In a move aiming to enhance the evaluation process of corporate compliance programmes, the U.S. Department of Justice (DOJ) has introduced updates to its Evaluation of Corporate Compliance Programs (ECCP) policy document. Announced on September 23, 2024, these revisions bring to the forefront the importance of managing risks associated with new technologies, particularly focusing on artificial intelligence (AI) to prevent "deliberate or reckless misuse."

The ECCP is a crucial document used by prosecutors to assess the integrity of corporate compliance programmes, guiding decisions on whether to pursue charges and determine financial penalties. One of its key roles is to help prosecutors evaluate if companies have instituted robust safeguards against potential legal violations while deploying cutting-edge technologies like AI. This update follows a directive from Deputy U.S. Attorney General Lisa Monaco in March 2024, which called for the integration of new technology risk assessments, including AI, into the existing compliance evaluation framework.

The revised ECCP sets precise criteria to discern whether companies have robust controls to mitigate risks associated with AI. Prosecutors are encouraged to explore whether businesses have processes to identify and manage emerging risks, including those from AI, as part of their overarching enterprise risk management (ERM) strategies. This involves questioning the company's ability to curb unintended negative outcomes and misuse by insiders, maintaining accountability, and verifying technology use aligns with company codes of conduct and applicable laws.

Moreover, the report positions AI usage as a core element of business operations, asserting that companies should implement specific policies ensuring the tech's trustworthy deployment. This includes the creation and monitoring of auditing procedures for AI performance, employee training to prevent misuse, and ensuring that these technologies enhance, rather than undermine, corporate compliance.

Another significant addition to the ECCP concerns data resources and access. The revisions suggest that companies should leverage data analytics to improve the efficiency and effectiveness of compliance operations. It outlines the need for compliance staff to have full access to pertinent data, ensuring they can properly gauge the programme's effectiveness. Questions for prosecutors now include how companies manage and ensure the quality of their data sources and measure the performance of their data analytics models.

These updates underscore the DOJ's commitment to addressing the risks posed by AI misuse and enhancing corporate accountability through improved compliance evaluation criteria. By making these risks a focal point, the DOJ aims to ensure that companies are proactive in their risk management strategies, particularly when integrating emerging technologies into their operations. The ECCP revisions also reinforce that access to data analytics tools and relevant data is fundamental for compliance personnel to effectively implement compliance programmes.

The DOJ's stance, as articulated by Deputy U.S. Attorney General Lisa Monaco, is clear: Fraud involving AI remains fraud, necessitating a vigilant approach to compliance in the age of rapidly advancing technology. By updating the ECCP, the DOJ is taking an assertive step in ensuring corporations maintain robust compliance frameworks that account for modern technological risks.

Source: Noah Wire Services