Skip to main content
Category: Compliance Program Frameworks

Corporate Enforcement Policy

Also known as: CEP, Corporate Enforcement and Voluntary Self-Disclosure Policy, FCPA Corporate Enforcement Policy (former name)
Simply put

The Corporate Enforcement Policy (CEP) is a U.S. Department of Justice policy that offers companies defined benefits for voluntarily telling the government about criminal wrongdoing they discover, cooperating with investigators, and fixing the underlying problems. It is intended to encourage self-reporting by making the potential outcome more predictable for companies that come forward. This policy is specific to U.S. federal criminal enforcement and does not apply to matters outside that jurisdiction.

Formal definition

The Corporate Enforcement Policy (CEP), formerly known as the FCPA Corporate Enforcement Policy, is a U.S. Department of Justice Criminal Division policy codified at Justice Manual 9-47.120. As revised in March 2026, it was extended into the Department's first uniform, Department-wide framework applying to all FCPA cases nationwide and other corporate criminal matters, providing concrete incentives for companies that voluntarily self-disclose discovered misconduct, cooperate, and remediate. The CEP is a prosecutorial charging and resolution policy governing how DOJ exercises enforcement discretion; it is not a compliance program standard, a certifiable framework, or a substitute for an organization's compliance and ethics infrastructure. Its scope is limited to U.S. federal criminal enforcement, and the specific benefits available and the conditions attached depend on the policy's precise text and DOJ's discretion in a given case. Practitioners should confirm current requirements, benefit tiers, and any effective dates against the primary policy text, and treat application to specific facts as a matter requiring qualified legal counsel.

Why it matters

The Corporate Enforcement Policy shapes one of the most consequential decisions a company faces after discovering potential criminal wrongdoing: whether to voluntarily disclose that conduct to the U.S. Department of Justice. Because the policy sets out defined benefits for companies that self-report, cooperate, and remediate, it is intended to make the outcome of coming forward more predictable than it would otherwise be. For compliance officers and legal teams, that predictability affects how internal investigations are scoped, how findings are escalated, and how the organization weighs the risks and potential benefits of disclosure. It is important to understand that these are incentives offered at DOJ's discretion, not guaranteed results; the actual benefit available in any matter depends on the policy's precise terms and the facts of the case.

The policy also carries weight because it was extended in its March 2026 revision into the Department's first uniform, Department-wide framework, applying to all FCPA cases nationwide and other corporate criminal matters. This broader reach means the same disclosure-and-cooperation framework now governs a wider range of federal criminal exposure than the earlier FCPA-specific version, which is relevant to how programs are designed to detect and respond to misconduct across multiple risk areas.

At the same time, the CEP should not be mistaken for a compliance program standard. It governs how prosecutors exercise charging and resolution discretion; it does not tell an organization how to build its code of conduct, training, risk assessment, or monitoring functions. Effective remediation, one of the conditions the policy contemplates, still depends on the strength of that underlying infrastructure. Its scope is also limited to U.S. federal criminal enforcement and does not extend to matters outside that jurisdiction, and applying it to specific facts is a matter requiring qualified legal counsel.

Who it's relevant to

Compliance officers and ethics program managers
The policy affects how discovered misconduct is escalated and remediated, since remediation is one of the conditions it contemplates. It underscores the need for a compliance program capable of detecting problems and responding effectively, though the policy itself is not a program standard and does not prescribe how to build that infrastructure.
Legal and investigations teams
These teams weigh whether and how to voluntarily self-disclose to DOJ, scope internal investigations, and manage cooperation. Because the available benefits are discretionary and depend on the policy's precise terms and the facts of a case, application to specific matters requires qualified legal counsel.
Audit and monitoring functions
Because the policy rewards timely detection, cooperation, and remediation, monitoring and auditing functions that surface potential misconduct feed directly into decisions the policy influences, though these functions remain distinct components of a broader compliance system, not something the policy itself establishes.
Learning and development staff
Training that helps employees recognize and report potential misconduct supports the early detection on which any decision to self-disclose depends. Training is only one part of a larger program, however, and does not by itself satisfy the cooperation or remediation expectations the policy contemplates.

Inside CEP

Voluntary self-disclosure
A component under which an organization proactively reports misconduct to enforcement authorities before an investigation is underway or imminent. The policy generally treats such disclosure as a factor that may support more favorable treatment, though the specific criteria and timing thresholds are jurisdiction-specific and should be confirmed against the primary policy text.
Cooperation with authorities
The expectation that an organization provides timely, meaningful assistance to investigators, which may include preserving evidence and identifying individuals involved. Cooperation is generally regarded as one weighted factor rather than a guarantee of any particular outcome.
Remediation
Steps taken to address the underlying conduct and its root causes, which may include enhancing controls, disciplining responsible individuals, and improving the compliance program. Remediation concerns corrective action after misconduct is identified and is distinct from routine preventive training.
Enforcement discretion and potential resolution outcomes
A framework describing how authorities may exercise discretion in resolving matters, potentially including declinations or reduced penalties where stated conditions are met. Exact benefit levels, penalty reductions, and eligibility conditions vary and should be verified against primary sources rather than assumed.
Jurisdictional scope
The defined legal authority and geographic or subject-matter reach of the policy. A corporate enforcement policy issued by a specific authority governs only matters within that authority's jurisdiction and does not carry force in others.

