Compliance operations

Turn obligations into evidence, decisions, and verified remediation

A credible compliance program does not prove effectiveness by accumulating policies. It shows which requirements apply, who owns the resulting risks and controls, what evidence demonstrates operation, how problems are detected, and whether remediation changes outcomes.

Substantively reviewed . This revision corrects DORA article mappings, replaces superseded DOJ references, and separates legal obligations from prosecutorial guidance and sentencing incentives.

Primary sources: DOJ Evaluation of Corporate Compliance Programs (September 2024), DOJ corporate-enforcement materials, 2025 U.S. Sentencing Guidelines Chapter Eight, and EU DORA.

One operating system, multiple scoped authorities

The strongest compliance operations model has a common workflow without pretending that every authority creates the same duty. Statutes and regulations create legal obligations. Supervisory guidance may describe regulator expectations for entities within scope. DOJ's Evaluation of Corporate Compliance Programs (ECCP) is prosecutorial evaluation guidance. U.S. Sentencing Guidelines Chapter Eight creates sentencing incentives and criteria for an effective compliance and ethics program. Those sources can shape the same operating model, but they should remain labeled accurately.

Obligation

What legal, regulatory, contractual, or policy requirement actually applies to the entity, activity, product, or jurisdiction?

Control

What preventive, detective, approval, monitoring, or response mechanism addresses the requirement or underlying risk?

Evidence

What retained record shows the control operated, exceptions were handled, and accountable people reached a defensible conclusion?

Keep the authority map precise

DOJ: program effectiveness, not a universal control checklist

The Criminal Division's current ECCP remains the September 2024 update. It asks prosecutors to evaluate whether a compliance program is well designed, applied earnestly and in good faith, adequately resourced and empowered, and effective in practice. The 2024 update also asks how organizations identify and manage risks from emerging technologies such as artificial intelligence.

DOJ's corporate-enforcement materials have continued to evolve around that document, including a department-wide Corporate Enforcement Policy dated March 10, 2026. Treat the ECCP as an evaluation lens and the enforcement policy as a separate current policy source; do not describe a DOJ questionnaire as if it were a regulation that every company must implement identically.

U.S. Sentencing Guidelines: structural incentives for effective programs

The 2025 Guidelines Manual retains Chapter Eight's organizational framework. Section 8B2.1 describes an effective compliance and ethics program around due diligence, governing-authority oversight, responsible personnel, resources and authority, training, monitoring and auditing, reporting mechanisms, incentives and discipline, response to misconduct, and periodic risk assessment.

For operations teams, the practical value is not a sentencing-score calculation. It is the reminder that an effective program needs governance, resourcing, communication, detection, evaluation, and response working together.

DORA: apply the regulation to in-scope financial entities

DORA has applied since January 17, 2025 to the financial entities and other actors within its scope. Its article structure matters when converting the regulation into a control catalog:

  • Article 5: governance and management-body responsibility for ICT risk arrangements.
  • Article 6: the ICT risk-management framework.
  • Article 17: the ICT-related incident-management process.
  • Article 18: classification of ICT-related incidents and cyber threats.
  • Article 19: reporting of major ICT-related incidents and voluntary notification of significant cyber threats.
  • Articles 24–26: digital operational resilience testing, including advanced threat-led penetration testing for entities meeting the applicable criteria.
  • Article 28: general principles for ICT third-party risk, including the register of information on contractual arrangements.
  • Article 29: preliminary assessment of ICT concentration risk.
  • Article 30: key contractual provisions for ICT services.

DORA source: Regulation (EU) 2022/2554. Confirm entity scope and applicable delegated/implementing acts before converting any article into a mandatory task.

Build an obligation register that can survive a challenge

A useful obligation register is not a list of regulation names. It lets a reviewer trace a requirement from authoritative text to implementation and current evidence.

  • Authority: source name, section/article, jurisdiction, regulator, URL, effective date, and version.
  • Applicability: why the requirement applies to this entity, product, location, transaction, data type, or service—and what facts would change that conclusion.
  • Requirement: a bounded statement of what must be done, not a copy-paste of pages of legal text.
  • Owner: accountable business or control owner plus the second-line function responsible for interpretation or monitoring.
  • Controls: the mechanisms that prevent, detect, approve, monitor, report, or remediate the relevant risk.
  • Evidence: where proof of operation lives, how long it is retained, and what makes it complete enough for review.
  • Change trigger: rule amendment, business change, new product, acquisition, incident, regulator communication, or control failure that forces reassessment.

Make the control library operational

Controls should be written so a person who did not design them can understand what happens, who performs the work, what inputs are used, how exceptions are recognized, and what evidence remains.

Control record

  • control objective and linked risk;
  • linked obligations or internal requirements;
  • owner, performer, and reviewer;
  • frequency or event trigger;
  • population and data source;
  • criteria, thresholds, or decision rules;
  • exception and escalation path;
  • evidence artifact and retention basis.

Do not confuse these

  • a policy statement with a control;
  • a dashboard with evidence that someone acted;
  • a certification with proof that every relevant control is effective;
  • a risk acceptance with permanent closure of the underlying issue;
  • an auditor's procedure with a management control.

