Document type: Article Practice area: Corporate — Compliance and Investigations Jurisdiction: United States (federal and Delaware) Last reviewed: 5 September 2026


Liability is easy; consequence is the fight

Corporate criminal liability in the federal system rests on a doctrine that is over a century old and startlingly broad.

New York Central & Hudson River Railroad Co. v. United States, 212 U.S. 481 (1909) held that a corporation may be criminally liable for the acts of its agents committed within the scope of their employment for the benefit of the corporation. United States v. Hilton Hotels Corp., 467 F.2d 1000 (9th Cir. 1972) made the reach explicit: a corporation may be liable for an agent's act even where the agent acted contrary to express instructions and a stated corporate policy, because a rule permitting a corporation to escape liability by issuing instructions it does not enforce would gut the statute.

Read those two cases together and the practical consequence is stark. A single mid-level employee, acting for the company's benefit, in violation of a policy the company published and trained on, creates corporate criminal exposure. There is no "we told them not to" defense.

So the entire field is about consequence, not liability. Whether the company is charged at all; whether the resolution is a declination, a non-prosecution agreement, a deferred prosecution agreement, or a guilty plea; how large the penalty is; and whether a monitor is imposed. Every one of those outcomes turns substantially on the compliance program and on what the company did after it found the problem.


The Sentencing Guidelines architecture

The Guidelines' organizational sentencing provisions supply the vocabulary everyone else uses.

The culpability score. A base score is adjusted upward for factors including involvement or tolerance of criminal activity by high-level personnel, prior history, violation of an order, and obstruction — and adjusted downward for an effective compliance and ethics program and for self-reporting, cooperation, and acceptance of responsibility. The culpability score drives a multiplier applied to the base fine, and the range between the best and worst cases is very wide.

The seven elements of an effective program, which every regulator's framework restates in its own words:

  1. Standards and procedures to prevent and detect criminal conduct.
  2. Governing authority knowledge of the program and reasonable oversight; specific high-level responsibility; day-to-day operational responsibility delegated to persons with adequate resources, authority, and direct access to the governing authority.
  3. Reasonable efforts not to include in substantial authority personnel any individual whom the organization knew or should have known had engaged in illegal activities.
  4. Periodic, practical training and communication at all levels.
  5. Monitoring and auditing to detect criminal conduct; a periodically evaluated system; and a mechanism for anonymous or confidential reporting without fear of retaliation.
  6. Consistent promotion and enforcement, including appropriate incentives and disciplinary measures.
  7. Reasonable steps to respond appropriately after detection, including remediation and modification of the program to prevent recurrence.

And the antecedent requirement that carries all seven: the organization must periodically assess the risk of criminal conduct and design, implement, and modify the program accordingly. Risk assessment is the load-bearing element, because a program not built to the company's actual risks is a program built to somebody else's.

A significant caveat. Where high-level personnel participated in, condoned, or were willfully ignorant of the offense, there is a rebuttable presumption that the program was not effective. This is why the involvement of a business unit head changes the entire posture of a case, and why identifying the seniority of the wrongdoers is among the first tasks in any investigation.

One structural point often missed. Since United States v. Booker, 543 U.S. 220 (2005), the Guidelines are advisory, and sentencing proceeds under the factors in 18 U.S.C. § 3553 with fines constrained by 18 U.S.C. § 3571. But the Guidelines' compliance framework has taken on a life far beyond sentencing: it is the template for charging decisions, for resolution terms, and for what every prosecutor and regulator means by "effective program."


The three questions

The Justice Department's Evaluation of Corporate Compliance Programs guidance organizes the inquiry around three questions that prosecutors are directed to ask. They are worth memorizing, because they structure every conversation a company will have about its program.

One: Is the program well designed?

Does it rest on a risk assessment that reflects the company's actual business — its geographies, its industry, its sales model, its third-party relationships, its transaction history? Are the policies accessible, in the right languages, and integrated into the processes where decisions are made? Is training targeted and practical rather than generic and annual? Is third-party diligence risk-based and refreshed? Is compliance embedded in the M&A process, before and after closing? Are there controls — approvals, segregation of duties, system limits — and not only rules?

