DOJ Fraud Enforcement Is Expanding: What Businesses Should Do Now
- Todd Nurick
- 9 minutes ago
- 14 min read

The United States Department of Justice has spent much of 2026 building a substantially larger, more centralized, and more data-driven fraud enforcement operation.
The National Fraud Enforcement Division was formally established in April. By August, DOJ said the Division was expected to reach approximately 500 attorneys and staff, supported by asset-recovery personnel, corporate-enforcement specialists, privilege-review resources, data-science expertise, and litigation technology. On August 24, DOJ launched a separate National Fraud Detection Center designed to combine information and analytical capabilities from multiple federal agencies and Inspectors General.
Then, on September 1, the United States Attorney's Office for the Southern District of New York reported a substantial increase in corporate self-reports under its financial-crimes program and stated that, in most cases, it had issued conditional declination letters within two to three weeks of receiving qualifying self-reports.
For businesses, these developments create two related risks. The government is investing more heavily in detecting fraud through data, interagency coordination, whistleblowers, and specialized prosecutors. At the same time, DOJ is offering potentially significant benefits to companies that discover misconduct themselves, investigate appropriately, cooperate where advisable, and remediate the underlying problem.
That combination places greater importance on something businesses can control before a government investigation begins: how quickly and effectively the company identifies, escalates, investigates, preserves, and responds to credible allegations of misconduct.
For many small and midsized companies, those are precisely the issues that should be addressed through corporate governance and an established Fractional General Counsel or Outside General Counsel function before a crisis occurs.
DOJ Fraud Enforcement Has Changed Significantly in 2026
The National Fraud Enforcement Division did not begin as merely another prosecutorial unit.
DOJ's April 7 memorandum described the objective as creating a comprehensive and coordinated approach to fraud involving taxpayer dollars and taxpayer-funded programs. The Division was directed to coordinate with agencies administering government programs, develop fraud-identification systems, work with law enforcement nationally, and expand prosecutorial resources.
By August, the scope had become much clearer. Assistant Attorney General Colin M. McDonald's August 13 enforcement memorandum identifies five principal areas of priority:
public trust and financial integrity;
health care;
internal revenue;
global trade and commerce; and
corporate misconduct.
The memorandum specifically identifies government procurement schemes such as defective pricing, bid rigging, self-dealing, bribery, product substitution, and billing fraud. It also identifies tax fraud, health care fraud, customs and trade violations, sanctions evasion, country-of-origin fraud, undervaluation of imported goods, and other corporate economic crimes.
The inclusion of corporate misconduct is important for companies that assume the new structure concerns only businesses receiving federal benefits or government money.
DOJ expressly states that Fraud Division prosecutors will prioritize anti-fraud corporate enforcement and work with the Department's Corporate Enforcement Section.
The Department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy is broader still. It applies generally to DOJ corporate criminal matters other than criminal antitrust violations. This is therefore not solely a government-contractor issue.
DOJ Fraud Enforcement Now Has a National Fraud Detection Center
One of the most consequential developments came on August 24, when DOJ launched the National Fraud Detection Center. DOJ describes the Center as a prosecutor-led, multi-agency team intended to identify fraud across taxpayer-funded programs and generate criminal investigative leads. Its initial participants include the Federal Bureau of Investigation, Homeland Security Investigations, Internal Revenue Service Criminal Investigation, Financial Crimes Enforcement Network, the Small Business Administration, Social Security Administration, Treasury Department, and numerous federal Offices of Inspector General. State partners are also participating.
The operational concept is significant. Historically, information held by one program or agency might not readily expose a pattern involving another program. DOJ says the National Fraud Detection Center is intended to reduce those information silos by combining analytical capabilities and cross-program visibility.
That changes the risk calculation for companies interacting with federal programs.
An organization should not assume that an irregularity will remain isolated within the agency or program where it first appears. Discrepancies involving billing, tax information, grants, procurement, health care, benefits, trade, or other government-facing activity may be more readily compared against information from other sources.
The Government Accountability Office has separately estimated federal fraud losses at approximately $233 billion to $521 billion annually based on fiscal-year 2018 through 2022 data. GAO has also emphasized analytics, information sharing, and improved fraud-related data as important tools for government fraud prevention and detection. The federal government is now putting considerably more institutional infrastructure behind that approach.
The Enforcement Risk Extends Beyond Traditional Government Fraud
The National Fraud Enforcement Division's August priorities illustrate how far fraud enforcement can reach into ordinary business operations.
Government contractors face obvious exposure involving pricing, billing, procurement, certifications, product substitution, subcontractors, and representations concerning performance.
Health care companies face billing, reimbursement, referral, compensation, and medical-necessity risks. Businesses involved in international trade face a different set of issues involving tariffs, customs declarations, country of origin, antidumping and countervailing duties, sanctions, transshipment, and forced-labor restrictions.
DOJ reported in July that its Trade Fraud Task Force had surpassed $1 billion in civil and criminal recoveries, penalties, forfeitures, and publicly charged losses in less than a year. The Task Force's stated scope extends beyond importers to customs brokers, downstream distributors, industrial and commercial end users, and other supply-chain participants that knowingly profit from unlawfully imported merchandise.
The trade initiative is also a useful example of the potential intersection between criminal prosecution and civil False Claims Act enforcement. That does not mean every False Claims Act matter has been transferred into the National Fraud Enforcement Division. DOJ continues to maintain distinct civil enforcement functions and to coordinate among the Fraud Division, Civil Division, United States Attorneys' Offices, and agency partners.
For businesses, the practical concern is coordination. A problem that begins as an administrative, contractual, regulatory, or civil inquiry can develop additional dimensions as agencies share information and prosecutors examine the same underlying conduct.
Pennsylvania Businesses Already Face Coordinated Criminal and Civil Review
The Eastern District of Pennsylvania provides a particularly relevant example.
The United States Attorney's Office established its White-Collar Justice Program in September 2025 and describes a more proactive model for identifying and investigating significant white-collar cases.
It also operates a Government Fraud Alliance.
Under that program, the office states that every qui tam filing or whistleblower complaint it receives under the False Claims Act is immediately reviewed by both criminal and civil Assistant United States Attorneys together with federal law-enforcement partners. Those teams can coordinate investigative strategies and share resources from the beginning of an investigation.
The Eastern District also participates in DOJ's Corporate Whistleblower Awards Pilot Program, which can provide financial incentives to individuals who supply qualifying information concerning corporate misconduct that leads to successful forfeiture. The office identifies federal contracting, government programs, trade and customs fraud, health care matters, immigration violations, sanctions offenses, and other categories within the program's potential scope.
For Pennsylvania companies, internal reporting systems therefore operate in an environment where an employee who reports internally may also have a separate incentive to approach the government.
A company should be prepared for both possibilities.
New York Is Showing How Quickly Corporate Self-Reporting Can Move
New York provides another important development.
The Southern District of New York adopted a Corporate Enforcement and Voluntary Self-Disclosure Program for Financial Crimes in February 2026. It now operates alongside DOJ's Department-wide policy.
On September 1, SDNY reported that corporate self-reporting had increased substantially. In most matters, according to the office, a conditional declination letter had been issued within two to three weeks after the self-report. SDNY also states that information supplied through corporate self-reporting has exposed previously unknown illegal activity and that corporate cooperation in at least one matter enabled charges against individuals approximately six weeks after the self-report.
SDNY also issued unusually direct language concerning management misconduct. Its program states that companies knowingly choosing not to report criminal misconduct by management should expect prosecution.
That statement should be read in the context of SDNY's particular financial-crimes program. It does not create a universal statutory duty requiring every corporation everywhere to report every suspected violation.
It does, however, demonstrate the increasingly important role that corporate self-reporting plays in federal enforcement strategy.
Voluntary Self-Disclosure Can Produce Major Benefits, but It Is a Legal Decision
DOJ's March 2026 Corporate Enforcement and Voluntary Self-Disclosure Policy establishes a Department-wide framework for corporate criminal cases other than antitrust matters.
Under Part I of the policy, DOJ states that it will decline prosecution where the company voluntarily self-discloses qualifying misconduct, fully cooperates, timely and appropriately remediates, and does not present disqualifying aggravating circumstances. Even where aggravating circumstances exist, DOJ retains discretion to decline prosecution depending upon the circumstances.
The policy also provides a separate path for certain "near miss" disclosures or cases involving aggravating circumstances. Potential benefits can include a non-prosecution agreement, a term of fewer than three years, no independent compliance monitor, and a substantial reduction from the applicable Sentencing Guidelines fine range.
Those incentives are substantial.
They do not mean that a company discovering possible wrongdoing should immediately contact DOJ.
A self-disclosure decision requires analysis of the known facts, the reliability of the allegation, applicable reporting obligations, whether misconduct is continuing, whether DOJ or another agency already knows of the conduct, potential civil or regulatory consequences, affected contracts and licenses, insurance issues, individual exposure, and the consequences of making representations before the internal facts are adequately understood.
Other laws or contracts may independently require disclosure. In other circumstances, disclosure may be voluntary.
The appropriate decision depends upon the particular legal regime and the evidence.
Why DOJ Fraud Enforcement Changes the Timing of Internal Reporting
DOJ encourages voluntary disclosure at an early stage and expressly states that a company need not complete an internal investigation before making a qualifying disclosure.
To obtain full voluntary-self-disclosure treatment, the misconduct generally must not already be known to DOJ, disclosure must occur before an imminent threat that the government will learn of the conduct, and the company must report within a reasonably prompt period after becoming aware of it.
That creates a difficult timing problem.
A company needs enough facts to make a responsible decision. At the same time, an unnecessarily prolonged internal investigation can reduce the advantages of being the first party to approach the government.
The problem becomes more acute when a whistleblower is involved.
Under the Corporate Whistleblower Awards Pilot Program exception incorporated into DOJ's policy, a company can potentially retain eligibility for a declination even if an employee reports to DOJ first, provided the employee also reported internally and the company reports the matter to DOJ as soon as reasonably practicable, but no later than 120 days after receiving the internal report, while satisfying the policy's other requirements.
A serious internal report should therefore reach the appropriate decision-makers quickly.
An Internal Investigation Should Begin With Governance, Not Interviews
When a credible allegation arrives, many organizations instinctively begin interviewing employees.
That is not always the best first step.
The company should first determine who has authority to direct the response and whether any decision-maker has a conflict. An allegation against a junior employee presents a different governance problem from an allegation involving the chief executive officer, chief financial officer, owner, General Counsel, board member, or head of the affected business unit.
Counsel should also determine the purpose and scope of the investigation, whether specialized white-collar counsel is required, whether forensic accountants or technical experts are needed, and how attorney-client privilege and attorney work-product protections will be addressed.
DOJ's current policy makes an important point on privilege: eligibility for cooperation benefits is not conditioned upon waiver of attorney-client privilege or work-product protection. DOJ seeks relevant facts and nonprivileged evidence, not a blanket privilege waiver.
That distinction favors deliberate investigative structure at the beginning rather than attempting to reconstruct privilege and decision-making lines after an investigation has expanded.
Document Preservation Now Includes Personal and Ephemeral Messaging
Document preservation is no longer limited to company email servers and paper files.
DOJ's policy expressly identifies appropriate retention of business records as part of timely remediation. It specifically discusses controls concerning personal communications and messaging applications, including ephemeral messaging platforms that can undermine the organization's ability to preserve business communications or comply with legal obligations.
For businesses using text messaging, WhatsApp, Signal, Teams, Slack, personal email, disappearing-message functions, or employee-owned devices for business communications, the issue should be addressed before a litigation hold or government investigation arises.
A preservation plan that exists only on paper but does not reflect how employees actually communicate can create substantial investigative problems.
DOJ Is Also Looking at Remediation, Not Only the Original Misconduct
DOJ's policy requires more than stopping the specific conduct under investigation.
Its remediation analysis includes root-cause analysis and an effective compliance and ethics program appropriate to the company's size, resources, and risk profile. The policy considers management commitment, compliance resources, personnel quality and experience, disciplinary measures, record retention, and other steps designed to reduce the likelihood of recurrence.
Two 2026 declinations illustrate the point.
