No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance
Sponsored by

How to Use the DOJ’s ECCP to Build (or Fix) Your Compliance Program

3 deceptively simple questions drive DOJ compliance assessments, but answering them effectively requires moving beyond “paper programs” to measurable outcomes

by Susan Divers
June 5, 2025
in Compliance, Featured
doj exterior sign

(Sponsored) Corporate compliance programs face increasing scrutiny as the DOJ applies its evaluation framework across industries and company sizes, from multinational corporations to mid-market businesses like e.l.f. Cosmetics. The department’s guidance centers on three fundamental questions about program design, implementation and effectiveness, but many organizations struggle to move beyond “paper programs” that exist in theory but fail in practice. Ethena’s Susan Divers explains how to use the ECCP proactively to build programs that not only satisfy regulators but create genuine cultural change and measurable risk reduction.

When it comes to ethics and compliance programs, “good enough” is anything but. From record-breaking FCPA settlements to sweeping investigations across industries, the DOJ has made it clear: If your compliance program can’t withstand scrutiny, your company is vulnerable — legally, financially and reputationally.

The “Evaluation of Corporate Compliance Programs” (ECCP) is the DOJ’s playbook for evaluating corporate ethics and compliance programs. But it’s not just a tool for prosecutors. For E&C leaders, it’s a roadmap for building a modern, risk-aligned and effective program — and a shield against enforcement actions when things go wrong.

Whether you’re updating an existing compliance program or building one from scratch, the ECCP can be your best tool for avoiding fines, earning leniency in enforcement actions and, most importantly, protecting your organization from real harm.

Let’s explore how you can use it as a proactive tool to future-proof your compliance program.

Why the ECCP matters

The DOJ’s “Evaluation of Corporate Compliance Programs” is a guidance document that outlines how prosecutors assess whether a company’s compliance program is effective. It plays a key role in determining whether a company is prosecuted — or granted leniency — in the event of corporate misconduct.

You don’t have to be a global giant to land in the DOJ’s crosshairs, either. In recent years, companies of all sizes — including Brazilian airline GOL and California beauty brand e.l.f. Cosmetics — have found themselves under DOJ scrutiny. These cases underscore a clear message: every company, regardless of size, needs a strong compliance program.

Using the ECCP as a self-assessment tool

At its core, the ECCP is structured around three deceptively simple questions:

  1. Is your compliance program well-designed?
  2. Is it being applied earnestly and in good faith?
  3. Does it work in practice?

Let’s walk through each one and how to tackle them:

1. Is your program well-designed?

This is the foundation of any effective ethics and compliance program. A well-designed program isn’t a generic, off-the-shelf solution — it’s carefully crafted to reflect the specific risks, structure and operations of your organization. The DOJ has made clear that it expects companies to tailor their programs to their unique risk profile, industry and workforce — not simply replicate what another company is doing.

So, what does good design look like?

  • Risk assessments that are specific, ongoing and dynamic. Your compliance efforts should be grounded in a deep understanding of where the greatest risks lie. This includes evaluating your industry, geographic footprint, supply chain, third-party relationships and prior misconduct (if applicable).
  • Clear, updated policies that are easy to find and understand. Every employee should be able to navigate your code of conduct and other issue-specific company policies like sexual harassment and anti-retaliation. Use plain language, real-world examples, and remember culturally relevant adaptations when operating globally.
  • Compliance training that’s relevant to employees’ roles, interactive and regularly updated. Ethena’s in-house production studio builds custom courses with this exact purpose in mind.
  • Confidential reporting channels with clear investigation protocols. Ethics hotlines, web portals, mobile apps — the more accessible, the better. But just as important as the channel is what happens next: Are investigation protocols standardized and well-documented? Regulators will want to see a track record of prompt, impartial investigations and responsive remediation when warranted.

Use your compliance training data to flag trends and tailor improvements. For example, if learners are consistently missing questions in a certain area, it might point to a policy gap or risk hotspot.

2. Is your program being applied in good faith?

It’s not enough to have a great compliance program on paper. Regulators want to see that it’s truly being used, championed and integrated into the daily operations of the organization. This is where many companies stumble: A beautifully crafted code of conduct or a state-of-the-art training platform won’t matter if the program isn’t actively supported and enforced.

Applying a program “in good faith” means the organization is doing more than checking boxes. It involves making a genuine effort to embed ethics and compliance in how business gets done. That includes:

  • Tone at the top: Leadership must visibly and vocally champion the compliance program. When executives reference ethical behavior in all-hands meetings, tie it to performance metrics and model it through ethical decision-making, it signals to employees that compliance isn’t optional — or superficial.
  • Independence and resources: The compliance function should have the autonomy to operate without interference and the budget and tools it needs to be effective. This includes access to data and decision-makers and the ability to raise concerns directly to the board or audit committee when necessary.
  • Consistent enforcement: Ethical standards must apply to everyone. If a high-performing executive escapes accountability for a policy violation, it undermines the program’s credibility. The DOJ explicitly looks for documentation of disciplinary actions taken across roles and ranks to ensure fairness and follow-through.