Monitor signals that can change the compliance conclusion

Continuous monitoring should not mean collecting every possible metric. It should detect events that make the current risk assessment, control design, or applicability decision unreliable.

  • Control failures: missed approvals, rejected reconciliations, overdue reviews, failed automated jobs, or repeated exceptions.
  • Business change: new products, jurisdictions, customer types, payment flows, acquisitions, reorganizations, or new technologies.
  • Third-party change: material incidents, subcontracting, data-location changes, financial distress, service degradation, or expiring assurance.
  • Regulatory change: new rules, effective dates, regulator FAQs, technical standards, enforcement policy, or supervisory findings.
  • Behavioral signals: hotline themes, retaliation allegations, repeated override patterns, disciplinary inconsistency, or incentives that conflict with policy.

Connect reporting, investigations, and remediation

A program cannot demonstrate that it works in practice if allegations disappear into disconnected case folders. Compliance operations should preserve a traceable lifecycle from intake through triage, investigation, conclusion, remediation, discipline where appropriate, and verification.

  1. Intake. Record source, issue type, affected business, confidentiality requirements, conflicts, and urgency.
  2. Triage. Apply documented criteria for legal privilege, independence, escalation, preservation, regulator-notification analysis, and immediate risk containment.
  3. Investigate. Maintain an evidence log, interview record, decision history, and scope changes.
  4. Conclude. Distinguish substantiated facts, policy or control failures, unresolved uncertainty, and broader systemic implications.
  5. Remediate. Assign actions to accountable owners with due dates, expected evidence, and validation criteria.
  6. Verify. Confirm the change operated and addressed root cause rather than simply recording management's promise to fix it.

Govern technology used by the business and by compliance itself

The September 2024 DOJ ECCP explicitly asks how companies assess and govern risks from new technologies, including AI. That creates two separate operating questions: what technology-related misconduct or control risk exists in the business, and whether the technology used by compliance is itself reliable and appropriately governed.

For business use of AI and automation

  • identify where the technology can influence regulated decisions, transactions, communications, pricing, approvals, or records;
  • define prohibited and high-risk uses;
  • assign accountable owners for deployment and monitoring;
  • retain testing and change evidence proportionate to the risk;
  • create a path to investigate misuse or unexpected outcomes.

For compliance technology

Do not assume a monitoring platform, anomaly model, hotline classifier, or automated screening workflow is reliable because it is automated. Validate source data, access, configuration, thresholds, change management, exception handling, and false-positive/false-negative consequences.

Example: translate DORA without creating a parallel compliance silo

For an in-scope financial entity, DORA can be mapped into the same evidence architecture rather than maintained as a separate binder:

Governance & risk

Map Articles 5–6 to management-body oversight, role definitions, ICT risk strategy, policy approval, training, and evidence of periodic review.

Incidents

Map Articles 17–19 to detection, logging, classification, escalation, notification decisions, reporting records, root cause, and corrective action.

Testing

Map Articles 24–26 to the testing program, scope decisions, remediation evidence, and threat-led penetration-testing obligations where applicable.

Third parties

Map Articles 28–30 to the contractual-arrangement register, concentration assessment, due diligence, required contract terms, monitoring, and exit readiness.

Use metrics that support decisions

Activity metrics are useful for capacity management but weak evidence of effectiveness on their own. Pair them with outcome and risk indicators.

Coverage

Material obligations with an owner, control mapping, current source, and evidence path.

Control health

Failure rate, recurring exceptions, overdue reviews, automation failures, and unresolved design gaps.

Remediation

Age of high-risk findings, repeat findings after closure, root-cause recurrence, and validation failure.

Investigations

Triage timeliness, aging by severity, repeat themes, retaliation concerns, and remediation conversion.

Change

New regulatory or business changes awaiting applicability review and controls awaiting redesign.

Governance

Decisions requiring executive or board action, expired risk acceptances, and unresolved resource constraints.

A 90-day compliance-operations reset

  1. Days 1–30: fix the inventory. Reconcile active legal/regulatory sources, applicability decisions, owners, controls, evidence locations, third parties, and open findings. Retire superseded citations.
  2. Days 31–60: fix evidence and escalation. Standardize evidence records, exception handling, investigation intake, remediation verification, and management escalation.
  3. Days 61–75: validate the system. Sample high-risk obligations end to end. Confirm a reviewer can trace authority → applicability → control → evidence → finding → remediation without relying on oral explanation.
  4. Days 76–90: report the decisions. Give leadership a short list of residual risks, overdue high-risk actions, material scope changes, systemic control failures, and resources needed to close them.

Primary-source map

This guide describes an operating model, not a universal list of legal duties. Applicability, reporting deadlines, regulator jurisdiction, privilege, disclosure, and escalation requirements must be determined from the organization's facts and current authoritative sources.

Put this guide to work

Turn Compliance Operations Evidence System into a decision-ready next step.

Use the source-backed research to pressure-test assumptions, then build a reusable evaluation brief before you compare products, scope implementation, or request a fit review.