Statement from A. Tysen Duva: AAG of DOJ Criminal Division
In the Ethicsverse Day 2026 keynote, Assistant Attorney General Tysen Duva — head of the Justice Department's Criminal Division — spoke directly to the compliance community for roughly thirty minutes. This recap captures every part of his statement and Q&A: his three enforcement priorities, the June 2025 FCPA memo, the corporate enforcement policy and its flowchart, the Balt and Scoular cases, and his working definition of good-faith self-disclosure.
Joah Park
Lead Producer for The Ethicsverse

The keynote of Ethicsverse Day 2026 gave the compliance community something it rarely gets: thirty uninterrupted minutes with a sitting Assistant Attorney General. Tysen Duva, head of the Justice Department's Criminal Division, joined host Nick Gallo to lay out in plain, line-prosecutor language exactly where the department is pointing its resources, how its corporate enforcement policy is meant to function, and what the DOJ expects from compliance professionals and ethical leadership. This recap walks through every part of that statement and the question-and-answer session that followed.
What made the talk notable was not just its candor but its framing. AAG Duva repeatedly cast the relationship between the government and corporate compliance as a partnership, and grounded abstract policy in concrete cases, a published flowchart, and a working definition of "good faith." A companion piece covers the practitioner panel that debriefed these remarks; here we stay with the source, capturing the AAG's own words and priorities.
Key Takeaways
Who Tysen Duva Is — and the "Common-Sense" Lens He Brings
AAG Duva introduced himself as a career trial lawyer with more than two decades as a prosecutor at the U.S. Attorney's Office in the Middle District of Florida, where he tried many fraud and corporate-compliance cases before taking over the Criminal Division in late December.
He said the foundation of almost every crime is the same: someone getting paid (whether through material misrepresentation, narcotics, or laundering money). That the root of criminal conduct is money.
His governing test for deploying the DOJ Criminal Division's resources is a common-sense one a colleague dubbed the "Aunt Donna test," named for a blue-collar worker outside Phoenix: he asks what ordinary Americans actually care about, even when weighing international matters.
The Mission: Restoring American Trust
AAG Duva tied his agenda to the acting Attorney General's theme of restoring American trust, and framed his first six months in the role around focusing division resources on protecting a free society and the interests of everyday citizens.
He previewed three priorities in order: cartels and their financiers, corporate enforcement, and cyber-enabled crime. He noted that the middle topic would be the most relevant to the compliance audience.
Priority One: Cartels and Their Financiers
He described attending the guilty-plea hearing of Ismael Zambada García ("El Mayo") in the Eastern District of New York, co-founder of the Sinaloa cartel (the other co-founder being the infamous El Chapo). The hearing took place in the same courthouse where El Chapo was convicted a decade earlier. AAG Duva credited the previous DOJ administration's prosecutors and agents who built the case over two decades.
As an example closer to the compliance world, he cited the prosecution of Yan Lin in a Chinese money-laundering conspiracy involving bulk-cash pickups across the United States, overseas electronics purchases, trade-based laundering through fictitious corporations, and the movement of funds into stablecoin — a cryptocurrency that settles in minutes and holds its value.
The through-line: cartels and their financiers sit at the apex of the Criminal Division's priorities, and financial crime increasingly runs through cryptocurrency and the legitimate banking system.
Why Compliance and Banking Professionals Are the "First Line of Defense"
AAG Duva stressed that to launder money and stand up fictitious corporations, criminals must use the banking system, typically at several degrees of separation from a real company.
That, he said, makes compliance and banking professionals the people best positioned to see it, spot it, and figure out what is going on — the "first line of defense" that prosecutors and agents genuinely rely on.
Priority Two: Corporate Enforcement and the June 2025 FCPA Memo
The department is actively enforcing the Foreign Corrupt Practices Act under a June 2025 memo that defines four criteria for FCPA cases: ties to cartels, money laundering, and transnational criminal organizations; harm to U.S. business interests abroad, where companies are squeezed out of markets and business opportunities by way of fraud or financial crime; U.S. national security interests; and other major conduct falling outside the first three.
He acknowledged the FCPA unit had shrunk but said he intends to staff it back up and follow the memo's dictates, pointing to The Scoular Company case brought the previous Friday.
Cases That Make the Incentive Concrete
The first resolution after the policy's promulgation involved Balt, a medical-device company whose U.S. subsidiary paid bribes through a consultant to a doctor at a French public hospital to buy and sell their devices. Balt found the conduct, disclosed it, cooperated, and cleaned house — and the Criminal Division declined to prosecute the company while indicting the two most culpable individuals.
By contrast, The Scoular Company, an agricultural business from Omaha, Nebraska, paid roughly $400,000 in bribes to Mexican customs officials over six years to avoid inspection costs. Because it did not self-disclose, it entered a three-year deferred prosecution agreement, agreed to pay more than $10 million, and committed to implementing a compliance program.
He also referenced Purdue Pharma — more than $5 billion in fines and forfeiture for marketing OxyContin to prescribers writing medically baseless scripts and for misleading the DEA on manufacturing quotas — as an example of hotly litigated health-and-safety enforcement.
The dividing line between a declination and a deferred prosecution agreement, he said, is timely voluntary disclosure — and the policy is explicitly not a mechanism for culpable individuals to escape prosecution.
The Corporate Enforcement Policy: Four Mechanisms and a Flowchart
AAG Duva said he and his predecessors authored the Corporate Enforcement Policy, which rests on four mechanisms: voluntary self-reporting of conduct DOJ does not already know about; full cooperation; full remediation, including removing the individuals who sponsored, knew about, or participated in the conduct; and the absence of aggravating circumstances.