Too often, compliance falters in this implementation stage. Programs that lack visible leadership support, proper funding or real consequences for bad behavior quickly become what the DOJ calls “paper programs” — frameworks that exist in theory but are ignored in practice.

A well-written policy might keep regulators interested, but a well-executed program is what earns their trust.

3. Does your program actually work?

This is where theory meets practice. It’s one thing to design a comprehensive E&C program and say all the right things; it’s another to prove that your efforts are producing real, measurable outcomes. This third pillar of the ECCP is arguably the most critical, because it tests whether your compliance program is functioning effectively in the real world.

It’s important to note that the DOJ isn’t expecting perfection. Instead, the department looking for evidence that your program can detect misconduct, respond to it and evolve in response to changing risks.

  • Monitor effectiveness through data. Are employees completing training? Are they retaining the material? Are reports being filed and followed up on promptly? Culture surveys, training analytics, case management trends and even test-out rates can all provide valuable insight into what’s working and where improvement is needed.
  • Audit and test regularly. Conducting periodic audits, especially in high-risk areas, helps ensure policies are being followed. The DOJ also encourages companies to test internal systems proactively. For example, you might simulate a reporting scenario to test how your hotline, triage protocols and investigation processes function in real time.
  • Investigate incidents promptly and learn from them. Ensure every concern raised is taken seriously, investigated thoroughly and addressed appropriately. These investigations should feed back into your risk assessments, training updates and policy revisions. If one team has repeated violations, it may signal a leadership gap or unclear expectations — both of which should be addressed at the root.
  • Adapt and evolve over time. Compliance is not a static discipline. New regulations, shifting enforcement priorities, internal growth and emerging risks (like AI, data privacy or hybrid work policies) require ongoing adaptation. Your program should include a built-in process for regular policy reviews, training updates and process improvements.

In the end, the program that works is one that builds trust, both internally and externally. Employees feel confident raising concerns. Managers know how to respond. And when things go wrong (as they inevitably will), your organization has the processes and cultural foundation to respond with integrity.

That’s what regulators want to see — and it’s what a truly effective compliance program delivers.

The bottom line

When you use the ECCP as more than just a regulatory reference, you build something more durable: a workplace grounded in trust, transparency and ethical decision-making.

An effective compliance program isn’t just a shield against prosecution. It’s a strategic asset that fosters a speak-up culture, earns stakeholder confidence and enables sustainable growth. It tells regulators that you’re serious about accountability. It shows employees that their concerns matter. And it proves to investors and customers that ethics aren’t just part of your brand.

For more best practices, including a simple checklist for staying aligned with the ECCP, download our playbook, “Aligning Your E&C Program with DOJ Guidelines.”

Build a better E&C program with Ethena

Ethena’s compliance training platform is designed to keep you aligned with the ECCP and compliant with SOX, SOC II and more. From a modular training library of 150-plus customizable courses to our built-in ethics hotline, case manager and phishing simulator, we help you meet — and exceed — compliance expectations.

Ready to see how your program stacks up? Book a demo with our team and explore how Ethena can help bring the ECCP to life in your organization.


Tags: Corporate CultureDOJ
Previous Post

The Devil You Know …

Next Post

ThetaRay and Spayce Partner on FinCrime Detection

Susan Divers

Susan Divers

Susan Divers is an ethics adviser and consultant at Ethena. She previously was director of thought leadership at LRN and sesrved several years as chief ethics and compliance officer at AECOM.

Related Posts

Ethisphere 2025 E&C Program Trends & Employee Perceptions

2025 E&C Program Trends & Employee Perceptions

by Corporate Compliance Insights
May 27, 2025

Are ethics and compliance programs keeping pace with risk? Annual report E&C Program Trends & Employee Perceptions What’s in this...

no right answer

That ‘Do the Right Thing’ Mug? It’s Missing Some Fine Print.

by Vera Cherepanova
May 20, 2025

Ethics isn’t a slogan; it’s a practice

doj sign front

Assessing the Business Risks of the Trump Administration’s ‘Total Elimination’ Strategy

by José Cortina and Jennifer Christian
May 20, 2025

As cartels increasingly participate in mainstream economic activities, traditional due diligence practices become inadequate to address new material support risks

LRN 2025 Program Maturity Global Study

2025 Global Study on Ethics & Compliance Program Maturity

by Corporate Compliance Insights
May 16, 2025

How does your ethics and compliance program measure up? Global study Ethics & Compliance Program Maturity What’s in this global...

Next Post
Theta Ray Spayce Partnership

ThetaRay and Spayce Partner on FinCrime Detection

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights