The Justice Department's National Fraud Enforcement Division issued a directive on October 1 that tells its prosecutors which corporate cases to look for and how to handle the ones they find, and the four categories it names have a common thread. In each of them, the victim is the federal government or the taxpayers who fund it.
The document is Directive 26-12, titled "Corporate Enforcement in the Fight Against Fraud," and it comes from Colin M. McDonald, the assistant attorney general who leads the division. It is the first statement of priorities from a unit created in April, and it arrives as the division is staffing up under an August restructuring plan that would move roughly five hundred attorneys and staff into it from other parts of the department and from United States Attorneys' Offices. Directive 26-12 is the map those attorneys will use.
The four categories, and what they leave out
Prosecutors are directed to prioritize four kinds of corporate fraud: health care schemes, including health care fraud, the distribution of controlled substances and violations of the Federal Food, Drug, and Cosmetic Act; schemes involving the public trust or the financial integrity of Americans and markets, including procurement, government contracts and other government functions; significant evasion of internal or external revenue; and schemes involving tariff evasion, the importation of goods or services, or forced labor.
Read as a set, the priorities describe a division organized around fraud against the United States rather than fraud in general. Health care fraud draws on Medicare and Medicaid dollars. Procurement and contract fraud takes from government programs. Revenue evasion deprives the Treasury directly, and tariff and forced-labor violations touch the government's control of the border and the conditions under which goods enter the country.
The omissions are as telling as the list. Schemes in which companies are the victims, such as trade secret theft or embezzlement by an employee, are not among the enumerated priorities, though the analyses of the directive note that they are not excluded either. Companies in the four priority sectors should expect more attention. Companies in the others should not read their absence as a promise.
Ten factors, and a phrase that does the work
The directive also directs prosecutors to give "great weight" to a list of ten factors when deciding whether to bring charges and when negotiating plea or other agreements. They include what corporate management knew about the scheme or did to advance it, efforts to conceal conduct from regulators or auditors, schemes that last three years or more, conduct that threatens safety or security including military readiness, conduct causing substantial hardship to a taxpayer-funded program or government function, conduct affecting multiple such programs, conduct spanning three or more federal districts, schemes with twenty-five or more victims or twenty-five million dollars or more in losses, the movement of American dollars to support foreign adversaries, and immigration offenses.
The list is not a set of thresholds. The directive calls it non-exhaustive, and the analyses stress that these considerations inform prosecutorial discretion rather than establish minimums for a case. What they do is tell defense counsel where a company's exposure will be argued. A compliance program that missed three years of misconduct reads differently from one that missed a quarter. Diversion of funds abroad reads differently from a domestic accounting failure.
The factors also give prosecutors a vocabulary that matches the department's public framing. The directive's stated mission is fraud against the United States and American taxpayer dollars, and its aggravating factors are the ones that measure how much damage was done to government programs, how long it lasted, and whether it crossed borders or district lines.
A new section that sits on every corporate case
The directive gives the division's Corporate Enforcement Section a role at every stage of a corporate matter. Prosecutors must report ongoing corporate investigations to the section's chief within seven days of the directive's issuance. New investigations and significant developments in existing ones have to be flagged promptly, and the section is expected to assist with counseling, litigation and negotiations across the division's portfolio.
The section's mandate extends past the resolution. It has primary responsibility for evaluating whether a company is complying with the terms of a corporate criminal resolution, including whether it has implemented or enhanced its compliance program and whether it is meeting its reporting obligations during the agreement's term. The directive's stated reason is consistency: a single section assessing compliance is meant to keep outcomes aligned and to free line prosecutors to bring more cases.
That is a significant concentration of authority. In practice the section becomes the office that decides whether a company under a deferred prosecution agreement is living up to it, which is the difference between a resolution that quietly expires and one that produces a new charge.
