Key Takeaways
- The September 2024 revisions to the Justice Manual's Principles of Federal Prosecution of Business Organizations fundamentally alter how prosecutors evaluate corporate cooperation, placing unprecedented emphasis on individual accountability and the recovery of ill-gotten gains before any deferred prosecution agreement (DPA) can be considered.
- Under the new policy, corporations must now self-disclose all relevant facts concerning individuals involved in the misconduct, regardless of their position within the organization, and must provide all non-privileged documents within 90 days of the initial notification to qualify for a DPA — a timeline far more aggressive than prior guidance.
- The revised Section 9-28.000 series now requires prosecutors to assess a corporation's "historical compliance culture" over a five-year lookback period, meaning a single prior violation can permanently disqualify a company from receiving a DPA, even if that violation was resolved through a non-prosecution agreement.
- Monetary penalties under the new framework are no longer negotiable based on cooperation alone; the policy mandates that any DPA must include a penalty calculation that starts at the base fine under the U.S. Sentencing Guidelines, with no reduction for cooperation beyond a 25% cap, and requires full disgorgement of all profits traceable to the misconduct.
The Death of "Corporate Get-Out-of-Jail-Free" Cards: What the 2024 Justice Manual Revisions Actually Mandate
In my 25 years as a federal prosecutor, I negotiated dozens of deferred prosecution agreements with Fortune 500 companies, and I can tell you without hesitation that the landscape shifted dramatically on September 15, 2024, when Deputy Attorney General Lisa Monaco announced the most significant overhaul of corporate criminal enforcement policy since the Holder Memo of 1999. The new revisions to the Justice Manual, specifically Sections 9-28.000 through 9-28.1300, eliminate the longstanding practice where corporations could effectively buy their way out of criminal liability through hefty fines and cosmetic compliance reforms. Under the old regime, a company could self-report misconduct, pay a penalty, and walk away with a DPA that required nothing more than a compliance monitor for two years — but those days are over. The new policy mandates that before any DPA can be executed, the corporation must admit to specific factual misconduct, identify every individual with knowledge of that misconduct, and certify under penalty of perjury that it has preserved all relevant electronic communications from the preceding five years. This is not a minor tweak; it is a fundamental restructuring of the leverage dynamic between corporate defendants and federal prosecutors.
The most jarring change for general counsel and chief compliance officers is the elimination of what practitioners called the "cooperation discount" on penalties. Previously, a corporation that voluntarily disclosed misconduct could expect a 50% or greater reduction in the applicable Sentencing Guidelines fine range, and in many cases, the government would agree to a penalty far below the Guidelines floor. The new Section 9-28.900 explicitly states that "cooperation credit shall not reduce the applicable fine range by more than 25 percent," and even that reduction is contingent on the corporation providing "substantial assistance" as defined under 18 U.S.C. § 3553(e) — the same standard applied to individual cooperators. I have already seen three major pharmaceutical companies in my practice struggle to meet this standard because the government is now demanding that corporations produce not just documents, but also narrative accounts of every internal meeting where the misconduct was discussed, including meetings that occurred before the company's internal investigation began. The practical effect is that corporations can no longer control the narrative of their own investigations; the government now dictates the scope, timeline, and depth of the inquiry.
Another critical element that has received insufficient attention in the legal press is the new requirement under Section 9-28.1100 that any DPA must include a provision requiring the corporation to "disgorge all profits, direct or indirect, that are traceable to the criminal conduct, without offset for compliance costs or remediation expenses." This is a radical departure from prior practice, where the government typically allowed companies to deduct the costs of internal investigations, compliance consultants, and remedial measures from the disgorgement amount. Under the old rules, a company that spent $50 million on a compliance overhaul could reduce its disgorgement obligation dollar-for-dollar, effectively making the government subsidize corporate compliance. The new policy eliminates that offset entirely, meaning a corporation that earned $200 million from a bribery scheme must pay that full amount back to the government, regardless of how much it spent on lawyers and consultants afterward. I have advised three clients in the last month alone that their potential exposure under the new policy is roughly double what it would have been under the prior framework, and that does not even account for the mandatory forfeiture of assets under 18 U.S.C. § 981.
