[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"article-body-the-eccp-grades-your-algorithms":3},"\nIn September 2024, the US Department of Justice revised the ECCP,\nits guidance on how prosecutors evaluate corporate compliance\nprogrammes. Buried in the revision is a shift most of the\ncompliance AI market has declined to mention. Prosecutors\nassessing a company's programme are now directed to examine how\nthe company manages risks from its own use of AI, from safeguards\nagainst misuse to monitoring and the ability of humans to\nintervene.\n[Cooley](https://investigations.cooley.com/2024/10/09/doj-focuses-on-ai-emerging-tech-in-newly-issued-guidance-updates-for-evaluating-corporate-compliance-programs/)\nand\n[Jones Day](https://www.jonesday.com/en/insights/2024/10/doj-updates-corporate-compliance-program-guidance-with-a-focus-on-ai)\nanalysed the revision at the time. The guidance also presses a\nquieter question. Do compliance teams get access to company data\non par with the business functions they police?\n\nFollow the logic one step further and it turns recursive. The AI\nyou deploy to run compliance is itself AI the company uses. It is\nin scope.\n\n*The evaluator's AI gets evaluated.*\n\n## What changed, precisely\n\nBefore the revision, compliance AI was an operational choice,\njudged on effectiveness, nobody's enforcement exposure. The 2024\ntext moves it. If a screening model quietly deteriorates, if a\ntriage algorithm buries the complaint that mattered, if nobody can\nsay who validated the model that clears third parties, those stop\nbeing tooling disappointments. They become answers a prosecutor\ncollects while grading your programme, and the grade influences\ncharging decisions, monitorships and penalties.\n\nMark one boundary honestly, because in this territory the dates\nmatter. The operative text remains the September 2024 guidance.\nReports of a further revision have circulated without\nmaterialising, and this argument needs none of them.\n\n## The questions a prosecutor would ask\n\nWhich AI systems touch your compliance programme, and does an\ninventory exist? How was each validated before deployment, and by\nwhom? How would you know a model had degraded, and how quickly?\nWhen it flags, or fails to flag, can a human see why, override it,\nand have the override recorded? And does compliance see the same\ndata the business sees, or a curated subset?\n\nMost compliance functions running AI today would answer from\nmemory and hope. Many bought their AI precisely to demonstrate\nprogramme seriousness, without noticing that an unvalidated,\nunmonitored model demonstrates the opposite, in writing, to the\nleast sympathetic audience available.\n\n## The artefact that answers in writing\n\nEvery question on that list is a record-keeping question, so it\nhas a record-keeping answer. That answer is an inventory with\nowners, validation reports dated before deployment, continuous\nperformance scoring so degradation is a detected event rather than\na retrospective discovery, logged overrides with reasons, and\naccess parity you can demonstrate rather than assert.\n\nThat bundle is a [Model Passport](/insights/the-model-passport),\napplied to the compliance stack itself. The same discipline that\nmakes\n[misconduct prediction defensible](/insights/predicting-misconduct-before-the-hotline-call)\nmakes the ECCP conversation short. Prophesee ships it by\nconstruction, for our models and the ones you already run, because\nevidence produced by operation is the only kind that stands up to\na prosecutor's timeline. [Start here](/contact).\n",1786984937417]