Field Guide

How to Run a Compliance Program Effectiveness Review for a Client

The short version

A compliance program effectiveness review tests whether a client's program is well designed and actually working, rather than whether its documentation exists. The review runs against the seven elements the Federal Sentencing Guidelines use to define an effective program (USSG §8B2.1), with the DOJ's three evaluation questions as its spine: is the program well designed, is it applied earnestly and in good faith, and does it work in practice. The reviewer inventories the artifacts, gap-tests each element against its controlling authority, confirms the risk assessment still drives the rest of the program, scores each element, and delivers a report a board can act on. The review is broader than a single-domain independent test, and it begins after the engagement is already signed.

A compliance program effectiveness review is an independent assessment of whether an organization's compliance and ethics program is well designed and operating as designed, measured against the seven elements of USSG §8B2.1 and the DOJ Criminal Division's Evaluation of Corporate Compliance Programs. It is commissioned by a chief compliance officer, a board or audit committee, a regulator or partner bank, or an acquirer's diligence team, and it is performed by a function or firm independent of the program under review. Clients often commission it under other names — a health check before a fundraise, a baseline for a newly hired chief compliance officer, or a readiness read ahead of a DOJ inquiry — but the deliverable is the same: an independent answer to whether the program would hold up if a prosecutor, examiner, or acquirer's diligence team looked at it closely.

This guide covers how the review is run once the engagement is signed: how it is scoped, what is inventoried, how each element is tested against the authority that governs it, and how findings are scored and reported. It picks up where engagement planning ends — the guide to planning a compliance audit engagement covers the client-acceptance, independence, and engagement-letter work that precedes it — and it hands off to corrective action planning once the findings are delivered.

Boundaries of an effectiveness review

An effectiveness review is not a single-domain independent test. BSA/AML independent testing, for example, is the third pillar of one program under one statute, run on its own cycle against its own rule. An effectiveness review is broader: it tests whether the corporation has an effective compliance and ethics program overall, against the element set the U.S. Sentencing Guidelines use to decide whether program quality should mitigate a criminal sentence. A mature client may eventually need both, run as separate engagements on separate cycles.

It is also not the engagement itself. Screening the client, clearing independence, and signing a letter is its own discipline, and it has to happen first. This guide assumes that work is done and the reviewer already holds a signed mandate to look at the program.

The review is also not a rebuild of the officer's own compliance management system. A consumer-finance client already organized around the CFPB's Compliance Management System framework has its own board-oversight-plus-four-element structure built by the CCO, covered from the officer's side in the guide to compliance management systems. An effectiveness review evaluates a program built by others; constructing the program is a separate engagement.

The three questions that structure the review

The DOJ Criminal Division's Evaluation of Corporate Compliance Programs reduces every effectiveness question to three: is the program well designed, is it being applied earnestly and in good faith, meaning implemented effectively, and does it work in practice? Those three questions are the spine of the review, and every element tested below maps back to one or more of them. A program can be well designed on paper and still fail the third question, which is why an inventory of documents does not on its own constitute an effectiveness review. The distance between design and operation is the region the review is built to measure.

Step 1: Scope the review

Before any artifact is pulled, the reviewer fixes five things: the entity type (public, private, pre-IPO, PE-portfolio, or nonprofit), the industry and material regulatory exposure, the trigger for the review (a new program standup, pre-DOJ readiness, post-finding remediation scoping, an annual board-driven review, or M&A diligence), the audience for the output (the CCO, the board, a regulator, a partner bank, or an acquirer's diligence team), and any incident or finding constraints, such as DPA terms or a monitor mandate, that shape what the review has to cover. The trigger in particular decides depth: a pre-IPO baseline reads differently than a review scoped to close out a single DPA finding.

Step 2: Inventory the artifacts against the seven elements

USSG §8B2.1 sets seven elements an effective program has to contain. For each one, the reviewer pulls the artifacts the DOJ ECCP expects to see and marks each present, absent, or stale, recording the last review date, reviewer, and version.

ElementArtifacts inventoried
1. Standards and proceduresBoard-approved code of conduct, the policies and procedures that operationalize it, and the acknowledgment log confirming employees actually signed.
2. Officer + resourcesThe board resolution designating a compliance officer, the reporting line, budget authority, and whether the role is crowded out by another job title.
3. Risk assessmentThe enterprise compliance risk-assessment methodology, the current risk register, and the material-change log that should trigger a refresh.
4. Training and communicationThe role-tailored training plan, completion records by employee and date, and any effectiveness measurement beyond a quiz score.
5. Monitoring and auditingThe monitoring plan, the internal or external audit plan and workpapers, and the findings report delivered to the board or audit committee.
6. Reporting and investigationThe hotline contract, the investigation methodology, and the discipline matrix showing treatment is consistent across seniority levels.
7. Continuous improvementThe most recent annual program-effectiveness evaluation and the action log tying findings to the changes they actually produced.

Step 3: Gap-test each element against its controlling authority

Each gap the review names carries a citation to the authority it is measured against. The reviewer walks each element's USSG subsection, the applicable DOJ ECCP question, the relevant COSO Internal Control or COSO ERM component, and, for Element 1's board-oversight half, the governing Delaware case law (Caremark, Marchand v. Barnhill). A finding that reads "training is thin" is not testable; a finding that cites §8B2.1(b)(4) and the ECCP's training-and-communications question, and shows the board has not received compliance training in two years, is. This step also confirms which internal-control layer applies: COSO Internal Control (2013) if the engagement needs ICFR-grade rigor, such as a public company, a SOX §404 filer, or a pre-IPO client; COSO ERM (2017) if the program needs to read as integrated with strategy rather than a cost center; and ISO 31000:2018 where the client operates internationally or wants principle-based framing for a non-U.S. board.

