Both the Justice Department and the Securities and Exchange Commission make clear the need for a risk assessment to inform your compliance program. I believe that most, if not all CCOs and compliance practitioners understand this well-articulated need. The 2012 FCPA Guidance could not have been clearer when it stated, โ€œAssessment of risk is fundamental to developing a strong compliance program, and is another factor DoJ and SEC evaluate when assessing a companyโ€™s compliance program.โ€ While many compliance practitioners have difficulty getting their collective arms around what is required for a risk assessment and then how precisely to use it, the FCPA Guidance makes clear there is no โ€œone size fits allโ€ for anything in an effective compliance program.

Thomas Fox has practiced law for over 40 years. Tom writes the daily award-winning blog, the FCPA Compliance and Ethics blog and founded the Compliance Podcast Network. Tom leads the discussion on AI in...