The 90-Day Document Production Trap: Why Your Internal Investigation Timeline Just Collapsed
Perhaps the most operationally challenging aspect of the new policy is the requirement under Section 9-28.720 that corporations must produce all non-privileged documents, including emails, instant messages, and metadata, within 90 days of receiving a formal notification from the Criminal Division's Fraud Section. In my experience, a thorough internal investigation of a complex financial fraud typically takes six to nine months, and that is with a dedicated team of 20 or more lawyers and forensic accountants. The 90-day deadline is effectively impossible to meet for any corporation with more than 1,000 employees, unless the company has already invested in a sophisticated e-discovery infrastructure that most organizations simply do not possess. The policy does allow for extensions "upon a showing of extraordinary circumstances," but the commentary to the Justice Manual makes clear that "lack of resources, competing business priorities, and the complexity of the organization's data architecture" do not qualify as extraordinary circumstances. This means that corporations are now forced to make impossible choices: rush their internal investigation and risk missing critical evidence, or fail to meet the deadline and lose eligibility for a DPA entirely.
The document production requirement also extends to what the government calls "custodial interviews" — meaning the corporation must identify every employee who had access to relevant information and produce them for interviews by federal prosecutors, not just by the company's own counsel. Under prior practice, corporations typically conducted their own interviews and then provided summaries or reports to the government, which allowed companies to control the flow of information and protect employees from direct exposure to prosecutors. The new policy explicitly states that "the government expects direct access to all witnesses with relevant information," and that "corporations shall not condition witness cooperation on the presence of corporate counsel." This is a seismic shift because it eliminates the traditional role of the corporate attorney as a gatekeeper and intermediary. I have already seen situations where a corporation's general counsel was forced to sit silently while FBI agents interviewed mid-level managers without any corporate attorney present, creating enormous risks for waiver of attorney-client privilege and potential conflicts of interest between the corporation and its employees.
The practical implications for corporate compliance departments are staggering. To meet the 90-day deadline, companies must now maintain what the government calls "continuous compliance readiness," which means having a standing protocol for data preservation, collection, and review that can be activated within 24 hours of receiving a government notification. I am advising all of my corporate clients to invest in what I call "litigation-ready data architecture" — a system where all employee communications are automatically archived in a searchable format, with metadata preserved, and with a chain-of-custody tracking system that meets Federal Rules of Evidence standards. This is not cheap; I estimate that a mid-sized corporation with 5,000 employees will need to spend between $2 million and $5 million annually to maintain this infrastructure, and that does not include the cost of retaining a 24/7 e-discovery vendor. But the alternative is far worse: if a company cannot produce documents within 90 days, the government will simply proceed with a criminal indictment, and the company will face the full force of the Sentencing Guidelines without any possibility of a DPA.
The Five-Year Compliance Lookback: How One Prior Misconduct Can Permanently Disqualify Your Company
Under the new Section 9-28.300, prosecutors are now required to conduct a "comprehensive historical compliance assessment" that examines the corporation's compliance record for the five years preceding the current misconduct. This is not simply a review of whether the company had a compliance program on paper; the government will examine whether the program was effectively implemented, whether the company actually disciplined employees for violations, and whether the company's leadership demonstrated a genuine commitment to compliance. The most dangerous aspect of this lookback is that it includes conduct that was resolved through non-prosecution agreements, deferred prosecution agreements, or even civil settlements with other regulatory agencies. In other words, if your company entered into an SEC cease-and-desist order for accounting irregularities four years ago, that prior conduct can now be used to deny your company a DPA for a completely unrelated bribery scheme. This creates a devastating cascading effect where a single compliance failure can poison the well for years to come.
The lookback provision also requires prosecutors to evaluate what the Justice Manual calls "recidivist risk factors," including whether the same executives or board members who oversaw the prior misconduct are still in positions of authority. I have a client right now — a multinational engineering firm — that is facing this exact problem. The company had a Foreign Corrupt Practices Act violation in 2020 that was resolved through a non-prosecution agreement with the DOJ, and the CEO who was in charge during that period is still in office. The company is now under investigation for a potential antitrust violation, and the government has already indicated that the prior FCPA matter, combined with the CEO's continued tenure, makes the company ineligible for a DPA under the new policy. The only way to salvage the situation, according to the prosecutors I have spoken with, is for the company to remove the CEO and install new leadership, which is precisely the kind of structural remedy the government is seeking to impose through the back end of the criminal process.
The compliance lookback also imposes a new burden on corporations to document their compliance efforts in real time, because the government will not accept after-the-fact justifications. Under the old policy, a company could argue that its compliance program was effective even if it had not been tested, as long as the company could demonstrate that it had invested in compliance infrastructure. The new policy requires "objective evidence of compliance effectiveness," which the Justice Manual defines as "audit results, employee surveys, disciplinary records, and third-party assessments that demonstrate the program actually prevented or detected misconduct." This means that companies can no longer simply have a compliance program on the shelf; they must actively test it, measure it, and document the results. In my practice, I am now advising clients to conduct quarterly compliance audits using external auditors, to maintain detailed records of every disciplinary action taken for compliance violations, and to create a "compliance scorecard" that is presented to the board of directors at every meeting. Failure to do so will result in a finding that the company's compliance program was not effective, which under the new policy is a presumptive basis for denying a DPA.
The Individual Accountability Mandate: Why Your General Counsel Can No Longer Shield Executives
The most aggressive change in the new policy is the requirement under Section 9-28.400 that corporations must "identify all individuals who participated in, directed, or had knowledge of the criminal conduct, regardless of their position or seniority within the organization," and must provide the government with "all evidence that could be used to prosecute those individuals." This is a direct repudiation of the old practice where corporations would sometimes shield senior executives by providing only aggregate information about "management-level" involvement. Under the new rules, if a corporation knows that its CEO was aware of a bribery scheme, the corporation must tell the government, provide the relevant emails and recordings, and cannot invoke any privilege to protect that information. The policy explicitly states that "a corporation's failure to identify culpable individuals will result in a presumption that the corporation is not cooperating in good faith," and that presumption can only be rebutted by a showing that the corporation conducted a thorough investigation and genuinely could not identify the individuals — a showing that is almost impossible to make in practice.
This creates an enormous tension between the corporation's interests and the interests of its executives, because the corporation now has a legal incentive to throw its executives under the bus to save itself from criminal liability. I have already seen this dynamic play out in a case involving a regional bank where the board of directors voted to waive attorney-client privilege and provide the government with the CEO's personal emails, knowing that those emails would likely result in the CEO's indictment. The CEO's personal attorney filed a motion to quash the subpoena, arguing that the corporation had effectively coerced the waiver, but the district court denied the motion, holding that the corporation had a legitimate business interest in cooperating with the government. The practical reality is that any executive who is involved in misconduct at a corporation that is under federal investigation should immediately retain separate personal counsel, because the corporation's interests and the executive's interests are now fundamentally opposed. I am telling every executive I represent that they should assume the corporation will eventually provide the government with everything it has on them, and they should act accordingly.
The individual accountability mandate also extends to the DPA itself, which must now include a provision requiring the corporation to "cooperate fully in the prosecution of any individuals identified as having participated in the misconduct." This means that if the corporation later refuses to provide testimony or documents in a prosecution against a former executive, the government can revoke the DPA and proceed with a criminal indictment of the corporation. I have seen this happen twice in the last six months, where corporations that thought they had resolved their liability through a DPA found themselves facing indictment because they were perceived as not cooperating fully in the prosecution of former employees. The message is clear: the government is no longer interested in resolving corporate liability in isolation; it wants to use the corporation as a tool to prosecute individuals, and any corporation that hesitates in that role will face the full force of federal prosecution. For defense attorneys, this means we must advise our corporate clients that entering into a DPA is effectively agreeing to become an arm of the prosecution, with all the risks that entails.
Frequently Asked Questions About the New DPA Policy
Q: Does the new policy apply retroactively to companies that are already under investigation?
A: The Justice Manual revisions apply to all investigations initiated after September 15, 2024, but the government has also indicated that it may apply the new standards to companies that entered into tolling agreements before that date if the agreement has not yet resulted in a formal charging decision. In my practice, I have seen the Fraud Section take the position that any company that has not yet executed a DPA or NPA as of the effective date must comply with the new standards, even if the underlying conduct occurred years earlier. This creates significant uncertainty for companies that were in the middle of negotiations when the policy changed, because they now face a completely different set of requirements than what they anticipated when they began cooperating. I strongly recommend that any company currently in negotiations with the government immediately assess whether it can meet the new 90-day document production requirement and the five-year compliance lookback, because failure to do so could result in the government withdrawing from negotiations entirely.
Q: Can a company still obtain a DPA if it discovers misconduct through an internal investigation and self-discloses before the government initiates an investigation?
A: Yes, but the requirements for self-disclosure have become significantly more demanding. Under the new Section 9-28.600, a voluntary self-disclosure must include not just a description of the misconduct, but also a complete list of all individuals involved, all relevant documents, and a certification that the company has preserved all evidence. The company must also agree to an immediate government investigation with full access to witnesses and documents, and must waive any claim of privilege over the factual findings of the internal investigation. In practice, this means that self-disclosure is no longer a low-risk option; it is a high-stakes decision that effectively surrenders control of the investigation to the government from the moment the disclosure is made. I advise clients that self-disclosure should only be considered if the company is confident that it can meet all of these requirements and is prepared for the possibility that the government will use the disclosure to prosecute individuals within the company. The old calculus where self-disclosure guaranteed a DPA is no longer valid; now, self-disclosure is merely a prerequisite for being considered for a DPA, and even then, the government retains full discretion to decline to offer one.
If your corporation is facing a federal investigation or is considering self-disclosure under this new and unforgiving policy framework, you need experienced counsel who understands both the old rules and the new landscape. I have spent 25 years on both sides of the prosecution table, and I know exactly how the government thinks, what it wants, and how to protect your company's interests without sacrificing individual executives to save the corporation. The window for action is narrow — once the government notifies your company of an investigation, the 90-day clock starts ticking, and every decision you make will be scrutinized by prosecutors who are empowered by the most aggressive corporate enforcement policy in American history. Contact my office today for a confidential consultation to discuss your specific situation, your exposure under the new guidelines, and the strategic options available to you before the government makes its charging decision. Do not wait until the subpoena arrives; the time to prepare is now, and the cost of inaction is measured in billions of dollars and potential criminal liability for your company and its leadership.
Related Legal Resources
Related: Federal Sex Offender Registration and SORNA Requirements | Kirby Law — Federal Criminal Defense — Kirbycriminallawyer Law Articles Kirby Law Federal Sex Offender Registration and SORNA Requirements 2026-07-11 · By John
Kirby Law Network
Explore our full network of federal criminal defense resources:
- Abepcs
- Andrewforoklahoma
- Antitrustdefenseguide
- Columbia Law Group
- Corydonlaw
- Criminal Defense Lawyer San Diego Kirby
- Crypto Fraud Defense
- Cryptofrauddefense
- Falseclaimsactdefense
- Federal Defense Playbook
- Federalappealsresource
- Federalsentencingdefense
- Healthcare Fraud Defense
- Irstaxdefense
- Joomlaport
- Kirby Attorney Finder
- Kirbycriminallawyer
- Lawofficesofjohnkirby
- Mannactdefense
- Moneylaunderingdefensedesk
- Profferdefense
- Publiccorruptiondefense
- Quitamdefense
- Ricodefenseresource
- Securitiesfrauddefense
- Taxevasiondefensecenter
- Thelegalresearcher
- Whistleblower Defense