Compliance and Ethics Program
DETAIL

U.S. Department of Justice, Criminal Division – Evaluation of Corporate Compliance Programs (Updated September 2024)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

The Evaluation of Corporate Compliance Programs (ECCP) is guidance from the Criminal Division of the U.S. Department of Justice, updated in September 2024, that assists prosecutors in deciding whether, and to what extent, a corporation's compliance program was effective at the time of an offense and at the time of a charging decision or resolution. It applies the Principles of Federal Prosecution of Business Organizations in the Justice Manual (JM 9-28.000) and the Sentencing Guidelines standard in §8B2.1.

The document is written for prosecutors, but corporations, boards, and compliance officers use it as the most detailed public statement of what the Department expects. It organizes its sample topics and questions under three fundamental questions: Is the corporation's compliance program well designed? Is the program adequately resourced and empowered to function effectively? Does the program work in practice? The Division states that the topics and questions are neither a checklist nor a formula.

Organizations apply the ECCP by benchmarking their programs against its topics, which include risk assessment, policies and procedures, training and communications, confidential reporting and investigations, third-party management, mergers and acquisitions, management commitment, autonomy and resources, compensation and consequence management, continuous improvement and testing, investigation of misconduct, and analysis and remediation of root causes. The 2024 update adds questions on emerging technology such as artificial intelligence, whistleblower protection, and access to data.

Why it Matters

The ECCP determines how much credit a company receives for its compliance program when the Criminal Division decides whether to charge, what resolution to offer, whether a monitor is needed, and how large a penalty should be. Because it is public and specific, it has become the de facto design standard for corporate compliance programs in the United States and for multinationals subject to U.S. jurisdiction.

Key benefits include:

  • Benchmark against the prosecutor's questions

Test the program against the same topics and questions the Criminal Division uses in investigations and resolutions.

  • Earn credit in a resolution

A well-designed, resourced, and effective program influences charging decisions, penalty calculations, and whether a monitor is imposed.

  • Prove the program works in practice

Show through testing, data, and remediation that the program detects and addresses misconduct, not just that policies exist.

  • Manage emerging risk

Address the 2024 additions on new and emerging technology, including artificial intelligence, and on whistleblower protection.

  • Align with the Sentencing Guidelines

Satisfy the §8B2.1 requirements that the ECCP builds on, including periodic risk assessment and board oversight.

How it Works

Part I, design, covers risk assessment, policies and procedures, training and communications, confidential reporting structure and investigation process, third-party management, and mergers and acquisitions. Part II, resources and empowerment, covers commitment by senior and middle management, autonomy and resources, and compensation structures and consequence management. Part III, whether the program works in practice, covers continuous improvement, periodic testing, and review, investigation of misconduct, and analysis and remediation of any underlying misconduct. Each topic contains questions prosecutors may ask, and the Division states the questions are not a checklist.

Companies implement the ECCP by documenting a risk assessment methodology and showing how the program is tailored to it, maintaining and updating policies, training by role, operating a reporting hotline and investigation process with data on outcomes, applying risk-based due diligence to third parties, integrating acquired businesses, giving compliance adequate autonomy, resources, and access to data, aligning incentives and discipline, and testing the program periodically with root-cause analysis of any misconduct. The 2024 update expects companies to assess the risks of the technology they use, including AI, and to protect whistleblowers.

SmartSuite operationalizes the ECCP by holding its topics and questions as a requirement set linked to the risk assessment, policies, training, hotline cases, third-party due diligence, testing results, and remediation actions, so that the answers prosecutors expect are backed by records with owners, dates, and an audit trail.

Key Elements

  • Risk assessment

The methodology used to identify, analyze, and address the particular risks the company faces, and how the program is tailored and updated in light of lessons learned.

  • Policies, procedures, training, and communication

A code of conduct and policies that address risk, communicated through training tailored to roles and reinforced by management.

  • Confidential reporting and investigations

A reporting mechanism that employees trust, an investigation process that is independent and properly scoped, and protection for whistleblowers.

