Admissions
A clear factual statement of the underlying conduct and any agreed admissions of wrongdoing or responsibility by the organization, tailored to legal and factual risk.
A DPA can resolve alleged misconduct without a conviction, limit collateral consequences, and allow remediation while preserving public accountability; it also imposes structured compliance obligations and oversight to reduce recurrence.
DPAs involve prosecutors and corporate representatives negotiating terms shaped by the severity of alleged conduct, remediation steps, and public interest.
Execution usually requires senior corporate authorization and may require court approval; signatories should confirm signing authority and any required judicial filings before execution.
A clear factual statement of the underlying conduct and any agreed admissions of wrongdoing or responsibility by the organization, tailored to legal and factual risk.
Specific corrective measures such as policy updates, disciplinary action, enhanced training, or systems remediation with deadlines and responsible parties.
Agreed fines, forfeitures, restitution, or disgorgement amounts and payment schedules tied to resolution terms and government recovery priorities.
Mandatory enhancements to compliance frameworks, internal controls, and reporting lines, often requiring written plans and evidence of implementation.
Appointment of an independent compliance monitor or reporting officer, with scope, duration, reporting frequency, and access rights defined.
Conditions for reinstatement of charges, cure periods, termination triggers, confidentiality limits, and provisions governing public disclosure.
| Field | Configuration |
|---|---|
| Signer Authentication | Email link, SMS code, or higher assurance KBA |
| Document Versioning | Enable version control and retain prior drafts |
| Audit Trail | Capture IP, timestamp, and signer actions |
| Access Control | Limit downloads and editing to authorized roles |
Use a platform that provides secure authentication, a tamper-evident audit trail, and long-term record retention to support enforceability.
Preserve signed PDFs with audit metadata and ensure any BAA or special compliance addenda (for HIPAA or 21 CFR Part 11) are in place before sharing patient or regulated data.
Often weeks to months depending on complexity
File with court promptly if judicial approval is required
Monthly or quarterly compliance reports are common
Independent monitor reports may be semiannual
Final certification and potential dismissal on successful completion
Facts compiled and internal report finalized for negotiation.
Agreed obligations, payments, and monitoring are defined.
Authorized signatories execute the document and date it.
Ongoing obligations observed until the agreed termination date.
A regional bank agreed to a DPA after AML deficiencies were identified
A healthcare provider entered a DPA following disclosure shortcomings tied to PHI handling
Typically a CEO or authorized corporate officer signs on behalf of the organization; board or special committee approval may be required depending on governance rules and materiality.
A designated U.S. Attorney, Assistant Attorney General, or state prosecutor signs for the government; court approval may also be entered by a judge where required.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | No | No | Yes, limited | Yes, limited |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |