No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

2025’s Burning Question: Can Your Compliance Program Pass DOJ Scrutiny?

New regulatory expectations and emerging technologies create urgent challenges for corporate compliance teams

by Jonny Frank
January 2, 2025
in Compliance, Opinion
matches on fire

The DOJ has raised the bar for corporate compliance programs, with recent updates demanding new attention to AI risks and electronic communications. StoneTurn’s Jonny Frank breaks down the essential elements of a DOJ-ready program and explains why 2025 is the year to get serious about implementation.

Which is more likely: a company coming under DOJ investigation or a commercial building being destroyed by fire? Answer: DOJ investigation.

Don’t believe me? Destruction from fire is less frequent due to modern fire safety measures and rapid response times. According to the National Fire Protection Association, there were about 130,000 non-residential building fires in the US in 2022, a low probability per building, given there are almost 6 million commercial buildings in the US. On the contrary, the range of issues that trigger DOJ investigations is vast, and the proliferation of government whistleblower programs has increased the likelihood of detection. 

Yet, despite the statistical differences, companies are more willing to install fire extinguishers and buy insurance than invest in compliance programs that satisfy DOJ “Evaluation of Corporate Compliance Program” guidance. Just as building owners buy fire insurance and keep fire extinguishers on hand — not expecting a fire but ready for the worst — companies should invest in ECCP-compliant programs because it makes good business sense. Both investments are made with the hope that they will never be needed and the understanding that the benefits of prevention and timely detection far outweigh the potential expense and disruption that arise from unanticipated events. Following the updated ECCP guidance means taking concrete steps.

Conduct an AI-facilitated ECCP gap assessment

ECCP gap assessments cross-reference the organization’s policies, processes and controls against the questions the ECCP poses to prosecutors. While this may seem straightforward on paper, executing these assessments often proves costly and time-consuming, given the volume of documents and file formats the team must analyze.

Enter generative AI. Begin by ingesting the organization’s compliance policies, processes, controls and the ECCP into a securely held, locally hosted large language model (LLM). Then, craft a series of prompts to address each ECCP requirement, resulting in LLM-generated responses to each requirement. The responses will create a first draft of observations, enabling human analysts to kickstart their work. Leveraging proven technology solutions enables organizations to more efficiently and effectively get their arms around otherwise cumbersome processes.

department of justice
Compliance

DOJ Is Asking Questions About How Companies Use AI. Do You Know the Answers?

by Robert K. Hur, Leah B. Grossi and Michael Galdo
October 23, 2024

Federal authorities’ expectations around AI are evolving

Read moreDetails

Address recent ECCP updates

The DOJ updated the ECCP in 2023 and 2024. These amendments likely will come up in the ECCP gap assessment and should be addressed in law and compliance function’s 2025 plans.

2023 electronic communications update

The 2023 update pertains to messaging apps, personal devices and communication platforms. Building on the SEC and CFTC’s off-channel communication sweep, the update requires companies to establish policies to collect and preserve business data for compliance. Meeting the 2023 electronic communications update requires companies to:  

  • Review existing policies on using personal devices, communication platforms and messaging apps.
  • Identify all communication channels across business functions and jurisdictions, mapping preservation settings and accessibility.
  • Examine policies related to bring your own device (BYOD) programs and messaging apps, focusing on data preservation and access protocols.
  • Create or refine policies to ensure business-related electronic data is accessible and preserved
  • Implement comprehensive employee training programs.
  • Establish regular audits and monitoring procedures to enforce policies consistently.
  • Document the rationale behind policy decisions for regulatory transparency.

2024 data and technology updates

In September 2024, the DOJ announced a round of ECCP updates, including several relating to data and technology. The risk assessment section of the ECCP includes a new section titled “Management of Emerging Risks to Ensure Compliance with Applicable Law,” which requires companies to identify and manage emerging internal and external risks, including AI.

The ECCP section on third-party management includes an update on leveraging data to evaluate vendor risk, and the compliance program autonomy and resources section asks whether the organization can measure the commercial value of investments in compliance and risk management. The ECCP section on how the compliance program works in practice asks how the company (1) leverages data to gain insights into compliance program effectiveness; (2) monitors tests and corrects flawed technologies; and (3) whether the compliance function can access data to detect misconduct and compliance program deficiencies.

