Competitive Audit Process for Compliance Programs

A standard compliance audit checks internal conformance. Did we follow our own policies? Did we satisfy minimum regulatory requirements? Useful, yes. But it's an inward-facing exercise. It tells you whether you met the bar you set for yourself. It does not tell you where the bar is moving, or how far behind the market you've drifted.
A competitive audit adds an external layer. It asks how your program compares to peer organizations, industry benchmarks, and regulatory best-practice frameworks.
Three distinct activities are involved, and keeping them separate is what makes the whole thing work.
Gap analysis identifies missing or incomplete program elements. Think of it as a checklist review: do you have a policy for this? Is the control documented? It's narrower in scope and faster to complete than the other two layers.
Effectiveness evaluation goes deeper, examining documentation but also requiring interviews with executives, board members, and front-line staff. A policy that exists on paper and a policy that governs real behavior are different things. I've sat in enough of those interviews to tell you: the person who wrote the policy and the person working under it often describe it as if they're talking about two separate organizations. That gap is data.
Competitive benchmarking uses peer organization data or recognized standards to assess relative program maturity. This is the layer that transforms an internal review into something genuinely actionable.
The OIG Compliance Program Guidance is explicit on this: benchmarks demonstrating implementation and achievement are essential to any effective compliance program. Peer comparison is a regulatory expectation, not a management preference. A competitive audit runs all three layers simultaneously. The output is more than just a list of what's missing; it's a ranked picture of where the program actually sits relative to what regulators and sophisticated peers expect.
The DOJ's Evaluation of Corporate Compliance Programs as the Primary External Benchmark
The DOJ's Evaluation of Corporate Compliance Programs, first published in 2017 and most recently updated in September 2024, is the benchmark that matters most for any organization with U.S. federal enforcement exposure. Its three fundamental questions haven't changed: is the program well designed, is it adequately resourced and empowered, and does it work in practice? What satisfies each question, however, has grown substantially more demanding with each revision.
The enforcement stakes are concrete. Per Skadden's analysis of the 2024 update, a company with an effective compliance program is more likely to receive reduced monetary penalties and less burdensome ongoing obligations as part of any resolution. Strong programs can earn a presumption of declination, even when misconduct has occurred. That's the difference between a fine that stings and a resolution that changes the company.
The September 2024 update sharpened four areas in particular, and these are now where sophisticated peers are being evaluated.
AI and emerging technology risk. Prosecutors will assess whether a compliance program evaluates and manages AI-related risk, following direction from Deputy AG Monaco in March 2024 to incorporate disruptive technology risks into the ECCP framework. If your program doesn't address AI governance, it has a gap that a peer program likely has already closed.
Whistleblower protections. The DOJ launched its Corporate Whistleblower Awards Pilot Program in August 2024 and had already received tips from more than 100 individuals by the time the ECCP update published. Prosecutors now review policies, training, and how the organization actually treated anyone who raised a concern. Not a checkbox; a behavioral test.
Data access and analytics. Compliance teams must have timely access to relevant data, and prosecutors will evaluate whether organizations use analytics to identify risk and measure program effectiveness, not just to generate reports. The distinction between using data to understand your program and using data to describe it is now prosecutorially relevant.
Peer benchmarking, codified. The 2024 revision explicitly requires companies to consider lessons learned from other organizations in similar industries and geographies when revising policies. Competitive benchmarking is now a prosecutorial expectation.
For organizations outside the U.S. or in specific regulated sectors, other frameworks serve as the equivalent external benchmark: FFIEC BSA/AML, HIPAA, GDPR, ISO 27001, SOC 2, PCI DSS, CMMC. The ECCP's core logic, design, resourcing, and effectiveness in practice, translates across all of them.
The ECCP is not a prosecutor's checklist you consult after something goes wrong. It has become the reference standard compliance practitioners use to stress-test program design before an enforcement action arrives.
Step 1: Define Scope by Choosing a Benchmark Framework Before Reviewing a Single Control
The most common audit failure I've seen is starting with evidence collection before anyone has decided what the evidence is being measured against. You end up with a pile of observations and no architecture to organize them. It's genuinely frustrating to work through, and it's entirely avoidable.
Scope has two dimensions that must be fixed before the audit begins. First, which benchmark framework applies: regulatory (DOJ ECCP, FFIEC, HIPAA, GDPR), industry standard (ISO 27001, SOC 2, PCI DSS 4.0.1, CMMC), or a peer dataset drawn from published industry surveys. Second, which parts of the program are in scope for this cycle, whether that's a full-program review or a targeted examination of high-risk areas.
The benchmark choice drives everything downstream. It determines what evidence is relevant, what gaps can be scored, and what peer data is actually comparable.
One complication that comes up regularly: most organizations operate under multiple frameworks simultaneously. A financial services firm might face FFIEC requirements, SOC 2 expectations from enterprise customers, and ECCP scrutiny if it has federal enforcement exposure. Scoping should clarify where frameworks overlap and where they create contradictory obligations, because discovering that conflict mid-audit wastes everyone's time.
The output here is a written scope document. It names the benchmark framework or frameworks, the program areas in scope, and the time period under review. Everything else flows from it.
Step 2: Apply a Risk-Based Approach to Prioritize Where the Audit Concentrates Its Resources
Equal time across all controls is audit theater. It signals diligence without producing it, and it consistently leaves the highest-risk areas underexamined.
FinCEN's 2024 consent order against TD Bank illustrates what poor prioritization looks like when regulators find it. The order explicitly cited that TD Bank's scope of testing was insufficient relative to the bank's high-risk customers, products, and services, resulting in trillions of dollars going unmonitored. That's a $1.3 billion penalty with a root cause traceable directly to audit design.
Risk-based prioritization means allocating depth to the intersection of two factors: likelihood of failure, and severity of consequence if failure occurs. High-likelihood, high-impact areas get intensive testing. Low-likelihood, low-impact areas get lighter review or defer to the next cycle. This isn't complicated in theory; the discipline is in actually doing it, rather than defaulting to equal distribution because it's easier to justify.
A useful cross-check: the areas your benchmark framework weights most heavily should be treated as at least moderate-priority regardless of what your internal risk model shows. The ECCP's 2024 emphasis on data analytics, AI governance, and whistleblower mechanisms is a signal about where enforcement attention is concentrating. That signal belongs in your prioritization even if internal scoring doesn't flag those areas independently.
The output is a risk-ranked list of program areas, each with a documented rationale for the testing depth assigned. That documentation matters. In an enforcement context, it demonstrates that resource allocation was deliberate.
Step 3: Establish Independence So Findings Carry Weight Inside and Outside the Organization
An audit conducted by the team responsible for the controls being tested is a self-assessment. Regulators treat it as such, and so will any sophisticated external reviewer.
The FFIEC mandates that independent BSA/AML testing be conducted by internal audit, outside auditors, consultants, or other qualified independent parties, with results reported directly to the board of directors or a designated board committee, not filtered through the compliance function itself. That reporting line is structural protection for the integrity of the findings.
Independence has three components that actually matter in practice. Structural independence: the auditor has no operational responsibility for the controls being reviewed. Reporting independence: findings go to the board or audit committee directly. Analytical independence: the auditor has unrestricted access to data and personnel. Remove any one of these and the audit is compromised, regardless of how well every other step was executed.
The business case beyond regulatory compliance is real and underappreciated. Findings from an independent party carry credibility in enforcement negotiations, M&A due diligence, and enterprise procurement reviews that internal self-assessments simply cannot replicate. When a regulator, an acquirer, or a sophisticated buyer evaluates your program, they want to know who tested it and whether that party had anything to protect in the result.
On the practical question of internal versus external auditors: internal audit is sufficient for routine annual reviews. External parties are appropriate when the organization faces elevated enforcement risk, is post-acquisition, or when internal audit lacks specialized expertise in the relevant framework.
Step 4: Map the Current State and Score Each Gap by Severity Before Comparing Anything
Current-state mapping means documenting what the program actually does, not what the policies say it does. That distinction is precisely what prosecutors and peer reviewers test.
The evidence base needs to be broad. Policy and procedure documents establish the intended design. Training completion records reveal whether the design has been communicated. Hotline and speak-up data, specifically volume, resolution rates, and time-to-close, reveal whether the reporting culture is functional. Prior audit findings and their remediation status reveal whether the program learns from itself. Interviews with executives, board members, and front-line employees surface the effectiveness layer that document review alone cannot reach.
