The ECCP grades your algorithms

Since September 2024, US prosecutors evaluating a compliance programme are directed to assess how the company governs its own AI. The tool you bought to manage compliance risk is itself in scope, and "we use AI for compliance" became a claim you must be able to defend.

2 min read

In September 2024, the US Department of Justice revised the ECCP, its guidance on how prosecutors evaluate corporate compliance programmes. Buried in the revision is a shift most of the compliance AI market has declined to mention. Prosecutors assessing a company's programme are now directed to examine how the company manages risks from its own use of AI, from safeguards against misuse to monitoring and the ability of humans to intervene. Cooley and Jones Day analysed the revision at the time. The guidance also presses a quieter question. Do compliance teams get access to company data on par with the business functions they police?

Follow the logic one step further and it turns recursive. The AI you deploy to run compliance is itself AI the company uses. It is in scope.

The evaluator's AI gets evaluated.

What changed, precisely

Before the revision, compliance AI was an operational choice, judged on effectiveness, nobody's enforcement exposure. The 2024 text moves it. If a screening model quietly deteriorates, if a triage algorithm buries the complaint that mattered, if nobody can say who validated the model that clears third parties, those stop being tooling disappointments. They become answers a prosecutor collects while grading your programme, and the grade influences charging decisions, monitorships and penalties.

Mark one boundary honestly, because in this territory the dates matter. The operative text remains the September 2024 guidance. Reports of a further revision have circulated without materialising, and this argument needs none of them.

The questions a prosecutor would ask

Which AI systems touch your compliance programme, and does an inventory exist? How was each validated before deployment, and by whom? How would you know a model had degraded, and how quickly? When it flags, or fails to flag, can a human see why, override it, and have the override recorded? And does compliance see the same data the business sees, or a curated subset?

Most compliance functions running AI today would answer from memory and hope. Many bought their AI precisely to demonstrate programme seriousness, without noticing that an unvalidated, unmonitored model demonstrates the opposite, in writing, to the least sympathetic audience available.

The artefact that answers in writing

Every question on that list is a record-keeping question, so it has a record-keeping answer. That answer is an inventory with owners, validation reports dated before deployment, continuous performance scoring so degradation is a detected event rather than a retrospective discovery, logged overrides with reasons, and access parity you can demonstrate rather than assert.

That bundle is a Model Passport, applied to the compliance stack itself. The same discipline that makes misconduct prediction defensible makes the ECCP conversation short. Prophesee ships it by construction, for our models and the ones you already run, because evidence produced by operation is the only kind that stands up to a prosecutor's timeline. Start here.

New essays land on LinkedIn first. Follow 3RDi to catch them, or get a demo to see Prophesee on your own data.