Common questions

Answers to the questions practitioners most commonly ask about CEP.

Does self-reporting under a corporate enforcement policy guarantee that a company will avoid prosecution?
No. A corporate enforcement policy that offers incentives for voluntary self-disclosure does not guarantee a declination or immunity from prosecution. Such policies generally describe a presumption or the possibility of more favorable treatment where specified conditions are met, but prosecutorial discretion, aggravating circumstances, and the specific facts of a matter all affect the outcome. Because these are jurisdiction-specific and consequential decisions, companies should confirm the current terms of the applicable policy against primary sources and consult qualified legal counsel; this entry is educational and not a substitute for professional advice.
Is a corporate enforcement policy a compliance program requirement that a company must implement?
No. A corporate enforcement policy is issued by an enforcement authority and describes how that authority intends to exercise its discretion when responding to corporate misconduct; it is not itself a component of a company's compliance program. It is distinct from internal program elements such as training modules, a code of conduct, risk assessment, whistleblower channels, and monitoring and auditing. A company may design its program with the policy's stated expectations in mind, but the policy does not impose the program itself, and its terms and applicability vary by jurisdiction.
What conditions do enforcement policies typically expect a company to satisfy to be considered for more favorable treatment?
Enforcement policies of this type generally reference conditions such as voluntary self-disclosure, cooperation with the authority, and timely and appropriate remediation. The specific definitions, timing expectations, and weight given to each factor differ by policy and jurisdiction. Because exact criteria and any qualifying language change over time, the precise requirements should be confirmed against the current text of the applicable policy and interpreted with qualified legal counsel before a company relies on them.
How should a compliance team keep its program aligned with an enforcement policy without over-relying on it?
A compliance team can map the general expectations reflected in an applicable enforcement policy, such as those relating to cooperation and remediation, to distinct program elements it controls, while recognizing that the policy governs the authority's discretion rather than the program's design. Alignment is intended to support, not guarantee, a favorable posture, and effectiveness depends on implementation and context. Teams should periodically verify the current policy text against primary sources and involve legal counsel, since applicability is jurisdiction-specific.
What role does documentation play when a company considers acting under an enforcement policy?
Documentation of the underlying conduct, the timeline of discovery, disclosure decisions, cooperation, and remediation steps is generally regarded as important context when an authority evaluates a matter under such a policy. However, this glossary entry does not prescribe specific documentation standards, which vary by jurisdiction and situation. Decisions about what to document, when, and how to preserve legal protections involve significant legal judgment and should be made with qualified counsel.
Who within an organization should be involved before invoking or relying on a corporate enforcement policy?
Because relying on an enforcement policy touches decisions with legal consequences, such as whether and when to disclose and how to characterize cooperation and remediation, qualified legal counsel should be involved, typically alongside compliance, ethics program, and audit stakeholders. The appropriate participants and process vary by organization and jurisdiction. This entry is educational and does not constitute legal advice; the current terms of any applicable policy should be confirmed against primary sources.

Common misconceptions

Following a corporate enforcement policy guarantees a declination or immunity from prosecution.
The policy is intended to describe factors and discretion that may support more favorable treatment. Outcomes depend on implementation, the facts of the matter, and the exercise of enforcement discretion, and no policy of this kind guarantees a specific legal result.
A corporate enforcement policy is the same as a compliance program.
A corporate enforcement policy is an external, authority-issued framework describing how misconduct may be resolved. A compliance program is the organization's internal system of policies, training, monitoring, and controls. The policy may reference or credit an effective program, but the two are distinct.
The terms of one jurisdiction's enforcement policy apply universally.
Such policies are jurisdiction-specific and reflect the issuing authority's legal reach. Eligibility criteria, benefits, and definitions do not automatically transfer to other jurisdictions or authorities.

Best practices

Consult qualified legal counsel before making any voluntary self-disclosure decision, as these matters involve legal judgment that falls outside educational guidance.
Verify the specific eligibility criteria, timing thresholds, and stated benefits against the primary policy text of the relevant authority rather than relying on summaries.
Confirm which jurisdiction and authority govern a given matter before relying on any enforcement policy, since scope and terms are jurisdiction-specific.
Document remediation steps and cooperation efforts contemporaneously so the organization can substantiate its actions if a matter is later reviewed.
Treat the enforcement policy as one external framework and maintain a distinct, well-documented internal compliance program rather than conflating the two.
Frame any internal communications about potential outcomes in qualified terms, avoiding assurances of declination or immunity that the policy does not provide.