Two: Is the program adequately resourced and empowered to function effectively?

Is compliance staffed and funded in proportion to risk? Does the compliance function have autonomy, seniority, and direct access to the board? Does it have access to the data it needs? Is compliance treated as a cost center to be minimized, or as a function with a voice in business decisions? Are compliance personnel compensated and promoted in ways that do not depend on the business units they oversee? Is there evidence the function has ever stopped anything?

Three: Does the program work in practice?

This is the question that separates a real program from a documented one. Has the company tested its controls, and what did the testing find? Does it investigate reports thoroughly and consistently? Does it perform root cause analysis and act on it? Does it discipline people, at every level, including senior ones? Does it adjust the program when it finds a gap? Can it show a record of continuous improvement over time?

The guidance's most consequential move is that it asks prosecutors to evaluate the program at the time of the offense and at the time of the charging decision, separately. A company with a weak program at the time of the conduct that has genuinely rebuilt it by the time of resolution gets credit for the rebuild — which is why remediation is not merely damage control but the single most productive investment available once a problem surfaces.


What regulators actually credit

Reading resolution documents rather than guidance documents produces a shorter and more useful list.

Risk assessment tied to observed conduct. Not a generic heat map produced by a consultant. An assessment that identifies the specific ways this business could be defrauded or could defraud, ranks them, and demonstrably drives where controls and testing effort go. The question a prosecutor asks is: show me where your risk assessment identified this risk, and show me what you did about it.

Testing, not training. Training is table stakes and proves little. Testing — sampling transactions, examining third-party payments, reperforming approvals, running data analytics against expected patterns — proves the controls operate. Companies with a documented testing program that found problems before the government did are in a categorically different position from companies that trained everyone annually.

Data analytics. The guidance asks explicitly whether the compliance function has access to relevant data and whether it uses it. A compliance function that cannot query the payment system is a compliance function that cannot detect anything.

Discipline that reaches upward. Terminating the junior employee who executed the scheme and retaining the supervisor who created the pressure is a pattern regulators recognize instantly. Consistency across levels is the tell.

Compensation consequences. Clawbacks, forfeiture of unvested awards, and compliance metrics in incentive plans. The Department has run programs that reduce a corporate penalty in the amount of compensation the company claws back from culpable employees — which converts an abstract principle into an arithmetic one.

Root cause analysis. Not "an employee violated policy" but why the control did not catch it, why the incentive structure rewarded it, why the escalation did not happen. A remediation plan that does not rest on root cause analysis is a plan aimed at the symptom.

Speed and completeness of investigation and disclosure. Voluntary self-disclosure that is genuinely voluntary — before the government knows and before an imminent disclosure by someone else — carries substantial, sometimes decisive, benefit.

Preservation. Document preservation from the first moment, including messaging applications. The single most common cooperation failure in recent years is ephemeral messaging — employees conducting business on applications that auto-delete, on personal devices, under a policy the company never enforced.

And what regulators discount. A thick policy manual nobody reads. Annual online training with a certification click. A hotline with no case management system behind it. A compliance officer who reports to the general counsel who reports to the CEO with no board access. A risk assessment that was performed once, three years ago. A program that has never generated a single instance of a business decision being stopped.


The resolution ladder

Declination. No charges. Under the Department's corporate enforcement policy framework, a presumption of declination applies where a company voluntarily self-discloses, fully cooperates, and timely and appropriately remediates, absent aggravating circumstances — with disgorgement of ill-gotten gains typically still required. The economic difference between a declination and a deferred prosecution agreement is enormous, which is why the self-disclosure decision, made in the first days, is the most consequential decision in the case.

Non-prosecution agreement. No charges filed; obligations undertaken by agreement; typically a shorter term and lighter obligations than a DPA.

Deferred prosecution agreement. An information is filed, prosecution is deferred for a term, and the charges are dismissed if the company complies. The Speedy Trial Act exclusion in 18 U.S.C. § 3161(h)(2) is what makes the structure work, and it contemplates court approval.

