Assistant Attorney General Colin M. McDonald of the Department of Justice's (DOJ) National Fraud Enforcement Division issued Directive 26-12, Corporate Enforcement in the Fight Against Fraud (the Directive), on October 1, 2026, to all Fraud Division personnel. The Directive builds on DOJ's restructuring of fraud enforcement and commits the Division to an "aggressive, all-tools approach" to prosecuting fraud in four priority areas: health care, government, tax, and trade. Perhaps most significantly, the Directive directs that every corporate matter will now be routed through the Division's newly formed Corporate Enforcement Section (the Section). As the Firm discussed in DOJ's Fraud Division Expands Manpower and Regional Coordination, the Fraud Division has been retooled over the past few months with additional personnel, expanded jurisdiction, intentional regional coordination, and enhanced data-analytics capabilities. These efforts are aimed at five enforcement priorities: public trust and financial integrity, health care, internal revenue, global trade and commerce, and corporate misconduct. The Directive demonstrates how those priorities will apply across corporate cases and provides companies with specific insight into how a particular matter might end up in a prosecution setting.
Key Takeaways
- Four Areas of Government Focus: Health care, government programs and functions, revenue, and trade fraud.
- Ten Aggravating Factors: Prosecutors must treat various factors, including management involvement, concealment, duration of misconduct, geographic scope, and financial harm, as carrying "great weight" in charging and resolution decisions.
- Newly Formed Corporate Enforcement Section: The Section will participate throughout investigations and oversee compliance with corporate resolutions.
- Disclosure and Detection: DOJ is emphasizing voluntary self-disclosure while expanding data analytics and whistleblower channels.
- Practical Use: Companies should use aggravating factors to guide internal investigations and evaluate potential self-disclosure decisions.
Four Enforcement Priorities
When opening and conducting corporate investigations, the Directive instructs prosecutors to prioritize:
- Health care fraud, including unlawful controlled-substance distribution and Federal Food, Drug, and Cosmetic Act violations;
- Schemes undermining public trust or financial integrity in procurement, government contracts, or other government functions;
- Schemes involving significant evasion of internal or external revenue; and
- Tariff evasion, importation of goods or services, and forced labor.
With these priorities explicitly stated, it is important for companies operating in these areas to pay particular attention to operations, update compliance programs, and respond appropriately when red flags are raised.
Ten Factors That Will Carry "Great Weight"
The Directive lists ten factors prosecutors "must place great weight on" when deciding whether to charge a company or negotiate a plea or other agreement:
- Corporate management's knowledge of or involvement in the scheme;
- Efforts to conceal fraud from government agencies or auditors, or obstruct government oversight;
- Conduct furthering the scheme for three years or more;
- Actions threatening Americans' safety or security, including military readiness;
- Substantial financial hardship to a taxpayer-funded program or government function;
- Impact on multiple taxpayer-funded programs or government functions;
- Conduct affecting three or more federal districts;
- Financial harm to 25 or more victims, or losses of $25 million or more;
- Exfiltration of American dollars to support foreign adversaries; and
- Conduct involving immigration offenses.
The list is non-exhaustive, but they give companies a clearer picture of circumstances that may elevate an internal compliance problem into a significant criminal enforcement matter.
A Single Section Will Touch Every Corporate Fraud Case
The Directive gives the Corporate Enforcement Section, created earlier this year, a role in each phase of a corporate matter, from intake through resolution or trial. Prosecutors had seven days to report open corporate investigations to the Section's Chief and must promptly report new investigations and significant developments.
The Section also has primary responsibility for post-resolution oversight, including evaluating compliance programs, reporting obligations, and other issues during the agreement's term. The Directive excludes cases handled by a District Fraud Counsel at a U.S. Attorney's Office unless the Fraud Division also supervises them.
Self-Disclosure, Data Analytics, and Whistleblowers – Including Participants
The Directive reaffirms DOJ's emphasis on voluntary self-disclosure and requires Fraud Division prosecutors to follow the department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy (CEP). As discussed in DOJ Announces New, Centralized Corporate Enforcement Policy, the CEP offers substantial potential benefits to companies that timely self-disclose, cooperate, and remediate qualifying misconduct.
