The Department of Justice (DOJ) in the United States has made significant updates to its "Evaluation of Corporate Compliance Programs" document, with a particular focus on the integration and governance of Artificial Intelligence (AI) within corporate frameworks. Released recently, this revision signals the DOJ's increasing attention on the role AI plays in corporate operations and the associated compliance implications.
This updated guidance becomes a pivotal tool for the DOJ in its decision-making processes, including whether to initiate investigations, file charges, or negotiate plea agreements with corporations. The updated document underscores the importance of businesses adopting a comprehensive approach to managing AI-related risks within their operations.
One of the central elements of the updated guidance is Risk Assessment. The DOJ expects corporations to assess and proactively address risks linked to their use of AI. Companies are assessed on their efforts to mitigate potential risks stemming from AI integration in their operations. Furthermore, the revised guidance suggests that corporations should revise their Policies and Procedures to reflect the evolving risks, notably those associated with new technologies like AI.
Employee training has also received attention. The revised guidance emphasises that training programmes should incorporate lessons learned from compliance issues encountered by others in the same sector. This could encompass challenges and incidents related to AI implementation.
The guidance notably stresses the importance of Monitoring and Testing AI technologies. Organisations employing AI in their operations or compliance frameworks must establish systems to monitor AI performance and test its functionality. This includes ensuring that AI operations align with the company's ethical standards and objectives. Measures should be instituted to detect and amend AI decisions that might deviate from the company's core values.
A commitment to Continuous Improvement is another significant aspect highlighted in the DOJ's updates. Corporations are urged to continually refine their compliance programmes by drawing lessons from their own misconduct and examining the pitfalls encountered by other businesses facing similar threats. Companies need to maintain the capability to evaluate whether AI technologies are achieving their intended purposes and if they adhere to the company’s ethical code.
In terms of AI Governance, the DOJ will evaluate how companies incorporate AI risk management within their broader enterprise risk management strategies. This includes assessing efforts to mitigate any negative or unintended consequences that might arise from AI use. Companies are expected to establish controls to ensure the trustworthiness and reliability of AI, and demonstrate compliance with applicable legal standards and company policies. Accountability mechanisms for AI utilisation are also under scrutiny.
The DOJ's updated guidance conveys a clear expectation for companies to align their compliance programs with these provisions to avoid potential penalties or legal investigations. For those incorporating AI into their operations, a thorough review and adjustment of current compliance measures is advisable to navigate this complex landscape effectively.
Source: Noah Wire Services