Key Takeaways
- The September 2022 Department of Justice policy revision, codified in the Justice Manual Section 9-28.000, fundamentally shifts corporate criminal liability from a strict respondeat superior model to a more nuanced evaluation of the corporation's compliance program and self-reporting efforts at the charging decision stage.
- Under the new framework, prosecutors must now consider the "adequacy and effectiveness" of a corporation's compliance program at the time of the offense, not merely at the time of charging, which creates a powerful incentive for companies to maintain robust, continuously monitored internal controls.
- The policy formally incorporates the "Yates Memo" requirement that corporations disclose all individual wrongdoers to qualify for cooperation credit, but adds a critical new layer: prosecutors must now evaluate whether the corporation engaged in "meaningful" self-policing and remediation before any government investigation began.
- This rewrite creates a rebuttable presumption against prosecution for companies that can demonstrate a pre-existing, effective compliance program and voluntarily self-disclose misconduct within a "reasonable time" of discovery, a standard that draws directly from the U.S. Sentencing Guidelines Chapter Eight factors.
The DOJ's Quiet Revolution: How Section 9-28.000 Rewrote the Rules of Corporate Accountability
In my 25 years as a federal prosecutor, I witnessed firsthand how the Department of Justice wielded the formidable weapon of corporate criminal liability under the doctrine of respondeat superior. For decades, any rogue employee acting within the scope of employment could expose an entire corporation to criminal charges, regardless of the company's good-faith compliance efforts. The September 2022 policy revision, formally codified in Justice Manual Section 9-28.000, represents what I consider the most significant shift in federal corporate prosecution policy since the Holder Memo of 1999. This new framework does not eliminate respondeat superior, but it fundamentally rewrites how prosecutors evaluate whether to exercise their charging discretion against corporate entities. The policy now requires a rigorous, multi-factor analysis that prioritizes the existence and efficacy of a corporation's compliance program at the precise moment the misconduct occurred, not merely at the time of the government's investigation.
The legal reasoning behind this shift is both pragmatic and principled. From a pragmatic standpoint, the DOJ recognized that the old model created perverse incentives: corporations would invest heavily in crisis management after an investigation began but had little structural motivation to invest in prevention before any wrongdoing surfaced. The new policy directly addresses this by making the pre-existing compliance program the central determinant of whether prosecution is appropriate. From a principled perspective, the policy acknowledges that punishing shareholders and innocent employees for the acts of a single bad actor often serves no legitimate deterrent purpose. The policy draws heavily on the U.S. Sentencing Guidelines, specifically U.S.S.G. § 8B2.1, which has long provided a framework for evaluating effective compliance and ethics programs. By incorporating these guidelines directly into the charging analysis, the DOJ has effectively elevated compliance from a mitigating factor at sentencing to a determinative factor at the charging stage.
The practical implications for corporate defendants are enormous. Under the old regime, a corporation could be indicted even with a gold-standard compliance program if a single mid-level manager committed fraud. The new policy creates a clear pathway to declination for companies that can demonstrate three critical elements: a genuinely effective compliance program in place before the misconduct, voluntary self-disclosure within a reasonable time after discovery, and full cooperation including identification of all individual wrongdoers. The policy explicitly states that prosecutors should consider whether the corporation "engaged in meaningful self-policing and remediation before any government investigation began," language that I believe was deliberately chosen to incentivize proactive internal investigations. This represents a complete inversion of the old paradigm, where corporations waited for a subpoena before conducting any serious internal review.
The policy's reliance on the "adequacy and effectiveness" standard creates both opportunities and pitfalls for defense counsel. The term "adequacy" is borrowed directly from U.S.S.G. § 8B2.1(a), which requires that a compliance program be "reasonably designed, implemented, and enforced so that it is generally effective in preventing and detecting criminal conduct." The DOJ's own Evaluation of Corporate Compliance Programs guidance, updated in March 2023, provides a detailed 12-factor test that prosecutors must apply. In my experience representing corporate clients, the most critical factor is whether the compliance program is tailored to the specific risks of the company's industry, size, and geographic footprint. A boilerplate compliance manual downloaded from the internet will not suffice; the program must demonstrate genuine integration with the company's operations, including regular risk assessments, confidential reporting mechanisms, and disciplinary measures for non-compliance that are consistently enforced.