How much court approval? Very little, as it turns out. United States v. Fokker Services B.V., 818 F.3d 733 (D.C. Cir. 2016) held that a district court may not withhold approval of a DPA based on disagreement with the government's charging choices or the adequacy of the terms, because those are core prosecutorial functions. United States v. HSBC Bank USA, N.A., 863 F.3d 125 (2d Cir. 2017) likewise confined the district court's supervisory role and held that the monitor's report was not a judicial document subject to a public right of access. Together they establish that a DPA is substantially a negotiation with the prosecutor, not a proceeding before a judge, which tells you where the leverage is.

Guilty plea. Sometimes to a subsidiary rather than the parent, to manage collateral consequences — debarment, licensing, and, for regulated entities, existential ones.

Collateral consequences deserve early attention. Debarment or suspension from government contracting; exclusion from federal health care programs; loss of licenses; mandatory disclosure obligations; consequences under 15 U.S.C. § 7241 and 15 U.S.C. § 7262 certifications and internal control reporting; and the derivative and securities litigation that reliably follows. The criminal resolution is frequently not the largest cost.


Monitors

An independent compliance monitor is imposed where the government concludes the company cannot be trusted to complete remediation on its own.

When a monitor is more likely. Pervasive misconduct across business units or geographies; involvement of senior management; a program that was weak at the time of the offense and has not been meaningfully rebuilt; recidivism; and inadequate cooperation.

When a monitor is less likely, and this is the actionable part. Where the misconduct was contained; where senior management was not involved; where the company has already invested in remediation, tested it, and can demonstrate it works at the time of resolution; where the compliance function has been rebuilt with resources and authority; and where the company has a functioning internal audit and testing capability that the government can rely on.

The practical lesson: remediation completed before resolution is the best monitor-avoidance argument available. Remediation promised in the resolution agreement is not.

What a monitorship costs. Fees, obviously — and the larger costs are management attention, business friction, and the fact that the monitor's workplan will expand into areas nobody anticipated. Terms typically run two to five years, with annual workplans, extensive access, and periodic reports.

Self-monitoring and reporting obligations are the middle path: the company certifies compliance and reports periodically without an independent monitor. Increasingly common where remediation is credible.

The monitor's reports. HSBC held that a monitor's report filed with the court is not a judicial document to which a public right of access attaches — an important holding, because the prospect of public reports would change the monitor relationship fundamentally.


The Delaware overlay: oversight as a fiduciary duty

Separate from the criminal and regulatory frame, directors owe a duty of oversight, and the standard has real teeth in a narrow set of cases.

In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996) established that a director's obligation includes a good-faith attempt to assure that a corporate information and reporting system exists, and that a sustained or systematic failure to exercise oversight — such as an utter failure to attempt to assure a reasonable information and reporting system — establishes the lack of good faith that is a necessary condition to liability.

Stone v. Ritter, 911 A.2d 362 (Del. 2006) confirmed Caremark as the standard and located it within the duty of loyalty, requiring that directors either utterly failed to implement any reporting system or controls, or, having implemented them, consciously failed to monitor or oversee their operations.

Marchand v. Barnhill, 212 A.3d 805 (Del. 2019) is the case that made Caremark a live risk again. The Delaware Supreme Court sustained an oversight claim against the directors of an ice cream company following a listeria outbreak, emphasizing that the board had no committee overseeing food safety, no regular process for board-level reporting on it, and no protocol requiring management to escalate — for a monoline company whose central compliance risk was food safety.

The transferable holding. A board must have a system for monitoring the company's mission-critical compliance risks specifically, not compliance generally. Identify what would destroy this company; establish board-level reporting on it; and keep minutes that show engagement.

And the drafting consequence. Board and committee minutes are the evidence. Minutes recording that "management provided a compliance update" prove nothing. Minutes recording that the committee reviewed specific metrics, asked specific questions, and directed specific follow-up are what defeat a Caremark claim at the pleading stage.