The reach of the directive has a boundary worth noting. It applies to matters handled by the fraud division, and the analyses point out that cases assigned to a district fraud counsel in a United States Attorney's Office, without division supervision, sit outside it. The section can still assist those offices when it helps the department's overall mission, but the seven-day reporting duty and the compliance oversight follow the division's docket rather than every corporate fraud case in the country. A company's exposure to the new section therefore depends in part on which office opened its matter.
Whistleblowers, including the ones who were there
The directive's last section deals with where cases come from. It credits a mix of additional resources, technology and data analytics at the National Fraud Detection Center for letting the division generate leads and open investigations at what the document calls a rapid pace. It then directs division leadership to design policies and programs that encourage whistleblowers to come forward with credible information about fraud, including whistleblowers who took part in the conduct, and to make those programs public where possible.
Paying insiders for information about their own companies is a tool the department has been building for several years, and the directive moves it into the fraud division's standard playbook. For companies, the practical consequence is that the population of people who might report misconduct now includes participants who have a reason to be the first one through the door, which is the same logic that drives the self-disclosure credit in the department's existing policy.
The lead-generation side deserves the same attention as the whistleblower programs. The directive credits data analytics and the National Fraud Detection Center with letting the division open investigations faster than it could on tips alone, which points to a department that screens data sets for patterns before it talks to anyone. Companies that keep their records in order, including the records that show what they disclosed and when, are better positioned to answer a question that arrives from a database rather than a subpoena.
What did not change
The directive leaves the department's Corporate Enforcement and Voluntary Self-Disclosure Policy in place and tells prosecutors to follow it in all circumstances, alongside the Justice Manual's principles for prosecuting business organizations. Companies that disclose misconduct, cooperate with investigators and remediate the problem can still earn credit, and the directive's own text commits the division to guarding against overbroad corporate enforcement that interferes with legitimate business.
Ballard Spahr's analysis concludes that the directive does not materially alter the department's approach to corporate and white collar enforcement, which is a fair reading of a document that restates existing policies while concentrating them in one division. Greenberg Traurig's reading notes the same continuity and adds the observation that matters more for planning: the directive signals a focus on fraud in which the government is the victim, and enforcement activity in those sectors is likely to increase.
Both things can be true. A directive that changes no legal standard can still change outcomes by telling five hundred prosecutors, a new section and the defense bar where the department intends to spend its attention. The compliance programs of companies in health care, government contracting, tax and trade have a new audience, and that audience has said what it will be measuring.
Where the exposure lands
The groups most affected are the ones the priorities name. Health care companies face a list that includes controlled substances and the food, drug and cosmetics laws, which reaches beyond billing fraud into how products are marketed and distributed. Contractors face a public trust category broad enough to cover procurement and other government functions. Tax and trade practices that were previously handled in civil proceedings now sit alongside criminal fraud priorities.
For those companies, the analyses offer a consistent checklist: know what management knew and when, be able to show what was reported to auditors and regulators and what was withheld, map which programs and locations the conduct touched, and be prepared to demonstrate compliance for the life of any agreement. None of that is new advice. It is more pointed now because the directive makes those factors the terms of the negotiation and assigns their evaluation to a section whose business is compliance over time.
The directive's balance is deliberate. It pairs an aggressive posture with an explicit promise to protect companies that disclose, cooperate and remediate, and it keeps the self-disclosure policy that gives those promises weight. Whether that balance holds will be visible in the cases the division brings, the resolutions it signs, and how often the Corporate Enforcement Section concludes that a company under an agreement has fallen short.
Primary sources
- Ballard Spahr's analysis in the National Law Review for the directive's title, issuance date and author, the four priority categories, the ten factors, the Corporate Enforcement Section's reporting and compliance duties, and the whistleblower provisions.
- Greenberg Traurig's analysis in the National Law Review for the division's creation in April 2026, the August restructuring plan, the scope of the directive relative to district fraud counsel, and the whistleblower and self-disclosure framework.
- The Justice Manual, section 9-28.000, for the principles of federal prosecution of business organizations that the directive instructs prosecutors to follow.