Ask your compliance data anything. Sienna Insights, now available.
Join the webinar

DOJ guidelines on corporate compliance programs (ECCP)

What the DOJ's Evaluation of Corporate Compliance Programs (ECCP) requires, what changed in the September 2024 update, and what it means for your compliance program.

August 25, 2026
15 min read
Share

Table of contents

DOJ guidelines on corporate compliance programs (ECCP)

Most compliance programs look fine from the outside. Policies documented, training logged, a reporting channel in place. Prosecutors at the U.S. Department of Justice don't evaluate programs from the outside.

The Evaluation of Corporate Compliance Programs (ECCP) is the framework DOJ prosecutors use to decide whether your compliance program actually works. It sits behind every criminal enforcement decision involving a corporate defendant. Score well against it and you can walk away with reduced penalties, fewer ongoing obligations, and a real distinction between "this company had a bad actor" and "this company had a bad culture."

Where the ECCP comes from

The DOJ's Criminal Division publishes the ECCP as guidance for prosecutors evaluating corporate compliance programs. The current version is dated September 2024, and it adds explicit expectations around artificial intelligence, whistleblower culture, and whether your compliance team has the resources the rest of the business takes for granted.

The ECCP was written for prosecutors, but compliance teams now use it as a working benchmark, a way to stress-test a program before enforcement pressure forces the question.

The three questions your program has to answer

Every evaluation comes back to three questions:

Is the program well-designed? Does it address your company's actual risk profile, or does it borrow risks from a generic template?

Is it resourced and empowered? Does your compliance function have the independence, budget, and data access to do its job, or is it set up to fail structurally?

Does it work in practice? Can you show that you monitor, investigate, and improve over time, or does the program exist only on paper?

That third question is where most programs fall apart. Prosecutors aren't looking for documentation. They're looking for evidence that compliance is lived, not filed.

What prosecutors actually examine

Risk assessment

Prosecutors want to see that you know your specific risks: your industry, your geography, your business model, not a generic list. They also expect risk assessments to happen on a schedule and to incorporate lessons from incidents elsewhere in your sector, not just your own history. A risk assessment done once at launch and never revisited won't hold up.

Policies, procedures, and training

Policies need to live somewhere employees actually look, not in a portal nobody opens. The 2024 update sharpened the language here: your program needs to actively mitigate risk, not just aim to reduce it. Training should track the policies employees actually need to follow and update when circumstances change. Prosecutors also expect training to cover anti-retaliation and external whistleblower protection laws, not just your internal reporting steps. Employees need to know their rights, not just the rules.

Confidential reporting and anti-retaliation

This is where the 2024 update moved the furthest. Having a reporting channel is now table stakes. What prosecutors examine is whether employees use it, whether your company actively encourages that use, and whether company practices discourage people from coming forward. A policy that discourages reporting in practice can be worse than no policy at all.

The updated ECCP asks prosecutors to compare how you treat employees who report misconduct against employees who knew and said nothing. It asks whether you train people on anti-retaliation, and whether you measure their willingness to report in the first place. That last point is new: the DOJ now expects you to measure your speak-up culture, not describe it. The question has shifted from "do you have a hotline" to "do your people trust it."

If you run an anonymous reporting solution, the infrastructure is a starting point. The culture around it is what the ECCP is really probing. Our guide to what whistleblowing is covers how effective reporting programs work in practice.

Third-party risk management

Vendor risk doesn't get a pass. The 2024 update puts more weight on ongoing due diligence: not a one-time screen at onboarding, but continuous monitoring that uses live data to re-evaluate third-party relationships as they change. A clean initial check means little three years later if nothing has happened since.

Mergers and acquisitions

Compliance needs a seat at the table during acquisitions, especially in post-transaction integration. If a target carries compliance risk, prosecutors will ask what your compliance function did to catch it and what happened after the deal closed. The ECCP now explicitly asks whether compliance helped design and execute the integration.

Senior management commitment

A compliance program is only as credible as the leadership behind it. Prosecutors look for genuine commitment from senior and middle management, not a mention at the annual all-hands. That shows up in budgets, in what happens when compliance flags a concern, and in whether leadership models the behavior it asks of everyone else.

Resourcing and autonomy

The 2024 ECCP makes a pointed observation: if you invest heavily in technology that grows revenue and barely at all in technology that detects and manages risk, prosecutors are now told to treat that gap as a signal. Your compliance team needs independence to do its job without interference, and the tools to do it properly.

