Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
The DOJ Just Rewrote Compliance Policy RulesRegulatory Obligations Management
5 min readFor Compliance Officers

The DOJ Just Rewrote Compliance Policy Rules

Your compliance program probably treats policies like static documents. You draft them, get them approved, publish them to SharePoint, and move on. Maybe you review them annually if someone remembers to add it to the calendar.

The Department of Justice's latest update to its Evaluation of Corporate Compliance Programs guidance says that's not enough anymore. If prosecutors come calling, they'll ask pointed questions about how you keep policies current.

These myths about policy management persist because they worked well enough in the past. But the DOJ's new language makes it clear: prosecutors expect you to run a dynamic policy program that responds to what you learn, not just what you knew when you first wrote the document.

Myth 1: Annual policy reviews satisfy regulatory expectations

Reality: The DOJ now explicitly asks whether your program includes "a process for updating policies and procedures to reflect lessons learned either from the company's own prior issues or those from other companies operating in the same industry and/or geographic location."

Notice the language: it's not asking if you review policies annually. It's asking if you have a process triggered by lessons learned. When your internal investigation uncovers the same policy violation for the third time, or when a competitor settles an enforcement action for conduct your company could plausibly engage in, the DOJ expects you to update relevant policies in response.

Document this process in your policy governance framework. If you maintain a policy-on-policies, add a section requiring updates when internal issues or external enforcement actions reveal gaps. If you don't have formal policy governance, create a procedure that defines who evaluates lessons learned, how often, and what triggers a policy update outside the normal review cycle.

Myth 2: Risk assessments and policy updates are separate activities

Reality: The updated guidance asks, "Is there a process for updating policies and procedures to address emerging risks?"

Your annual risk assessment shouldn't just produce a heat map for the board. It should trigger policy changes. When you identify a new third-party risk, ransomware threat, or regulatory obligation, your policy program needs a documented pathway to incorporate that risk into relevant policies.

This means your risk and compliance functions need to work together, not in parallel. When your risk team identifies an emerging threat, your compliance team should have a defined process for evaluating whether existing policies address it. If they don't, you need a timeline and owner for the update.

The DOJ didn't ask whether your policies anticipate every possible risk. They asked whether you have a process for updating policies when new risks emerge. That's a process question, and you can answer it by documenting the connection between risk identification and policy revision.

Myth 3: Technology changes are IT's problem

Reality: Prosecutors will ask whether you have a process for updating policies to address emerging risks "relating to the use of new technologies."

When your company adopts generative AI tools, moves to cloud infrastructure, or implements new collaboration platforms, your compliance policies need to catch up. The DOJ recognizes that technology creates new compliance risks, and they expect your policy program to respond.

You probably already update policies when technology changes, but you're likely doing it reactively and inconsistently. Document the process: Who evaluates new technology deployments for compliance implications? What's the timeline for updating affected policies? How do you communicate changes to employees who use the technology?

Add this to the same policy governance document where you addressed lessons learned and emerging risks. The pattern is consistent: the DOJ wants to see documented processes, not ad hoc responses.

Myth 4: Publishing policies to your intranet means employees can access them

Reality: The guidance now asks, "How does the company confirm that employees know how to access relevant policies?"

There's a difference between making policies available and confirming employees know where to find them. You might have a beautifully organized policy library, but if employees don't know it exists or can't navigate it, you haven't met the DOJ's expectation.

Survey your employees. Add a question to your ethics and compliance culture survey asking whether people feel confident finding policies when they need them. Include a similar question at the end of training modules: "Do you know where to find the policy we just discussed?"

If your survey results show employees struggle to access policies, you have a documented gap to address. Maybe your policy library needs better search functionality. Maybe you need to reference policy locations more consistently in training. Maybe you need to send periodic reminders about where policies live. The point is to confirm access, not assume it.

Myth 5: Post-M&A policy integration can wait until other priorities settle

Reality: The updated guidance includes a new paragraph on post-M&A compliance integration, specifically asking, "What is the company's process for implementing and/or integrating a compliance program post-transaction?"

When you acquire another company, you inherit their compliance risks. If their policies are weaker than yours, or if employees don't know which policies now apply, you've created a gap that prosecutors will scrutinize if something goes wrong.

Your M&A integration playbook should explicitly address policy integration. Who evaluates the target company's existing policies? What's the timeline for replacing them with your policies or integrating them into your framework? How do you communicate policy changes to newly acquired employees?

Don't treat policy integration as a low-priority administrative task. The DOJ's new language suggests they view it as a critical part of compliance program integration overall.

What to do instead

Start with your policy governance documentation. If you don't have a policy-on-policies or a documented policy management procedure, create one. It should define:

  • Who triggers policy updates when lessons learned, emerging risks, or technology changes require them
  • What the evaluation and approval process looks like
  • How you communicate changes to affected employees
  • How you confirm employees know where to access policies

Add policy access questions to your next employee survey. If you don't run regular culture surveys, this is a good reason to start.

Update your M&A integration playbook to include policy integration as a defined workstream with clear ownership and timelines.

These aren't difficult changes, but they require you to document processes you might currently handle informally. The DOJ's updated guidance makes it clear that informal isn't good enough anymore. When prosecutors evaluate your compliance program, they'll ask specific questions about how you keep policies current. Make sure you have specific answers.

Evaluation of Corporate Compliance Programs

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like