Why complete-looking programs still miss things
Many companies have a code of conduct and a hotline and still miss fraud for years, because the controls that matter sit inside ordinary processes: who can approve a payment, who can add a vendor, who reconciles the accounts, and whether anyone checks the person doing that work. Federal prosecutors have said publicly that they evaluate whether a compliance program works in practice, not just whether it exists on paper, and regulators tend to take a similar view. A program built for a different size of company, or never updated after a reorganization, often has gaps in exactly the places someone has learned to exploit. Industry matters as well. Health care providers, financial institutions, and government contractors face fraud rules of their own, and their programs are expected to reflect them.
Taking stock of what exists
A useful review begins with the documents a company already has, such as written policies, approval limits, the vendor master list, audit findings, prior hotline reports and how they were closed, and training records. Just as important is how things actually work, which usually means talking with the people who process payments and handle accounts. Where a review is meant to stay privileged, its structure matters, because an assessment run by business staff on their own may be discoverable later in litigation or an investigation. If a specific concern has already surfaced, it should be handled as an investigation with its own scope rather than folded into a general review.
Scoping the first engagement
We usually begin by asking what prompted the call, whether a new regulatory obligation, a transaction, a board request, or a problem that has already happened. The answer shapes whether the work is a forward-looking program review, an internal investigation, or both on separate tracks. We also talk through reporting lines, since a compliance function that reports only to the people it monitors has a structural weakness. Where whistleblower reports are already in hand, how they are handled, including protection against retaliation, is an early priority. The goal is a program your people can actually follow, sized to the company you are rather than one in a template.