Where the tips come from

Most corporate misconduct is discovered by a person, not a control. Understanding the reporting architecture explains why internal programs must compete with external ones.

The securities whistleblower program. 15 U.S.C. § 78u-6 directs awards to whistleblowers who voluntarily provide original information leading to a successful enforcement action above a monetary threshold, in an amount between ten and thirty percent of collected sanctions. The awards are large enough to change behavior, and they create a direct financial incentive to go to the government rather than to the company.

And they narrowed in one important respect. Digital Realty Trust, Inc. v. Somers, 583 U.S. 149 (2018) held that the Dodd-Frank anti-retaliation provision protects only individuals who report to the Commission, not those who report only internally — because the statute defines "whistleblower" that way. Internal reporters retain protection under other statutes, notably the Sarbanes-Oxley provision at 18 U.S.C. § 1514A, but the holding created an incentive to report externally in order to secure the broader protection.

The False Claims Act. 31 U.S.C. § 3729 and its qui tam provisions let a private relator sue on the government's behalf and share in the recovery. For companies with government revenue, this is the dominant enforcement risk.

The internal channel has to compete. It competes on three dimensions: speed (does anyone respond within days?), credibility (does anything visibly happen?), and safety (has anyone who reported been retaliated against, and does everyone know it?). A hotline that takes three weeks to acknowledge a report is training its workforce to call a lawyer instead.

Retaliation is the unforced error. A company that responds to an internal report by managing the reporter out converts a compliance issue into a retaliation case, a whistleblower award, and an aggravating factor at resolution. Every adverse employment action affecting anyone who has made a report within the preceding period should require compliance review before it is executed — a control that costs almost nothing and prevents an entire category of disaster.

Non-disparagement and separation agreements. Provisions that impede reporting to regulators have been an enforcement priority in their own right. Separation agreements, confidentiality agreements, and codes of conduct should carve out protected reporting explicitly.


The FCPA as the worked case study

Anti-corruption enforcement is where the compliance framework was built and where it is most fully developed, so it repays attention even for companies with no foreign operations.

The anti-bribery provisions. 15 U.S.C. § 78dd-1 covers issuers, § 78dd-2 covers domestic concerns, and § 78dd-3 covers other persons acting within U.S. territory. The prohibition reaches corrupt payments, offers, and promises of anything of value to foreign officials to obtain or retain business, including payments made through third parties where the payer knows or is aware of a high probability that the value will be passed on.

The accounting provisions. 15 U.S.C. § 78m requires issuers to keep books, records, and accounts that accurately and fairly reflect transactions, and to devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances about authorization, recording, and access. These provisions do not require a bribe. A great many resolutions are books-and-records and internal controls cases in which the underlying payment was never charged.

Why this matters for program design. The accounting provisions convert a compliance failure into a strict-liability-flavored regulatory exposure for issuers, and they apply to the whole enterprise, not only the parts that touch foreign officials. Controls over payments, vendor onboarding, and expense classification are anti-corruption controls whether or not anyone thinks of them that way.

Third parties are the dominant risk vector. Agents, distributors, consultants, customs brokers, freight forwarders, joint venture partners. A risk-based diligence program — screening, questionnaires, red flag resolution, contractual protections including audit and termination rights, training, and periodic refresh — is the single highest-return investment in an anti-corruption program.

Successor liability in M&A. An acquirer inherits the target's exposure. Pre-closing anti-corruption diligence, post-closing integration of the target into the acquirer's program, and prompt remediation of anything found are all specifically credited. A company that discovers and self-discloses a target's misconduct promptly after closing is in a materially better position than one that discovers it two years later, and the guidance says so.


Worked example: Vantage Precision finds a problem

Vantage Precision makes industrial sensors. Revenue one point four billion, plants in Ohio and Malaysia, sales through distributors across Southeast Asia and the Gulf. General counsel Adaeze Fontaine gets an anonymous hotline report alleging that the regional sales director for the Gulf has been directing distributor rebate credits to a consultant who has no apparent function.

