The Question at Hand
When the Supreme Court makes significant regulatory changes, compliance officers face a dilemma: should you adjust your program in response, or continue with your current obligations?
Three June 2024 Supreme Court decisions have created this tension. SEC v. Jarkesy limited the SEC's ability to impose civil penalties through administrative judges. Snyder v. United States narrowed corruption law for state and local officials. Loper Bright Enterprises v. Raimondo ended the Chevron doctrine, removing judicial deference to agency regulations.
These rulings clearly reshape enforcement mechanics and regulatory predictability. The real question is whether they should change how you build, maintain, and defend your compliance program.
The Case for Recalibration
Some argue that major legal shifts require program adjustments. Their reasoning is worth considering.
First, enforcement uncertainty creates operational questions. If Loper Bright allows judges to second-guess agency interpretations, you might face inconsistent rulings across circuits. A compliance control that satisfies one court could fail in another. This suggests building more defensive documentation, capturing not just what you did but why your interpretation of ambiguous regulations was reasonable.
Second, resource allocation should follow actual risk. If SEC enforcement through administrative proceedings drops significantly after Jarkesy, you might shift resources from SEC-specific controls to areas with more aggressive enforcement. If Section 666 prosecutions decline after Snyder, perhaps anti-corruption training for domestic operations deserves less emphasis than FCPA training for international teams.
Third, legal developments can signal broader shifts in regulatory philosophy. When the Supreme Court constrains agency power, it might indicate a less aggressive enforcement environment overall. Some compliance officers see this as an opportunity to optimize, not just for efficiency but to avoid over-controlling business operations. If regulators face more constraints, companies might afford slightly more risk.
These positions are reasonable. Compliance programs should adapt to changing risk landscapes, and court rulings are legitimate risk signals.
The Case for Staying the Course
The counterargument is equally compelling: these rulings changed enforcement mechanics, not your underlying obligations.
Consider the practical reality. Most companies facing SEC enforcement never see an administrative judge. Cases involving accounting fraud, insider trading, or Foreign Corrupt Practices Act violations typically land in federal court, and most settle before trial. Jarkesy affects the SEC's tactical options, not whether your financial reporting controls need to meet the Sarbanes-Oxley Act requirements.
Snyder is even narrower. It applies only to Title 18, Section 666 of the U.S. Criminal Code. Your FCPA obligations haven't changed. The Anti-Kickback Statute still applies. The U.K. Bribery Act doesn't care what the Supreme Court said about gratuities to U.S. local officials. If your anti-corruption program splits hairs among these statutes, teaching employees that some corruption is acceptable post-action while other corruption requires pre-action coordination, you've already lost the program's credibility.
Loper Bright creates the most uncertainty, but uncertainty about future regulations doesn't eliminate current ones. You can't stop complying with existing rules because a judge might someday overturn them. Even if a lower court invalidates a regulation, appeals can take years. During that time, continuing to comply is cheaper and safer than mounting a legal challenge.
More fundamentally, these rulings don't touch the core expectations for effective compliance programs. The U.S. Sentencing Guidelines' criteria haven't changed. The Justice Department's guidance on evaluating corporate compliance programs still applies. These aren't agency regulations subject to Chevron deference; they're prosecutorial policy and sentencing framework. A federal judge can't simply dismiss them.
Where Practitioners Actually Land
In practice, most compliance officers are doing exactly what they did before June 2024: managing the same risk universe with the same control objectives.
Your data processing register still needs to track personal data flows under GDPR. Your vendor risk profiles still need to assess third-party security controls. Your policy exception registry still needs documented approvals and remediation timelines. None of that infrastructure changes because the SEC lost some enforcement flexibility or because judges can now challenge agency interpretations more freely.
The compliance officers adjusting their programs are making tactical tweaks, not strategic pivots. They're monitoring Loper Bright's downstream effects to anticipate which regulations might face judicial challenges. They're watching whether Jarkesy actually reduces SEC enforcement volume or just shifts more cases to federal court. They're noting that Snyder doesn't affect their international anti-corruption obligations.
But they're not pulling back controls, reducing training, or declaring victory over regulatory burden. The compliance risks that existed before these rulings still exist. The capabilities your program needed then, it needs now.
Our Take
Hold steady, but stay informed.
These rulings will have long-term effects on regulatory development and enforcement patterns. Loper Bright particularly could slow new rulemaking and increase litigation over existing rules. That's worth monitoring. If you're in a heavily regulated industry, assign someone to track how courts interpret agency rules post-Chevron. Build that intelligence into your risk assessments.
But don't confuse enforcement uncertainty with reduced obligations. Your compliance program exists to prevent violations, detect problems early, and demonstrate good faith if enforcement comes. None of that changes because the government has fewer tools or faces more judicial scrutiny.
The real risk isn't that you'll over-comply after these rulings. It's that you'll mistake procedural changes for substantive permission to relax controls. That's the kind of thinking that leads to the next enforcement action, and no Supreme Court ruling will help you then.
Your obligations haven't shifted. Neither should your program.





