One of the obviously expected elements of any compliance and ethics (“C&E”) program is to conduct audits to determine what is really happening in the company, how well the program has been implemented, and whether it is getting the right results. Such audits feature prominently in government guidelines on compliance programs and as accepted practice in these programs.
But beneath this obvious point, there is another question to be considered. Should those being audited be told in advance, or should there be audits that hit a business operation by surprise? Should there be reviews where the auditors show up unannounced?
Let’s start with a clarifying point. What we are dealing with here is not investigations. Investigations are triggered by specific allegations of misconduct, and have a specific reason for being conducted without notice and without opportunity to cover up ongoing illegal activity. Investigations have a different purpose and dynamic. We are also not dealing with overall program assessments, such as those that may be conducted by an outside assessment provider. These reviews are examining the program on a broader basis. Rather, what we are examining here are reviews typically focused on specific risk areas, such as antirust, bribery, unsafe practices or environmental compliance.
When it comes to internal compliance audits, the question is whether the process should include unannounced or surprise audits. I have had the experience of doing both announced and unannounced audits in my own practice. I could understand the rationale for this, and in doing them did uncover things that were at least interesting from a compliance perspective. But I did not like them and especially disliked the potential impact on the relationship between employees and the compliance program. Showing up like US Marshalls or EU competition law enforcers engaged in dawn raids, did, perhaps, have a shock value and sent a message, but there were serious trade-offs. Did we want to come across as a group whose favorite expression was “gotcha”?
What would be the reason to do surprise audits?
An important element in any compliance program is the impact it would have on government enforcers and regulators when a violation occurs. Will the C&E program actually demonstrate a good faith commitment to doing the right thing and preventing misconduct. Or is it just form with no substance? So it is important to look at government perspectives on this question.
In the US the first instinct is to look at the DOJ guidance, typically on the assumption that the Criminal Division’s Evaluation of Corporate Compliance Programs[i] guidance document, covering the types of questions a Criminal Division prosecutor might ask about a company’s compliance program, speaks for all of DOJ (it does not – it addresses only that one Division in DOJ). The reference to audits does not specifically call for unannounced audits. It says “How are audits carried out? What types of audits would have identified issues relevant to the misconduct?” This could give scope to the Criminal Division to fault a company’s efforts, if it had appeared that only conducting unannounced audits would have uncovered the misconduct. But there is no more detail about this in the ECCP, and nothing that directs companies to conduct surprise audits.
Review of the DOJ/SEC guidance on the FCPA and compliance programs related to bribery also does not reference surprise audits. Similarly, for the Environmental and Natural Resources Division’s compliance program guidance (July 1, 1991), there is no reference to surprise audits.
There is, however, one Division in DOJ that has been more specific. As early as 1992, a senior official in the Antitrust Division, discussing their expectation for antitrust compliance programs, did include a reference to unannounced reviews:
“Both regular and unannounced audits of price changes, discount practices and bid sheets, conducted by those familiar with the firm’s past and present business practices and trained in recognizing questionable divergence, would be examples of creditable affirmative action.”[ii] (emphasis added)
The Division’s current guidance carries this forward:
“What monitoring or auditing mechanisms does the company have in place to detect antitrust violations? . . . For example, are there routine or unannounced audits (e.g., a periodic review of documents/communications from specific employees; performance evaluations and employee self-assessments for specific employees; interviews of specific employees)? . . .” (emphasis added).[iii]
What are the practical reasons for doing unannounced audits? Consider the Antitrust Division’s perspective. Antitrust crimes are deliberate conspiracies. If the participants know in advance there will be a review they would have the opportunity to destroy evidence and coordinate with their counterparts to put together a consistent lie to cover up their crimes.
Surprise audits could also serve as a deterrence in high-risk areas. In theory, at least, unannounced audits increase the risk that any wrongdoing will be uncovered. Similarly, if the objective is to discover if the compliance program is actually working, surprise allows no opportunity for anyone to cover up the lapses in the program.
What are the problems with unannounced audits?
There are a number of reasons why the surprise approach is problematic. On a basic level, there is a very practical resource issue. The result may be a waste of time and resources. If you show up by surprise and no one in an office knows you are coming, then key people may not be present, there may be other activities going on in the business there that interfere with the ability to conduct the audit, and the audit resources may be wasted. The unplanned audit may disrupt serious work operations.
There is also a very significant morale issue. Showing up suddenly like government marshals can convey a message of mistrust. You may have people who do the right thing every day, devote their energies to the company, and try diligently to do their work honestly and squarely within the law. Yet the company shows them it does not trust them enough to tell them in advance. Compliance can come across as merely looking for gotchas.
Instead of increasing the information C&E receives, the loss of trust may disrupt communications. Will employees really want to draw attention to their work with a group that might be planning a compliance raid? There is the notion that one can be a counselor or a cop, but not both. Employees subject to such treatment may become less likely to ask you for advice. Ironically, conducting surprise audits may cause C&E to become less able to uncover or hear about misconduct, because people in the company no longer trust them. It would be a terrible mistake to do something that decreased the willingness of people to speak up or trust the company’s C&E staff.
