Skip to content
Tiatra, LLCTiatra, LLC
Tiatra, LLC
Information Technology Solutions for Washington, DC Government Agencies
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact
 
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact

DoJ gets tough on evaluation of corporate compliance

There are now strict new rules CIOs and other senior executives need to adhere to after the US Department of Justice (DoJ) this week released an update to its Evaluation of Corporate Compliance Programs (ECCP) guidance.

The changes, which were announced Monday by Principal Deputy Assistant Attorney General Nicole M. Argentieri in Grapevine, Texas, will, according to a Gartner advisory released on Wednesday, mean that “compliance leaders are facing heightened expectations to provide clear guidance on the responsible use of AI for their employees.”

In her address to members of the Society of Corporate Compliance and Ethics (SCCE), Argentieri focused on the ECCP update, and said it “includes an evaluation of how companies are assessing and managing risk related to the use of new technology such as artificial intelligence, both in their business and in their compliance programs.”

Under the ECCP, she added, “prosecutors will consider the technology that a company and its employees use to conduct business, whether the company has conducted a risk assessment of the use of that technology, and whether the company has taken appropriate steps to mitigate any risk associated with the use of that technology.”

Argentieri said, “we have also updated the ECCP to expand upon an important concept — that companies should be learning lessons, from both the company’s own prior misconduct and from issues at other companies, to update their compliance programs and train employees.”

Further to that, the update states, “this document is meant to assist prosecutors in making informed decisions as to whether, and to what extent, the corporation’s compliance program was effective at the time of the offense … for purposes of determining the appropriate form of any resolution or prosecution; monetary penalty, if any; and compliance obligations contained in any corporate criminal resolution.”

It goes on to say that, during the course of an investigation, there are three fundamental questions a prosecutor should ask: Is the corporation’s compliance program well designed? Is the program being applied earnestly? (In other words, is the program adequately resourced and empowered to function effectively?) Does the corporation’s compliance program work in practice?

Beyond that, there are other supplemental questions that will be asked and answered, such as “how does a company assess the potential impact of new technologies, such as on its ability to comply with criminal laws? What is the company’s approach to governance regarding the use of new technologies such as AI in its commercial business and in its compliance program? What baseline of human decision-making is used to assess AI? How is accountability over use of AI monitored and enforced?”

Argentieri ended her speech thusly: “Companies that step up and own up to misconduct send a powerful message about the importance of a robust compliance program and ethical corporate culture. I hope you will take this message back to your companies: Now is the time to make the necessary compliance investments to help prevent, detect, and remediate misconduct. And when you uncover misconduct, call us before we call you.”

The law firm of Crowell & Moring, headquartered in Washington, DC, addressed the update on its website, and in one of two key takeaways said, “the updated ECCP highlights the DoJ’s growing expectations for corporate compliance programs and personnel in an environment with changing technology and business pressures, and it directs prosecutors to consider whether corporate compliance programs are reactive or proactive.”

It described the update as “an evergreen reminder that companies should continually reassess their compliance programs to ensure they are keeping pace with the organization’s risk profile — including risks presented by technological advances.”   

Peter Eyre, a partner with the firm, said Thursday, “there have been a series of speeches, memos, press events, where DoJ is highlighting the importance of compliance in terms of the overall approach it takes to enforcement. And there are some notable changes in this September 23 version over the prior version. I do not think it is really out of step at all with what they have said before. It emphasizes and shifts the focus onto some new areas consistent with prior public announcements that office has made.”

It is, he said, a “good opportunity for companies that have not refreshed their compliance and risk assessments in some time to do [so], recognizing these new areas of focus and key takeaways from the DoJ discussion.”

Lauren Kornutick, director analyst in the Gartner legal and compliance practice, said, “incorporating AI guidance into an organization’s codes of conduct is critical. These codes act as a comprehensive resource for employees seeking corporate direction, and for stakeholders monitoring a firm’s governance.”