  • Third-party management and M&A

Risk-based due diligence and monitoring of third parties and integration of compliance into the acquisition process.

  • Commitment, autonomy, and resources

Senior and middle management commitment, compliance function stature and independence, adequate funding and staff, and access to relevant data.

  • Compensation and consequence management

Incentives for compliance and consistent discipline for misconduct, applied across the organization.

  • Continuous improvement, testing, and remediation

Periodic testing and review of the program, investigation of misconduct, and root-cause analysis and remediation.

Framework Scope

The ECCP applies to any corporation under investigation by the Criminal Division and, by extension, to every company that may be subject to U.S. federal criminal jurisdiction, including foreign companies with U.S. operations or listings. It covers the whole compliance program rather than any single law, and is used by compliance, legal, internal audit, and board functions to design and test programs and by counsel in resolutions with the Department.

Framework Objectives

The Criminal Division issued the ECCP to help prosecutors make informed decisions about the effectiveness of a corporate compliance program, and it serves companies as the statement of what an effective program looks like.

Assess whether a compliance program was effective at the time of the offense and at the time of the charging decision or resolution.

Apply the Justice Manual factors and the Sentencing Guidelines standard in §8B2.1 consistently across cases.

Determine whether a program is well designed, adequately resourced and empowered, and working in practice.

Inform decisions on charges, resolution form, monetary penalties, and the need for a compliance monitor.

Signal to companies the topics the Division considers relevant, including risk assessment, third parties, incentives, data access, and emerging technology.

Encourage companies to test, improve, and remediate their programs through lessons learned.

Framework in Context

The ECCP applies the Sentencing Guidelines' §8B2.1 and the Justice Manual, and it is cited in the FCPA Resource Guide and the Corporate Enforcement Policy that govern FCPA resolutions. Its topics map to the compliance management system requirements of ISO 37301, to the six principles of the UK Bribery Act guidance, to COSO's internal control components, and to the assurance roles of the IIA's Three Lines Model.

Common Framework Mappings

Compliance teams map the ECCP's topics to the laws, standards, and control frameworks their program already answers to so that one set of evidence serves prosecutors, auditors, and regulators.

Mapped frameworks include:

USSG §8B2.1

FCPA

UK Bribery Act 2010

COSO IC 2013

COSO ERM 2017

SOX

IIA Three Lines Model

OCEG Red Book 3.5

ISO 31000:2018

ISO 42001

ISO 37301:2021

ISO 37001:2016

At a Glance
U.S. Department of Justice, Criminal Division – Evaluation of Corporate Compliance Programs (Updated September 2024)
  • Classification
    Category
    Compliance and Ethics Program
    Domain
    Risk Management
    Framework Family
    Other
  • Regulatory Context
    Type
    Guidance
    Legal Instrument
    Prosecutorial Guidance
    Sector
    Cross-Sector
    Industry
    Cross-Industry
  • Region / Publisher
    Region
    North America
    Region Detail
    United States
    Publisher
    U.S. Department of Justice, Criminal Division (DOJ)
  • Versioning
    Version
    Updated September 2024
    Effective Date
    September 2024
    Issue Date
    September 2024
  • Adoption
    Adoption Model
    Voluntary
    Implementation Complexity
    Medium
  • Official Reference
License Information

License included / downloadable: Yes

The ECCP is a U.S. Government publication available free of charge from the Department of Justice, and its topics and questions are included with the platform as a requirement set.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
DOJ Criminal Division: Compliance
The Division's compliance page listing the Evaluation of Corporate Compliance Programs (September 2024) and related policy documents.
Evaluation of Corporate Compliance Programs (PDF)
The 25-page guidance organized under the three fundamental questions on design, resources, and whether the program works in practice.
DOJ Criminal Division: Policy materials
The Division's collection of corporate enforcement and compliance policy documents.
DOJ Corporate Enforcement Policy
The Criminal Division's policy on voluntary self-disclosure, cooperation, and remediation credit that works alongside the ECCP.
SMARTSUITE

How SmartSuite Supports DOJ ECCP

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For the ECCP, SmartSuite holds the three fundamental questions and their topics as a requirement set linked to the risk assessment, policies, training, hotline cases, third-party due diligence, testing results, and remediation actions, so each answer prosecutors expect is backed by records.

