The Department of Justice released its updated Evaluation of Corporate Compliance Programs guidance on September 23, 2024, at the Society of Corporate Compliance and Ethics conference. This regulatory shift revealed critical gaps in how most compliance programs assess technology and AI risk. Here's what failed, what the standard now requires, and what you need to fix.
What Happened
The DOJ's ECCP update mentioned "technology" or its variations 22 times across 22 pages, with 17 of those references being new. The guidance added entire sections on AI use and set clear expectations for documenting emerging risks. The message is clear: if your risk assessment doesn't treat technology and AI as distinct risk categories, it's incomplete by DOJ standards.
This wasn't a minor tweak. The DOJ fundamentally redefined what constitutes an adequate compliance risk assessment.
Timeline
- Pre-September 2024: Most compliance programs treated technology as infrastructure, not as a discrete compliance risk category.
- September 23, 2024: DOJ publishes ECCP update at SCCE conference.
- Current state: Compliance officers lack baseline technology inventories needed to meet the new guidance.
Which Controls Failed or Were Missing
Missing: Technology Risk Category
Most compliance risk assessments are organized by regulatory domain: anti-bribery, trade compliance, data privacy, retaliation. Technology appeared, if at all, as a control mechanism or detail, not as a risk source.
The DOJ now expects you to evaluate how each system you operate affects compliance risk. You can't do that without knowing which systems you're running.
Missing: AI-Specific Risk Analysis
The guidance distinguishes between AI used by the company and AI used by the compliance function. Both require separate risk analyses. Most programs haven't documented either.
For company-wide AI, assess whether each AI application increases the likelihood of compliance violations. For compliance AI, document how AI-assisted tools (policy search, monitoring systems, data analytics) mitigate specific risks.
Missing: Emerging Risk Documentation
The DOJ added a paragraph on emerging risks, a term that appears throughout the updated guidance. Yet most risk assessments don't structure emerging risks as a distinct category.
The guidance expects you to identify "specific factors that mitigate the company's risk" and document whether your approach is reactive or proactive. It's not enough to think about emerging risks; you must show your methodology.
Missing: Technology Inventory
You can't assess technology risk without a baseline inventory. The DOJ assumes you know which systems operate where, what data they process, whether they use AI, and who owns them internally.
Most compliance teams don't have this information. IT might. Procurement might. Privacy might. But compliance typically doesn't maintain a consolidated view.
What the Standard Requires
The ECCP isn't a regulation with enforceable requirements. It's the framework DOJ prosecutors use to evaluate your program when deciding whether to charge your company or offer cooperation credit.
Here's what the updated guidance expects:
Technology as a Risk Category: Your risk assessment must evaluate how technology affects compliance risk. This means scoring technology like you score geographic markets or business units.
AI Risk Subcategory: Within your technology assessment, AI requires separate analysis. Document how AI is used, by whom, and what compliance risks it creates or mitigates.
Emerging Risk Analysis: Your risk assessment must identify emerging risks and document your methodology for tracking them. The DOJ wants to see whether you take a proactive or reactive stance.
Risk-Based Resource Allocation: The guidance emphasizes that risk assessment outcomes must drive resource decisions. You need to document how higher-risk areas receive greater scrutiny and investment.
Methodology Documentation: It's not enough to complete a risk assessment. You must document your approach, the factors you considered, and how you determined risk levels.
Lessons and Action Items for Your Team
Build a Technology Inventory First
You can't assess what you don't know. Start with five columns:
- System name
- Internal owner
- Business function
- AI usage (yes/no, and how)
- Personal data processed
Work with IT, Procurement, and Privacy to compile this list. If those teams can't help, survey business unit heads directly. Keep it simple; you're building a baseline, not a CMDB.
Add Technology and AI to Your Risk Assessment
Create a technology risk category in your next risk assessment cycle. For each major system, document whether it increases or decreases compliance risk and what the impact would be if something went wrong.
Treat AI as a subcategory. For company-wide AI, assess compliance risk exposure. For compliance-function AI, document which risks each tool mitigates.
Document Your Emerging Risk Process
Add "Emerging Risks" as a section header in your risk assessment documentation. Include technology and AI risks here, but don't limit it to tech. Regulatory proposals, geopolitical shifts, and business model changes all qualify.
Document whether you're reactive (responding to risks as they materialize) or proactive (anticipating risks before they manifest). The DOJ wants to see proactive thinking.
Show Resource Allocation Tied to Risk
The updated guidance emphasizes risk-based resource allocation. Document how your risk assessment results influence budget decisions, headcount, training investment, and monitoring frequency.
If you identify third-party AI vendors as a high-risk area, show how you're allocating more resources to vendor due diligence and ongoing monitoring in that category.
Update Your Assessment Methodology Documentation
Don't just run your risk assessment; document how you run it. Capture the factors you consider, the data sources you use, the stakeholders you consult, and the criteria you apply to score likelihood and impact.
The DOJ added specific language about documenting "features" that reduce risk exposure. Make your methodology visible and repeatable.
This isn't the last ECCP update you'll see. The DOJ revises this guidance every 12 to 18 months. Treat this as a continuous improvement cycle, not a one-time compliance project. Your next risk assessment should reflect these changes before prosecutors ask to see it.





