Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
How to Screw Up Your Fraud Risk Program in Five Easy StepsRegulatory Obligations Management
6 min readFor Compliance Officers

How to Screw Up Your Fraud Risk Program in Five Easy Steps

The Justice Department's new National Fraud Enforcement Division changes more than just who prosecutes fraud; it shifts what your compliance team needs to worry about and when. Assistant Attorney General Colin McDonald's seven-page memo outlines five fraud categories the division will target, but the scope is vague and the enforcement priorities are political.

This creates a specific risk: compliance teams are likely to make predictable mistakes in response to an unpredictable mandate. Here's how to avoid them.

Why These Mistakes Keep Happening

Most compliance programs are designed to address clear regulatory obligations with stable enforcement patterns. You map controls to requirements, track regulatory updates, and adjust when rules change. The Fraud Division disrupts this model. McDonald's memo promises to prosecute "fraud in the United States, no matter its size or complexity" across five categories, four involving fraud against the federal government and one labeled "corporate misconduct" with no further detail.

Vice President J.D. Vance announced the division on January 8 during a political crisis, stating prosecutors would report directly to him and Trump rather than the Justice Department. The Administration later claimed the division would report to the deputy attorney general, but it's unclear if that's true or relevant when Justice Department leaders prioritize political directives.

You're dealing with enforcement that's broad by design and political by nature. Standard compliance strategies don't cover that.

Mistake 1: Treating This Like a Normal Regulatory Update

Why it happens: Your team reads McDonald's memo, notes the five fraud categories (public trust and financial integrity, healthcare, internal revenue, global trade and commerce, corporate misconduct), and starts mapping controls to each one like any new regulation.

Real consequence: You create a compliance response for a stable rule set when you're actually facing arbitrary enforcement. McDonald never defines "corporate misconduct" beyond noting that "businesses frequently engage in fraud and other economic crimes, eager to benefit financially from the criminal misconduct of their employees." That's not a standard you can map controls to. It's a placeholder for whatever the division decides to prosecute.

The fix: Shift from compliance mapping to Scenario Analysis. Don't ask "what controls do we need for each category?" Ask "which of our current operations could be reframed as fraud under political pressure?" Run scenario analysis on your government contracts, healthcare billing, import documentation, grant spending, and employee conduct. Identify where your documentation is weak, where your controls rely on trust rather than verification, and where a prosecutor could construct a fraud narrative from incomplete records.

Mistake 2: Assuming Political Enforcement Won't Affect You

Why it happens: Your company isn't politically connected, doesn't lobby, and stays out of controversial sectors. You figure political enforcement targets Trump's enemies, and you're nobody's enemy.

Real consequence: Political enforcement doesn't just mean prosecuting opponents. It means not prosecuting friends, which changes the competitive landscape. If your competitors are politically connected and get informal assurance they won't face scrutiny for customs violations or Medicare billing practices, they can undercut your prices while you maintain expensive controls. You're not the target, but you're still disadvantaged.

The fix: Monitor enforcement actions, not just enforcement announcements. Track which companies in your sector face Fraud Division scrutiny and which don't. If patterns emerge that correlate with political connections rather than misconduct severity, document it. Your board needs to understand that maintaining strong controls might be a competitive disadvantage in this environment, and that's a business risk decision, not a compliance decision.

Mistake 3: Focusing Only on the Four Clear Categories

Why it happens: McDonald's memo gives specific guidance on four fraud types: procurement fraud, healthcare fraud, tax evasion, and customs violations. These are concrete. You can build controls around them. The fifth category, corporate misconduct, is vague, so you defer it.

Real consequence: The corporate misconduct category is where the White Collar Enforcement Section operates, and McDonald explicitly says his division will work closely with them. That section handles securities fraud, financial statement fraud, bribery, and other offenses that hit public companies and large private firms hardest. By ignoring the vague category, you're ignoring the category most likely to affect your organization.

The fix: Treat corporate misconduct as a catch-all for any fraud the division wants to pursue but can't fit into the other four buckets. Review your existing controls for financial reporting accuracy, anti-bribery compliance, and employee misconduct reporting. Strengthen your whistleblower hotline and retaliation protection policies. The False Claims Act already incentivizes employees to report fraud to the government rather than internally, and that risk just increased.

Mistake 4: Waiting for Enforcement Patterns to Emerge

Why it happens: You don't want to overreact to a new division before you see what it actually does. Better to wait six months, see which cases it brings, then adjust your program based on real data.

Real consequence: The first cases will be the test cases, and prosecutors choose those carefully. If your company becomes a test case because you waited to strengthen controls, you're facing an enforcement action specifically designed to set precedent. You won't get the benefit of established case law or prosecutorial discretion patterns.

The fix: Conduct a fraud risk assessment now, before enforcement patterns emerge. Identify your highest-risk areas across all five categories. For government contractors, that's procurement documentation and billing accuracy. For healthcare companies, it's Anti-Kickback policies and Medicare billing. For importers, it's customs broker oversight and tariff classification. Strengthen those controls immediately, not because you know they'll be scrutinized, but because you can't afford to learn they'll be scrutinized by becoming a defendant.

Mistake 5: Assuming Your Current Controls Are Sufficient

Why it happens: You already have a fraud prevention program. You've got segregation of duties, approval workflows, expense monitoring, and vendor due diligence. You're not committing fraud, so you're not at risk.

Real consequence: Your controls might prevent fraud, but they probably don't document the absence of fraud. Under normal enforcement, that's fine. Under arbitrary enforcement, it's not. A prosecutor with a broad mandate and political motivation can construct a fraud narrative from incomplete documentation even when no fraud occurred. Your controls need to create an audit trail that makes that narrative impossible to sustain.

The fix: Audit your documentation practices, not just your controls. Can you prove why you classified imports under specific tariff codes? Can you demonstrate that your Medicare billing reflects actual services provided, not just that services were provided? Can you show that your grant spending matched approved budgets, not just that you spent the grant money? If your controls rely on "we trust our people" or "we've never had a problem," strengthen your evidence collection now.

Prevention Checklist

  • Run scenario analysis on how current operations could be reframed as fraud under political pressure
  • Monitor enforcement actions in your sector for patterns that correlate with political connections
  • Strengthen controls for financial reporting, anti-bribery, and employee misconduct reporting
  • Conduct fraud risk assessment covering all five Fraud Division categories
  • Audit documentation practices to ensure you can prove the absence of fraud, not just prevent fraud
  • Brief your board on competitive risks if politically connected firms face less scrutiny
  • Review customs broker oversight and import documentation if you import goods
  • Strengthen Anti-Kickback policies and Medicare billing controls if you're in healthcare
  • Review procurement documentation and billing accuracy if you're a government contractor
  • Ensure your whistleblower hotline and retaliation protection policies exceed False Claims Act incentives

The Fraud Division's broad mandate means you can't wait to see what enforcement looks like. By the time patterns emerge, you're either already compliant or already exposed.

Promotional banner for the Penetration Report Template Kit

You Might Also Like