Skip to main content
The state of ai impact assessment
What the DOJ Actually Wants to Know About Your AI ControlsRegulatory Obligations Management
5 min readFor Compliance Officers

What the DOJ Actually Wants to Know About Your AI Controls

The Justice Department's Criminal Division released updated compliance program guidance this week, focusing on practical questions that impact cooperation credit negotiations, declination decisions, and sentencing memos.

Nicole Argentieri, head of the Criminal Division, shared these updates at the Society of Corporate Compliance & Ethics conference. The new guidance includes sections on AI risk management, speak-up culture assessment, and compliance team data access. These are not just theoretical topics; they are criteria prosecutors will use to evaluate the effectiveness of your compliance program.

Here's what compliance officers are asking about the new guidance and what the actual requirements reveal.

Does the DOJ really expect us to predict how AI might be used to defraud us?

Yes, and they're specific about it. The guidance asks if your company is "vulnerable to criminal schemes enabled by new technology, such as false approvals and documentation generated by AI."

This isn't about theoretical AI risk. It's about the fraud scenarios you're facing now: vendors submitting AI-generated compliance certificates that look legitimate but reference nonexistent audits, business email compromise attacks using AI voice cloning to mimic your CFO, and third parties using large language models to fabricate corporate registration documents or financial statements.

The guidance asks if you have "controls and tools in place to identify and mitigate those risks, such as tools to confirm the accuracy or reliability of data used by the business." Your due diligence process needs independent verification steps. Cross-reference vendor certifications against the issuing body's database. Require multi-factor authentication for payment requests regardless of who's asking. Build challenge controls that don't take documentation at face value.

If you're still relying on visual inspection of PDFs and email domain checks, you're behind.

How do they actually measure "speak-up culture"?

The guidance doesn't accept self-reported culture metrics. It asks three pointed questions: Does your company encourage reporting? Does it use practices that chill reporting? How do you assess employees' willingness to report?

That third question is the hardest. You can't answer it by counting hotline calls or showing employees your reporting poster. The DOJ wants to know how you measure the gap between misconduct that occurs and misconduct that gets reported.

Consider what would tell you employees feel comfortable speaking up: pulse surveys that ask directly about retaliation fears, exit interview data on why people didn't report concerns before leaving, and focus groups that probe whether people understand what constitutes misconduct worth reporting. The guidance specifically asks whether you discipline internal reporters differently than others involved in the same misconduct, which means you need data on how reporters are treated post-investigation.

The guidance also asks whether you train employees on external whistleblower programs and Retaliation Protection laws, not just your internal policies. This signals that the DOJ wants employees to know they have options outside your company if they don't trust internal channels.

What does "proportionate resource allocation" actually mean?

The DOJ asks: "How do the assets, resources, and technology available to compliance and risk management compare to those available elsewhere in the company?"

And then: "Is there an imbalance between the technology and resources used by the company to identify and capture market opportunities and the technology and resources used to detect and mitigate risks?"

They're asking whether your company treats compliance as a cost center that gets table scraps while growth initiatives get whatever they need. If your sales team has a sophisticated CRM with real-time analytics and your compliance team is tracking vendor due diligence in spreadsheets, that's the imbalance they're looking for.

The guidance also asks about impediments to data access: "Do compliance personnel have knowledge of and means to access all relevant data sources in a reasonably timely manner?"

This matters in practical terms. Can your team pull transaction data to investigate a whistleblower allegation without waiting three weeks for IT to run a report? Do you have read access to the same operational systems that business teams use? When you need to verify whether controls are working, can you see the underlying data or do you rely on someone else's summary?

Do we need to document AI governance decisions we're making now?

You should assume yes. The guidance asks whether companies think about "the ways it uses AI itself; and how much do you think about the ways AI might be used against you" and "what system does the company have in place to adjust its policies, procedures, and controls accordingly."

That's three separate inquiries: offensive AI use (where are we deploying it?), defensive AI concerns (where are we vulnerable?), and governance process (how do we make decisions about both?).

Document your AI use inventory. Document the risk assessment you conducted before deploying AI tools in customer-facing or operational contexts. Document how you're monitoring AI outputs for accuracy, bias, or control failures. Document the decision not to use AI in certain contexts if that's what you decided.

If prosecutors are evaluating your compliance program two years from now after an AI-enabled fraud, they'll want to see that you thought about these questions in 2024, not that you started thinking about them after the incident.

What if we don't have the budget for AI detection tools or better compliance tech?

The guidance doesn't explicitly require specific tools. It requires that you identify the risks and have controls proportionate to those risks.

If you can't get budget for AI detection capabilities, document that you requested it, explain what risks remain unmitigated, and escalate that gap to the board. The DOJ evaluates whether management is making informed decisions about risk, not whether you have unlimited resources.

But here's the harder truth: if your company is investing heavily in AI for growth while refusing to fund AI risk controls, that's exactly the resource imbalance the guidance is designed to catch. Prosecutors will ask why the company found money for one but not the other.

Where does this leave us on Retaliation Protection policies?

The guidance asks whether you train employees on "both internal Retaliation Protection policies and external Retaliation Protection and Retaliation Protection laws." It also asks whether you train them on "internal reporting systems as well as external whistleblower programs and regulatory regimes."

Check your training materials. Do they mention the SEC whistleblower program? OSHA protections? Dodd-Frank provisions? State-specific whistleblower statutes that might apply to your workforce?

Most companies train employees on the internal hotline and stop there. The DOJ is telling you that's not sufficient. They want employees to know about external options, which suggests they view external reporting as a legitimate check on companies that might otherwise bury complaints.

Where to go for more

The updated guidance document is public and includes the full question set prosecutors will use. Read the sections on "Access to Data and Resources" and "Speak Up Culture and Whistleblower Protections" in detail; the questions are more specific than the summary suggests.

For AI-specific fraud controls, look at what your financial crime and cybersecurity teams are already tracking. They're likely seeing AI-enabled attacks that your compliance program hasn't formally addressed yet. Start there rather than building an AI governance framework from scratch.

DOJ Compliance Guidance

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like