The Individual Accountability Mandate: How the Policy Revives and Expands the Yates Memo's Core Requirements
The September 2022 policy rewrite does not exist in a vacuum; it explicitly builds upon and expands the individual accountability requirements first articulated in the September 2015 Yates Memo. Deputy Attorney General Sally Yates's memorandum directed that corporations must disclose all relevant facts about individual wrongdoers to qualify for any cooperation credit, a standard that many defense practitioners initially viewed as an overreach. The new policy goes further by requiring that this disclosure be "complete and timely" and that the corporation must provide all non-privileged information about individuals "regardless of their position, status, or seniority." In my practice, I have seen corporations struggle with this requirement when the wrongdoer is a senior executive or a top revenue producer, but the policy leaves no room for selective disclosure. The DOJ has made clear that partial cooperation is no cooperation at all, and a corporation that shields a valuable employee will forfeit all consideration for a declination or deferred prosecution agreement.
The legal reasoning behind this expanded individual accountability mandate rests on two pillars: deterrence and fairness. The deterrence rationale is straightforward: corporate prosecutions alone rarely deter individual misconduct because the corporation bears the financial penalty while the individual actors often remain untouched. By conditioning corporate leniency on the identification and prosecution of individuals, the policy aims to ensure that the actual decision-makers face personal consequences. The fairness rationale is equally compelling: it is fundamentally unjust to allow a corporation to pay a fine while the executives who orchestrated the fraud escape accountability entirely. The policy explicitly cites the principle that "individual accountability is the most effective deterrent to corporate misconduct," a statement that I believe reflects a genuine shift in prosecutorial philosophy. In my years as a prosecutor, I saw too many cases where corporations paid millions in penalties while the individuals who committed the underlying crimes walked away with their bonuses intact.
The practical mechanics of this requirement are complex and require careful navigation. The policy requires that corporations provide "all facts relevant to the misconduct" including "all information about individuals involved in or responsible for the misconduct." This includes not only the direct perpetrators but also supervisors who knew or should have known about the misconduct and failed to act. The policy explicitly states that the corporation must provide "all non-privileged information" and cannot use attorney-client privilege or work product protection as a shield to withhold factual information. However, the policy does recognize that corporations may need to conduct internal investigations under the protection of counsel, and it provides that the government will not demand disclosure of privileged communications themselves. The line between factual information and privileged legal advice is often blurry, and I advise my corporate clients to carefully document their internal investigations to clearly separate factual findings from legal analysis.
The timing of individual disclosure is also critical under the new policy. The policy requires that disclosure occur "as soon as practicable" after the corporation discovers the misconduct, and it specifically warns that delays in identifying individuals will be viewed negatively. This creates a significant tension with the corporation's need to conduct a thorough investigation before making any disclosures. In my experience, the safest approach is to begin an internal investigation immediately upon discovering potential misconduct, using a cross-functional team that includes legal, compliance, and forensic accounting professionals. The corporation should then make an initial disclosure to the government within 30 to 45 days, even if the investigation is not complete, and provide regular updates as new information emerges. The policy rewards this approach by providing that "timely and proactive disclosure" will be considered a significant mitigating factor at the charging decision stage.
Navigating the New Compliance Evaluation Framework: From Paper Programs to Living Systems
The most transformative aspect of the September 2022 policy rewrite is its elevation of the compliance program evaluation from a post-hoc analysis to a pre-charging determinative factor. Under the old framework, prosecutors would evaluate a compliance program primarily at the sentencing stage, after a conviction or guilty plea had already been secured. The new policy requires prosecutors to evaluate the compliance program at the very beginning of the charging analysis, before any indictment is sought. This evaluation is governed by the DOJ's Criminal Division's "Evaluation of Corporate Compliance Programs" guidance, which was updated in March 2023 to reflect the new policy's emphasis on pre-existing programs. The guidance asks three fundamental questions: Is the corporation's compliance program well-designed? Is it being applied earnestly and in good faith? Does it work in practice? These questions move the analysis far beyond the old "paper program" standard, where companies could satisfy requirements by having a compliance manual that nobody actually read.
The "well-designed" prong requires prosecutors to examine whether the compliance program is tailored to the corporation's specific risk profile. This means analyzing the company's industry, geographic footprint, regulatory environment, and business model to determine whether the program addresses the actual risks the company faces. For example, a pharmaceutical company with international operations would need a compliance program that addresses the Foreign Corrupt Practices Act, 15 U.S.C. §§ 78dd-1 et seq., while a financial institution would need robust anti-money laundering controls under the Bank Secrecy Act, 31 U.S.C. § 5311 et seq. The policy specifically requires that compliance programs include "periodic risk assessments" that are updated to reflect changes in the company's operations and the regulatory landscape. In my practice, I have seen companies fail this prong because they conducted a single risk assessment when the program was created and never updated it, even as the company expanded into new markets or acquired new business lines.
