How enforcers look at programs
The Antitrust Division of the Department of Justice has published guidance describing how it evaluates corporate compliance programs when making charging decisions and sentencing recommendations, and that guidance has been updated to address messaging apps and ephemeral communications. The questions it asks are practical, centering on whether a program fits the company's real risks and whether it actually works day to day, including whether problems get detected and reported. A strong program does not erase liability for past conduct, but it can affect how a matter is resolved. State enforcers and foreign competition authorities increasingly ask similar questions.
Building one that fits
A useful program starts with a risk assessment covering where employees interact with competitors, how pricing and bidding decisions are made, which markets the company holds a significant position in, and which jurisdictions it operates in. Policies should be written for the people who need them, with concrete guidance on trade association meetings, information exchange, and hiring practices. Training tends to stick when it is targeted and repeated for sales, procurement, and human resources staff. A reporting channel where employees can raise concerns without retaliation, periodic audits, and records of what the company did all become evidence later of how seriously it took compliance. Collect existing policies, training materials, organizational charts, and records of any past antitrust issues.
Starting or revisiting a program
Companies often begin a program after an acquisition, an entry into a new market, a competitor's investigation, or an internal incident. If the trigger is a specific concern, the first step is to look into that concern under counsel's direction rather than folding it quietly into general training. In a first conversation, we discuss the company's size and industry, how it meets its competitors, what program already exists, and whether there is a deadline, such as a board meeting or a customer requirement. We then propose a scope proportionate to the actual risks, rather than a template designed for a much larger company.