U.S. Department of Justice, Criminal Division – Evaluation of Corporate Compliance Programs (Updated September 2024)
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The Evaluation of Corporate Compliance Programs (ECCP) is guidance from the Criminal Division of the U.S. Department of Justice, updated in September 2024, that assists prosecutors in deciding whether, and to what extent, a corporation's compliance program was effective at the time of an offense and at the time of a charging decision or resolution. It applies the Principles of Federal Prosecution of Business Organizations in the Justice Manual (JM 9-28.000) and the Sentencing Guidelines standard in §8B2.1.
The document is written for prosecutors, but corporations, boards, and compliance officers use it as the most detailed public statement of what the Department expects. It organizes its sample topics and questions under three fundamental questions: Is the corporation's compliance program well designed? Is the program adequately resourced and empowered to function effectively? Does the program work in practice? The Division states that the topics and questions are neither a checklist nor a formula.
Organizations apply the ECCP by benchmarking their programs against its topics, which include risk assessment, policies and procedures, training and communications, confidential reporting and investigations, third-party management, mergers and acquisitions, management commitment, autonomy and resources, compensation and consequence management, continuous improvement and testing, investigation of misconduct, and analysis and remediation of root causes. The 2024 update adds questions on emerging technology such as artificial intelligence, whistleblower protection, and access to data.
Why it Matters
The ECCP determines how much credit a company receives for its compliance program when the Criminal Division decides whether to charge, what resolution to offer, whether a monitor is needed, and how large a penalty should be. Because it is public and specific, it has become the de facto design standard for corporate compliance programs in the United States and for multinationals subject to U.S. jurisdiction.
Key benefits include:
- Benchmark against the prosecutor's questions
Test the program against the same topics and questions the Criminal Division uses in investigations and resolutions.
- Earn credit in a resolution
A well-designed, resourced, and effective program influences charging decisions, penalty calculations, and whether a monitor is imposed.
- Prove the program works in practice
Show through testing, data, and remediation that the program detects and addresses misconduct, not just that policies exist.
- Manage emerging risk
Address the 2024 additions on new and emerging technology, including artificial intelligence, and on whistleblower protection.
- Align with the Sentencing Guidelines
Satisfy the §8B2.1 requirements that the ECCP builds on, including periodic risk assessment and board oversight.
How it Works
Part I, design, covers risk assessment, policies and procedures, training and communications, confidential reporting structure and investigation process, third-party management, and mergers and acquisitions. Part II, resources and empowerment, covers commitment by senior and middle management, autonomy and resources, and compensation structures and consequence management. Part III, whether the program works in practice, covers continuous improvement, periodic testing, and review, investigation of misconduct, and analysis and remediation of any underlying misconduct. Each topic contains questions prosecutors may ask, and the Division states the questions are not a checklist.
Companies implement the ECCP by documenting a risk assessment methodology and showing how the program is tailored to it, maintaining and updating policies, training by role, operating a reporting hotline and investigation process with data on outcomes, applying risk-based due diligence to third parties, integrating acquired businesses, giving compliance adequate autonomy, resources, and access to data, aligning incentives and discipline, and testing the program periodically with root-cause analysis of any misconduct. The 2024 update expects companies to assess the risks of the technology they use, including AI, and to protect whistleblowers.
SmartSuite operationalizes the ECCP by holding its topics and questions as a requirement set linked to the risk assessment, policies, training, hotline cases, third-party due diligence, testing results, and remediation actions, so that the answers prosecutors expect are backed by records with owners, dates, and an audit trail.
Key Elements
- Risk assessment
The methodology used to identify, analyze, and address the particular risks the company faces, and how the program is tailored and updated in light of lessons learned.
- Policies, procedures, training, and communication
A code of conduct and policies that address risk, communicated through training tailored to roles and reinforced by management.
- Confidential reporting and investigations
A reporting mechanism that employees trust, an investigation process that is independent and properly scoped, and protection for whistleblowers.
- Third-party management and M&A
Risk-based due diligence and monitoring of third parties and integration of compliance into the acquisition process.
- Commitment, autonomy, and resources
Senior and middle management commitment, compliance function stature and independence, adequate funding and staff, and access to relevant data.
- Compensation and consequence management
Incentives for compliance and consistent discipline for misconduct, applied across the organization.
- Continuous improvement, testing, and remediation
Periodic testing and review of the program, investigation of misconduct, and root-cause analysis and remediation.
Framework Scope
The ECCP applies to any corporation under investigation by the Criminal Division and, by extension, to every company that may be subject to U.S. federal criminal jurisdiction, including foreign companies with U.S. operations or listings. It covers the whole compliance program rather than any single law, and is used by compliance, legal, internal audit, and board functions to design and test programs and by counsel in resolutions with the Department.
Framework Objectives
The Criminal Division issued the ECCP to help prosecutors make informed decisions about the effectiveness of a corporate compliance program, and it serves companies as the statement of what an effective program looks like.
Assess whether a compliance program was effective at the time of the offense and at the time of the charging decision or resolution.
Apply the Justice Manual factors and the Sentencing Guidelines standard in §8B2.1 consistently across cases.
Determine whether a program is well designed, adequately resourced and empowered, and working in practice.
Inform decisions on charges, resolution form, monetary penalties, and the need for a compliance monitor.
Signal to companies the topics the Division considers relevant, including risk assessment, third parties, incentives, data access, and emerging technology.
Encourage companies to test, improve, and remediate their programs through lessons learned.
Framework in Context
The ECCP applies the Sentencing Guidelines' §8B2.1 and the Justice Manual, and it is cited in the FCPA Resource Guide and the Corporate Enforcement Policy that govern FCPA resolutions. Its topics map to the compliance management system requirements of ISO 37301, to the six principles of the UK Bribery Act guidance, to COSO's internal control components, and to the assurance roles of the IIA's Three Lines Model.
Common Framework Mappings
Compliance teams map the ECCP's topics to the laws, standards, and control frameworks their program already answers to so that one set of evidence serves prosecutors, auditors, and regulators.
Mapped frameworks include:
USSG §8B2.1
FCPA
UK Bribery Act 2010
COSO IC 2013
COSO ERM 2017
SOX
IIA Three Lines Model
OCEG Red Book 3.5
ISO 31000:2018
ISO 42001
ISO 37301:2021
ISO 37001:2016
- ClassificationCategoryCompliance and Ethics ProgramDomainRisk ManagementFramework FamilyOther
- Regulatory ContextTypeGuidanceLegal InstrumentProsecutorial GuidanceSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionNorth AmericaRegion DetailUnited StatesPublisherU.S. Department of Justice, Criminal Division (DOJ)
- VersioningVersionUpdated September 2024Effective DateSeptember 2024Issue DateSeptember 2024
- AdoptionAdoption ModelVoluntaryImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The ECCP is a U.S. Government publication available free of charge from the Department of Justice, and its topics and questions are included with the platform as a requirement set.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports DOJ ECCP
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For the ECCP, SmartSuite holds the three fundamental questions and their topics as a requirement set linked to the risk assessment, policies, training, hotline cases, third-party due diligence, testing results, and remediation actions, so each answer prosecutors expect is backed by records.
ECCP Topics and Questions Library
Hold the ECCP's three fundamental questions and their topics as structured requirements linked to your policies, controls, and evidence.
Ownership, Cadence, and Accountability
Assign compliance, legal, HR, and business owners to each topic, set review cycles, and record management and board commitment.
Evidence Collection and Audit Trail
Attach risk assessments, training data, hotline and investigation records, and due diligence files with timestamps and reviewers.
Program Testing and Continuous Improvement
Plan periodic testing and reviews, capture lessons learned, and track root-cause remediation to closure.
Third-Party and Acquisition Risk Alignment
Link third parties and acquired entities to the risk-based due diligence, monitoring, and integration steps the ECCP expects.
Prosecutor-Ready Reporting
Produce reports by fundamental question and topic showing design, resourcing, and effectiveness with supporting data for counsel and the board.
Related frameworks