The "application in good faith" prong examines whether the compliance program is actually being implemented, not just documented. This requires evidence that the company has dedicated adequate resources to compliance, including sufficient staffing, budget, and authority for the compliance function. The policy specifically looks at whether compliance officers have direct access to the board of directors and whether they have the independence to raise concerns without fear of retaliation. The policy also examines whether the company has a system for confidential reporting of potential misconduct, such as an anonymous hotline, and whether employees actually use it. In one case I handled, a company had a hotline that received zero reports in three years, which the government correctly viewed as evidence that employees did not trust the system rather than evidence that no misconduct occurred. The policy requires that companies actively promote their reporting mechanisms and take all reports seriously, regardless of the source.
The "works in practice" prong is perhaps the most demanding, as it requires the company to demonstrate that its compliance program has actually prevented or detected misconduct. This is where many companies stumble, because it requires evidence of continuous monitoring and testing. The policy looks at whether the company conducts regular audits of its compliance controls, whether it uses data analytics to identify patterns of potential misconduct, and whether it takes corrective action when problems are identified. The policy also examines the company's response to past misconduct: did the company discipline the wrongdoers, remediate the root causes, and make changes to prevent recurrence? In my experience, companies that can demonstrate a pattern of identifying and addressing compliance issues before the government gets involved are far more likely to receive favorable treatment. The policy explicitly states that "a culture of compliance" is the ultimate goal, and that companies must show that compliance is a core value, not just a box-checking exercise.
Frequently Asked Questions
Q: Does the new DOJ policy completely eliminate the risk of corporate prosecution if we have a compliance program?
No, the policy does not create a blanket safe harbor for corporations with compliance programs. The policy creates a rebuttable presumption against prosecution only when three conditions are met: the corporation had an effective compliance program in place at the time of the misconduct, the corporation voluntarily self-disclosed the misconduct within a reasonable time, and the corporation provided full cooperation including identification of all individual wrongdoers. If any of these conditions is not fully satisfied, the presumption disappears, and the prosecutor retains full discretion to seek an indictment. Additionally, the policy does not apply to cases involving "significant and pervasive" misconduct that implicates senior leadership, and it does not protect corporations that engaged in obstruction of justice or made false statements to the government. In my experience, the policy provides a powerful incentive for proactive compliance, but it is not a get-out-of-jail-free card.
Q: How does the new policy affect the statute of limitations for corporate crimes?
The policy does not directly change any statute of limitations, which remain governed by the specific federal criminal statutes at issue. Most federal fraud offenses, including wire fraud under 18 U.S.C. § 1343 and mail fraud under 18 U.S.C. § 1341, carry a five-year statute of limitations under 18 U.S.C. § 3282. However, the policy's emphasis on timely self-disclosure creates practical implications for the statute of limitations analysis. If a corporation discovers misconduct and delays self-disclosure, the government may argue that the corporation's delay prejudiced the investigation and use that as a factor supporting prosecution. Conversely, prompt self-disclosure can lead to a deferred prosecution agreement that effectively tolls the statute of limitations while the corporation completes its remediation efforts. I always advise clients that the clock starts ticking from the date of discovery, not the date of the misconduct, and that any delay in self-disclosure should be documented with a clear justification.
Strategic Counsel for Corporate Clients in the New Era
In my 25 years as a federal prosecutor and now as a defense attorney, I have never seen a more favorable policy environment for corporations that take compliance seriously. The September 2022 policy rewrite has fundamentally altered the risk calculus for corporate criminal liability, creating a clear path to declination for companies that invest in robust compliance programs and act promptly when misconduct is discovered. However, the policy also creates significant traps for the unwary. Companies that maintain paper compliance programs without genuine implementation, that delay self-disclosure while conducting internal investigations, or that attempt to shield individual wrongdoers will find themselves facing even harsher treatment than under the old regime. The key is to treat compliance as a living system, not a static document, and to build a culture where every employee understands that ethical conduct is a non-negotiable requirement of employment. If your corporation is facing a potential criminal investigation or wants to ensure your compliance program meets the new standards, I urge you to contact our firm for a confidential assessment. The time to act is now, before the government comes knocking on your door.
Kirby Law Network
Explore our full network of federal criminal defense resources:
- Abepcs
- Andrewforoklahoma
- Antitrustdefenseguide
- Columbia Law Group
- Corydonlaw
- Criminal Defense Lawyer San Diego Kirby
- Crypto Fraud Defense
- Cryptofrauddefense
- Falseclaimsactdefense
- Federal Defense Playbook
- Federalappealsresource
- Federalsentencingdefense
- Healthcare Fraud Defense
- Irstaxdefense
- Joomlaport
- Kirby Attorney Finder
- Kirbycriminallawyer
- Lawofficesofjohnkirby
- Legallawtopic
- Mannactdefense
- Moneylaunderingdefensedesk
- Profferdefense
- Publiccorruptiondefense
- Quitamdefense
- Ricodefenseresource
- Securitiesfrauddefense
- Taxevasiondefensecenter
- Whistleblower Defense