No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

One CEP to Rule Them All?

New department-wide policy purports to standardize carrots & sticks

by Jennifer L. Gaskin
March 18, 2026
in Compliance, Featured
corporate enforcement policy wording changes collage

The DOJ released its first-ever department-wide corporate enforcement policy ostensibly to bring fairness and transparency to the government’s decisions on charges against companies accused of criminal conduct. For corporate leaders hoping the new CEP would provide them with clarity on whether to self-report misconduct, some experts told CCI editorial director Jennifer L. Gaskin corporations may need to continue to live in hope.

The Holder memo. The Thompson memo. The McNulty memo. The Yates memo. The Monaco memo. The Blanche memo. Since the 1990s, the DOJ has published a litany of missives on its policies for prosecuting corporate criminal cases. In a March 10 news release announcing its latest CEP update, this time, the DOJ went a step further, applying the policy department-wide, except for antitrust cases, and saying it supersedes other policies across DOJ divisions and US attorneys offices.

Among the questions for senior corporate leaders, according to the experts who spoke with CCI about the new CEP, are what exactly supersession means and whether the blanket application of the policy, the text of which is largely identical to a 2025 update, with important exceptions, will meaningfully inform a company’s decision-making on whether to self-report misconduct.

“As with the previous versions of the CEP, the new CEP moves the needle somewhat because it provides a more uniform framework and gives companies more clarity about the likely range of outcomes, but it does not completely change the analysis,” said Laura Perkins, a former prosecutor in the DOJ’s Criminal Division who now is a partner in the global litigation group at Cadwalader, Wickersham & Taft. “Even with the benefits offered by the CEP, the decision of whether to self-report remains a complicated one that needs to be carefully evaluated.”

What’s new in the 2026 CEP?

The text of the 2026 update is quite similar to the Criminal Division CEP published in 2025, with “Department” replacing “Criminal Division.” However, at least one substantive change was made, one that may inject even more uncertainty. 

In 2025, the Criminal Division introduced a series of potential paths to declination, which were outlined in a flow chart it said would help companies decide whether to self-report. The chart included a “near-miss” category in which a company could receive a fine reduction even if it did not meet the conditions for a declination. That flow chart is duplicated in the 2026 DOJ-wide CEP (in fact, it looks like a copy of a copy), but the promised fine reduction for near-miss cases has changed, from a flat 75% off the low end of the US sentencing guidelines range to between 50% and 75% of the sentencing guidelines range. (The 2023 CEP, released under the previous presidential administration, similarly had a 50% to 75% range.)

So while added uniformity in handling disclosures is a step in the right direction, said Keith Rosen, a former assistant US attorney and now co-head of global investigations at Norton Rose Fulbright, certainty is not iron-clad.

“This iteration may actually make outcomes less predictable, as in some places it dilutes the level of certainty offered to companies and inserts more prosecutorial discretion into the process,” Rosen told CCI.

Other substantive changes:

  • Recidivism: The 2025 version disqualified companies with a resolution or enforcement action “within the last five years based on similar conduct.” The new version adds “or otherwise,” removing the time limit for similar misconduct and leaving it to the DOJ’s discretion to determine when past conduct is similar enough to be disqualifying.
  • Whistleblowing: In 2025, the Criminal Division gave companies 120 days from an internal whistleblower report to self-disclose conduct; now, the guidance requires disclosure “as soon as reasonably practicable but no later than 120 days.” That means even if a company reports within the 120-day window, the department may still find the report was too slow.
  • Regulatory disclosure: Both the 2023 and 2025 Criminal Division CEPs were silent on whether disclosures to regulators or civil enforcement agencies could qualify as self-reporting; the 2026 version is explicit: it’s up to the DOJ. This is handled in a footnote rather than in the policy itself.

Notably, the language around supersession of DOJ component- and US attorneys office-specific policies appears only in the news release announcing the policy, not in the policy itself. And the timing of the new DOJ-wide CEP is eyebrow-raising, coming just two weeks after the US Attorney’s Office for the Southern District of New York (SDNY) released its own corporate enforcement policy, which while it has a narrower scope, applying only to financial crimes affecting market integrity, offered more definitive policies: a defined timeline, a narrower definition of aggravating circumstances and a more forgiving definition of voluntary disclosure.

Whether the timing of the two announcements is more than simple coincidence is unclear, and experts who spoke with CCI were split on exactly what supersession means in this case.

