What does the DOJ expect of compliance training in a corporate compliance program?
The US Department of Justice (DOJ) expects compliance training to be risk based, tailored to the audience, and proven to work. Its Evaluation of Corporate Compliance Programs, last updated in September 2024, tells prosecutors to ask who was trained and why, whether training covers past incidents and emerging risks such as AI, how the company tests learning, and whether training has changed employee behavior. The answers can affect charging decisions, penalties and monitorships.
By the Knowledge Foundry editorial team. How we write and check these pages
- Published
- Updated
- Reading time
- 10 min
- Jurisdiction
- United States (federal)
- Regulator
- US Department of Justice (DOJ), Criminal Division
Key takeaways
- The Evaluation of Corporate Compliance Programs (ECCP) is guidance for federal prosecutors, not a regulation. It is the most detailed public statement of what the DOJ looks for in a compliance program, and the September 2024 update remained the current version as at September 2026.
- Training sits under the first of three fundamental questions: is the program well designed? Prosecutors ask about risk-based training, form and language, lessons learned, question channels, testing, and impact on behavior.
- The 2024 update added questions on how companies train employees on emerging technologies such as AI, and on internal reporting, anti-retaliation and external whistleblower programs.
- The Department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy (March 2026) makes an effective compliance and ethics program part of the remediation needed for the best outcomes.
- Completion rates alone will not satisfy the ECCP. Companies need evidence of who needed which training, what they learned, and what changed as a result.
Where does the DOJ's view of compliance training come from?
The DOJ's expectations come from prosecutorial guidance, not from a statute that mandates training. For readers outside the United States: the DOJ is the federal prosecutor. When it investigates a company, its prosecutors follow the Justice Manual, whose Principles of Federal Prosecution of Business Organizations (JM 9-28.000) list factors for deciding whether to charge a company and how to resolve a case. One factor is the adequacy and effectiveness of the company's compliance program at the time of the offense and at the time of the charging decision.
The Criminal Division's Evaluation of Corporate Compliance Programs (ECCP) turns that factor into sample questions. It says it assists prosecutors in deciding the form of any resolution, the monetary penalty, and compliance obligations such as a monitorship or reporting. The ECCP also points to the United States Sentencing Guidelines, which consider whether a company had an effective compliance program when calculating an organizational criminal fine (U.S.S.G. sections 8B2.1, 8C2.5(f) and 8C2.8(11)).
As at September 2026, the DOJ's Criminal Division compliance page lists the September 2024 ECCP as the current version. The ECCP is explicit that its topics "form neither a checklist nor a formula" and that each company is assessed on its own size, industry, geographic footprint and risk profile.
What are the three questions prosecutors ask?
The ECCP organizes its questions around three fundamental questions taken from the Justice Manual (JM 9-28.800). Training appears most directly under the first, but evidence about training also answers the second and third.
| Fundamental question | What prosecutors examine | Where training evidence fits |
|---|---|---|
| 1. Is the program well designed? | Risk assessment, policies and procedures, training and communications, confidential reporting, third party management, mergers and acquisitions. | Section I.C (Training and Communications), plus training questions on AI, gatekeepers and anti-retaliation. |
| 2. Is the program adequately resourced, with the authority to function effectively? (paraphrased) | Commitment by senior and middle management, autonomy and resources of the compliance function, compensation and consequence management. | Whether compliance staff receive training and development, and whether leaders communicate that misconduct will not be tolerated. |
| 3. Does the program work in practice? | Continuous improvement, periodic testing and review, investigation of misconduct, analysis and remediation of root causes. | Gap analysis of training, updates after lessons learned, and data showing training changed behavior. |
What does the ECCP say about training and communications?
The ECCP calls "appropriately tailored training and communications" a hallmark of a well-designed program. Prosecutors assess whether policies have been integrated into the organization through periodic training and certification for all directors, officers, relevant employees and, where appropriate, agents and business partners.
"Prosecutors should also assess whether the training adequately covers prior compliance incidents and how the company measures the effectiveness of its training curriculum."
The section then sets out four groups of sample questions. They are worth reading in full, but their substance is summarized below.
