The DOJ’s newest division has given its corporate fraud prosecutors their most substantive public guidance yet in the form of a memo that outlines factors they are to consider when deciding whether to bring charges against a corporation. CCI’s Jennifer L. Gaskin reports on what the McDonald memo means for corporate compliance programs and what’s still to come (spoiler alert: more whistleblower incentives).
The Justice Department’s newest division has given its prosecutors their most substantive public guidance yet on how they should approach corporate enforcement.
In a directive issued Oct. 1, Colin McDonald, assistant attorney general for the National Fraud Enforcement Division, listed 10 factors prosecutors are instructed to weigh heavily when deciding whether to charge a company, negotiate a plea or otherwise resolve a corporate case.
The directive also requires the division’s prosecutors to bring every corporate case to its new Corporate Enforcement Section, which will lead the way in judging whether companies are living up to the terms of their resolutions. And it instructs division leaders to design incentives for whistleblowers, including those who may have taken part in misconduct, adding to a growing list of federal programs that encourage insiders to report corporate misdeeds.
McDonald’s memo offers the clearest public accounting yet of a division that the DOJ assembled this year largely from units moved out of its Criminal Division, a reorganization that raised eyebrows because other parts of the department already handled much of the same work.
Experts CCI spoke with say most corporate compliance programs don’t need to make wholesale changes; rather, they should focus now on re-assessing their exposure to enforcement risk in areas called out by both the October memo and creation of the new division itself: federal programs, government money and international trade.
“For companies with those touchpoints, the memo provides a useful roadmap of the conduct DOJ intends to scrutinize,” Carla Baumel, a trial litigator at Robins Kaplan and former assistant US attorney in the District of Minnesota, told CCI in a written interview.
And as ever, ensuring your program works as designed is of the utmost importance; it can’t simply look good on paper.
“The new memo does not create a new compliance standard; it reinforces the existing message that DOJ will look beyond written policies to how a company identifies, escalates, investigates and responds to misconduct,” Allen Slaughter, partner at Robins Kaplan and a former federal prosecutor, told CCI in a written interview.
Fleshing out the details
The October directive builds on priorities McDonald first set out in August, when he listed corporate misconduct among the division’s five focus areas, but offered scant details about what that would mean in practice. The memo applies several factors to corporate cases in the division’s priority areas: healthcare, government programs and procurement, revenue evasion and trade, including forced labor and tariffs.
When deciding how to resolve a case, National Fraud Enforcement Division prosecutors are instructed to give “great weight” to whether management knew of or was involved in alleged schemes and whether the company attempted to hide the misconduct from government agencies or auditors. Other factors include threats to Americans’ safety or security, including military readiness; substantial financial hardship to taxpayer-funded programs; harm to multiple government programs; and schemes that send money to foreign adversaries or involve immigration offenses.
Several factors come with specific numbers: conduct lasting at least three years, reaching at least three federal districts or harming at least 25 victims or causing at least $25 million in losses.
Experts cautioned against reading those figures as bright lines.
“Companies should not mistake those numbers for safe harbors,” Baumel said. “The memo expressly describes the factors as non-exhaustive and preserves prosecutorial judgment. A scheme involving $24 million or lasting 35 months does not suddenly become insignificant. The thresholds give companies greater visibility into what DOJ considers significant — and should help compliance teams identify matters that warrant immediate escalation.”
Nor are the priorities limited to healthcare companies and government contractors. Companies should read the memo by exposure, not by industry, Slaughter said.
“The practical exercise for compliance teams is … to identify where the company touches federal funds, federal programs, government revenue or the movement of goods into the United States,” he said. “Where those connections exist, the directive provides a fairly direct indication of both the conduct DOJ is targeting and the circumstances likely to elevate misconduct into a corporate enforcement matter.”
Because the memo also tells prosecutors which corporate investigations to prioritize from the outset, not just how to resolve them, it could shrink the division’s corporate docket, said Jacqueline Kelly, a partner at Boies Schiller Flexner and former federal prosecutor in the Southern District of New York.
“This can be expected to affect the types of investigations that get opened at all, which legally have a low bar to initiate,” Kelly said. “We can expect this will result in fewer corporate investigations being opened.”
What the Enforcement Record Says About ‘Timely’ Disclosure
Of the nine enforcement cases CCI examined where companies received credit for timely disclosure, only two included a measurable time window. In several others, the timeliness clock had effectively run out before the company acted
Read moreDetailsA race to disclose
The memo doesn’t rewrite the rules for self-disclosure of misconduct, but it may give companies a fresh reason to make sure they can actually do that — and quickly.
The new division’s prosecutors are instructed to follow the DOJ’s department-wide corporate enforcement policy (CEP), which was issued in March and which offers a declination to companies that voluntarily self-disclose, fully cooperate and timely remediate, absent aggravating circumstances.
