Skip to main content
Does Your Fraud Risk Assessment Cover What DOJ Can Now See?Financial & Accounting Fraud
6 min readFor Compliance Training Managers

Does Your Fraud Risk Assessment Cover What DOJ Can Now See?

The DOJ's new National Fraud Enforcement Division is more than just a reshuffling of attorneys. It's a sign that the government now has the tools to detect patterns your internal audit might miss. With around 500 attorneys and staff, including data scientists and specialized investigators, this centralized unit is designed to connect dots across government programs, procurement systems, customs databases, and healthcare claims.

If your compliance program still treats fraud risk as merely a finance issue or an ethics checkbox, you're using an outdated map. This checklist will help you assess whether your controls can withstand scrutiny from investigators who can query millions of records before they knock on your door.

Prerequisites

Before you start this assessment, gather three things:

Your current fraud risk assessment. If it's more than 18 months old or doesn't address data analytics capabilities, it needs updating.

Access to your data governance lead. You'll need to understand what data your company generates, where it lives, and who can query it.

A cross-functional team. Don't do this alone. Involve procurement, trade compliance, healthcare operations (if applicable), tax, and IT security. The Fraud Division's structure assumes your risks intersect; your assessment should too.

Fraud Risk Assessment Checklist

1. Map your government-facing data footprint

List every system where your company submits data to government agencies: procurement portals, customs declarations, healthcare claims, tax filings, grant applications, Environmental Permitting. Then identify what internal systems feed those submissions.

Aim for a single-page diagram showing data flow from source systems to government filings, with clear ownership for each touchpoint. You should be able to answer "where could a pricing error, misclassification, or false certification originate?" within five minutes.

2. Test whether your data would survive cross-agency comparison

The Fraud Division's National Fraud Detection Center will parse data across agencies. If you report one product classification to Customs and a different one to the EPA, or if your Medicare billing doesn't match your FDA registration, those inconsistencies are now detectable at scale.

Run a reconciliation: Do your customs declarations match your country-of-origin certifications? Do your government contract labor categories align with your payroll data? Do your grant expense reports match your general ledger?

Document quarterly reconciliations with variance explanations. Any discrepancy over a defined threshold should trigger a review before the next filing.

3. Assess your third-party intermediary controls in high-risk categories

The Fraud Division focuses on customs brokers, freight forwarders, billing intermediaries, and grant consultants. These actors touch government data and can create both fraud and corruption risk.

Review your due diligence: Do you verify credentials? Monitor for red flags like unusually low pricing or promises of expedited approvals? Have clear contractual terms about accurate reporting?

Implement risk-tiered due diligence with enhanced reviews for intermediaries who interact with government systems. Conduct annual recertification. A termination within the past 24 months based on a red flag you detected (which means your monitoring actually works) is a good sign.

4. Break down silos between compliance functions

The Fraud Division's structure assumes that procurement fraud, trade violations, kickbacks, and tax issues can appear in the same fact pattern. If your procurement team doesn't talk to your anti-corruption team, and neither talks to customs, you can't spot these intersections.

Test it: Take a recent government contract or customs shipment. Who reviewed it for fraud risk? For corruption risk? For trade compliance? For tax implications? If the answer is "different people who've never met," you have a structural problem.

Conduct quarterly cross-functional risk reviews. Use shared case management systems. Develop training scenarios that present multi-issue fact patterns.

5. Review your government procurement controls for the five fraud types DOJ highlighted

The Memorandum calls out defective pricing, bid rigging, self-dealing, bribery, and product substitution as critical priorities. Your procurement controls should address each specifically.

Audit your process: Do you verify cost and pricing data before submission? Screen for conflicts of interest in bid processes? Have specifications that prevent substitution? Maintain segregation of duties between pricing, bidding, and delivery?

Ensure documented controls for each fraud type, tested annually. Establish clear escalation protocols when someone spots a potential issue. Provide evidence that you've caught and corrected errors before submission.

6. Evaluate your data analytics maturity against DOJ's capabilities

The government will use statistical analysis to spot outliers. Can you do the same? If DOJ can query your Medicare claims and see that your billing patterns diverge from peers, your compliance team should have spotted that first.

Assess your capabilities: Can you run comparative analyses of your own data? Identify anomalies in pricing, volume, or timing? Detect duplicate payments or phantom vendors?

Regularly run analytics with defined thresholds and investigation triggers. Aim for at least one fraud detection in the past year that came from analytics, not a whistleblower tip.

7. Document your voluntary disclosure decision framework

The Fraud Division's first corporate declination involved a healthcare company that self-disclosed, cooperated, and remediated. That case (Campus Eye Management Holdings, LLC) shows the policy works. But you need criteria for when to disclose, not just good intentions.

Define your triggers: What severity, scope, or type of misconduct requires escalation to leadership for a disclosure decision? Who makes that call? What's the timeline?

Create a written protocol that compliance, legal, and audit teams all reference. Develop decision trees for common scenarios. Ensure evidence of at least one disclosure discussion in the past 18 months (even if you concluded disclosure wasn't warranted).

8. Test your forced labor supply chain controls

The Fraud Division will coordinate criminal enforcement on supply chains involving forced labor, working through the Trade Fraud Task Force. This isn't just an import compliance issue; it's now a criminal fraud priority.

Verify your process: Do you have country and supplier risk assessments? Audit rights in supplier contracts? A response plan if you discover forced labor indicators?

Map your supply chain beyond Tier 1 suppliers for high-risk categories. Update documented risk assessments within the past 12 months. Establish clear criteria for supplier suspension or termination.

Common Mistakes

Treating fraud risk as static. The Fraud Division's data capabilities mean patterns that looked normal last year might trigger investigation this year. Update your risk assessment annually, at minimum.

Assuming small-dollar issues are safe. Data analytics can aggregate thousands of small transactions into a pattern. A $500 billing error repeated across 10,000 claims becomes a $5 million problem.

Waiting for a clear red flag. The government won't wait for a smoking gun. Unexplained variances, statistical outliers, and process gaps are enough to open an inquiry.

Siloing your FCPA compliance. Yes, the FCPA Unit remains in the Criminal Division's White Collar Section. But corruption issues often appear alongside fraud, procurement violations, and trade misconduct. Your anti-corruption program should connect to these other risk areas, not operate independently.

Next Steps

Schedule a cross-functional meeting within the next 30 days. Bring this checklist. Identify your three biggest gaps. Assign owners and deadlines.

Then update your training. Your employees need to understand that accuracy in government-facing data isn't just a quality issue. It's a fraud risk that DOJ now has unprecedented capacity to detect.

The Fraud Division's emphasis on data-driven enforcement means one thing for compliance programs: you need to find your problems before the government's algorithms do.

You Might Also Like