Step 4: Confirm the risk assessment actually drives the program

Element 3 carries its own step because the remaining elements depend on it. The reviewer confirms that the enterprise risk assessment is current (most engagements treat anything over 24 months as stale absent a documented reason), that its methodology is written down rather than held as tribal knowledge, that it covers the institution's actual geographies, products, channels, and customer types including third-party intermediaries, and that every control in the program traces back to a named risk in the register. Strong Element 1 and Element 5 artifacts resting on a two-year-old risk assessment document a program aimed at the prior period's risk profile rather than the current one.

Step 5: Score each element and write the finding

The reviewer rates every element satisfactory, moderate, or high-gap, and writes the finding in an issue-rule-application-conclusion structure so the rating carries its own reasoning rather than standing alone as a label.

RatingWhat it means
SatisfactoryRequired artifacts present, current, and operating; no material gap against the controlling authority.
ModerateCore artifacts exist but a specific, nameable weakness limits reliance, such as a reporting line that creates a conflict.
High gapA required artifact is absent, stale beyond a defensible window, or the element fails a named ECCP question outright.

Elements almost never land on the same rating, and a review that scores all seven identically is usually a sign the testing wasn't granular enough. A worked example: a pre-IPO client with a newly hired CCO can score satisfactory on Element 2 (board-designated, budgeted, direct board access) while Element 3 rates high-gap because no enterprise risk assessment has run in over two years, a real exposure for an S-1 risk-factor section. Each element is reported on its own terms, and the pattern across all seven sets the priority list.

Testing the client's framework choices

Some clients arrive already chasing a certifiable framework, ISO 27001, SOC 2, or a similar standard, without having tested whether that framework is the right first move. The seven §8B2.1 elements plus COSO and ISO 31000 are the content a program needs regardless of which certifiable wrapper it takes; a separate two-column check decides which wrapper, if any, is worth the client's budget. Every candidate framework is run through both columns.

Stakeholder expectations (external pull)Organizational capabilities (internal readiness)
Mandatory compliance requirements in the client's jurisdictionCompany size and maturity of existing GRC processes
Partner and client contractual obligationsBudget for training, consulting, audit, and certification
Frameworks common in the client's industry or countryAvailability of internal expertise and resources
Competitors' certificationsOrganizational readiness for the implementation complexity involved
Priorities set by top managementFrameworks already implemented and load-bearing

A framework earns adoption when it scores meaningfully on both columns. External pull without internal capability produces a certification the client cannot sustain, one driver of the Element 5 failure pattern in which monitoring is evidenced but never analyzed. Internal capability without external pull directs effort toward an expectation no stakeholder holds. This check belongs in Step 1 scoping, or as an addition to Step 3 where a client has treated "we need a compliance program" and "we need ISO 27001" as the same requirement without testing either column.

Step 6: Deliver the report and hand off remediation

The deliverable has three parts: the per-element narrative with its issue-rule-application-conclusion reasoning, the cited gap list, and a priority remediation list ordered by exposure and timing rather than alphabetically by element number. The review ends at that report. Material gaps are sequenced into a remediation plan with owners and dates as a separate, downstream deliverable; the guide to writing a corrective action plan sets out the format that plan takes once a finding requires one.

Where reviews miss real problems

Where this sits next to a fraud risk assessment

A compliance-program effectiveness review and a fraud risk assessment are related but distinct engagements. This review tests whether the program's seven elements are present and operating; a dedicated fraud risk assessment tests the client's exposure to specific fraud schemes and the controls built against them, and often runs alongside Element 3 rather than inside it. See the guide to running a fraud risk assessment for a client for how that engagement is scoped and where its findings feed back into this one.

Primary sources

Common questions

What's the difference between a compliance program effectiveness review and independent testing?
Independent testing, BSA/AML's third pillar for example, tests one program under one statute on its own cycle. An effectiveness review is broader: it tests whether the corporation has an effective compliance and ethics program overall, against the seven-element set the Federal Sentencing Guidelines use to decide whether program quality should mitigate a criminal sentence. A mature client may need both, run separately, on different cycles.
Who can run a compliance program effectiveness review?
An internal function independent of the program being reviewed, or an external consultant or firm. What matters is independence from the people who run the program and competence to test it against the seven-element set and its underlying authority, not a specific title or credential.
How is an effectiveness review different from planning a compliance audit engagement?
Planning is the client-acceptance, independence-clearance, and engagement-letter work that happens before the reviewer looks at a single document. An effectiveness review is what runs after that letter is signed: scoping, inventory, gap-testing, and scoring the program itself. Planning ends where this review begins.
Does every element have to score the same, or can some be stronger than others?
Elements almost never score the same, and a review that rates all seven identically is a signal the testing wasn't granular enough. A newly designated compliance officer with board access can score well on Element 2 while the risk assessment under Element 3 is two years stale. Each element is reported on its own merits, and the pattern across all seven drives the priority list.
What happens to the findings after the review is delivered?
Material gaps get sequenced into a remediation plan with owners and dates, a separate deliverable built from the review's cited findings. The review itself ends at the report and the priority list; it doesn't extend into managing the remediation unless that's a separately scoped engagement.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.