A compliance program effectiveness review tests whether a client's program is well designed and actually working, rather than whether its documentation exists. The review runs against the seven elements the Federal Sentencing Guidelines use to define an effective program (USSG §8B2.1), with the DOJ's three evaluation questions as its spine: is the program well designed, is it applied earnestly and in good faith, and does it work in practice. The reviewer inventories the artifacts, gap-tests each element against its controlling authority, confirms the risk assessment still drives the rest of the program, scores each element, and delivers a report a board can act on. The review is broader than a single-domain independent test, and it begins after the engagement is already signed.
A compliance program effectiveness review is an independent assessment of whether an organization's compliance and ethics program is well designed and operating as designed, measured against the seven elements of USSG §8B2.1 and the DOJ Criminal Division's Evaluation of Corporate Compliance Programs. It is commissioned by a chief compliance officer, a board or audit committee, a regulator or partner bank, or an acquirer's diligence team, and it is performed by a function or firm independent of the program under review. Clients often commission it under other names — a health check before a fundraise, a baseline for a newly hired chief compliance officer, or a readiness read ahead of a DOJ inquiry — but the deliverable is the same: an independent answer to whether the program would hold up if a prosecutor, examiner, or acquirer's diligence team looked at it closely.
This guide covers how the review is run once the engagement is signed: how it is scoped, what is inventoried, how each element is tested against the authority that governs it, and how findings are scored and reported. It picks up where engagement planning ends — the guide to planning a compliance audit engagement covers the client-acceptance, independence, and engagement-letter work that precedes it — and it hands off to corrective action planning once the findings are delivered.
Boundaries of an effectiveness review
An effectiveness review is not a single-domain independent test. BSA/AML independent testing, for example, is the third pillar of one program under one statute, run on its own cycle against its own rule. An effectiveness review is broader: it tests whether the corporation has an effective compliance and ethics program overall, against the element set the U.S. Sentencing Guidelines use to decide whether program quality should mitigate a criminal sentence. A mature client may eventually need both, run as separate engagements on separate cycles.
It is also not the engagement itself. Screening the client, clearing independence, and signing a letter is its own discipline, and it has to happen first. This guide assumes that work is done and the reviewer already holds a signed mandate to look at the program.
The review is also not a rebuild of the officer's own compliance management system. A consumer-finance client already organized around the CFPB's Compliance Management System framework has its own board-oversight-plus-four-element structure built by the CCO, covered from the officer's side in the guide to compliance management systems. An effectiveness review evaluates a program built by others; constructing the program is a separate engagement.
The three questions that structure the review
The DOJ Criminal Division's Evaluation of Corporate Compliance Programs reduces every effectiveness question to three: is the program well designed, is it being applied earnestly and in good faith, meaning implemented effectively, and does it work in practice? Those three questions are the spine of the review, and every element tested below maps back to one or more of them. A program can be well designed on paper and still fail the third question, which is why an inventory of documents does not on its own constitute an effectiveness review. The distance between design and operation is the region the review is built to measure.
Step 1: Scope the review
Before any artifact is pulled, the reviewer fixes five things: the entity type (public, private, pre-IPO, PE-portfolio, or nonprofit), the industry and material regulatory exposure, the trigger for the review (a new program standup, pre-DOJ readiness, post-finding remediation scoping, an annual board-driven review, or M&A diligence), the audience for the output (the CCO, the board, a regulator, a partner bank, or an acquirer's diligence team), and any incident or finding constraints, such as DPA terms or a monitor mandate, that shape what the review has to cover. The trigger in particular decides depth: a pre-IPO baseline reads differently than a review scoped to close out a single DPA finding.
Step 2: Inventory the artifacts against the seven elements
USSG §8B2.1 sets seven elements an effective program has to contain. For each one, the reviewer pulls the artifacts the DOJ ECCP expects to see and marks each present, absent, or stale, recording the last review date, reviewer, and version.
| Element | Artifacts inventoried |
|---|---|
| 1. Standards and procedures | Board-approved code of conduct, the policies and procedures that operationalize it, and the acknowledgment log confirming employees actually signed. |
| 2. Officer + resources | The board resolution designating a compliance officer, the reporting line, budget authority, and whether the role is crowded out by another job title. |
| 3. Risk assessment | The enterprise compliance risk-assessment methodology, the current risk register, and the material-change log that should trigger a refresh. |
| 4. Training and communication | The role-tailored training plan, completion records by employee and date, and any effectiveness measurement beyond a quiz score. |
| 5. Monitoring and auditing | The monitoring plan, the internal or external audit plan and workpapers, and the findings report delivered to the board or audit committee. |
| 6. Reporting and investigation | The hotline contract, the investigation methodology, and the discipline matrix showing treatment is consistent across seniority levels. |
| 7. Continuous improvement | The most recent annual program-effectiveness evaluation and the action log tying findings to the changes they actually produced. |
Step 3: Gap-test each element against its controlling authority
Each gap the review names carries a citation to the authority it is measured against. The reviewer walks each element's USSG subsection, the applicable DOJ ECCP question, the relevant COSO Internal Control or COSO ERM component, and, for Element 1's board-oversight half, the governing Delaware case law (Caremark, Marchand v. Barnhill). A finding that reads "training is thin" is not testable; a finding that cites §8B2.1(b)(4) and the ECCP's training-and-communications question, and shows the board has not received compliance training in two years, is. This step also confirms which internal-control layer applies: COSO Internal Control (2013) if the engagement needs ICFR-grade rigor, such as a public company, a SOX §404 filer, or a pre-IPO client; COSO ERM (2017) if the program needs to read as integrated with strategy rather than a cost center; and ISO 31000:2018 where the client operates internationally or wants principle-based framing for a non-U.S. board.
Step 4: Confirm the risk assessment actually drives the program
Element 3 carries its own step because the remaining elements depend on it. The reviewer confirms that the enterprise risk assessment is current (most engagements treat anything over 24 months as stale absent a documented reason), that its methodology is written down rather than held as tribal knowledge, that it covers the institution's actual geographies, products, channels, and customer types including third-party intermediaries, and that every control in the program traces back to a named risk in the register. Strong Element 1 and Element 5 artifacts resting on a two-year-old risk assessment document a program aimed at the prior period's risk profile rather than the current one.
Step 5: Score each element and write the finding
The reviewer rates every element satisfactory, moderate, or high-gap, and writes the finding in an issue-rule-application-conclusion structure so the rating carries its own reasoning rather than standing alone as a label.
| Rating | What it means |
|---|---|
| Satisfactory | Required artifacts present, current, and operating; no material gap against the controlling authority. |
| Moderate | Core artifacts exist but a specific, nameable weakness limits reliance, such as a reporting line that creates a conflict. |
| High gap | A required artifact is absent, stale beyond a defensible window, or the element fails a named ECCP question outright. |
Elements almost never land on the same rating, and a review that scores all seven identically is usually a sign the testing wasn't granular enough. A worked example: a pre-IPO client with a newly hired CCO can score satisfactory on Element 2 (board-designated, budgeted, direct board access) while Element 3 rates high-gap because no enterprise risk assessment has run in over two years, a real exposure for an S-1 risk-factor section. Each element is reported on its own terms, and the pattern across all seven sets the priority list.
Testing the client's framework choices
Some clients arrive already chasing a certifiable framework, ISO 27001, SOC 2, or a similar standard, without having tested whether that framework is the right first move. The seven §8B2.1 elements plus COSO and ISO 31000 are the content a program needs regardless of which certifiable wrapper it takes; a separate two-column check decides which wrapper, if any, is worth the client's budget. Every candidate framework is run through both columns.
| Stakeholder expectations (external pull) | Organizational capabilities (internal readiness) |
|---|---|
| Mandatory compliance requirements in the client's jurisdiction | Company size and maturity of existing GRC processes |
| Partner and client contractual obligations | Budget for training, consulting, audit, and certification |
| Frameworks common in the client's industry or country | Availability of internal expertise and resources |
| Competitors' certifications | Organizational readiness for the implementation complexity involved |
| Priorities set by top management | Frameworks already implemented and load-bearing |
A framework earns adoption when it scores meaningfully on both columns. External pull without internal capability produces a certification the client cannot sustain, one driver of the Element 5 failure pattern in which monitoring is evidenced but never analyzed. Internal capability without external pull directs effort toward an expectation no stakeholder holds. This check belongs in Step 1 scoping, or as an addition to Step 3 where a client has treated "we need a compliance program" and "we need ISO 27001" as the same requirement without testing either column.
Step 6: Deliver the report and hand off remediation
The deliverable has three parts: the per-element narrative with its issue-rule-application-conclusion reasoning, the cited gap list, and a priority remediation list ordered by exposure and timing rather than alphabetically by element number. The review ends at that report. Material gaps are sequenced into a remediation plan with owners and dates as a separate, downstream deliverable; the guide to writing a corrective action plan sets out the format that plan takes once a finding requires one.
Where reviews miss real problems
- Every element scored the same. Usually a sign the testing stopped at "does the document exist" instead of testing operation.
- The risk assessment predates the current business. Product launches, new geographies, or M&A activity happened after the last refresh and nobody flagged it.
- Monitoring evidence never gets analyzed. Logs exist; nobody reviewed them for what they show.
- The board never sees the findings in detail. A summary slide replaces the findings register the board is actually accountable for reviewing.
- Program-as-a-whole effectiveness gets conflated with an ICFR-scope audit. A SOX-scoped audit tested financial controls, not whether the compliance program as a whole works.
- Prior findings carry forward untouched. The same gap appears in this year's review and last year's, with no evidence anything changed in between.
Where this sits next to a fraud risk assessment
A compliance-program effectiveness review and a fraud risk assessment are related but distinct engagements. This review tests whether the program's seven elements are present and operating; a dedicated fraud risk assessment tests the client's exposure to specific fraud schemes and the controls built against them, and often runs alongside Element 3 rather than inside it. See the guide to running a fraud risk assessment for a client for how that engagement is scoped and where its findings feed back into this one.
Primary sources
- U.S. Sentencing Commission, Federal Sentencing Guidelines Manual, Chapter 8, §8B2.1: the statutory element set defining an effective compliance and ethics program.
- DOJ Criminal Division, Fraud Section: publisher of the Evaluation of Corporate Compliance Programs, the three-question framework this review's spine is built on.
- COSO, Internal Control: Integrated Framework (2013): the ICFR-grade internal-control layer underneath Elements 1, 3, and 5.
- COSO, Enterprise Risk Management: Integrating with Strategy and Performance (2017): the strategy-integrated layer for Element 3 and Element 7.
- ISO 31000:2018, Risk Management: Guidelines: the process-discipline layer for international or non-financial-sector clients.
- Singh, Nitish, and Bussen, Thomas J. (2015). Compliance Management: A How-to Guide for Executives, Lawyers, and Other Compliance Professionals. Praeger / ABC-CLIO.
- Prozorov, Andrey. The GRC Handbook, Volume 2: Standards & Frameworks. Self-published, source of the two-column framework-selection method above.