DOJ Fraud Division Issues Corporate Enforcement Directive Establishing Framework for Corporate Fraud Investigations

Highlights
- Dedicated U.S. Department of Justice (DOJ) Fraud Division team will oversee corporate cases: The Fraud Division’s Corporate Enforcement Section, announced earlier this year, will be involved in the Fraud Division’s corporate cases from start to finish.
- Fraud Division underscores key areas of focus: The Directive identifies four priority areas for corporate investigations by the DOJ Fraud Division (healthcare, government contracts and programs, tax and revenue, and trade fraud) and 10 factors that will drive whether and how the Fraud Division investigates and prosecutes a company.
- Maintaining an effective whistleblower reporting channel is more important than ever: DOJ is using data analytics to find fraud faster and is developing programs to encourage whistleblowers, including insiders who took part in the misconduct, making it imperative that companies ensure they have an effective whistleblower reporting channel that allows them to learn about, investigate, and react to potential misconduct, including an appropriate assessment of the merits and costs of self-disclosure.
On Oct. 1, Assistant Attorney General Colin M. McDonald issued Directive 26-12: Corporate Enforcement in the Fight Against Fraud (the Directive). The Directive signals an aggressive push against corporate fraud involving four key areas — healthcare, government programs, tax, and trade — while promising to separate serious wrongdoing from legitimate business activity. For companies, the message is clear: the DOJ’s new National Fraud Enforcement Division (the Fraud Division) is ramping up its capacity and establishing a framework for corporate investigations and prosecutions, emphasizing its intention to move quickly and to credit companies that come forward, cooperate, and appropriately remediate.
Corporate Enforcement Section to Oversee DOJ Fraud Division Corporate Cases
The Fraud Division announced the creation of its Corporate Enforcement Section earlier this year. The new Directive expands the Corporate Enforcement Section’s role, requiring that it be involved in corporate cases from the start through resolution or trial. Within seven days of the Directive’s issuance, Fraud Division prosecutors must report all ongoing corporate investigations to the Corporate Enforcement Section, and they must keep it updated on new investigations and major developments. In practice, companies should expect a more centralized approach to corporate cases being investigated by the Fraud Division.
The Corporate Enforcement Section will also take the lead in evaluating a company’s compliance with the terms of a corporate criminal resolution, such as a deferred prosecution agreement (DPA) or non-prosecution agreement (NPA), including reporting and disclosure obligations. Companies already under such a resolution should expect closer follow-up.
The Corporate Enforcement Section also will maintain primary responsibility for assessing whether a company with a case before the Fraud Division has implemented an effective compliance program, including any enhancements following identification of the misconduct.
DOJ Fraud Division's Corporate Enforcement Priorities and Charging Factors
The Directive instructs Fraud Division prosecutors to prioritize four areas when opening and conducting corporate investigations: (1) healthcare fraud, including distribution of controlled substances and violations of federal food and drug law; (2) fraud involving government contracts, procurement, and other government functions; (3) significant tax and revenue evasion; and (4) tariff evasion, importation of goods or services, and forced labor.
The Directive also identifies ten factors to which prosecutors must give “great weight” in determining whether to charge a company or reach a corporate resolution. Broadly speaking, these factors fall into three groups.
- First — how the company behaved, including whether:
- Company management knew about or took part in the fraud; or
- Company employees or executives tried to hide the misconduct from government agencies or auditors or otherwise sought to obstruct a government function or measure of oversight.
- Second — the size and scope of the conduct, including whether it:
- Furthered a scheme lasting three years or more;
- Caused substantial financial hardship to a taxpayer-funded program or government function;
- Affected multiple taxpayer-funded programs or government functions;
- Reached three or more federal districts; or
- Harmed 25 or more victims or caused $25 million or more in loss.
- Third — national security-related concerns, including conduct that:
- Threatened Americans’ safety or security (including military readiness);
- Sent U.S. funds abroad to support foreign adversaries; or
- Involved immigration offenses.
Under the new Directive, this list of factors is not exhaustive, and prosecutors maintain discretion to weigh other facts and circumstances in making determinations in corporate cases. Still, companies and their counsel can consider these factors in assessing potential risk exposure and sizing up potential issues in Fraud Division investigations.
DOJ Fraud Division Looking to Amplify Whistleblower Incentives and Fraud Detection
Fraud Division leadership says it is already using new technology and data analytics through its National Fraud Detection Center to generate leads and open investigations “at a rapid pace.” The Directive pairs that effort with an added emphasis on whistleblowers. It states that the Fraud Division’s policies must encourage and protect disclosures by whistleblowers, including those who participated in the criminal conduct, and it directs Fraud Division leadership to design programs that incentivize people to bring credible fraud information to DOJ.
For companies, this raises the stakes and crystallizes the importance of maintaining an effective and well-functioning whistleblower reporting channel to receive reports and complaints related to potential misconduct. The new Directive appears to foreshadow that the Fraud Division may establish its own whistleblower awards program, similar to the one rolled out by the DOJ Criminal Division in August 2024. These programs create risk that an employee, contractor, or business partner, including one with direct knowledge of potential misconduct, may approach DOJ instead of raising concerns internally. Companies that encourage internal reporting, respond promptly to complaints, and protect employees who speak up will be in a better position to identify potential problems, properly investigate the scope of the conduct, and appropriately remediate and assess next steps, including potential self-disclosure and cooperation.
Risks for Companies with International Operations and Trade Exposure
For companies with international operations, the risks resulting from potential misconduct and government investigations can multiply. Healthcare, government contracting, and tax matters may involve foreign affiliates, suppliers, data, and witnesses. Companies, therefore, should assess cross-border exposure across their full fraud-risk profile.
Trade is the clearest example. As with prior guidance issued by the Fraud Division, the new Directive underscores DOJ’s high-priority focus on trade fraud, tariff evasion, importation of goods or services, and forced labor. Companies that import goods face potential criminal and civil exposure for underpaid duties. For a closer look at how DOJ is pursuing these cases, see our September 2026 detailed white paper, “False Claims Act and Criminal Enforcement in the Tariff Context: Practical Guidance for Companies, Corporations, and Executives.”
Practical Steps for Companies
- Assess your exposure by conducting a properly tailored risk assessment (or refreshing a prior risk assessment in light of these priorities). Review controls in the four priority areas that apply to your business (for example, billing, government contracts, tax, or supply chain and customs) and compare any known issues against the ten factors discussed above.
- Test compliance program and internal controls. Based upon the results of the tailored risk assessment, test the functioning of your compliance program and internal controls in practice to address current risks in light of the Fraud Division’s stated priorities.
- Review internal reporting channels and escalation protocols to appropriately address internal reports. Strengthen reporting hotlines, anti-retaliation protections, and training to encourage internal reporting and to appropriately respond to reports when raised. Set a clear process for escalating government inquiries, audits, and internal reports.
- Evaluate voluntary self-disclosure under DOJ’s Corporate Enforcement and Voluntary Self-Disclosure Policy (CEP). The Directive confirms that Fraud Division prosecutors must follow the DOJ’s department-wide CEP. Companies that identify fraud or other misconduct should evaluate the potential benefits of voluntary self-disclosure, cooperation, and remediation. Of course, whether to voluntarily self-disclose to the government is highly dependent on the specific facts and circumstances at issue. Companies should always consult experienced counsel to gain a thorough understanding of the potential benefits, costs, and risks of self-disclosing to DOJ or any other government authority. A properly scoped internal investigation is of the utmost importance in making an appropriate determination in this context.
Keep Up to Date in a Changing World