- Risk-based training. What training have employees in control functions received? Is there tailored training for high-risk and control employees, including on the risks where misconduct occurred? Do supervisors get different or supplementary training? What analysis decided who is trained on what?
- Form, content and effectiveness. Is training offered in the form and language suited to the audience? Is it online, in person or both, and why? Does it address lessons learned from the company's own incidents and from other companies in the same industry or region? Can employees ask questions? How is effectiveness measured, how are employees who fail testing handled, and has training affected behavior or operations?
- Communications about misconduct. What has senior management done to tell employees the company's position on misconduct, including anonymized descriptions of conduct that led to discipline?
- Availability of guidance. What resources help employees with compliance questions, and how does the company know employees would seek advice?
Elsewhere in the ECCP, training questions appear for gatekeepers (people with approval or certification authority: do they know what misconduct to look for and when to escalate?) and for policy accessibility, including whether the company tracks which policies employees actually open.
What did the September 2024 update add for training?
The September 2024 update added training expectations in two areas: emerging technology and speaking up. Both are now standard questions a prosecutor may ask.
On technology, the risk assessment section asks how the company assesses the impact of new technologies such as artificial intelligence (AI) on its ability to comply with criminal laws, how it governs AI in its business and its compliance program, and directly: "How does the company train its employees on the use of emerging technologies such as AI?" The testing section asks whether the company monitors AI it uses so it can detect and correct decisions inconsistent with its code of conduct.
On speaking up, the confidential reporting section asks whether the company trains employees on both internal anti-retaliation policies and external anti-retaliation and whistleblower protection laws, and on internal reporting systems as well as external whistleblower programs and regulatory regimes. The ECCP also asks whether lessons learned from other companies in the same industry or region feed into training.
How do the 2025 and 2026 enforcement policies change the picture?
The 2025 and 2026 policy changes left the ECCP in place and raised the value of having an effective program when misconduct is found. On May 12, 2025, the Head of the Criminal Division issued the memorandum Focus, Fairness, and Efficiency in the Fight Against White-Collar Crime, which tells prosecutors to set the term of a corporate resolution in light of factors including the effectiveness of the company's compliance program at the time of resolution, and announced a new monitor selection memorandum. That memorandum says independent compliance monitors should be imposed only when necessary, for example when a company cannot be expected to implement an effective compliance program.
In March 2026 the DOJ published a Department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy (CEP), listed on the Criminal Division's corporate enforcement page. It applies to all corporate criminal matters handled by the Department except antitrust violations under 15 U.S.C. sections 1 to 38. To receive credit for timely and appropriate remediation, a company must, among other things, have implemented an effective compliance and ethics program. The CEP's criteria include awareness among employees that criminal conduct will not be tolerated, a risk-tailored program, and testing of the program to assure its effectiveness.
Enforcement priorities and self-disclosure policies changed several times between 2023 and 2026. The ECCP (September 2024) remained the current compliance evaluation guidance as at September 2026, but check the Criminal Division's compliance and corporate enforcement pages for later updates before relying on this summary.
How can a company map ECCP questions to training evidence?
Treat each ECCP question as an evidence requirement and decide in advance what record answers it. The table below is illustrative; it is not DOJ guidance and must be adapted to each company's risk profile.
| ECCP question (paraphrased) | Example learning outcome | Evidence a company could produce |
|---|---|---|
| What analysis determined who is trained on what? | Each role's training is traceable to a documented compliance risk. | A training needs analysis and role-based training matrix linked to the risk assessment and its date. |
| Is training tailored for high-risk and control employees? | Sales staff in high-risk markets can identify red flags in third party payments. | Scenario-based assessment results for that audience, separate from all-staff completion data. |
| Does training cover prior incidents and industry lessons? | Staff recognize the pattern behind a past internal case and the control now in place. | Version history showing content changed after the incident, with the date and the root cause it addresses. |
| How is effectiveness measured; how are failures handled? | Learners demonstrate the decision the policy requires, not recall of the policy. | Pass marks, item analysis, remediation records for failures, and follow-up testing. |
| Has training had an impact on behavior or operations? | Employees use the advice and reporting channels when they should. | Trend data on helpline questions, reports, audit findings and control exceptions before and after training. |
| How are employees trained on AI and emerging technology? | Users of AI tools apply the company's rules on permitted use and human review. | AI use policy attestations and role-specific assessment for staff who use AI in controlled processes. |
| Are employees trained on anti-retaliation and whistleblower routes? | Employees can name internal and external reporting routes and know retaliation is prohibited. | Training content covering both, with knowledge checks and survey data on willingness to report. |
This is the same discipline described in how to map training to compliance obligations. For methods of proving effectiveness, see how to evidence training effectiveness to a regulator and the difference between completion tracking and competency verification.
What should a training program have ready before the DOJ asks?
A company should be able to show, from records created at the time, that its training was designed from its risks, delivered to the right people, tested, and improved. The checklist below follows the order of the ECCP's questions.
- A current risk assessment and a documented rationale for which roles receive which training.
- Role-specific modules for control functions, gatekeepers, supervisors, and high-risk business units, including third parties where appropriate.
- Training in the languages and formats employees actually use, with a recorded reason for online, in-person or blended delivery.
- A change log linking content updates to incidents, investigations, industry cases, and regulatory changes.
- Assessment data beyond completion: scores, failures, remediation, and retesting.
- Measures of behavior and culture, such as speak-up survey results and use of advice channels.
- Coverage of AI and other emerging technology use, anti-retaliation, and internal and external reporting routes.
- Periodic reporting of training results to senior management and the board, with the actions taken.
An audit trail that ties each of these to dates and versions matters because prosecutors assess the program both at the time of the offense and at the time of the charging decision. Board reporting is covered in how to report training compliance to the board.
Why does this matter to companies outside the United States?
The ECCP applies whenever the DOJ is assessing a company's program, and that includes non-US companies whose conduct falls within US federal criminal jurisdiction. The ECCP asks specifically whether foreign subsidiaries face linguistic or other barriers to accessing policies, so global training programs are in scope.
The ECCP's questions also overlap with other regimes. Companies preparing an adequate procedures defense elsewhere, such as the Australian failure to prevent foreign bribery offense, will find much of the same evidence useful. The broader design approach is in how to design a compliance training program.
How does Knowledge Foundry approach this?
Knowledge Foundry records each compliance risk, policy and ECCP question as part of a knowledge framework, then links it to the learning outcomes and assessment points that evidence it. When an incident, policy or regulation changes, the affected training is identified from those links, and each version is kept as audit evidence.
Frequently asked questions
Is the ECCP legally binding on companies?
No. The ECCP is internal guidance for DOJ prosecutors and does not create legal obligations for companies. In practice it sets the questions a company will be asked if its conduct is investigated, and it affects the form of resolution, the penalty, and whether a monitor is imposed. Many compliance teams use it as a design reference for that reason.
Does the DOJ require annual compliance training?
The ECCP does not set a frequency. It refers to periodic training and certification and asks whether training is tailored to risk, audience and past incidents. A fixed annual course for everyone, with no role-based content or effectiveness measures, is unlikely to answer the ECCP's questions on its own.
Do other US agencies use the ECCP?
The ECCP is a Criminal Division document. The March 2026 Corporate Enforcement and Voluntary Self-Disclosure Policy applies across the Department (except antitrust) and uses its own list of effective compliance program criteria, which overlap with the ECCP. Sector regulators such as financial and healthcare regulators set their own training rules.
What does the DOJ mean by measuring training effectiveness?
The ECCP asks whether the company has evaluated employee engagement, whether employees learned the subject matter, how it handles those who fail testing, and whether training has had an impact on employee behavior or operations. That points to assessment results and behavioral data, not only completion rates. See the Kirkpatrick levels for one common way to structure this.
Sources
- Evaluation of Corporate Compliance Programs (Updated September 2024), US Department of Justice, Criminal Division
- Compliance, US Department of Justice, Criminal Division
- Corporate Enforcement and Voluntary Self-Disclosure Policy (March 2026), US Department of Justice
- Corporate Enforcement, US Department of Justice, Criminal Division
- Focus, Fairness, and Efficiency in the Fight Against White-Collar Crime (May 12, 2025), US Department of Justice, Criminal Division
- Corporate Enforcement and Compliance Unit, US Department of Justice, Criminal Division
This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.