At the same time, the Division is leveraging new resources, technology, and data analytics through the National Fraud Detection Center to generate leads and open investigations at a "rapid pace," while developing incentives for whistleblowers, including participants in the criminal conduct, to bring credible information to DOJ. Taken together, the faster DOJ can identify misconduct on its own, through data or whistleblowers, the more important prompt internal detection and investigation become for companies that want to preserve self-disclosure options. As discussed in DOJ Fraud Qui Tam Enforcement is Coming into FOCUS, DOJ increasingly uses data analytics and outside sources to identify suspected fraud before an investigative demand.
How the Directive Fits Within DOJ's Existing Framework
The Directive is a Fraud Division-specific overlay on, not a replacement for, DOJ's department-wide corporate enforcement and voluntary self-disclosure framework. The Directive carries forward the prior administration's emphasis on individual accountability, disclosure, cooperation, remediation, and effective compliance programs. Its changes are in the Division's lens and guardrails: case selection centers on fraud affecting taxpayer funds and American interests, the Directive supplies more concrete charging markers, and it expressly cautions against overbroad enforcement that could interfere with legitimate business operations.
The Directive also preserves a carve-out for matters assigned to a District Fraud Counsel by a U.S. Attorney's Office unless the Fraud Division supervises them. That distinction likely means greater national consistency in cooperation credit, resolution terms, and compliance obligations in Fraud Division-supervised and multi-district matters, while U.S. Attorney's Office-only cases may continue to reflect local priorities.
What Companies Should Do Now
The Directive reflects a Fraud Division that is better resourced, more centralized, and explicit about expectations. Companies, particularly in health care, government contracting, defense industry, and international trade, should consider:
Review high-risk areas: Reassessing health care billing and life sciences operations; government contracting and certifications; tax and revenue; and customs classification, tariffs, imports, and supply-chain practices, especially for importers with complex supply chains or tariff exposure, in light of the Firm's outline Trade Enforcement Risks Escalate with Increasing Tariffs: What Companies Should Do to Mitigate Risk.
Using the factors as an internal escalation tool: Incorporate the aggravating factors into investigation and compliance protocols so allegations involving management, concealment, prolonged misconduct, multiple programs or jurisdictions, or substantial losses receive prompt attention. Use the three-year, three-district, 25-victim, and $25 million markers as early risk gauges, and consider whether isolated, short-lived, promptly addressed conduct supports a proportionate response in light of the Directive's instruction to guard against "overbroad corporate enforcement."
Plan for centralized oversight: Expect the Corporate Enforcement Section to benchmark cooperation and resolution terms and closely scrutinize compliance commitments; commit only to obligations the company can meet.
Strengthen internal reporting: Ensure concerns, including reports from employees who may have participated in the conduct, reach legal and compliance personnel quickly through effective reporting, triage, and anti-retaliation processes, because ignored concerns increase whistleblower risk.
Preserve disclosure options: Not every compliance issue requires disclosure to DOJ, but companies should investigate significant potential misconduct quickly enough to make an informed decision while CEP benefits may remain available, including the 120-day window to self-report after a whistleblower reports internally and to DOJ. Early counsel involvement can help assess scope, apply the Directive's factors, and determine whether self-disclosure is appropriate.
Consider what your data shows: Evaluate information available to regulators and, where appropriate, conduct internal analytics on billing, reimbursement, procurement, customs, pricing, and other relevant data, recognizing that DOJ may spot anomalies before an internal complaint.
Conduct focused and intentional compliance training: Despite their best efforts, some companies are exploited by employees within their ranks who are intent on not following the rules. In these scenarios, it is essential to demonstrate to the government that all employees were initially trained on compliance expectations, received recurring training on compliance requirements, and that, from a cultural perspective, the company did things the right way as compared to individual rogue employees.
***
Baker Donelson attorneys in the Firm's Government Enforcement and Investigations Group represent companies and individuals in fraud investigations, self-disclosure decisions, and negotiated DOJ resolutions. The team also advises on internal investigations, compliance, voluntary self-disclosure, and parallel civil and criminal enforcement risks. Questions about the Directive or its effect on your company may be directed to Sean B. O'Connell, John S. Ghose, Nathaniel "Tyler" Lemons, Sabrina N. Marquez, or any member of Baker Donelson's Government Enforcement and Investigations practice group.