Days 1–3: preservation and scoping. Adaeze issues a litigation hold covering the region, the distributor relationships, and the individuals named, including messaging applications and personal devices used for business. She confirms with IT that the hold has actually suspended auto-deletion — a step companies skip and regret. Outside counsel is engaged and the work is structured for privilege. The audit committee chair is notified within seventy-two hours.

Weeks 1–4: the investigation. Transaction analysis of the rebate accounts. Payment records for the consultant. Email and messaging review. Interviews, each preceded by an Upjohn warning. The picture that emerges: approximately two point one million dollars routed over three years through the consultant, with roughly six hundred thousand traceable to a procurement official at a state-owned customer.

Week 5: three decisions, in order.

Does the conduct implicate § 78dd-1? Yes — the recipient is a foreign official and the payments were made to obtain business through an intermediary in circumstances that establish knowledge.

Do the accounting provisions of § 78m apply? Yes, and independently — the rebates were recorded as customer credits, which is a books-and-records violation whether or not the anti-bribery charge is brought.

Voluntarily self-disclose? Adaeze's analysis: the government does not know; there is a live whistleblower who may go to the Commission under § 78u-6 at any moment; the conduct is contained to one region and one director; and no member of senior management is implicated. The presumption of declination is available if the company discloses now, cooperates fully, and remediates. She recommends disclosure. The board approves it in week six.

Weeks 6–20: remediation, which is where the case is actually won.

Root cause analysis, not incident description. The findings: distributor rebate approvals required only regional sign-off with no central review; the consultant was onboarded through a legacy process with no diligence; the regional director's incentive compensation was ninety percent volume-based with no compliance modifier; and the compliance function had no access to the distributor payment data.

Controls built to those root causes. Central approval for rebates above a threshold. Third-party onboarding consolidated into a single diligence workflow with screening, questionnaires, and documented red flag resolution. Compliance granted direct query access to the ERP payment tables. A compliance modifier added to sales incentive compensation. Automated analytics on rebate-to-revenue ratios by distributor, with an escalation threshold.

Discipline. The regional director is terminated. So is his supervisor, the Asia-Pacific vice president, for failing to escalate two prior anomalies. Unvested equity is forfeited under the clawback provision. Three other employees receive written discipline.

Testing. Six months after implementation, internal audit tests the new controls against a sample of two hundred transactions across all regions, and finds two exceptions — both remediated and documented. Vantage arrives at resolution with a testing report showing the controls work, not a policy document showing the controls exist.

Month 9: resolution. A declination with disgorgement of the profits attributable to the affected contracts. No monitor — because the misconduct was contained, senior management was uninvolved, disclosure was genuinely voluntary, remediation was completed and tested before resolution, and the compliance function had been visibly strengthened.

Month 10: the derivative demand. A stockholder demands that the board investigate. Because the audit committee had a charter covering anti-corruption risk, received quarterly reporting on third-party diligence metrics, and had minutes reflecting substantive questions about the Gulf region eighteen months earlier, the Caremark theory under Marchand and Stone v. Ritter is weak. The demand is refused and the ensuing complaint is dismissed.

What made the difference. Not the code of conduct, which was fine and irrelevant. Preservation on day one, disclosure in week six, root cause analysis instead of incident description, discipline that reached upward, and testing that proved the fix worked before anyone asked.


Individual accountability and the cooperation bargain

Corporate cooperation credit is conditioned on the company identifying the individuals involved and producing the relevant facts about them. This creates a structural tension every practitioner should understand before the first interview.

The company's interest is in a favorable resolution, which requires full cooperation, which requires identifying culpable individuals promptly.

The individual's interest is in not being identified.

And the lawyer's position is defined by the fact that company counsel represents the company. The Upjohn warning — that counsel represents the corporation, not the employee; that the conversation is privileged and the privilege belongs to the company; and that the company may waive it — is not a formality. It is delivered at the start of every interview, documented, and delivered again if circumstances change.

Separate counsel. Employees whose conduct is genuinely at issue need their own lawyers, and whether the company advances or indemnifies their fees is governed by the charter, bylaws, indemnification agreements, and state law. Decide the advancement question early and on the documents, not ad hoc under pressure.

Joint defense and common interest arrangements are useful and dangerous. They facilitate information flow and they can constrain the company's ability to cooperate later. Enter them deliberately, in writing, with a termination mechanism.

Obstruction is the aggravating factor that eliminates everything else. Not just document destruction under the obstruction statutes but the softer forms: coaching witnesses, delaying productions, producing selectively, or making misleading statements to the government. 18 U.S.C. § 1001 reaches false statements in the investigation itself, and a company that mishandles cooperation converts a manageable case into an unmanageable one.

And messaging applications remain the recurring failure. A policy prohibiting business communications on ephemeral platforms, unenforced, is worse than no policy, because it establishes that the company knew and did nothing. Preservation capability, not policy language, is what the government asks about.


Designing a program that will hold up

Start with risk assessment and let it drive everything. Identify the ways this specific business could break the law, rank them by likelihood and impact, and map each to a control, an owner, and a test. A program not traceable to a risk assessment cannot answer the first of the three questions.

Give compliance real authority. Reporting line to the board or the audit committee. Budget proportional to risk. Seniority sufficient to be in the room. Access to systems and data. And a documented instance of the function having stopped something — which is the single most persuasive fact a compliance officer can offer.

Build controls, not just rules. A policy prohibiting a payment is a rule. A system configuration that will not process the payment without two approvals is a control. Regulators credit controls.

Test. Sample transactions. Reperform approvals. Run analytics. Document findings and remediation. A testing program that has never found anything is not being run properly, and saying so out loud inside the company is healthy.

Align incentives. Compliance metrics in incentive compensation. Clawback provisions that actually get used. Promotion decisions that consider compliance conduct. A sales organization compensated purely on volume will produce volume by whatever means are available.

Make the reporting channel work. Multiple intake paths, anonymity where the law permits, a case management system, defined response timelines, consistent investigation quality, and a retaliation control on every adverse action affecting a reporter.

Do root cause analysis on everything material. And feed the results back into the risk assessment, the controls, and the training. The Guidelines' seventh element is precisely this loop, and it is the element most often missing.

Cover third parties and M&A. Risk-based diligence, contractual protections, audit rights, refresh cycles, and integration of acquired businesses on a defined timeline.

Document engagement at the board level. Charter, cadence, metrics, and minutes that record questions and follow-up. This is the Caremark defense and it is built years before it is needed.


Sizing the program to the company

The guidance is written for large multinationals and applied to everyone, and the most common question from a mid-sized company is what "adequate" means at its scale.

The governing principle is proportionality. The Sentencing Guidelines expressly contemplate that a small organization may demonstrate the same commitment with less formality — using available personnel rather than dedicated staff, relying on outside resources, and modeling conduct through direct involvement of senior leadership rather than through documented systems.

What does not scale down. Risk assessment. Board or owner-level oversight of the top risks. A reporting channel with a response commitment and a retaliation control. Testing of the top few controls. Discipline applied consistently. Root cause analysis when something happens. A one-hundred-person company can do all of these in a few days a quarter.

What scales down. Dedicated compliance headcount, standalone policy libraries, formal training platforms, and elaborate metrics packages. A small company that borrows outside resources for periodic testing and keeps a short, current risk register is doing this properly.

The failure mode at small scale is not insufficient documentation. It is the absence of any separation between the person who executes transactions and the person who reviews them, combined with a founder or owner whose word overrides every control. Regulators recognize the pattern immediately, and it is also the pattern that makes fraud easy.

The failure mode at large scale is a program that is formally complete and operationally hollow — every element present on paper, nothing tested, no one ever disciplined at a senior level, and a compliance function that has never stopped anything.


Compliance in the transaction lifecycle

Compliance obligations do not begin at closing, and integration is specifically credited.

Pre-signing diligence. Risk-based: what is the target's geography, customer base, sales model, and third-party network? Are there government customers, state-owned enterprises, or high-risk intermediaries? What does the target's own program look like, and has it ever tested anything? Are there pending or closed investigations, hotline reports, or terminations for cause?

