Every ethics and compliance leader faces the perennial questions: Is my program working? How do I demonstrate its effectiveness? And where are my gaps? Answering those questions is easier than ever in some ways, but to do it well requires a layered process.
Self-assessments have gotten faster, cheaper, and more sophisticated. A team can run a structured internal review in a few weeks using existing staff, benchmark against public frameworks, and produce a report that looks defensible without engaging outside counsel or consultants. That said, with FCPA enforcement activity at historic lows1, there is a very real temptation to treat a periodic outside review as discretionary spending rather than a program requirement.
That reasoning misreads what an external assessment is for. It was never primarily an enforcement hedge. It is the mechanism that tells program owners what their own team structurally cannot see about itself, and it remains valuable when regulators are quiet and no one outside the organization is checking your work for you.
The Three-Year Benchmark
The idea that programs need an outside look every three years2 did not originate as a blanket rule. It traces to a specific 2004 FCPA Opinion Procedure Release, in which the U.S. Department of Justice (DOJ) approved a private equity acquisition on the condition that the target’s ethics and compliance program undergo “independent audits by outside counsel and auditors, at no longer than three-year intervals, to ensure that the Compliance Code, including its anti-corruption provisions, [is] implemented in an effective manner.” That was a negotiated condition attached to one transaction, not a generally applicable regulation, but the compliance field adopted the interval as informal best practice, and it has circulated as such for two decades.
The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) guidance, most recently updated in September 2024, never adopted a fixed number. It asks how an organization determines “where and how frequently internal audit will undertake an audit, and what is the rationale behind that process,” and it ties testing frequency to the organization’s size, complexity, and risk profile rather than prescribing a cycle. The U.S. Sentencing Guidelines take the same open-ended approach: Section 8B2.1(b)(5)(B) requires organizations “to evaluate periodically the effectiveness” of their ethics and compliance program without naming an interval.
So the specificity has faded from written guidance even as the underlying expectation (i.e., some outside check) has not. Current practice has converged on roughly the same cadence anyway: 79% of World’s Most Ethical Companies® Honorees report conducting a comprehensive program review every one to three years, according to Ethisphere’s benchmarking data. The three-year figure survives less as a rule than as the interval the field has independently decided works. And if you think about what transpires inside your business during the course of 36 months, that interval makes sense. Over three years, the average business will acquire entities, divest entities, launch and deprecate products, enter markets and leave them (in some cases, multiple times). All of those business activities require program adaptations to continue to mitigate risk.
What Each Tool Does Well
Self-assessment is the right instrument for continuous tuning. It is inexpensive enough to run annually or more often, draws on deep institutional knowledge of how the organization operates, and is well suited to tracking metrics a program already owns, such as training completion, hotline volume, and policy attestation, over time. What it cannot do is see around its own corner. The people running the assessment work inside the culture, reporting lines, and incentive structures they are evaluating, and employees calibrate what they tell an internal team differently than what they tell an outsider with no stake in the answer.
External assessment supplies exactly what that internal position rules out.
- It gives the DOJ, a board, or an acquirer’s counsel a source of evidence with no incentive to grade the program generously, which is what the ECCP and the Sentencing Guidelines ask programs to demonstrate.
- It benchmarks against peer and leading programs an internal team has no comparable visibility into.
- It produces a more honest read of culture, because employees raise concerns about leadership integrity and psychological safety more candidly with reviewers who have no reporting relationship to them.
- And it prioritizes gaps by risk rather than by internal politics, which is the difference between a roadmap and a wish list.
None of this requires an enforcement action to justify; it is what makes the resulting investment decisions defensible in the first place.
A Simple Framework
Four questions determine which tool fits a given moment.
- Purpose. Is this a routine tune-up, or does the result need to hold up in front of a board, a regulator, or an acquirer’s diligence team? Internal audiences can run on self-assessment; external audiences require independence.
- Trigger. Is this scheduled maintenance, or is it responding to an event: an enforcement action, a whistleblower spike, an acquisition, entry into a higher-risk market, a leadership change, or the close of a monitorship term? Event-driven reviews should default to external.
- Credibility requirement. Who has to trust the finding, and would they trust it coming from the team being evaluated? If the answer is no, the assessment has to come from outside.
- Cadence. Run self-assessment annually as the operating rhythm, and bring in an external reviewer at least every three years or whenever a trigger event fires, whichever comes first.
The Bottom Line
Self-assessment and external review are not competing options for the same job. Self-assessment is the operating rhythm; external review is the credibility check that rhythm cannot produce on its own. Enforcement activity will cycle up again, and the organizations that treated the external check as an interval rather than an insurance policy against active scrutiny will be the ones that do not have to scramble to prove, on short notice, that their program works.
Notes
1 The DOJ brought seven Foreign Corrupt Practices Act (FCPA) actions in 2025, only two against corporations, and the U.S. Securities and Exchange Commission brought zero. That is the lowest level of publicly announced FCPA enforcement since WilmerHale began tracking it in 2010, following President Trump’s February 2025 executive order pausing enforcement and the subsequent guidance to the DOJ to direct enforcement toward cartel-linked bribery cases.
2 The 2004 Opinion Procedure Release was a condition negotiated for one specific transaction, not a standing regulation of general applicability. This piece treats it as the origin point for a best practice the field adopted informally, and cites it as that rather than as current binding DOJ policy, since no subsequent ECCP or Sentencing Guidelines text prescribes a fixed interval.
Sources
“Ethisphere’s Guide to Ethics and Compliance Program Assessments” (Ethisphere)
“Why an External Assessment of Ethics and Compliance Programs Is Beneficial” (Ethisphere, September 19, 2025)
“DOJ Evaluation of Corporate Compliance Programs – September 2024 Updates” (Ethisphere Magazine, September 23, 2024)