“In light of the odd sequence of events, it is notable that the language about the CEP superseding other policies appeared in DOJ’s announcement of the CEP, not in the policy itself, which invites the question to what extent other policies are prohibited, particularly where they enhance but do not contradict with the CEP,” Perkins said. “Given that, it is possible that SDNY will take the position that certain features of its policy, such as how it approaches conditional declination, remain despite the CEP because they simply describe how SDNY intends to exercise its discretion in areas where the CEP has left flexibility, rather than contradicting the CEP.”

In a written Q&A with CCI, Eric Beste and Scott Hulsey, both former DOJ officials who now are partners at Barnes & Thornburg, said that the DOJ’s desire for one blanket CEP will indeed constrain individual offices.

“SDNY may have been trying to stake out ground or move quickly on an issue it viewed as important, while Main Justice was focused on standardization across the department,” they wrote. “The March 10 policy makes clear, however, that DOJ ultimately wants a single, unified framework — and that individual offices will have less room to differentiate going forward, at least at the policy level.”

divergent paths aerial view
Featured

2 Paths, 2 Outcomes: DOJ’s Inconsistent Corporate Self-Disclosure Policies

by Josh Hurwit, Greg Goldberg, John Anderson and John Sullivan
December 22, 2025

Read moreDetails

Carrots, sticks & fine print

For all of the DOJ’s years of deploying a variety of carrots and sticks to incentivize self-reporting of misconduct, that remains a difficult decision, affected by many moving parts, experts agreed. So while the new CEP seeks to provide unified guidance, the document is just that — guidance.

“The policy serves as a guide — not a guarantee,” Beste and Hulsey wrote. “Early strategic judgment still matters enormously, including how and when to engage DOJ, how to frame the narrative and how to sequence internal investigative steps.”

They also cautioned that while corporate compliance, risk and governance professionals are closely examining this CEP, the corporate community is not exactly the audience and that the government and business leaders may have different goals.

“Keep in mind that this memo is directed to prosecutors to guide their efforts and does not create ‘rights’ for defendants. The department’s objective is to encourage early disclosure, but this objective may not always be what is best for a company.”

Perkins agreed, adding that individual fact patterns matter more than flow charts.

“Overall, compliance officers should not read the CEP as making self-reporting an easy or automatic choice,” Perkins said. “The CEP may offer meaningful benefits, but the decision as to whether to self-report still requires a careful, case-specific analysis.”

Rosen similarly cautioned companies against assuming they will have ample time to run their internal investigation.

“The issue that some might overestimate is the amount of time a company has to make a decision about whether to disclose and try to get credit for self-reporting an issue,” Rosen said. “To get credit, the self-disclosure needs to happen at the ‘earliest possible time,’ which for many companies may be before there is time to fully investigate and assess an allegation.”

Tags: DOJ
Previous Post

Are Your Anonymous Reporting Channels Hiding a Bigger Problem?

Next Post

US Regulatory Fines Plummet in 2025

Jennifer L. Gaskin

Jennifer L. Gaskin

Jennifer L. Gaskin is editorial director of Corporate Compliance Insights. A newsroom-forged journalist, she began her career in community newspapers. Her first assignment was covering a county council meeting where the main agenda item was whether the clerk's office needed a new printer (it did). Starting with her early days at small local papers, Jennifer has worked as a reporter, photographer, copy editor, page designer, manager and more. She joined the staff of Corporate Compliance Insights in 2021.

Related Posts

gulf coast countries map

FCPA Compliance Programs Are Missing Important Nuances About How Bribery Works in the Persian Gulf

by Majid Mumtaz
April 1, 2026

Applying a Western compliance framework can obscure the tell-tale signs of fraud and corruption in Gulf Cooperation Council markets. Majid...

coal ready for transport

FCPA Enforcement Isn’t Dead; a Former Coal Executive Found Out the Hard Way

by Staff and Wire Reports
March 11, 2026

An executive went to trial. Another alleged scheme participant cooperated. Corsa Coal itself went bankrupt. Whatever executives thought the FCPA...

mexico landscape viewer

A Year After Designation of Cartels as Terrorists, What Is the Risk Landscape for Multinationals Operating in Mexico?

by Robert Johnston, Brian Mich and Ulla Pentinpuro
February 18, 2026

A year after the Trump Administration designated six Mexican cartels as foreign terrorist organizations, the compliance implications for multinationals are...

data nodes concept

Q&A: How to Prepare for AI-Powered Investigations While Managing Your Own AI Risk

by Staff and Wire Reports
February 10, 2026

AI can lead to inaccurate assumptions, so context still matters when challenging government data analytics in False Claims Act or...

Next Post
news roundup_june 14 2024

US Regulatory Fines Plummet in 2025

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2026 Corporate Compliance Insights