools, and case management platforms. When an incident occurs in your sector, update your risk universe within days, not months.
Make policies searchable and track engagement: Publish your compliance policies in a format employees can actually search. Implement analytics to see which policies get accessed and which get ignored. If nobody's reading your third-party risk policy, that's a signal.
Test your whistleblower hotline: Don't wait for prosecutors to ask whether employees know it exists. Run quarterly tests where compliance team members submit anonymous test reports and track them through resolution. Measure time-to-response and quality of investigation.
Extend reporting mechanisms beyond employees: Your contractors, vendors, and partners see risks you don't. Make your whistleblower hotline available to third parties and publicize it in vendor onboarding materials.
Build compliance into compensation structures now: Before you're facing an investigation, design bonus criteria that reward compliance performance. Document how you measure it. The Pilot Program suggests prosecutors will look for this proactively.
Create a lessons-learned process: After every compliance issue (yours or a peer's), document what happened and what control gaps it revealed. Update your risk assessment, training content, and monitoring rules accordingly. Keep records showing this happened.
Plan M&A integration timelines: When you acquire a company, set a 90-day deadline for integrating it into your compliance program. That includes policy adoption, training completion, and system access. Document the integration plan before the deal closes.
The DoJ's message is clear: compliance programs must adapt in real time, not just during annual reviews. If your last risk assessment predates your last security incident, you're already behind.