In June, DOJ's National Security Division declined to prosecute Robert Bosch GmbH after the company voluntarily disclosed export-control misconduct, cooperated, and remediated. DOJ identified organizational changes, disciplinary measures, additional trade-compliance personnel, expanded compliance resources, and revised policies among the remediation steps considered. Bosch also agreed to disgorge approximately $11.43 million in profits, with a related Commerce Department civil resolution.
In July, the National Fraud Enforcement Division declined prosecution of Campus Eye Management Holdings LLC and an affiliate after voluntary disclosure, cooperation, remediation, and victim compensation. DOJ specifically cited an internal review, revised billing and compensation policies, ongoing risk assessments and monitoring, new compliance personnel, and compliance training. The Department separately pursued an individual executive.
These resolutions illustrate a distinction that corporate leadership should understand.
Misconduct by an employee or executive does not automatically determine the organization's ultimate treatment. The company's response after discovering misconduct, including investigation, cooperation, governance, discipline, remediation, and compensation of victims where appropriate, can materially affect the government's analysis.
Compliance Should Reflect the Company's Actual Risk Profile
A midsized company does not necessarily need the compliance infrastructure of a multinational public corporation.
DOJ's policy expressly recognizes differences in company size, sophistication, financial condition, resources, and business risk when evaluating cooperation and remediation.
The relevant question is whether the compliance system is credible for the business that actually exists.
A government contractor should understand procurement, billing, certification, subcontractor, and recordkeeping risks.
A health care organization should address reimbursement, coding, medical necessity, compensation, referral, and billing controls.
An importer or distributor should understand country-of-origin representations, customs valuation, tariffs, sanctions, forced-labor restrictions, and supplier documentation.
A technology or professional-services business may have different exposure involving government grants, data, cybersecurity representations, intellectual property, artificial intelligence, third-party vendors, financial controls, or export restrictions.
Compliance should follow the company's risk profile rather than a generic policy manual.
What Businesses Should Have in Place Before a Serious Allegation Arrives
A useful corporate response structure begins before anyone receives a subpoena.
A reporting path. Employees should know where credible concerns can be reported, including an alternative path when the normal supervisor or senior management is implicated.
An escalation standard. Human resources, finance, compliance, operations, and management should understand which allegations require immediate legal review instead of routine handling.
Investigation authority. The company should know who can authorize an internal investigation and how that authority changes when senior executives or owners are involved.
A preservation protocol. The company should be able to preserve email, files, texts, collaboration platforms, personal-device business communications, and relevant financial or operational data quickly.
A government-contact protocol. Employees likely to encounter investigators or regulators should know whom to contact, who is authorized to speak for the company, and how to preserve an accurate record of the government's requests without speculation or improvisation.
Access to specialized professionals. Depending upon the allegation, the response team may require white-collar defense counsel, forensic accountants, cybersecurity professionals, employment counsel, regulatory specialists, government-contract lawyers, or other experts.
A disclosure decision process. The company should know who evaluates mandatory reporting obligations and who has authority to decide whether voluntary self-disclosure should be considered.
A remediation process. Management and the board should be prepared to address root causes, discipline, policy failures, internal controls, training, supervision, and other corrective measures rather than focusing exclusively on defending the original allegation.
A plan created after investigators arrive will usually be less effective than one established when there is no immediate crisis.
The Role of Fractional General Counsel and Outside General Counsel
Many businesses do not need a full-time internal General Counsel.
They still need someone responsible for connecting legal risk across departments.
A Fractional General Counsel or Outside General Counsel can help create the reporting, investigation, preservation, governance, and escalation framework before an enforcement issue develops. When an allegation arises, that lawyer can assist management or the board in identifying the legal issues, preserving information, evaluating conflicts, coordinating the initial investigation, determining whether specialist counsel is required, and overseeing remediation.
That role is particularly useful because potential fraud issues rarely remain confined to one legal category.
A billing problem can implicate a contract, employee conduct, regulatory requirements, insurance, government reporting, accounting, and potential civil or criminal exposure. A trade discrepancy can involve suppliers, customs documentation, contractual representations, sanctions, recordkeeping, internal controls, and individual employee conduct.