A flowchart is attached to the policy and publicly available, making the path easy to follow, with the express goal of bringing companies in early enough to earn a declination. (See the Ethico resource on this flowchart here.)
Following the steps outlined in the new Corporate Enforcement Policy is what allowed Balt to avoid criminal indictment (although the two most culpable individuals were indicted). Satisfying the four criteria allowed Balt to get a more favorable declination. AAG Duva cited timely disclosure as the main contributing factor that differentiated the Balt case's outcome from Scoular's.
What "Early Disclosure" Actually Means
Early disclosure, he clarified, is neither a 100-page treatise with 60 footnotes nor a phone call at the first rumor, but something in between: do not run the full multi-month investigation before coming forward, because delay invites DOJ cooperators, whistleblowers, or a reporter to reach the government first.
Quoting a mentor from his public-corruption days — "you're going to find your best cases in the newspaper" — he warned compliance officers not to let that happen to their company.
What he wants instead: use a beefed-up compliance department to evaluate the issue and come forward early with a developed — though not necessarily complete — record, saying in effect, "we have a problem, this is what it is, and we are committed to getting to the bottom of it with you."
AAG Duva understood there may be some mistrust when reporting to the DOJ, and hopes to earn trust by following the same process that allowed Balt to secure a favorable declination.
Indicting Individuals, Not Punishing the Whole Company
The goal, he repeated, is to hold individual wrongdoers accountable rather than force an entire company through years of investigation, litigation, and millions in fees because of a few bad actors.
Once a disclosure is made, he urged companies to meet the corporate enforcement prosecutors in the Fraud Section in person, work the agreed action items between meetings, and build trust through demonstrated progress.
Priority Three: Protecting Americans from Cyber-Enabled Crime
The third priority is protecting Americans — especially older Americans — from cyber-enabled scams, coordinated across the Fraud Section, the Computer Crime and Intellectual Property Section, the Child Exploitation and Obscenity Section, and the Office of International Affairs, with partners in Southeast Asia, West Africa, and across the Western Hemisphere.
Working with the Department of Homeland Security, the FBI, and the U.S. Attorney's Office in Washington, D.C., the division has located scam centers and executed takedowns in places including Indonesia and the United Arab Emirates.
He cited an FBI estimate of more than $16 billion stolen in a single year, said the division has frozen more than $700 million in cryptocurrency, seized a Telegram channel used to run the schemes, and arranged provisional arrests abroad even where no extradition treaty exists.
AAG Duva stressed the importance of this issue, considering it a critical priority to protect older American citizens who are most at risk of falling prey to these cyber-scams, and that targeting these scammers will be a mainstay feature of the DOJ under his leadership.
Closing Charge: "See Something, Say Something" and the Power of Precise Writing
Modern fraud, he said, is complex, global, borderless, now digital, and sophisticated, which is why he asked compliance professionals to evaluate what they see and, when something looks wrong, say something.
Prosecutors, agents, and compliance officers share one goal — prevent the crime, and if it cannot be prevented, detect it — achieved through great communication and precise writing.
Invoking Nathaniel Hawthorne's line that "easy reading is damn hard writing," he told the audience that the more precise and enterprising their written product, the more likely it is to catch a prosecutor's attention and connect the dots that make a reader want to act.
The Q&A: Good Faith, Timelines, and Staying "in the Green"
When asked where companies get it wrong — especially amid the tension between moving quickly and finishing a full investigation — AAG Duva said DOJ does not expect perfection on day one and genuinely wants companies to land in the "green" zone of the flowchart rather than face impossible standards.
He defined good faith operationally: preserve company emails and devices, issue litigation holds, run search terms, and keep those materials ready for DOJ — while noting that dumping a million documents is not, by itself, good-faith cooperation.
Drawing on his own practice, he described telling defense lawyers exactly which documents and arguments would hurt their client, by Bates number, to build genuine good faith — and said the same transparency works in the corporate context.
Timelines, he stressed, tell the story: document what was found and when, when it went to a supervisor, when emails were frozen, when interviews happened, and when the disclosure call was made. A detailed, expedient timeline makes it nearly impossible for DOJ to claim the company did not act in good faith.
The danger is opacity — someone spots an issue, 180 days pass, and then a whistleblower calls or an article appears, moving the company from green into yellow on the flowchart and into what he called the "trick bag."
His parting practical advice: build a relationship with the Criminal Division's corporate enforcement attorneys, make the calls, log the timeline of every interaction, and — if the experience is a good one — spread the word so others trust the process.
Closing Summary
AAG Duva's keynote was a rare, direct statement of how the Criminal Division intends to operate. His three priorities — cartels and their financiers, corporate enforcement, and cyber-enabled crime — frame a department focused on what he calls the common-sense concerns of ordinary Americans, with compliance professionals cast as the first line of defense. On corporate enforcement specifically, the message was consistent and concrete: self-report promptly, cooperate, remediate fully, avoid aggravating circumstances, and the published flowchart can lead to the declination the policy is designed to deliver — while individual wrongdoers are still pursued. Above all, he asked for good faith expressed through preservation, precise writing, detailed timelines, and an in-person relationship built meeting by meeting. For the panel's candid analysis of what these remarks mean in practice — and what was left unsaid — see the companion debrief.
Enjoyed this article?
Subscribe to our newsletter for more insights on ethics and compliance.
View All Articles