Contract protection. Representations on anti-corruption, sanctions, and trade compliance. Access to records pre- and post-closing. Indemnity, and consideration of whether the risk is insurable. In a stock deal, remember that the exposure comes with the entity.

Post-closing integration on a defined timeline. Extend the acquirer's policies, controls, and reporting channel. Onboard third parties through the acquirer's diligence process. Train the acquired workforce on what is actually different. Test within a defined period. A published integration timeline that the company actually meets is a document worth having.

And if the diligence or integration finds misconduct. Prompt investigation, prompt remediation, and consideration of voluntary disclosure. The framework specifically contemplates favorable treatment for an acquirer that uncovers and discloses misconduct at an acquired business — which converts diligence from a cost into an option.


When the program is the defense

There are two contexts in which the program does defensive work directly rather than through prosecutorial discretion.

Sentencing. The Guidelines' culpability score reduction for an effective program is real arithmetic, subject to the rebuttable presumption that applies when high-level personnel were involved. Even after Booker made the Guidelines advisory, the calculation frames the negotiation and the § 3553 analysis.

Derivative litigation. A documented oversight system, board-level reporting on mission-critical risks, and minutes reflecting engagement are what defeat a Caremark claim at the pleading stage, under the standard confirmed in Stone v. Ritter and applied in Marchand.

Where the program does not provide a defense. It does not defeat corporate criminal liability itself — Hilton Hotels forecloses that. It does not create a compliance defense to the FCPA accounting provisions at 15 U.S.C. § 78m, which impose affirmative obligations to maintain accurate records and adequate controls. And it does not immunize individuals, whose exposure is personal and unaffected by the corporation's remediation.

Which is worth saying plainly to a board. The compliance program is not a shield that prevents liability. It is the instrument that determines what happens after liability attaches — and given how easily liability attaches, that is where nearly all the value sits.


The metrics that mean something

Boards ask for compliance metrics and usually get the wrong ones. Training completion percentage is the canonical example: it measures whether people clicked, not whether anything works.

Better metrics, grouped by the three questions.

Design. Percentage of identified high risks with a documented control owner and test. Age of the current risk assessment. Percentage of high-risk third parties with current diligence. Time from acquisition to program integration.

Resourcing and empowerment. Compliance headcount and budget as a ratio to revenue and to headcount in high-risk functions. Number of business decisions escalated to compliance, and the number stopped or modified. Whether compliance has direct system access. Board reporting frequency and attendance.

Effectiveness in practice. Number of controls tested and exception rate. Time from report to acknowledgment and from report to closure. Investigation substantiation rate. Discipline imposed, by level of seniority — the distribution matters more than the count. Number of root cause analyses completed and program changes made as a result. Repeat findings, which are the strongest negative signal available.

One metric worth watching closely: the internal report volume. A sudden decline is usually not a sign that misconduct fell. It is usually a sign that people stopped reporting, and the reason is nearly always something the company did.


Practice pointers

Preserve on day one, including ephemeral messaging, and verify that auto-deletion actually stopped.

Make the self-disclosure decision deliberately and early, with the declination framework in view, and remember that a whistleblower with a claim under 15 U.S.C. § 78u-6 can eliminate the option at any moment.

Do root cause analysis, not incident description. Then build controls to the causes.

Discipline upward as well as downward, and record the reasoning.

Complete and test remediation before resolution. It is the best monitor-avoidance argument that exists.

Instrument the compliance function with data access. A function that cannot query the payment system cannot detect anything.

Put a compliance modifier in incentive compensation and use the clawback when it is warranted.

Route every adverse employment action affecting a reporter through compliance review.

Give the board a charter naming your mission-critical compliance risks, a reporting cadence, and minutes that show engagement — the lesson of Marchand.

Assume the program will be evaluated twice: as it was at the time of the conduct, and as it is at the time of the charging decision. You can only change the second one, and it is worth a great deal.


Related documents


This article is general information, not legal advice, and does not create an attorney-client relationship.