The General Counsel function provides a central point for identifying those intersections.
Where significant criminal exposure is possible, experienced white-collar criminal counsel may need to take the lead. Fractional General Counsel or Outside General Counsel can identify that need early and coordinate the broader corporate response rather than attempting to substitute general corporate counsel for specialized criminal defense expertise.
The Larger Business Lesson From DOJ's 2026 Fraud Strategy
DOJ fraud enforcement in 2026 reflects a broader shift toward coordinated detection, faster information sharing, specialized resources, whistleblower incentives, and corporate self-disclosure.
The National Fraud Enforcement Division is being staffed on a national scale. The National Fraud Detection Center is designed to reduce information silos. The Eastern District of Pennsylvania is expressly coordinating criminal and civil fraud review. The Southern District of New York is reporting increased corporate self-disclosure and rapid conditional declination decisions. DOJ's Department-wide policy creates substantial incentives for companies that disclose qualifying misconduct, cooperate, and remediate.
The practical consequence is not that every company needs a large compliance department or that every internal allegation belongs at DOJ.
Businesses need a reliable way to recognize when an ordinary operational problem has become a legal risk requiring investigation, preservation, governance oversight, specialized counsel, remediation, or a reporting decision.
The government is investing heavily in finding fraud earlier.
Businesses should invest in finding their own problems first.
Frequently Asked Questions
What is the National Fraud Enforcement Division?
The National Fraud Enforcement Division is a Department of Justice litigating division established in 2026 to coordinate and prosecute fraud matters nationally. Its current priorities include public trust and financial integrity, health care, tax, global trade and commerce, and corporate misconduct.
Does DOJ fraud enforcement affect companies that do not contract with the federal government?
Yes. Government contractors and recipients of federal funds face obvious exposure, but DOJ has expressly identified corporate misconduct, health care, tax, trade, customs, sanctions, and other economic crimes as enforcement priorities. The Department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy generally applies to corporate criminal matters other than antitrust violations.
Does a company have to report every suspected violation to DOJ?
No. DOJ's voluntary self-disclosure policy provides incentives for qualifying disclosures but does not itself create a universal obligation to report every suspected violation. Separate statutes, regulations, licenses, contracts, government-program requirements, or other legal obligations may independently require disclosure.
Should a company complete its internal investigation before considering self-disclosure?
Not necessarily. DOJ expressly encourages qualifying companies to disclose potential misconduct at an early stage even when an internal investigation has not been completed. The company still needs sufficient information and legal analysis to make a responsible disclosure decision.
Does cooperation with DOJ require waiving attorney-client privilege?
No. DOJ's current corporate enforcement policy expressly states that cooperation benefits are not conditioned upon waiver of attorney-client privilege or attorney work-product protection.
Why are employee whistleblower procedures important?
Federal programs now provide incentives for individuals to report qualifying corporate misconduct. DOJ's corporate policy also contains a 120-day provision that can preserve potential declination eligibility in certain circumstances where a whistleblower reports both internally and to DOJ. Companies therefore need internal reporting systems capable of escalating significant allegations promptly.
What can Fractional General Counsel or Outside General Counsel do before an investigation begins?
Fractional General Counsel or Outside General Counsel can establish reporting and escalation procedures, advise management and boards, develop preservation protocols, coordinate internal investigations, identify conflicts, oversee remediation, evaluate reporting requirements, and retain specialized white-collar or regulatory counsel when required.
SOURCES:
About Todd B. Nurick
Todd B. Nurick is a Pennsylvania and New York business attorney and Fractional General Counsel/Outside General Counsel with approximately 30 years of experience advising businesses concerning contracts, corporate governance, investigations, risk management, transactions, compliance, and disputes.
Through the Law Office of Todd B. Nurick, he advises businesses seeking experienced legal oversight without maintaining a full-time internal legal department.
This article is for general informational purposes only and does not constitute legal advice. Corporate criminal enforcement, voluntary self-disclosure, government investigations, reporting obligations, privilege, compliance requirements, and remediation obligations depend upon the particular facts, industry, jurisdiction, and applicable law. Reading this article does not create an attorney-client relationship.