There may also be legal issues. Certainly digging through an employee’s workspace could expose personal information. And how would one deal with work from home? It would be necessary to check local laws, especially when operating internationally. An intrusive review could certainly trigger privacy laws. There can also be special considerations when dealing with represented employees or interfacing with works councils. If going the additional step of conducting mock dawn raids this could raise the question of exactly what you intend to teach your people – to obey the law, or are you training them on why and how to conceal evidence of wrongdoing to evade the risk of government raids?
Fundamentally it is important to understand the distinction between surprise audits and C&E investigations. Employees will likely understand this difference. When there have been reports of wrongdoing then it makes sense for the company to investigate. No organization would be expected to remain passive if there were indications of wrongdoing. And in cases where there is real reason to believe someone is engaged in wrongdoing, most employees will understand the need to act before evidence disappears and conspirators act together to cover up their actions. But a review only based on what comes across as a general mistrust of the work unit can undercut morale and disrupt relations with C&E.
What is the answer? It depends
Notwithstanding the negatives, there may well be areas where unannounced checks are accepted, particularly high-risk areas where the possibility of failure is unacceptable. Nuclear safety and airplane safety come to mind. Safe production processes for food and medicines also can be on the list. For workplace safety, an unannounced compliance drive by or visit to the workplace is designed to save the lives of the very workers being checked.
It can also be a different dynamic when dealing with third party practices, particularly with new suppliers in high-risk areas. If the issue is supply-chain practices in areas where human trafficking and exploitation of children are common, for example, the compliance risks and possible harms may outweigh the possible disruptive aspects.
It is also important to remember the purpose of any audit. If a review finds weaknesses in the compliance program, then those need to be fixed. But if a review finds indications of misconduct, and the only message appears to be the need to be careful to avoid creating evidence of wrongdoing, the impact and message are wrong and dangerous to the company. This may, for example, color the EU’s negative view of companies conducting their own compliance dawn raids. If a company does conduct internal reviews and discovers evidence of misconduct, it must take appropriate disciplinary and corrective action and be sure the process is not cynically signaling to employees the need to be more careful in breaking the law. As is true in all audits and reviews, any weakness or wrongdoing must be fully addressed.
There is also the role of technology in choosing how to conduct audits and reviews. In today’s environment there are practical alternatives for at least certain aspects of onsite reviews – technology, AI and data analysis may uncover what in the past would have required onsite reviews of paper records. Of course, privacy laws may still come into play regarding access to and use of employee data, but data analysis can provide new sources of important information for C&E’S purposes. This ability to use technology can help C&E meet government expectations and enable C&E to advance its mission. This can take away from the perceived benefits of surprise audits.
In addition to using the advances in technology, there is another tried and true method for discerning what is actually happening in the day-to-day life of the company: listening. Reaching out to employees and truly listening to them may unearth key information that C&E would not otherwise uncover.[iv] The absence of fear and mistrust, and faith in the integrity of the C&E program can result in the company being much better informed about its real-world risks.
It is crucial that employees see the C&E operation is fair and impartial. It must also be perceived as safe. “Gotcha” audits may undercut that objective. There must also be a strong focus on preventing retaliation, so employees can feel safe speaking up.[v]
Finally, when conducting actual investigations, if this is done with eyes open and listening skills finely honed, C&E can pick up other possible issues. In this context it is also crucial to do true root cause analysis as part of investigations to discover the deeper causes of misconduct.[vi]
Must companies conduct unannounced audits? For C&E in general, this appears not to be a requirement. But for specific risk areas it is necessary to check regulatory requirements. Should such audits be conducted – are they necessary for an effective C&E program? My advice would be to spend time on the other ways to obtain information and awareness of what is happening in the company and how the C&E program is working. While there may well be some benefits to unannounced audits, in general the harms may outweigh the benefits, particularly when there are other viable alternatives that can work better, and will improve the trust employees have in the C&E program.
[i] Evaluation of Corporate Compliance Programs at 18, https://www.justice.gov/criminal/criminal-fraud/page/file/937501/dl?inline=
[ii] Neil E. Roberts, “Antitrust Compliance Programs Under the Guidelines: Initial Observations From the Government’s Viewpoint,” 2 Corporate Conduct Quarterly 1-2 (Summer 1992) (published by Rutgers University).
[iii] DOJ Antitrust Division, Evaluation of Corporate Compliance Programs in Criminal Antitrust Investigations, Nov. 2024, at 13. In Europe, the EU, in its guidance on compliance programs, contains no reference to unannounced audits. An AI search uncovered no other examples, but then the AI search did not uncover the one from 1991 for the Antitrust Division. I knew about it because I was the editor who requested the comments from the Antitrust Division; it was published before AI and the Internet. Just another caution about the limits of AI.
[iv] Dr. Camille Howard, “Harmony in Compliance: The Transformative Power of Active Listening in Ethics and Compliance.” https://ideasandanswers.com/harmony-in-compliance/
[v] Amii Barnard-Bahn & Joe Murphy, “How to Prevent Retaliation: 6 Practical Steps,” https://ideasandanswers.com/how-to-prevent-retaliation-6-practical-steps/
[vi] Rebecca Walker, “Root Cause Analysis: Driving Continuous Improvement,” https://ideasandanswers.com/root-cause-analysis-driving-continuous-improvement/ ; Wendy Evans & Georgina Heasman, “Fundamentals of Investigations – Lessons Learned from Root Cause Analysis.” https://ideasandanswers.com/fundamentals-of-investigations-lessons-learned-from-root-cause-analysis/ .