What the September 2024 update actually changes

Three areas got substantive new language.

Artificial intelligence

Prosecutors now check whether you have a governance framework for AI, whether it's integrated into your broader risk management, and whether controls exist to catch deliberate or reckless misuse. That applies to AI your business uses commercially and AI your compliance function uses internally. If you use AI to find opportunities but haven't thought through what happens when someone misuses it internally, that gap will be hard to explain.

Speak-up culture

The ECCP has always required a reporting mechanism. The 2024 update goes further: you need to actively encourage and incentivize reporting, assess whether employees are willing to use your channels, train on anti-retaliation, and show that people who speak up are treated fairly compared to people who don't.

In practice, that means your whistleblowing program needs to be something employees genuinely trust: anonymous access, real protection from retaliation, visible follow-through on reports, and a culture that treats speaking up as a contribution rather than a risk. If you operate in the EU, these expectations sit alongside the binding requirements of the EU Whistleblowing Directive, which sets its own standards for reporting channels, confidentiality, and anti-retaliation.

Data access and analytics

Compliance teams need real access to company data. The updated ECCP asks whether your compliance personnel can reach the systems they need to monitor program effectiveness, whether you use analytics to catch misconduct patterns, and how you manage data quality and model accuracy. The standard is explicit: compliance should have the same data access other business functions already have. If sales runs on real-time dashboards and compliance runs on quarterly spreadsheets, prosecutors are now told to treat that as a gap worth examining.

What this means for your compliance program

The ECCP describes a program that changes based on what the organization learns, backed by leadership that means it, where people trust that speaking up gets a response. Many programs on paper don't look like that. They look like binders.

The 2024 update turns several soft expectations into hard requirements: AI governance, measured speak-up culture, and real data access for compliance. If you haven't revisited your program since the last update, you're likely behind the current standard.

There's an upside to how the ECCP is built. A company that can show its program works, and can point to how it improved after something went wrong, is in a different position from one that can only produce a policy document. Prosecutors are told to look for continuous improvement, not perfection, within the DOJ's broader corporate enforcement framework. Our full guide to building an effective whistleblowing program covers the foundations a program like that is built on.

How SpeakUp helps you meet ECCP expectations

Confidential reporting, anti-retaliation, and measurable speak-up culture are the areas where the right infrastructure changes what you can prove.

With SpeakUp's whistleblowing software, your employees get a secure, anonymous channel to report concerns, and your compliance team gets the case management tools to act on what comes in, track outcomes, and show reports were handled properly. When the DOJ asks whether you actively encourage reporting, protect the people who speak up, and measure their willingness to do it, you have a documented answer instead of a policy binder and a hope.

Frequently asked questions

What is the DOJ ECCP?

The Evaluation of Corporate Compliance Programs is guidance from the DOJ's Criminal Division that tells prosecutors what to check when they evaluate a company's compliance program during an enforcement action.

When was the ECCP last updated?

The current version is dated September 2024.

What are the three core questions in the ECCP?

Is the program well-designed. Is it adequately resourced and empowered. Does it work in practice.

Does the ECCP apply to all companies?

The ECCP was written for DOJ prosecutors evaluating companies in criminal matters, but companies across industries use it as a benchmark for building and assessing compliance programs, whether or not they're under investigation.

What did the September 2024 update change?

The main additions cover AI and emerging technology risk, stronger whistleblower and anti-retaliation expectations, and data access requirements for compliance teams. It also expanded guidance on third-party risk management and post-acquisition integration.

What does the ECCP say about whistleblower protections?

A reporting channel alone isn't enough. The update expects active encouragement of reporting, anti-retaliation training that covers external laws, a way to assess whether employees are willing to report, and consistent, fair treatment of people who do.

What happens if a company's compliance program doesn't meet ECCP standards?

A weak program doesn't automatically trigger prosecution, but it removes one of the strongest mitigating factors in an enforcement decision. Companies with credible, working programs are more likely to get favorable resolutions, including reduced penalties and lighter ongoing obligations.

How can SpeakUp help my organization meet ECCP requirements?

SpeakUp gives you a secure, anonymous reporting channel and the case management tools to investigate, track, and close out reports consistently. That's the documented evidence the ECCP asks for: an active reporting culture, consistent treatment of people who speak up, and a system your compliance team can point to instead of a policy binder. See how SpeakUp's whistleblowing software works.

Subscribe to newsletter
By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share