The Sarbanes-Oxley Act requires public companies to maintain reliable financial reporting and robust internal controls to prevent fraud.

COSO ICFR guides organizations in designing and evaluating internal controls to ensure reliable financial reporting and regulatory compliance.

COSO ERM is a framework that helps organizations identify, assess, manage, and monitor enterprise risks to achieve objectives.

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

ISO/IEC 42001 is an AI management system standard for managing AI risk, ethics, security, and regulatory compliance.

The GLBA Safeguards Rule requires financial institutions to implement security programs to protect consumer financial information.
Frequently Asked Questions For DOJ ECCP
It is guidance from the Criminal Division of the U.S. Department of Justice that assists prosecutors in assessing whether a corporation's compliance program was effective at the time of an offense and at the time of a charging decision or resolution. The current version was updated in September 2024.
Is the corporation's compliance program well designed? Is the program adequately resourced and empowered to function effectively? Does the program work in practice? Each question groups the topics and sample questions prosecutors may consider.
No. The Division states that the sample topics and questions form neither a checklist nor a formula, and that in any case some topics may not be relevant and others may be more salient given the facts.
The update added questions on the risks of new and emerging technology, including artificial intelligence, on whistleblower protection and anti-retaliation, on access to and use of data by the compliance function, and on lessons learned from the company and others in the industry.
Boards, compliance officers, general counsel, and internal audit use it to design, test, and benchmark compliance programs, and outside counsel use it when presenting a program to the Department in an investigation or resolution.
The ECCP cites §8B2.1 and §8C2.5(f) and expands the seven requirements of an effective compliance and ethics program into detailed questions on design, resources, and operation.
SmartSuite holds the fundamental questions and topics as a requirement set linked to the risk assessment, policies, training, hotline cases, third-party due diligence, testing results, and remediation actions. Compliance teams use it to evidence each answer and to report program effectiveness to counsel and the board.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.
