On September 23, 2024, the United States Department of Justice (DOJ) unveiled an updated set of guidelines known as the Evaluation of Corporate Compliance Programs (ECCP). This revision introduces significant new expectations for companies in how they manage and use Artificial Intelligence (AI) and other emerging technologies within their compliance frameworks. The refreshed guidance reflects ongoing themes from other DOJ advisories and lays out particular points of interest for businesses regarding AI, especially within the context of mergers and acquisitions (M&A).

Incorporating AI Responsibly in Corporate Compliance

The updated ECCP urges companies to demonstrate their use of innovative technologies such as AI, while also emphasising the need for preparedness against associated risks. This move reiterates the stance previously articulated by Deputy Attorney General Lisa Monaco, who advocated for considering the risks posed by disruptive technologies in corporate compliance. Principal Deputy Assistant Attorney General Nicole Argentieri highlighted scenarios during the ECCP launch where companies could be exposed to criminal schemes enabled by AI technologies, such as false data entries or documentations.

Businesses are, therefore, expected to evaluate technological risks comprehensively. Several considerations include:

  • Assessing how AI's use is documented in their risk assessments, and establishing the risk levels for its implementation, especially in contexts involving privacy, cybersecurity, and bias.
  • Ensuring AI systems have adequate human oversight, relying on a baseline of human decision-making for comparison.
  • Taking steps to mitigate identified risks, such as potential misuse, through the use of monitoring tools, technical safeguards, and continuous testing.
  • Continual monitoring to ensure AI technologies are functioning as intended within both commercial operations and compliance programs.

Adopting and Evaluating Modern Technologies

In addition to AI, the ECCP now expects companies to keep their policies and procedures under regular review and to incorporate technology effectively to manage risks. Companies need to assess whether their technology generates new risks and whether they have adapted innovative solutions to mitigate exposure to criminal or civil liabilities.

When facing inquiries from prosecutors, companies will need to demonstrate a process for updating compliance policies. This includes learning from past issues, either within the company or in similar industries, and adapting policies to meet new risks presented by evolving technology.

Third-Party Relationships and Data Utilisation

The updated guidance places an emphasis on using data to analyse third-party management programs effectively. Prosecutors will look into whether businesses can evaluate vendor risk promptly and use data to manage these relationships throughout the lifecycle of a business arrangement.

Focus on Whistleblowing Policies

Following the introduction of the DOJ Corporate Whistleblower Awards Pilot Program, the ECCP now underscores the importance of fostering an environment where misconduct is reported without fear of retaliation. The guidance reviews whether companies incentivise reporting and adequately train employees on their internal reporting systems as well as external whistleblower programs.

Prosecutors are directed to examine anti-retaliation measures, scrutinising a company’s evaluation of employee discipline in cases of reported misconduct, and reviewing if changes are made based on such evaluations.

Compliance in M&A Activities

Aligned with the DOJ's M&A Safe Harbor Policy, the ECCP stresses rigorous due diligence throughout M&A transactions. The guidance clarifies that responsibilities extend beyond pre-acquisition checks to include post-acquisition diligence and compliance integration, ensuring continuous risk management and preventing potential misconduct from the target companies.

The questions prosecutors might consider include how effectively a company integrates compliance post-transaction, oversight procedures over new business units, and the execution of post-acquisition audits.

In summary, the revamped ECCP presents detailed directives and expectations for companies regarding the usage of modern technologies and the thorough examination of compliance measures in various operational aspects. The DOJ's heightened focus on corporate compliance underscores the importance of integrating these standards into a company's operational ethos and being prepared to substantiate their program's effectiveness in the face of scrutiny.

Source: Noah Wire Services