This week the Justice Department did the rare thing: it told compliance officers exactly where enforcement is about to land.
Colin McDonald, an Assistant Attorney General, sent staff of the new National Fraud Enforcement Division a memo that reads like a roadmap. To a compliance officer it feels like a gift. It isn't. It's a countdown.
Because the memo doesn't change what a good program looks like. It changes when someone finally opens yours to check whether the controls were ever real. And that exposes the pattern nobody says out loud: compliance programs don't die of bad design. They die because nobody treated the controls as binding until enforcement arrived to test them.
Two programs, same cause of death
Look at the UK.
Financial firms told the Financial Conduct Authority they had beefed up their financial crime checks. Assurances given. Boxes ticked. Then the regulator actually looked, and the gaps were still sitting there.
That is not a design failure. Nobody forgot what a KYC control is. The control existed on the page. It just wasn't binding on anyone until the FCA showed up and made it binding.
Now take the AI startup that just settled with the SEC. Its former chief executive published revenue projections the regulator later called material misrepresentations.
Somewhere in that company there was a review process, a policy about what you can and cannot tell investors. It existed. It just wasn't binding on the person who mattered, on the day it mattered, until the SEC arrived and read it back to him.
Two industries. Two regulators. One autopsy result.
In both cases the control was written down. In both cases everyone assumed it was working. In neither case did a single person own the job of proving it was working before an outsider did.
The problem isn't the program. It's the environment.
Here is the trap, and it is worth naming, because you are probably standing in it right now.
You can build a genuinely good program: real policy, real controls, real intent. It will still die, because the environment around it treats every control as a document until enforcement turns it into a fact.
A document doesn't push back. A document doesn't stop a launch, block a filing, or tell a CEO no. It sits in a folder radiating the feeling of safety while the actual behavior drifts away from it.
Do the math on that drift. A control quietly stops working in month one. The assurance keeps flowing upward the whole time: to the board, to the auditor, to the regulator. Enforcement doesn't arrive until year three. That is thirty-plus months where everyone in the chain believed something untrue, and every customer onboarded and every number reported carries the gap forward.
The cost was never the fine. The cost is that the gap compounds in the dark.
McDonald's memo is the DOJ telling you the lights are about to come on. Not because they found a new kind of fraud, but because they have decided to go read the programs everyone assumed were fine.
So the test is not whether your program looks good. It is whether anything in it is binding before someone with a subpoena makes it so. Ask it plainly:
- Which of your controls can stop a decision, not just describe one?
- Who, by name, owns the verdict on whether each one is working?
- When did that person last prove it to someone who could say no?
If the answers are a shrug, you don't have a program. You have a very well-written assurance, and assurances are exactly what the FCA and the SEC just watched die.
The DOJ handed you the roadmap. The real gift buried in it is time: a narrow window to make one control binding before enforcement does it for you.
So which control are you making real on Monday, and who owns the answer when it stops being optional?
Sources
- DOJ’s New Fraud Division Memo: A Roadmap to Where Enforcement Is Actually Headed, Volkov Law, Corruption, Crime & Compliance
- Gaps remain in firms’ KYC checks, says U.K. financial services regulator, Compliance Week
- AI startup and former CEO settle with SEC over alleged material misrepresentations, Compliance Week