What a program can and cannot do
A strong compliance program rarely erases liability on its own, because companies can often be held responsible for employees acting within the scope of their jobs. What it can do is influence whether prosecutors and regulators bring charges, what penalty they seek, and whether a monitor is required. Federal prosecutors evaluate corporate programs using published guidance that asks, in essence, whether the program was well designed and whether it actually worked in practice. Some statutes and agency rules also give weight to a program when setting penalties. A compliance defense is therefore usually a mitigation argument backed by evidence rather than a complete defense.
Evidence of a working program
Regulators look past the policy binder to how the program behaved. Training records, hotline reports and how they were handled, audit results, disciplinary decisions, and the resources given to the compliance function all help show whether controls were real. The response to this particular issue matters as well: how quickly the company investigated, whether it fixed the root cause, and whether discipline was applied consistently. Gather these records through counsel, and be careful about creating new documents that characterize past events. Old policies should never be revised after the fact to look more complete.
Presenting the case for mitigation
Timing matters, and so does whether the company disclosed the issue voluntarily, since many enforcement programs give significant weight to self-reporting and to cooperation. A presentation that acknowledges weaknesses and shows how they were fixed is often more credible than one that claims a flawless program. Our first conversation covers what the regulator is alleging, what the program looked like at the relevant time, and what remediation has already happened. We then decide whether to build the mitigation presentation now or after the facts are clearer.