Once the current state is mapped, compare it control by control against the benchmark framework chosen in Step 1. For each gap, assign a score on two axes: likelihood of failure and severity of consequence. This produces a risk-ranked gap register rather than a flat observation list. That ranking does two things: it tells the organization where to act first, and it creates a documented record of reasonable prioritization that matters in any subsequent enforcement conversation.
One quality problem worth addressing: risk assessments are only as useful as their participation rates. Internal risk surveys across many organizations attract completion well below two-thirds of the relevant population, which leaves meaningful blind spots in the current-state picture. If you can't get sufficient participation in your own risk assessment, that's a finding about culture and engagement, and it belongs in the register.
Step 5: Layer in Peer Benchmarking Data to Convert Internal Findings into Competitive Context
Internal findings answer "what are we missing?" Peer benchmarking answers a different question: "how does what we're missing compare to what our competitors have actually built?" Conflating those two questions is how organizations end up investing heavily in areas where peers have already set a high bar, while remaining blind to areas where even modest investment would create genuine differentiation.
Peer selection requires discipline. Benchmark against organizations that match on industry, size, and risk exposure. A regional credit union and a global investment bank are both subject to BSA/AML requirements, but treating their programs as comparable benchmarks would generate data that looks rigorous while producing misleading conclusions.
Peer data comes from several sources worth knowing. Published industry surveys, including PwC's Global Compliance Survey, A-LIGN's Compliance Benchmark Report, and Secureframe's Benchmark Report, provide aggregated program data at scale. Regulatory enforcement actions and consent orders against peers reveal what regulators found deficient in comparable programs, which is some of the most actionable intelligence available and consistently underutilized. Industry association benchmarking programs and framework certification data, specifically which certifications peer organizations hold and at what audit frequency, provide concrete maturity signals that don't always make it into published reports.
A useful calibration point from A-LIGN's 2026 Compliance Benchmark Report, which surveyed hundreds of global leaders: nearly all organizations now conduct at least two audits annually, with large enterprises running four or more. That's the baseline when benchmarking audit frequency.
The output of this step is a gap register where each finding is annotated with peer context: whether the gap is common across the industry, whether peers have invested heavily in that area, or whether closing it would represent genuine competitive differentiation. That context is what allows leadership to make resource allocation decisions calibrated to market reality rather than internal risk tolerance alone.
Step 6: Build a Remediation Roadmap That Assigns Ownership and Establishes a Review Cadence
A gap register without a remediation owner and a deadline is a document, not a plan.
Each finding in the roadmap needs four things. A named owner, meaning a specific individual accountable for closing the gap, not a department name that diffuses responsibility. A remediation action describing what specifically needs to change, whether that's policy, training, technology, process, or resourcing. A target date tied to the severity score, so critical gaps get near-term deadlines and low-severity gaps slot into the next annual cycle. And a success metric that is concrete: not "policy updated," but "training completion rate above a defined threshold and control retested."
The cadence should include a full competitive audit annually, with lighter quarterly reviews of the highest-risk areas from the gap register. This creates a documented history of continuous improvement, which is itself an ECCP evaluation criterion. A program that shows a regulator three years of audit cycles, each building on the last, is making a materially different argument about organizational commitment than a program that produces a single report in response to a government inquiry.
Board and senior leadership reporting should follow the same independence structure that governed the audit itself. The roadmap goes to the board or audit committee directly, closing the structural loop opened in Step 3 and ensuring the remediation process carries the same credibility as the findings.
The documented remediation history, what was found, what was prioritized, what was fixed, and by when, is the artifact that regulators, acquirers, and sophisticated customers review when assessing program credibility. It answers the question they're actually asking: does this organization treat compliance as a function that learns, or as a box that gets checked?
The roadmap is not a static deliverable. It updates as findings close, as new regulatory guidance is issued, and as peer benchmarking data shifts the competitive baseline. The ECCP has been revised five times since 2017. Organizations that treat the roadmap as a living document are the ones whose programs stay current. The ones that file it away are the ones explaining, during an enforcement inquiry, why they haven't addressed gaps their peers closed two years prior.


