Research Note
Product Compliance Review Framework
A product compliance review connects legal interpretation to the product that will actually ship. It is not a memo attachment, a generic checklist, or a claim that counse
Product Compliance Review Framework
Purpose
A product compliance review connects legal interpretation to the product that will actually ship. It is not a memo attachment, a generic checklist, or a claim that counsel approved everything.
Review sequence
The team first freezes the proposed feature, markets, users, and timing. It then walks the working flow, including cohort rules, data inputs, failure states, alternate paths, administrator behavior, and what different observers can see.
The legal and domain owners identify applicable rules, licenses, contracts, guidance, and unsettled questions. The team records the facts supplied to each reviewer and preserves the version of each authority. Advice based on incomplete or later-changed facts must not travel as unconditional approval.
Risk analysis names the affected party, possible harm, likelihood, detectability, reversibility, and externalized cost. Each control receives an owner, test method, evidence, monitoring signal, and response path.
The decision record identifies the approver, material dissent, assumptions, boundaries, launch state, and automatic stop conditions. A material change to data, cohort logic, jurisdiction, purpose, or user experience triggers reapproval.
Required artifacts
| Artifact | Minimum content |
|---|---|
| Working flow | Screens, API behavior, flags, exceptions, and failure states |
| Data map | Source, purpose, access, retention, transfer, and deletion |
| Authority record | Jurisdiction, rule, effective date, version, interpretation owner |
| Risk record | Affected party, harm, likelihood, detectability, reversibility |
| Control evidence | Test, result, owner, monitor, alert, and response |
| Decision record | Scope, approver, dissent, assumptions, stop condition |
| Operating record | Incidents, complaints, changes, refreshes, and outcomes |
DOJ alignment
The Justice Department's current materials ask whether a compliance program is well designed, adequately resourced and empowered, and working in practice. The framework borrows those governance questions. It does not claim that following the framework creates a legal safe harbor or predicts a prosecutor's decision.
Boundary
Counsel, privacy, security, records, regulatory, and domain owners must adapt the process to the organization and jurisdiction. Sensitive advice and personal data may require restricted systems rather than an ordinary project note.
Sources
Follow the evidence.
- daltonanderson.ghost.io: ubers greyball the dark side of tech innovationdaltonanderson.ghost.io
- whistleblowers.gov: complaint pagewhistleblowers.gov
- uber.com: an update on greyballinguber.com
- theguardian.com: uber used greyball fake app to evade police across europe leak revealstheguardian.com
- courthousenews.com: GREYBALL AUDIT REPORTcourthousenews.com
- justice.gov: jm 9 28000 principles federal prosecution business organizationsjustice.gov
- youtu.be: TiC4GmwZ nsyoutu.be
- sec.gov: whistleblower protectionssec.gov
- open.spotify.com: 32iYem7RXAQ2R7WyHdRrscopen.spotify.com
- justice.gov: dljustice.gov
- justice.gov: corporate enforcementjustice.gov
- whistleblowers.gov: faqwhistleblowers.gov
- NLRB protected concerted activitynlrb.gov
- portland.gov: statement mayor ted wheeler allegations uber used greyball tool sidestepportland.gov
- sec.gov: report possible securities law violationssec.gov
- ftc.gov: bringing dark patterns lightftc.gov
- justice.gov: criminal division announces publication guidance evaluating corporate compliance programsjustice.gov
- whistleblowers.govwhistleblowers.gov
- content.govdelivery.com: 198c3edcontent.govdelivery.com
- portland.gov: 631393portland.gov
- yahoo.com: exclusive uber faces criminal probe 083701705yahoo.com