Skip to main content
Category: Compliance Program Frameworks

Due Diligence to Prevent and Detect Criminal Conduct

Also known as: Due diligence prong (of an effective compliance and ethics program), Reasonable steps to prevent and detect criminal conduct
Simply put

Due diligence to prevent and detect criminal conduct is the ongoing effort an organization is expected to make to stop wrongdoing before it happens and to catch it when it does. Under the U.S. Federal Sentencing Guidelines, it is one of the two things an organization must show to have what those guidelines call an effective compliance and ethics program, the other being efforts to promote a culture that encourages ethical conduct. This is a legal and regulatory concept rooted in U.S. federal guidance, and how it applies to a specific organization should be reviewed with qualified legal counsel.

Formal definition

Under U.S.S.G. § 8B2.1(a), an organization seeking to demonstrate an 'effective compliance and ethics program' shall (1) exercise due diligence to prevent and detect criminal conduct and (2) otherwise promote an organizational culture that encourages ethical conduct and a commitment to compliance with the law. 'Due diligence to prevent and detect criminal conduct' is the first of these two paired prongs and refers to the reasonable, good-faith steps an organization takes to reduce the likelihood of criminal conduct and to identify it when it occurs. This is a compliance-oriented standard drawn from the U.S. Federal Sentencing Guidelines and applied in the U.S. Department of Justice's Evaluation of Corporate Compliance Programs, which assesses, among other things, whether a company exercised such due diligence; it is jurisdiction-specific to U.S. federal enforcement and is distinct from the separate culture-promotion prong under § 8B2.1(a)(2). Scope note: the specific program components that constitute adequate due diligence (for example, risk assessment, training, monitoring and auditing, and reporting channels) are addressed elsewhere in § 8B2.1 and are not restated in this high-level definition; the evidence provided does not enumerate them here, and exercising this due diligence is generally regarded as a factor in sentencing and enforcement decisions rather than a guarantee of preventing misconduct or of legal protection. This entry is educational and not a substitute for advice from qualified legal counsel.

Why it matters

The obligation to exercise due diligence to prevent and detect criminal conduct sits at the heart of what the U.S. Federal Sentencing Guidelines describe as an effective compliance and ethics program. Under U.S.S.G. § 8B2.1(a), it is one of two paired requirements an organization must satisfy, the other being the promotion of an organizational culture that encourages ethical conduct and a commitment to compliance with the law. Because this standard is embedded in federal sentencing guidance, it carries direct consequences for how organizations are treated when misconduct surfaces and enforcement attention follows.

The standard also shapes how enforcement authorities assess a company's program after the fact. The U.S. Department of Justice's Evaluation of Corporate Compliance Programs asks, among other things, whether a company exercised due diligence to prevent and detect criminal conduct, citing U.S.S.G. § 8B2.1(a)(1) directly. This means the concept is not merely aspirational language; it is a lens through which prosecutors and courts review the design and operation of a program when deciding how to proceed.

It is important to keep expectations calibrated. Exercising this due diligence is generally regarded as a factor in sentencing and enforcement decisions rather than a guarantee of preventing misconduct or of securing legal protection. The standard is jurisdiction-specific to U.S. federal enforcement, and how it applies to any particular organization should be reviewed with qualified legal counsel. This entry is educational and not a substitute for professional advice.

