Skip to main content
Category: Training and Monitoring

Periodic Review and Evaluation

Also known as: Periodic Program Review, Periodic Evaluation, Compliance Program Review
Simply put

Periodic review and evaluation is the practice of examining a compliance or ethics program at regular intervals to check whether it is working as intended and to identify what needs to change. It looks at whether policies, training, controls, and reporting mechanisms remain suitable given the organization's current risks and operations. It is one management activity within a broader compliance program and does not by itself ensure compliance or prevent misconduct.

Formal definition

Periodic review and evaluation refers to the structured, recurring assessment of the design and operating effectiveness of a compliance or ethics program's components, such as policies, the code of conduct, training, risk assessments, monitoring and auditing functions, and reporting channels, against the organization's current risk profile, regulatory obligations, and internal objectives. It is intended to surface gaps, drive remediation, and support continuous improvement, and it is distinct from ongoing real-time monitoring, one-off internal audits, and risk assessment, though it may incorporate outputs from each. Its scope, cadence, and rigor vary by organization; conducting a periodic review is a governance and management activity that may support program effectiveness but does not guarantee prevention of misconduct or confer legal protection, and its adequacy relative to specific regulatory expectations may require qualified legal counsel to determine. This entry is educational and not a substitute for professional advice.

Why it matters

Compliance and ethics programs are not static. An organization's risks shift as it enters new markets, adopts new technologies, restructures, or faces changes in the regulatory landscape. A program that was well-designed at one point can drift out of alignment with the organization's actual operations and exposures, leaving policies, training, and controls that no longer address the risks that matter most. Periodic review and evaluation is the mechanism through which an organization tests whether its program still fits its current circumstances rather than assuming that earlier design decisions remain adequate.

Beyond keeping a program current, periodic review supports the credibility of the program as a governance function. It provides a structured occasion to surface gaps, prioritize remediation, and document that leadership treats the program as something to be maintained rather than established once and left unattended. This should be understood as a supporting activity: conducting periodic reviews may help an organization identify and correct weaknesses, but it does not by itself ensure compliance, prevent misconduct, or confer legal protection. Its value depends on the quality of the review, the honesty of the findings, and whether the organization acts on what it learns.

Whether a given cadence or depth of review meets the expectations of any particular regulator or framework is a determination that varies by jurisdiction and context and may require qualified legal counsel. Organizations should avoid treating the mere existence of a review process as evidence that the program is effective; the substance and follow-through matter more than the ritual.

Who it's relevant to

Compliance Officers and Ethics Program Managers
These roles typically own the periodic review process, setting its cadence, defining what components are examined, coordinating inputs from monitoring and audit functions, and ensuring that findings translate into remediation. For them, periodic review is a primary tool for keeping the program aligned with changing risks and demonstrating that the program is actively maintained.
Legal and Audit Teams
Legal teams may be consulted on whether the scope and rigor of a review are adequate relative to applicable regulatory expectations, which vary by jurisdiction and often require qualified counsel to interpret. Audit teams may contribute findings that feed the review and may independently assess whether the review process itself is functioning, while keeping periodic review distinct from their own audit engagements.
Senior Leadership and Boards
Governance bodies rely on the results of periodic reviews to understand whether the compliance program remains fit for purpose and to make decisions about resourcing and remediation. Their engagement signals that the program is treated as a governance priority, though their attention should focus on the substance of findings and follow-through rather than the existence of the review alone.
Learning and Development Staff
Because training is one of the components examined during a review, L&D staff are relevant when evaluation identifies that training content, delivery, or reach no longer matches current risks. Findings from periodic review may prompt updates to training modules, but training remains one part of a larger program and its revision does not on its own satisfy broader program requirements.

Inside Periodic Review and Evaluation

Program Assessment
A structured examination of whether the compliance and ethics program is functioning as designed, covering elements such as policies, training, reporting channels, and monitoring and auditing functions. Assessment is one component of a larger program and does not, by itself, constitute the program.
Effectiveness Evaluation
An analysis intended to gauge how well program elements operate in practice, informed by sources such as the DOJ Evaluation of Corporate Compliance Programs, which addresses how U.S. federal prosecutors assess programs. Evaluation is intended to support improvement; it does not guarantee prevention of misconduct or confer legal protection, and outcomes depend on implementation and context.
Periodic Cadence
The recurring schedule on which reviews are conducted, whether annually or triggered by events such as regulatory change, organizational change, or identified incidents. Exact frequency expectations vary by framework and jurisdiction and should be confirmed against primary sources.
Risk-Responsive Updating
The practice of feeding evaluation findings back into risk assessment and program design so that identified gaps drive revisions to policies, training, or controls. This links the review function to remediation but is distinct from the risk assessment component itself.
Documentation and Evidence
The records demonstrating that reviews occurred, what was examined, and what actions followed. Documentation supports the ability to show a program is subject to ongoing scrutiny, though its evidentiary value depends on the facts and applicable legal standards.
Governance and Accountability
The assignment of responsibility for conducting reviews and acting on findings, typically involving compliance leadership and, where appropriate, oversight bodies. This clarifies who owns the evaluation process rather than describing the substantive content reviewed.

Common questions

Answers to the questions practitioners most commonly ask about Periodic Review and Evaluation.

Does completing a periodic review mean our compliance program is effective and legally defensible?
No. A periodic review is a diagnostic process intended to assess whether program elements are functioning as designed and to identify gaps for remediation; it does not by itself certify effectiveness or confer legal protection. Frameworks such as the DOJ Evaluation of Corporate Compliance Programs treat ongoing review as evidence that a program is dynamic rather than static, but any assessment of effectiveness depends on how findings are acted upon, the quality of underlying controls, and context. Outcomes cannot be guaranteed by the existence of a review process alone.
Is periodic review the same thing as our annual training completion audit?
No. Training completion tracking is one narrow input, not the full scope of periodic review. Periodic review and evaluation is a broader program element that examines multiple components, risk assessment currency, policy adequacy, reporting channel usage, investigation quality, monitoring results, and management engagement, among which training is only one. Treating a training completion metric as a substitute for whole-program review conflates a single indicator with a comprehensive evaluation. This entry is educational and not a substitute for professional advice on how to scope your review.
How often should periodic reviews be conducted?
There is no single mandated frequency that applies universally, and any specific interval should be confirmed against applicable regulatory guidance and your organization's risk profile. Many programs conduct broad reviews on an annual cycle while triggering additional targeted reviews after significant events such as a merger, entry into a new market, a regulatory change, or a discovered incident. Frequency is generally calibrated to the risk level of a given area rather than applied uniformly. Consult qualified counsel where local law imposes specific timing obligations.
Who should own and conduct the periodic review?
Responsibility is commonly assigned to the compliance function, often with support from internal audit, legal, and relevant business units, and with oversight by senior management or a board committee. Some organizations engage independent or external reviewers for objectivity in higher-risk areas. The appropriate structure depends on organizational size, resources, and the independence expected of the reviewer; separating those who design controls from those who evaluate them is generally regarded as supporting objectivity, though it does not guarantee it.
What should a periodic review actually examine?
A review typically examines whether program components remain current and functioning: the risk assessment against the present risk landscape, the code of conduct and policies against regulatory and operational changes, the usage and responsiveness of reporting channels, the timeliness and quality of investigations, monitoring and auditing results, and indicators of management and board engagement. Scope should be defined in advance and tied to the organization's risk profile. The specific elements included are a matter of program design and should reflect applicable frameworks and legal requirements.
How do we document and act on review findings?
Findings are generally documented in a form that records what was examined, what gaps were identified, and what corrective actions were assigned, with owners and timelines. Documenting follow-through on remediation is often as important as the review itself, since it demonstrates that a program is responsive rather than static. How documentation is retained and shared may touch on legal privilege and reporting obligations that vary by jurisdiction, so involve qualified legal counsel on those questions. This guidance is educational and not legal advice.

Common misconceptions

Conducting a periodic review guarantees that a compliance program will be deemed effective or will shield the organization from liability.
Review and evaluation are intended to support program improvement and to demonstrate ongoing attention to the program, but they do not guarantee prevention of misconduct or legal protection. Outcomes depend on implementation, context, and how findings are acted upon, and legal consequences vary by jurisdiction and the facts of a matter.
A once-a-year review satisfies the requirement regardless of what happens in between.
Periodic review contemplates a recurring cadence, but events such as regulatory change, organizational change, or identified incidents may warrant additional or event-triggered evaluation. Fixed frequency expectations vary by framework and are not universally prescribed.
Evaluating the program is the same as evaluating the training component.
Training is one element of a broader compliance and ethics program. A periodic review examines multiple distinct components, policies, reporting channels, monitoring and auditing, and training among them, so reviewing training alone does not constitute evaluation of the whole program.

Best practices

Establish a defined cadence for review while also specifying event-based triggers such as regulatory change, organizational change, or identified incidents.
Evaluate each distinct program component separately, policies, training, reporting channels, and monitoring and auditing, rather than treating any single element as a proxy for the whole.
Feed evaluation findings back into risk assessment and program design so that identified gaps drive concrete remediation.
Document what was reviewed, when, by whom, and what actions followed, recognizing that evidentiary value depends on the facts and applicable legal standards.
Use qualified framing when reporting results, describing the program as intended to support objectives rather than as guaranteeing prevention or legal protection.
Involve qualified legal counsel where review findings touch on jurisdiction-specific obligations or potential liability, since these matters vary by local law and are outside the scope of a glossary definition.