But two areas are worth special attention: the DOJ’s use of data analytics and an instruction in the memo for the division to create whistleblower incentives.
On the first, the memo says the division is already generating its own leads and opening corporate and individual investigations “at a rapid pace,” drawing on new resources, technology and data analytics through its National Fraud Detection Center, which the DOJ ordered created when it established the division in April.
On the second, McDonald directed division leaders to design policies and programs that encourage whistleblowers to bring credible fraud information to the government, including in cases where whistleblowers themselves may have participated in misconduct. The memo does not say what forms those incentives will take.
Both areas increase the odds that the government will learn about misconduct before a company reports it, which is relevant in the CEP context because self-disclosure will generally earn credit only if the DOJ did not already know about the misconduct. That policy’s whistleblower exception applies when someone reports internally and to the DOJ: A company must then self-report as soon as practicable and no later than 120 days after the internal report. An insider who goes straight to the government leaves no window at all. CCI’s review this year of enforcement actions found that companies have repeatedly lost voluntary-disclosure credit because a whistleblower, a press report or a parallel investigation got there first.
“The details of that program have not yet been announced, but a company investigating potential misconduct has even less reason to assume it is the only one that knows about it,” Baumel said.
Slaughter agreed that additional incentives to report “could make the existing race for voluntary-disclosure credit even more difficult.”
That puts a premium on the machinery for surfacing problems and deciding what to do about them, which needs to exist before an issue arises.
“Compliance teams should examine whether significant allegations reach the right decisionmakers quickly and whether they can investigate them efficiently,” Baumel said. “Written policies only go so far. Companies need processes that allow them to investigate serious issues and make informed disclosure decisions quickly.”
Firms should also revisit their whistleblower programs “to ensure that they are robust, easily accessible to their employees and that information learned is processed and evaluated in a timely manner,” said Jenelle Beavers, a managing director with Alvarez & Marsal Disputes and Investigations.
What’s next
McDonald’s Oct. 1 memo is the latest step in a DOJ reshuffle that has moved quickly this year. In January, the White House announced plans for the division, and in March, the Senate confirmed McDonald in a narrow partisan vote. An April DOJ memo moved the Criminal Division’s Health Care Fraud Unit, its Market, Government and Consumer Fraud Unit and its Tax Section into the new division. In August, the DOJ formalized the division via regulation, and the Criminal Division’s Fraud Section, long the department’s hub for corporate criminal enforcement, was renamed the White Collar and Corporate Enforcement Section.
The reshuffle moved people as well as portfolios. McDonald’s August memo said the division would reach roughly 500 attorneys and staff by late August, drawn from other DOJ components and US attorneys’ offices, and would keep growing. By comparison, the Criminal Division’s Fraud Section numbered about 200 lawyers in 2025. Other parts of the department have thinned. The Criminal Division’s market integrity unit lost attorneys to the new division, and its FCPA unit, which shrank from 32 prosecutors in 2024 to 22 in 2025, saw some of those lawyers move to healthcare and government fraud units now housed in the new division.
That renamed Criminal Division keeps its own corporate enforcement unit, so the DOJ now has two groups doing similar work, including evaluating compliance programs and overseeing corporate resolutions.
The department-wide CEP should limit inconsistency, Slaughter said, but “a more pressing question may be whether the two corporate-enforcement groups may develop different practical approaches within that common framework.”
Nor is it clear what the memo’s seven-day inventory of ongoing corporate investigations will produce. Slaughter cautioned against assuming it signals a review like the one the DOJ conducted after pausing FCPA enforcement last year, which led to many cases being closed.
“The better inference is that DOJ wants immediate visibility into its corporate docket,” he said. “That could result in some cases being accelerated, narrowed, coordinated, redirected or closed, but it could just as readily result in additional resources being assigned to matters that fit the division’s priorities.”
Civil fraud enforcement under the False Claims Act, meanwhile, remains with the DOJ’s Civil Division. The April memo gave the DOJ 120 days to recommend whether to fold non-criminal functions into the new division, but the department had not announced an outcome as of last month.
“What we are already seeing is greater coordination across civil and criminal enforcement,” Baumel said. “For now, companies should prepare for parallel proceedings.”
Whatever shape the division ultimately takes, the fundamentals for compliance teams haven’t changed, Slaughter said.
“The durable elements are familiar: effective internal controls, escalation, investigation, documentation, remediation and the ability to respond promptly when serious misconduct is identified.”


Jennifer L. Gaskin is editorial director of Corporate Compliance Insights. A newsroom-forged journalist, she began her career in community newspapers. Her first assignment was covering a county council meeting where the main agenda item was whether the clerk's office needed a new printer (it did). Starting with her early days at small local papers, Jennifer has worked as a reporter, photographer, copy editor, page designer, manager and more. She joined the staff of Corporate Compliance Insights in 2021 and also hosts the CCI-produced podcast "Queering Compliance." 