Who it's relevant to

Compliance officers and ethics program managers
These professionals design and maintain the program elements through which an organization seeks to demonstrate due diligence to prevent and detect criminal conduct. Understanding that this is the first of two paired prongs under § 8B2.1(a), and that it is distinct from the culture-promotion prong, helps them structure a program that addresses both requirements rather than conflating them.
Legal and enforcement-facing teams
In-house counsel and teams that interact with the DOJ need to understand that the Evaluation of Corporate Compliance Programs assesses whether a company exercised due diligence to prevent and detect criminal conduct, citing U.S.S.G. § 8B2.1(a)(1). Because this standard is jurisdiction-specific to U.S. federal enforcement and its application varies by facts and circumstances, decisions in this area call for qualified legal counsel.
Audit and monitoring functions
Teams responsible for monitoring and auditing contribute to the detection side of preventing and detecting criminal conduct. While this high-level definition does not enumerate the specific components required, these functions are among the program elements addressed within § 8B2.1 and are relevant to whether an organization can show it exercised reasonable, good-faith steps.
Learning and development staff
Those who build and deliver compliance training should recognize that training is one component that may support an organization's broader due diligence effort, not something that satisfies the standard on its own. Exercising due diligence is generally regarded as a factor in enforcement decisions rather than a guarantee against misconduct, so training should be positioned as part of a larger system.

Inside Due Diligence to Prevent and Detect Criminal Conduct

Established Standards and Procedures
Written policies, a code of conduct, and defined procedures designed to prevent and detect criminal conduct. In the U.S. Federal Sentencing Guidelines framework, from which this phrase derives, these standards form the foundation on which the remaining elements of an effective compliance and ethics program are built. This is a program-level element, not training alone.
Governing Authority and High-Level Oversight
Responsibility assigned to the organization's governing authority (such as the board) to be knowledgeable about the program's content and operation, and to specific high-level personnel who are given operational responsibility. Adequate resources and authority must be provided to those individuals.
Reasonable Efforts to Exclude High-Risk Personnel
Screening intended to avoid delegating substantial authority to individuals whom the organization knew, or should have known through reasonable diligence, had engaged in illegal activities or conduct inconsistent with an effective program. This concerns hiring and delegation decisions and is jurisdiction-specific to the U.S. Guidelines framing.
Training and Communication
Practical steps to communicate standards and procedures through effective training programs and by otherwise disseminating information appropriate to individuals' roles. Training is one component within due diligence and does not by itself constitute due diligence or a complete program.
Monitoring, Auditing, and Reporting Mechanisms
Ongoing monitoring and auditing to detect criminal conduct, evaluation of program effectiveness, and a mechanism (such as a whistleblower channel) allowing reporting or seeking guidance, including with anonymity or confidentiality where feasible and without fear of retaliation.
Incentives and Disciplinary Measures
Consistent promotion and enforcement of the program through appropriate incentives for compliant conduct and disciplinary measures for engaging in criminal conduct or failing to take reasonable steps to prevent or detect it.
Response and Remediation
Reasonable steps to respond appropriately to detected criminal conduct and to prevent further similar conduct, including modifying the program as needed. This reflects the detect-and-correct dimension implied by the phrase's reference to both preventing and detecting.

Common questions

Answers to the questions practitioners most commonly ask about Due Diligence to Prevent and Detect Criminal Conduct.