ECCP Topics and Questions Library

Hold the ECCP's three fundamental questions and their topics as structured requirements linked to your policies, controls, and evidence.

Ownership, Cadence, and Accountability

Assign compliance, legal, HR, and business owners to each topic, set review cycles, and record management and board commitment.

Evidence Collection and Audit Trail

Attach risk assessments, training data, hotline and investigation records, and due diligence files with timestamps and reviewers.

Program Testing and Continuous Improvement

Plan periodic testing and reviews, capture lessons learned, and track root-cause remediation to closure.

Third-Party and Acquisition Risk Alignment

Link third parties and acquired entities to the risk-based due diligence, monitoring, and integration steps the ECCP expects.

Prosecutor-Ready Reporting

Produce reports by fundamental question and topic showing design, resourcing, and effectiveness with supporting data for counsel and the board.

Related frameworks

SOX

The Sarbanes-Oxley Act requires public companies to maintain reliable financial reporting and robust internal controls to prevent fraud.

COSO IC 2013

COSO ICFR guides organizations in designing and evaluating internal controls to ensure reliable financial reporting and regulatory compliance.

COSO ERM 2017

COSO ERM is a framework that helps organizations identify, assess, manage, and monitor enterprise risks to achieve objectives.

ISO 31000:2018

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

ISO 42001

ISO/IEC 42001 is an AI management system standard for managing AI risk, ethics, security, and regulatory compliance.

GLBA Safeguards Rule (16 CFR Part 314)

The GLBA Safeguards Rule requires financial institutions to implement security programs to protect consumer financial information.

USSG §8B2.1

§8B2.1 of the U.S. Sentencing Guidelines defines the seven minimum requirements of an effective compliance and ethics program that reduce an organization's culpability score at sentencing.

FCPA

The FCPA prohibits corrupt payments to foreign officials to obtain or retain business and requires issuers to keep accurate books and records and adequate internal accounting controls.

ONBOARDING FAQS

Frequently Asked Questions For DOJ ECCP

What is the DOJ Evaluation of Corporate Compliance Programs?

It is guidance from the Criminal Division of the U.S. Department of Justice that assists prosecutors in assessing whether a corporation's compliance program was effective at the time of an offense and at the time of a charging decision or resolution. The current version was updated in September 2024.

What are the three fundamental questions?

Is the corporation's compliance program well designed? Is the program adequately resourced and empowered to function effectively? Does the program work in practice? Each question groups the topics and sample questions prosecutors may consider.

Is the ECCP a checklist?

No. The Division states that the sample topics and questions form neither a checklist nor a formula, and that in any case some topics may not be relevant and others may be more salient given the facts.

What did the September 2024 update add?

The update added questions on the risks of new and emerging technology, including artificial intelligence, on whistleblower protection and anti-retaliation, on access to and use of data by the compliance function, and on lessons learned from the company and others in the industry.

Who should use the ECCP besides prosecutors?

Boards, compliance officers, general counsel, and internal audit use it to design, test, and benchmark compliance programs, and outside counsel use it when presenting a program to the Department in an investigation or resolution.

How does the ECCP relate to §8B2.1 of the Sentencing Guidelines?

The ECCP cites §8B2.1 and §8C2.5(f) and expands the seven requirements of an effective compliance and ethics program into detailed questions on design, resources, and operation.

How does SmartSuite support the ECCP?

SmartSuite holds the fundamental questions and topics as a requirement set linked to the risk assessment, policies, training, hotline cases, third-party due diligence, testing results, and remediation actions. Compliance teams use it to evidence each answer and to report program effectiveness to counsel and the board.

Operationalize DOJ ECCP with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.