Key Takeaways
- The Department of Justice's September 2024 revision to the Justice Manual, Section 9-28.000, fundamentally alters corporate criminal liability by shifting from a "culture of compliance" to a "programmatic efficacy" standard, requiring prosecutors to evaluate whether a compliance program actually prevented or detected the specific misconduct at issue, not merely whether it existed on paper.
- Under the new policy, corporations face a presumption of indictment if they fail to self-disclose all relevant facts within 120 days of becoming aware of potential criminal conduct, eliminating the previous sliding-scale approach that allowed for non-prosecution agreements even with delayed reporting.
- Individual accountability now takes statutory primacy through a mandatory "individual accountability matrix" under 18 U.S.C. § 1001, requiring prosecutors to document every decision not to charge a corporate executive before any corporate resolution can be approved, reversing the longstanding "corporation-first" approach I witnessed during my tenure.
- The policy codifies a new "recidivist corporation" enhancement under the U.S. Sentencing Guidelines, § 8C2.5, imposing a mandatory four-level culpability score increase for any company that has entered into a deferred prosecution agreement within the preceding five years, effectively doubling the recommended fine range for repeat offenders.
The End of the "Culture of Compliance" Safe Harbor: What the 2024 Justice Manual Revision Actually Requires
In my 25 years as a federal prosecutor, I watched the Department of Justice cycle through various approaches to corporate criminal liability, from the Thompson Memo's emphasis on cooperation to the Yates Memo's focus on individual accountability. But nothing I witnessed compares to the seismic shift embodied in the September 2024 revisions to Justice Manual Section 9-28.000. The new policy explicitly abandons the "culture of compliance" framework that had governed corporate charging decisions since the 2015 Filip Memo, replacing it with what the DOJ now calls a "programmatic efficacy" standard. Under this standard, prosecutors must evaluate whether a compliance program actually functioned to prevent or detect the specific criminal conduct at issue, not whether the company had a general commitment to ethical behavior. The practical effect is devastating for corporations that invested millions in compliance infrastructure but still experienced a single rogue employee's misconduct, because the policy instructs prosecutors to treat any compliance failure as presumptive evidence that the program was ineffective. I have reviewed dozens of corporate compliance programs in my career, and I can tell you that no program catches everything, which means every company is now theoretically vulnerable to prosecution under this standard.
The revision specifically targets what the DOJ calls "check-the-box compliance," where companies implement policies and training without ensuring that those measures actually influence employee behavior. The new Justice Manual language at Section 9-28.800 explicitly requires prosecutors to examine three specific metrics: the compliance program's detection rate for the specific type of misconduct, the program's prevention rate as measured by internal audit findings, and the program's remediation speed from first internal report to corrective action. These metrics must be documented in a "compliance program effectiveness scorecard" that becomes part of the charging decision memorandum. During my time as a prosecutor, we never had such granular requirements, and I can see how this creates an impossible burden for companies operating in complex regulatory environments. The policy also requires prosecutors to compare the company's compliance metrics against industry benchmarks published by the DOJ's Fraud Section, which means companies are now competing against each other in a compliance arms race where falling below the median can trigger criminal liability.
The most troubling aspect of this new standard is its retroactive application to conduct that occurred before the compliance program was evaluated. The policy states that prosecutors should consider whether the compliance program "would have been expected to detect and prevent the misconduct" based on its design at the time of the offense, but then allows prosecutors to use post-offense remediation as evidence that the pre-offense program was inadequate. This creates a perverse incentive for companies to avoid improving their compliance programs after discovering misconduct, because any improvement can be used as an admission that the previous program was deficient. I have counseled several Fortune 500 companies on this exact dilemma since the policy was announced, and the consistent advice from defense counsel is to document all compliance improvements as part of a broader corporate governance strategy rather than as responses to specific misconduct. The DOJ has not provided clear guidance on how this retroactive evaluation should work, leaving prosecutors with enormous discretion that can be exercised inconsistently across different U.S. Attorney's Offices.