Does exercising due diligence to prevent and detect criminal conduct guarantee that an organization will avoid liability or prosecution?
No. Due diligence is intended to reduce the likelihood of misconduct and to demonstrate that an organization took reasonable steps to prevent and detect it, but it does not guarantee prevention or immunity from liability. Frameworks such as the U.S. Federal Sentencing Guidelines treat an effective compliance and ethics program as a factor that may be considered in assessing culpability, but outcomes depend on the specific facts, the quality of implementation, and the discretion of prosecutors and courts. Whether and how it affects liability in a given matter is a legal question that requires qualified counsel. This entry is educational and not a substitute for professional advice.
Is due diligence to prevent and detect criminal conduct the same as delivering compliance training?
No. Training is one component that can support due diligence, but the concept is broader. Due diligence generally encompasses multiple program elements, which may include a code of conduct, risk assessment, monitoring and auditing, reporting channels, and appropriate response to detected conduct. Treating training alone as satisfying due diligence misstates the concept. Training is intended to communicate expectations and build awareness, but it does not by itself constitute the full set of measures an organization is expected to take.
How do we decide where to focus our due diligence efforts across the organization?
Due diligence is generally expected to be risk-based, meaning efforts are prioritized according to the nature, likelihood, and potential impact of the risks an organization faces. A periodic risk assessment is commonly used to identify areas of higher exposure so that resources, controls, and oversight can be allocated accordingly. The appropriate scope and depth vary by organization, industry, and jurisdiction, and priorities should be revisited as the business and its risk environment change. Determining what is reasonable for a specific organization may warrant input from qualified legal and compliance professionals.
What role does senior management and the board play in due diligence?
Governance and oversight are generally regarded as integral to due diligence. Frameworks commonly contemplate that senior leadership sets expectations and that a governing authority, such as the board, exercises oversight of the program. Assigning responsibility to specific individuals with adequate authority and resources is often part of demonstrating that an organization takes prevention and detection seriously. The specific expectations for leadership and oversight can vary by framework and jurisdiction and should be confirmed against the applicable primary sources.
How should an organization respond when it detects potential criminal conduct?
Detection is only part of due diligence; the response matters as well. Organizations are generally expected to take appropriate steps after conduct is detected, which may include investigation, remediation, and measures intended to prevent recurrence. Because the appropriate response can implicate legal obligations, reporting duties, and privilege considerations that vary by jurisdiction, these situations typically require qualified legal counsel. This entry does not prescribe a specific response and is not a substitute for professional advice.
How can an organization evaluate whether its due diligence measures are working?
Monitoring, auditing, and periodic review are generally used to assess whether measures are operating as intended and to identify gaps. Evaluation may consider whether controls are functioning, whether reporting channels are used, and whether identified issues are addressed. No single metric or method establishes effectiveness on its own, and results depend on implementation and context. Ongoing review is generally regarded as important because risks and organizational circumstances change over time; specific evaluation approaches should be adapted to the organization and confirmed against applicable frameworks.

Common misconceptions

Delivering compliance training satisfies the due diligence obligation to prevent and detect criminal conduct.
Training is only one element. Due diligence in this sense refers to an integrated set of program components, standards, oversight, screening, monitoring and auditing, reporting channels, incentives and discipline, and remediation. Training may support these efforts but does not on its own establish that an organization exercised due diligence.
Meeting the elements associated with this phrase guarantees legal protection or immunity from liability.
The phrase originates in the U.S. Federal Sentencing Guidelines, which are relevant to how a program may be evaluated and, in some contexts, to sentencing considerations. Having a program is generally regarded as a mitigating factor but does not guarantee prevention of misconduct or protection from prosecution or penalties. Outcomes depend on implementation, context, and factors outside the program's control, and legal consequences require assessment by qualified counsel.
These due diligence elements are universal legal requirements applicable everywhere.
This formulation is specific to the U.S. Federal Sentencing Guidelines framework and is not a universal mandate. Other regimes and standards (for example, guidance under other jurisdictions or certifiable standards such as ISO 37301) address similar themes differently. Applicability and specific obligations vary by jurisdiction and should be confirmed against primary sources and local law.

Best practices

Treat due diligence as a program-wide function: map each element, standards, oversight, screening, training, monitoring and auditing, reporting, incentives and discipline, and remediation, to a named owner and documented process rather than relying on training alone.
Ensure the governing authority is demonstrably informed about the program's content and operation, and that high-level personnel assigned operational responsibility have adequate authority and resources.
Tailor training and communication to individuals' roles and risk exposure, and retain records of what was delivered, to whom, and how comprehension was reinforced.
Maintain reporting mechanisms that permit anonymity or confidentiality where feasible and protect reporters from retaliation, and periodically test that these channels function and are trusted.
Conduct ongoing monitoring and auditing to detect conduct and evaluate effectiveness, and document how the program is modified in response to findings or detected issues.
Confirm jurisdiction-specific requirements and citations against primary sources and involve qualified legal counsel before treating this framework as a compliance benchmark, recognizing this guidance is educational and not a substitute for professional advice.