Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
DOJ Fraud Division's 10-Factor Test: A Control Objective Mapping ExerciseRegulatory Obligations Management
5 min readFor Compliance Officers

DOJ Fraud Division's 10-Factor Test: A Control Objective Mapping Exercise

The Challenge

The Justice Department's National Fraud Division has outlined 10 factors prosecutors will use to decide on corporate prosecutions. These factors include estimated fraud losses, geographic reach of misconduct, senior management involvement, and whether executives concealed the fraud.

For your compliance team, the challenge is not just recognizing these priorities. It's about determining if your current controls can detect and prevent the specific misconduct the Fraud Division targets. If your program can't identify fraud that spans multiple U.S. attorney districts or can't flag schemes involving senior management, there's a gap between what prosecutors expect and what your controls deliver.

The question isn't whether you need a compliance program. You already have one. The question is whether that program can respond to this shift in enforcement focus.

Constraints in Compliance Programs

Your compliance program operates within tight constraints. You're managing hotline reports, training schedules, third-party risk assessments, and program audits with limited resources. Internal audit runs annual fraud risk assessments but may not see the urgency in reformatting controls to match prosecutorial priorities. Senior management might question why you need to adjust a program that's already in place.

The Fraud Division's focus on frauds that cut across multiple districts poses a specific challenge: can your controls analyze transactions across different offices or business units? Can you match hotline calls from different people at different times and locations that describe the same misconduct? If your incident tracking system treats each report as a standalone event, you'll miss patterns that span geographies.

There's also a coordination problem. Compliance officers typically own the Whistleblower Hotline and policy framework, but fraud analytics often sit with internal audit or finance. If those teams don't share data or escalation triggers, you won't get early visibility into incidents that meet the Fraud Division's criteria.

Mapping Controls to New Priorities

Start with control objective mapping. Take each of the 10 Fraud Division factors and map them to your existing detective and preventive controls. For frauds lasting multiple years, do you run trend analysis? If so, who performs it, with what data, and how often? For frauds exceeding $25 million in damages, do you analyze duplicate payments or refund claims? Who owns that control?

One compliance officer used AI to build a risk-control matrix that maps each fraud factor to principal risks, detective controls, preventive controls, monitoring activities, and escalation triggers. The matrix identifies general control categories. The harder work is associating those categories with actual control activities your company will perform.

For example, the matrix might list "trend analysis" as a detective control. Your job is to specify: trend analysis of what transactions, performed by which team, using which system, on what schedule? If the matrix calls for analysis of duplicate payments, you need to define the data source, the person responsible, and the frequency.

Internal audit can help here. They already run fraud risk assessments and understand Control Objective Mapping. The question is whether audit leadership sees the value in reformatting controls to address the Fraud Division's priorities. If they can't or won't help, you'll need to do more of this mapping work yourself.

The second piece is building an escalation dashboard. Compliance teams have used early-warning triggers for anti-corruption incidents for years. The same approach works for fraud risks. Define triggers that capture incidents with characteristics the Fraud Division cares about:

  • Number of fraud allegations involving management
  • Potential loss estimate
  • Number of potentially affected customers
  • Number of jurisdictions or business units implicated
  • Number of government programs potentially affected
  • Government-contract billing exceptions
  • Number of cases where management was implicated
  • Number of cases exceeding 90, 180, or 365 days before detection
  • Number of repeat findings after remediation

These triggers feed into a dashboard that alerts you to issues requiring immediate human review. You're not automating the decision to escalate. You're automating the signal that escalation might be warranted.

Some teams also implemented a mandatory escalation policy: if any incident reasonably indicates fraud and one or more Justice Department fraud factors are present, the matter must be escalated to the chief compliance officer to determine investigation scope, potential self-disclosure obligations, and further steps.

Results and Metrics

The source material doesn't provide measurable outcomes from a specific organization implementing this approach. What it does provide is a framework for assessing whether your controls can detect the misconduct prosecutors now prioritize.

The risk-control matrix gives you a structured way to identify gaps. If you can't monitor transactions across multiple districts, that's a gap. If you can't flag cases where management was implicated in concealment, that's a gap. The matrix makes those gaps visible.

The escalation dashboard creates a feedback loop. You'll see which triggers fire most often, which incidents meet multiple Fraud Division factors, and where your detective controls are catching issues early versus late.

Lessons Learned

The biggest lesson is to involve internal audit earlier. Audit teams understand control design and testing. They run fraud risk assessments. If you try to remap controls without their input, you'll miss opportunities to use work they're already doing.

The second lesson is to be specific about control activities. A matrix that says "perform trend analysis" isn't actionable. You need to define the data source, the responsible party, the tool, and the schedule. Otherwise, you've documented a control that doesn't actually exist.

The third lesson is to treat escalation triggers as a living document. The Fraud Division's priorities might shift. Your business might enter new markets or launch new products. The triggers that matter today might not be the triggers that matter in 18 months.

Takeaways for Your Team

Start with the 10 Fraud Division factors and map them to your existing controls. Don't assume your current program addresses these priorities just because it addresses other compliance obligations. Be specific about what each control actually does, who performs it, and how often.

Build escalation triggers that capture incidents with characteristics the Fraud Division cares about. Feed those triggers into a dashboard that alerts you to issues requiring immediate review.

Work with internal audit. They already run fraud risk assessments and understand Control Objective Mapping. If they won't help, document why you need to proceed without them.

Consider a mandatory escalation policy for incidents that implicate one or more fraud factors. You're not escalating every hotline report. You're escalating incidents that match the profile of misconduct prosecutors want to pursue.

The fundamentals of compliance programs haven't changed. But the capabilities your program needs to detect and prevent specific types of fraud have changed. If your controls can't keep pace with that shift in enforcement focus, you're carrying risk you don't need to carry.

Application Security Isn’t Optional Anymore.

You Might Also Like