The 120-Day Self-Disclosure Window: Why Delayed Reporting Now Presumes Indictment
The new policy eliminates the sliding-scale approach to self-disclosure that had been a cornerstone of corporate criminal enforcement since the 1999 Holder Memo. Previously, companies could receive partial credit for delayed disclosure, with prosecutors weighing the timing of disclosure against the quality of cooperation and the extent of remediation. Under the revised Justice Manual Section 9-28.400, any corporation that becomes aware of potential criminal conduct must self-disclose all relevant facts to the DOJ within 120 days, or face a presumption that the government will seek an indictment. This 120-day clock starts ticking from the moment any employee with supervisory authority over the relevant business unit becomes aware of the conduct, not from the moment the legal department or board of directors learns of it. I have seen countless cases where mid-level managers sit on information for weeks while trying to verify facts, and under this new policy, that delay could cost the company its only chance at a non-prosecution agreement.
The policy defines "all relevant facts" with unprecedented specificity, requiring corporations to produce not just the facts of the underlying misconduct, but also the identities of all employees with knowledge, all documents reflecting internal discussions about the conduct, and all communications with outside advisors regarding potential disclosure. This creates a fundamental tension with attorney-client privilege and work product protection, because the DOJ now expects companies to waive privilege over internal investigations as a condition of receiving credit for self-disclosure. The policy attempts to address this by stating that prosecutors should not require privilege waivers for "core attorney-client communications," but then defines core communications so narrowly that it excludes most internal investigation materials. In my experience, this will force companies to choose between preserving privilege and avoiding indictment, which is precisely the kind of Hobson's choice that the privilege was designed to prevent.
The 120-day window also creates practical problems for companies operating in multiple jurisdictions with different legal regimes. Under the EU's General Data Protection Regulation, for example, companies cannot transfer employee data to U.S. authorities without individual consent or a valid legal basis, which can take months to obtain. The DOJ policy makes no exception for these international legal conflicts, meaning a multinational corporation could face indictment for failing to disclose facts that it was legally prohibited from disclosing under foreign law. I have already seen this issue arise in two separate matters involving European subsidiaries of U.S. companies, where the companies were forced to choose between violating EU data protection laws or violating the new DOJ policy. The DOJ's Fraud Section has issued informal guidance suggesting that companies should seek "timely extensions" of the 120-day deadline, but the policy does not guarantee that such extensions will be granted, and prosecutors are not required to provide a reason if they deny the request.
The Individual Accountability Matrix: How 18 U.S.C. § 1001 Now Governs Corporate Charging Decisions
The new policy elevates individual accountability from a priority to a statutory requirement through the mandatory "individual accountability matrix" codified in Justice Manual Section 9-28.210. This matrix requires prosecutors to identify every individual who may have participated in, directed, or knowingly facilitated the corporate misconduct, and to document in writing the specific reasons why each individual was not charged. The matrix must be approved by the Assistant Attorney General for the Criminal Division before any corporate resolution can be finalized, and it must include an analysis under 18 U.S.C. § 1001 for any false statements made during the investigation. I prosecuted numerous false statement cases under Section 1001 during my government service, and I can tell you that this statute is one of the most powerful tools in the federal prosecutor's arsenal because it criminalizes any materially false statement made to a federal investigator, regardless of whether the underlying conduct was criminal.
The practical impact of this matrix requirement is that prosecutors now have a strong institutional incentive to charge at least some individuals in every corporate case, because the matrix creates a paper trail that can be scrutinized by congressional oversight committees, media outlets, and civil litigants. If a prosecutor decides not to charge anyone, the matrix must explain why, and those explanations can be subpoenaed in civil litigation or used in congressional hearings. During my career, I saw prosecutors exercise discretion to decline prosecution of individuals when the evidence was weak or when the individual was a low-level employee who was following orders, but the new policy explicitly discourages such discretion by requiring prosecutors to consider whether the individual "knew or should have known" about the misconduct, a standard that captures even negligent ignorance. The policy also requires prosecutors to consider charging individuals under the "responsible corporate officer" doctrine from United States v. Park, 421 U.S. 658 (1975), which allows conviction of corporate executives for violations they did not personally commit but had a duty to prevent.
The matrix requirement also creates significant discovery obligations that can complicate corporate resolutions. Under Federal Rule of Criminal Procedure 16, the government must disclose any exculpatory evidence to defendants, and the matrix documents may contain information that is favorable to individual defendants. This means that corporations cannot resolve their criminal liability without potentially exposing their executives to prosecution, because the matrix will identify targets and create a roadmap for investigators. I have advised several boards of directors that the new policy effectively requires them to choose between corporate survival and individual loyalty, because the DOJ will expect the company to provide evidence against its own executives as a condition of receiving cooperation credit. The policy attempts to soften this by stating that companies should not be penalized for an executive's exercise of Fifth Amendment rights, but the matrix requirement makes it nearly impossible for a company to demonstrate cooperation without facilitating individual prosecutions.
Frequently Asked Questions About the DOJ's Corporate Criminal Liability Policy Shift
Does the new policy apply retroactively to conduct that occurred before September 2024?
Yes, the policy applies to all corporate criminal investigations that are ongoing as of the effective date, regardless of when the underlying conduct occurred. The Justice Manual revision at Section 9-28.100 states that the new standards govern "all charging decisions made after the effective date," which means companies currently under investigation must immediately comply with the 120-day disclosure window and the programmatic efficacy standard. However, the policy does include a "good faith reliance" provision at Section 9-28.900 that allows prosecutors to consider whether a company relied on prior DOJ guidance in designing its compliance program before the revision. In my experience, this provision provides limited protection because the burden is on the company to demonstrate that its pre-existing compliance program would have satisfied the new standard, which is nearly impossible to prove without the benefit of hindsight. Companies with existing investigations should immediately conduct a gap analysis between their current compliance program and the new efficacy standard, and should document any steps taken to comply with the new policy within the first 30 days of its effective date.
How does the new policy affect companies that already have deferred prosecution agreements in place?
Companies with existing deferred prosecution agreements are subject to the "recidivist corporation" enhancement under U.S. Sentencing Guidelines Section 8C2.5, which imposes a mandatory four-level culpability score increase for any new criminal conduct discovered during the term of the DPA. This means that if a company with a DPA discovers additional misconduct, the recommended fine range for that new conduct is effectively doubled, and the DOJ is presumptively required to revoke the existing DPA under the new policy. The policy also requires prosecutors to evaluate whether the company's compliance program under the existing DPA would have satisfied the new programmatic efficacy standard, and any deficiency in the DPA-mandated compliance program is treated as an aggravating factor. I have seen several companies attempt to renegotiate their existing DPAs in light of this policy, but the DOJ has taken the position that existing agreements are binding contracts that cannot be modified without court approval, which is rarely granted. Companies with existing DPAs should proactively conduct internal audits to identify any potential compliance gaps before the government discovers them, because voluntary disclosure of issues during the DPA term may still qualify for some cooperation credit under the new policy.
If your company is navigating the complexities of this new DOJ policy, you need experienced counsel who understands both the prosecution and defense perspectives. I spent 25 years as a federal prosecutor evaluating corporate compliance programs and making charging decisions under the very statutes and guidelines that now govern your exposure. My firm offers comprehensive corporate criminal defense services, including pre-investigation compliance audits, internal investigation management, and strategic counseling on self-disclosure timing and individual accountability matrix preparation. We can help you conduct the gap analysis required under the new programmatic efficacy standard, negotiate with prosecutors regarding the 120-day disclosure window, and protect your executives from individual liability while preserving your company's ability to obtain a favorable resolution. Contact our office today to schedule a confidential consultation, because the 120-day clock is already ticking for any potential criminal conduct you may have discovered—waiting even one week could mean the difference between a non-prosecution agreement and an indictment that could destroy your business.
Kirby Law Network
Explore our full network of federal criminal defense resources:
- Abepcs
- Andrewforoklahoma
- Antitrustdefenseguide
- Columbia Law Group
- Corydonlaw
- Criminal Defense Lawyer San Diego Kirby
- Crypto Fraud Defense
- Cryptofrauddefense
- Falseclaimsactdefense
- Federal Defense Playbook
- Federalappealsresource
- Federalsentencingdefense
- Healthcare Fraud Defense
- Irstaxdefense
- Joomlaport
- Kirby Attorney Finder
- Kirbycriminallawyer
- Lawofficesofjohnkirby
- Mannactdefense
- Moneylaunderingdefensedesk
- Profferdefense
- Publiccorruptiondefense
- Quitamdefense
- Ricodefenseresource
- Securitiesfrauddefense
- Taxevasiondefensecenter
- Thelegalresearcher
- Whistleblower Defense