Meeting the 2024 data and technology updates requires companies to:

  • Create an inventory of all uses of AI and other emerging technologies
  • Conduct a risk assessment to identify inherent and residual compliance risks arising from AI and other emerging technologies
  • Re-perform the existing compliance risk assessment, considering AI and other technology

Close the gaps

Compliance and legal department planning for 2025 should include developing corrective action plans to address gaps identified in the assessment and the 2023 and 2024 ECCP updates. Corrective actions often take several months, if not years, to develop and implement. While DOJ policy mandates that prosecutors assess the effectiveness of a compliance program at the time of an offense, it is often enough for organizations to show they are actively working to improve their compliance programs and controls. But the plan should be documented and comprehensive.

Plans should (1) include governance (e.g., steering committee, project management office); (2) describe objectives; (3) detail necessary work steps; (4) assign responsibility and accountability; (5) set milestones; (6) create a realistic timeline; (7) provide sufficient expertise and resources; (8) note dependencies (e.g., technological solutions); and (9) avoid vague “plans for a plan.“

Test compliance program and controls

The ECCP emphasizes the importance of testing, as do other DOJ policies. The testing function must be independent — it cannot serve as an advocate or review its own work. Nor can it be subordinate to the function, department or business under evaluation (e.g., internal audit reporting to CCO testing compliance controls).

Testing the compliance program against the ECCP criteria differs from testing compliance controls. Compliance program testing applies standard audit procedures to validate whether the program’s design and implementation meet the ECCP criteria.

Compliance controls testing, in contrast, focuses on risks and risk response, including policies, processes and controls. The testing function applies standard audit procedures to assess the design and validate the operating effectiveness to determine if the controls suite brings the risk within risk appetite. 

Broadly summarized, the process entails (1) setting risk appetite; (2) selecting applicable laws and regulations; (3) identifying breach scenarios, (4) linking the scenarios to the control suite; (5) auditing control suite design and operating effectiveness; (6) identifying deficiencies, significant deficiencies or material weaknesses; and (7) issuing findings and recommendations.

Investing in DOJ-compliant compliance programs and controls is as prudent as installing fire safety measures. Fires may be rare, but building owners know the value of being prepared. Compliance programs are the equivalent of the overall fire safety program, and compliance controls are the equivalent of steps building owners take to mitigate specific risks and scenarios (e.g., electrical fires, evacuation).

As DOJ scrutiny grows, companies that prioritize compliance programs and controls that meet ECCP standards will be better equipped to anticipate and manage compliance risks and scenarios, detect and address compliance violations and weather any unexpected regulatory challenges in 2025 and beyond.


Tags: DOJ
Previous Post

Court Reinstates CTA, FinCEN Extends Filing Deadlines

Next Post

Gone SURFing: You Don’t Need a Sustainability Officer to Have a Positive Climate Impact

Jonny Frank

Jonny Frank

Jonny Frank, a partner with StoneTurn, brings more than 40 years of public, private and education sector experience in forensic investigations, compliance and risk management. He joined StoneTurn in 2011 from PricewaterhouseCoopers (PwC), where he was a partner and founded and led the firm’s global fraud risk & controls practice.

Related Posts

doj exterior sign

How to Use the DOJ’s ECCP to Build (or Fix) Your Compliance Program

by Susan Divers
June 5, 2025

Corporate compliance programs face increasing scrutiny as the DOJ applies its evaluation framework across industries and company sizes, from multinational...

doj sign front

Assessing the Business Risks of the Trump Administration’s ‘Total Elimination’ Strategy

by José Cortina and Jennifer Christian
May 20, 2025

As cartels increasingly participate in mainstream economic activities, traditional due diligence practices become inadequate to address new material support risks

doj sign and sculpture

DOJ’s New CEP Proposes Guaranteed Declination for Some Self-Reporters

by Jennifer L. Gaskin
May 13, 2025

The Trump Administration continues reshaping its approach to corporate crime, with the DOJ issuing major revisions of its corporate enforcement...

doj building sign with flags

‘Reasonable Steps’: What the DOJ Expects From Your Bulk Data Transfer Compliance Program

by Alexandra P. Moylan, Alisa L. Chestler and Michael J. Halaiko
May 5, 2025

Sample provisions offer blueprint for compliant data brokerage with foreign entities

Next Post
earth aerial view

Gone SURFing: You Don’t Need a Sustainability Officer to Have a Positive Climate Impact

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights