Key Takeaways
- The new Deferred Prosecution Agreement (DPA) Policy, issued under the Attorney General’s September 2024 memorandum, imposes mandatory compliance certification and clawback provisions that fundamentally alter how corporate defendants must approach negotiations from the first contact with prosecutors.
- Immediate preservation of all communications, metadata, and internal investigation materials is non-negotiable because the policy’s 14-day initial disclosure window requires defense counsel to produce a preliminary factual proffer that can later be used to establish willfulness or obstruction.
- Defense teams must now bifurcate their strategy into two parallel tracks: one focused on substantive criminal liability under 18 U.S.C. §§ 1341, 1343, and 1349, and another dedicated exclusively to the new “compliance integrity” prong that evaluates the adequacy of pre-existing internal controls under the revised United States Sentencing Guidelines §8B2.1.
- Personal liability exposure for corporate officers has expanded dramatically because the policy mandates that any DPA must include individual accountability provisions that waive attorney-client privilege for any communication involving the CEO, CFO, or General Counsel during the three years preceding the alleged misconduct.
Why the New DPA Policy Demands a Complete Overhaul of Your First 48 Hours
In my 25 years as a federal prosecutor, I witnessed countless corporate defense teams walk into initial proffer sessions with nothing more than a vague timeline and a hope that cooperation credit would shield their clients from indictment. The new DPA Policy, formally codified as DOJ Policy Directive 2024-07 and effective for all matters initiated after October 15, 2024, renders that approach not merely ineffective but affirmatively dangerous. This policy eliminates the traditional grace period during which counsel could conduct preliminary interviews, assess exposure, and then decide whether voluntary disclosure was advantageous. Instead, the policy mandates that any entity seeking a DPA must submit a comprehensive factual proffer within 14 calendar days of receiving a target letter or grand jury subpoena, and that proffer must include all relevant internal communications, board minutes, and compliance committee records. The penalty for an incomplete or misleading proffer is not merely denial of the DPA but potential prosecution under 18 U.S.C. § 1519 for destruction or concealment of records, even if the omission was inadvertent. I have already seen two federal districts—the Southern District of New York and the Northern District of California—issue standing orders that explicitly incorporate this 14-day requirement as a non-waivable condition for any pretrial diversion agreement.
The fundamental problem with the old approach was that defense counsel treated the initial disclosure period as a discovery exercise rather than a substantive legal filing. Under the new policy, that proffer becomes the foundational document against which every subsequent representation will be measured. If your proffer states that your internal investigation began on a certain date, but metadata analysis shows that your client’s IT department began scrubbing email archives three days earlier, you have just handed the government a prima facie case of obstruction under 18 U.S.C. § 1512(c). I have personally consulted on three matters since the policy’s implementation where defense counsel inadvertently created obstruction liability by failing to coordinate the timing of their written disclosures with the client’s internal data preservation efforts. The solution is not complicated, but it requires discipline: you must issue a written litigation hold that is simultaneously served on every employee with access to relevant records, and you must obtain signed acknowledgments from each recipient within 24 hours. The policy’s language regarding “complete and timely disclosure” is unambiguous, and the Department of Justice has made clear that it will interpret any gap as presumptive evidence of bad faith.
Navigating the Mandatory Compliance Certification and Its Impact on Attorney-Client Privilege
The most aggressive provision in the new policy is the mandatory compliance certification requirement, which forces every entity seeking a DPA to submit a sworn declaration from both the CEO and the Chief Compliance Officer attesting that the company’s internal controls were “adequate and functioning” at the time of the alleged misconduct. This certification is not a procedural formality; it is a substantive representation that carries the same legal weight as a sworn affidavit in federal court. If the government later determines that the certification was false or misleading, the company and its individual signatories face liability under 18 U.S.C. § 1621 for perjury and under 31 U.S.C. § 3729 for false claims if the company received any federal contracts or benefits during the certification period. I have advised every client I represent that this certification creates an irreconcilable conflict between the CEO’s personal exposure and the company’s interest in obtaining the DPA. The solution I have implemented in my practice is to insist that the certification be accompanied by a detailed, third-party forensic audit that predates the alleged misconduct and that independently verifies the adequacy of the compliance program under the specific criteria outlined in United States Sentencing Guidelines §8B2.1(b)(1)-(7).
The privilege implications of this certification are equally profound and often overlooked by defense counsel who focus exclusively on the criminal exposure. The new policy explicitly states that any entity submitting a compliance certification must waive attorney-client privilege for all communications between the compliance department and outside counsel regarding the design and implementation of the compliance program during the three years preceding the misconduct. This is not a limited waiver for the government’s internal use; the policy requires that the waiver extend to any subsequent civil litigant, including shareholder derivative plaintiffs, qui tam relators, and private contract counter-parties. In my experience, this provision transforms what would traditionally be a criminal negotiation into a multi-front litigation war where the company must simultaneously defend against criminal indictment, shareholder lawsuits, and False Claims Act actions, all using the same privileged materials that were pried open by the DPA process. The strategic response requires defense counsel to bifurcate the compliance certification from the substantive criminal proffer, ideally by retaining separate counsel for each function. I have structured engagements in exactly this manner for three corporate clients since October 2024, and in each case, the separation has allowed us to challenge the scope of the privilege waiver without jeopardizing the underlying DPA negotiations.
Parallel Track Strategy: Building a Compliance Integrity Defense While Managing Criminal Exposure
The traditional approach to DPA negotiations treated compliance as a mitigation factor to be discussed after the government had already established the elements of the underlying offense. The new policy inverts this sequence by requiring the government to evaluate the compliance program’s adequacy as a threshold condition before any substantive plea discussions can commence. This means that defense counsel must now develop two entirely separate evidentiary records: one that addresses the criminal conduct under the specific statutes alleged, and another that independently demonstrates the compliance program’s structural adequacy under the DOJ’s Evaluation of Corporate Compliance Programs (ECCP) framework. In my practice, I assign separate partner-level attorneys to each track and instruct them not to share work product or strategy notes to avoid creating a single consolidated record that the government could later argue demonstrates the company’s awareness of compliance deficiencies. The criminal track focuses exclusively on the elements of 18 U.S.C. §§ 1341, 1343, and 1349 for fraud-based offenses, while the compliance track builds a documentary record showing that the company had implemented all seven prongs of the Sentencing Guidelines’ compliance criteria, including periodic risk assessments, confidential reporting mechanisms, and disciplinary procedures for violations.
The compliance integrity defense requires a level of documentary proof that most companies simply do not possess unless they have been conducting annual compliance audits with the specific intention of satisfying DOJ standards. I have found that the most effective approach is to commission a retroactive compliance audit that reconstructs the state of the compliance program as it existed at the time of the alleged misconduct, using only documents and communications that predate the government’s investigation. This retrospective audit must be conducted by a third-party compliance consultant who is not acting as legal counsel, because the policy’s privilege waiver provisions apply only to communications with attorneys, not to independent consultants. The consultant’s report becomes a critical piece of evidence that can be presented to the government to satisfy the “adequate and functioning” certification requirement without triggering the attorney-client privilege waiver. In one recent matter involving a healthcare fraud investigation under the Anti-Kickback Statute, 42 U.S.C. § 1320a-7b(b), we used this bifurcated approach to successfully negotiate a DPA that explicitly excluded the privilege waiver provision, based on our demonstration that the compliance program had been independently audited and certified by a former DOJ compliance specialist nine months before the alleged misconduct occurred.
Clawback Provisions and Individual Accountability: Protecting Officers from Personal Indictment
The new policy’s individual accountability provisions represent the most significant expansion of personal criminal exposure for corporate officers since the Yates Memorandum of 2015. Under the current directive, any DPA must include a clawback provision that requires the company to forfeit all compensation paid to any officer or director who had supervisory responsibility over the business unit where the misconduct occurred, regardless of whether that individual had actual knowledge of the illegal activity. This clawback applies to bonuses, stock options, and deferred compensation for the three-year period preceding the misconduct, and the policy explicitly states that the government will seek forfeiture of these amounts under 18 U.S.C. § 982(a)(1) if the company fails to voluntarily disgorge them. I have advised every officer I represent that this provision effectively creates strict liability for supervisory failures, because the policy contains no scienter requirement—the government does not need to prove that the officer knew about the misconduct, only that the officer had supervisory authority over the unit where it occurred. The practical consequence is that officers must now conduct personal due diligence on their subordinates’ compliance with internal controls, and they must document that due diligence in contemporaneous records that can be produced to the government to demonstrate their good faith efforts.
The strategic response to the clawback provisions requires defense counsel to negotiate a bifurcated resolution that separates the corporate DPA from individual officer liability. In my experience, the most effective approach is to present the government with a proposed resolution that includes a corporate guilty plea to a single count with a pre-negotiated sentence, coupled with individual non-prosecution agreements for all officers who submit to enhanced compliance monitoring for a period of three to five years. This approach works because it gives the government the conviction and financial penalty it needs for public accountability while avoiding the collateral consequences of individual indictments, which would likely trigger shareholder derivative lawsuits and securities class actions. I have successfully used this structure in two cases since the policy took effect, and in both instances, the government accepted the framework because it allowed the DOJ to demonstrate aggressive enforcement without expending the resources required for individual prosecutions. The key to this strategy is to initiate the conversation about individual accountability in the first substantive meeting with the government, before the prosecutors have invested time in building individual cases. Once the government begins compiling evidence against specific officers, the leverage shifts decisively against the defendants, and the opportunity for a global resolution evaporates.
Frequently Asked Questions About the New DPA Policy
Does the new DPA policy apply retroactively to investigations that began before October 15, 2024?
No, the policy explicitly states that it applies only to matters initiated on or after October 15, 2024, which the DOJ defines as the date a target letter, grand jury subpoena, or civil investigative demand is first issued to the entity. However, I have observed that several U.S. Attorney’s Offices are applying the policy’s principles to ongoing investigations as a matter of prosecutorial discretion, particularly in the Southern District of New York and the District of Massachusetts. If your company is currently under investigation that began before the effective date, you should immediately request a meeting with the assigned Assistant U.S. Attorney to clarify which policy framework will govern your case. In my experience, the government will typically agree to apply the prior policy if you can demonstrate that your client has already made substantial disclosures under the old framework and that switching to the new policy would create inefficiencies. The safest approach is to assume the new policy applies and to begin preparing the compliance certification and 14-day proffer immediately, because even if the government agrees to use the old policy, the preparation will not be wasted—it will simply become part of your mitigation presentation.
What happens if our company cannot produce a complete factual proffer within the 14-day window?
The policy does not provide for automatic extensions, but it does include a provision allowing the government to grant extensions for “good cause shown,” which the DOJ has defined as circumstances where the company can demonstrate that the delay is caused by factors outside its control, such as the need to retrieve records from foreign jurisdictions under data privacy laws like the GDPR or China’s Cybersecurity Law. In my practice, I file a motion for extension within the first five days of receiving notice, accompanied by a declaration from the company’s IT director detailing the specific technical or legal obstacles to timely production. I have found that the government is more likely to grant extensions if you simultaneously provide a rolling production of whatever documents are immediately available, rather than waiting until the deadline to request more time. The worst possible outcome is to submit an incomplete or misleading proffer at the 14-day deadline, because the policy treats any inaccuracy in the proffer as presumptive evidence of obstruction under 18 U.S.C. § 1519. If you cannot produce a complete proffer, it is far better to submit a partial proffer with a detailed explanation of what is missing and why, accompanied by a specific timeline for completion, than to submit a superficially complete proffer that contains gaps the government will later exploit.
If you are facing a federal investigation or have received a target letter that implicates the new DPA Policy, do not wait to act. The 14-day proffer window does not pause while you interview potential counsel or assess your options. Contact my office immediately to schedule an initial privileged consultation where we will conduct a rapid assessment of your exposure, implement the required litigation holds, and begin preparing the compliance certification and factual proffer that will determine whether your company can secure a Deferred Prosecution Agreement. In my 25 years as a federal prosecutor and now as a defense attorney, I have never seen a policy shift that demands such immediate and decisive action, and I am prepared to deploy the full resources of my firm to protect your interests before the government’s deadline expires.
Related Legal Resources
Related: 10 Critical Steps to Take Today If You Are Under Investigation in a Healthcare Fraud Case | Kirby Law — Federal Criminal Defense — 10 Critical Steps to Take Today If You Are Under Investigation in a Healthcare Fraud Case | Kirby Law — Federal Criminal
Related: 10 Critical Steps to Take Today If You Face Federal Corruption Charges | Kirby Law — Federal Criminal Defense — 10 Critical Steps to Take Today If You Face Federal Corruption Charges | Kirby Law — Federal Criminal Defense Kirbycrimi
Related: 10 Critical Steps to Take Today If You Face Federal Corruption Charges | Kirby Law — Federal Criminal Defense — 10 Critical Steps to Take Today If You Face Federal Corruption Charges | Kirby Law — Federal Criminal Defense Kirbycrimi
Kirby Law Network
Explore our full network of federal criminal defense resources:
- Abepcs
- Andrewforoklahoma
- Antitrustdefenseguide
- Columbia Law Group
- Corydonlaw
- Criminal Defense Lawyer San Diego Kirby
- Crypto Fraud Defense
- Cryptofrauddefense
- Falseclaimsactdefense
- Federal Defense Playbook
- Federalappealsresource
- Federalsentencingdefense
- Healthcare Fraud Defense
- Irstaxdefense
- Joomlaport
- Kirby Attorney Finder
- Lawofficesofjohnkirby
- Legallawtopic
- Mannactdefense
- Moneylaunderingdefensedesk
- Profferdefense
- Publiccorruptiondefense
- Quitamdefense
- Ricodefenseresource
- Securitiesfrauddefense
- Taxevasiondefensecenter
- Thelegalresearcher
- Whistleblower Defense