She wrote in a Gartner Q&A that the reason for compliance leaders to consider adding AI guidance to their code is threefold:

  • Prevalent use of AI: The average employee now has access to AI, and without guardrails, they may give away sensitive data, make biased decisions, or use the technology to draft misleading or deceiving communications with customers.
  • Increased regulatory scrutiny: With warnings from the US Department of Justice against AI-facilitated misconduct, as well as new global regulations and government orders, appearing oblivious to these compliance obligations is not an option.
  • Growing stakeholder demand for transparency: Investors, suppliers, customers, and other external stakeholders demand to know more about the guardrails being placed around companies’ use of AI. 

Kornutick said in an interview that CIOs are “so tasked with executing on strategic vision — and that is OK — for you want them to be able to innovate and innovate safely. [The update] is a wakeup call that you need to build an empathetic partnership between the CIO and CDAO back to compliance.”

Compliance, she said, “on one hand, can actually help them deploy these new technologies safely. But the compliance teams are also going to need [a CIO’s] help with access to data to build out their compliance monitoring program. What this guidance does is it really brings it to life that, if that partnership does not yet exist, and the compliance team and legal team do not have a seat at the CIO’s table on strategic vision, now is a good time to facilitate that partnership.”


Read More from This Article: DoJ gets tough on evaluation of corporate compliance
Source: News

Category: NewsSeptember 27, 2024
Tags: art

Post navigation

PreviousPrevious post:인텔코리아 수장 바뀐다··· 배태원 신임 사장 선임NextNext post:CISO viewpoint part 2: Finding pearls among perils with AI productivity solutions

Related posts

휴먼컨설팅그룹, HR 솔루션 ‘휴넬’ 업그레이드 발표
May 9, 2025
Epicor expands AI offerings, launches new green initiative
May 9, 2025
MS도 합류··· 구글의 A2A 프로토콜, AI 에이전트 분야의 공용어 될까?
May 9, 2025
오픈AI, 아시아 4국에 데이터 레지던시 도입··· 한국 기업 데이터는 한국 서버에 저장
May 9, 2025
SAS supercharges Viya platform with AI agents, copilots, and synthetic data tools
May 8, 2025
IBM aims to set industry standard for enterprise AI with ITBench SaaS launch
May 8, 2025
Recent Posts
  • 휴먼컨설팅그룹, HR 솔루션 ‘휴넬’ 업그레이드 발표
  • Epicor expands AI offerings, launches new green initiative
  • MS도 합류··· 구글의 A2A 프로토콜, AI 에이전트 분야의 공용어 될까?
  • 오픈AI, 아시아 4국에 데이터 레지던시 도입··· 한국 기업 데이터는 한국 서버에 저장
  • SAS supercharges Viya platform with AI agents, copilots, and synthetic data tools
Recent Comments
    Archives
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • June 2020
    • May 2020
    • April 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019
    • June 2019
    • May 2019
    • April 2019
    • March 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • October 2018
    • September 2018
    • August 2018
    • July 2018
    • June 2018
    • May 2018
    • April 2018
    • March 2018
    • February 2018
    • January 2018
    • December 2017
    • November 2017
    • October 2017
    • September 2017
    • August 2017
    • July 2017
    • June 2017
    • May 2017
    • April 2017
    • March 2017
    • February 2017
    • January 2017
    Categories
    • News
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Tiatra LLC.

    Tiatra, LLC, based in the Washington, DC metropolitan area, proudly serves federal government agencies, organizations that work with the government and other commercial businesses and organizations. Tiatra specializes in a broad range of information technology (IT) development and management services incorporating solid engineering, attention to client needs, and meeting or exceeding any security parameters required. Our small yet innovative company is structured with a full complement of the necessary technical experts, working with hands-on management, to provide a high level of service and competitive pricing for your systems and engineering requirements.

    Find us on:

    FacebookTwitterLinkedin

    Submitclear

    Tiatra, LLC
    Copyright 2016. All rights reserved.