Document type: Checklist Practice area: Corporate — Compliance and Investigations Jurisdiction: United States (federal and Delaware) Last reviewed: 5 September 2026


How to use this checklist

Sections 1 through 5 track the first regulatory question — is the program well designed. Section 6 tracks the second — is it resourced and empowered. Sections 7 through 10 track the third and hardest — does it work in practice. Sections 11 and 12 are incident response.

Items marked [DECISIVE] are the ones that most often determine the outcome when something goes wrong.


1. Risk assessment

  • A written risk assessment exists and is less than twelve months old. [DECISIVE]
  • It was built from interviews across levels, including two levels below the executives.
  • It used transaction data, not only interviews.
  • Risks are stated concretely — naming the business practice, the counterparty type, and the jurisdiction — rather than as abstract categories. [DECISIVE]
  • Inherent likelihood, impact, control strength, and residual risk are scored with documented reasoning.
  • Mission-critical compliance risks are identified separately and explicitly.
  • A risk register exists mapping each risk to a control, an owner, a test, the last test date, and the result. [DECISIVE]
  • The register visibly drives the testing plan, the training plan, and the board agenda.
  • Refresh triggers are defined: annual, plus acquisition, new market, new product, regulatory change, or incident.


2. Controls

  • Every significant risk has a control, not merely a policy. [DECISIVE]
  • Each control has a named owner in the business, not in compliance.
  • System configurations enforce the controls where possible — payment blocks, approval workflows, screening at order entry, segregation of duties.
  • Known bypasses identified and closed (manual journal entries, emergency vendor creation, drop-ship orders).
  • Approval thresholds set and monitored for threshold-hugging.
  • Books and records controls address account use, journal entry approval, and period-end manual entry review — recognizing that 15 U.S.C. § 78m imposes affirmative obligations independent of any underlying misconduct. [DECISIVE]
  • Policies exist, are short, are in the right languages, and are located where the decision is made.

3. Reporting channel

  • Multiple intake paths exist: hotline, web, email, direct to compliance, any manager, and a board channel.
  • Anonymity is available where lawful, with two-way anonymous follow-up.
  • A case management system logs every report with number, category, dates, assignment, findings, and closure. [DECISIVE]
  • Published response commitments exist (acknowledge, triage, preliminary assessment) and are measured against actual performance.
  • Triage criteria define what goes where and what escalates immediately to the audit committee.
  • Investigation rigor is consistent regardless of the seniority of the accused. [DECISIVE]
  • Retaliation control: every adverse employment action affecting a person who reported within the preceding [24] months requires compliance review before execution. [DECISIVE]
  • Separation, confidentiality, and non-disparagement agreements expressly carve out communications with regulators. [DECISIVE]
  • The channel is understood to compete with 15 U.S.C. § 78u-6 awards and 31 U.S.C. § 3729 qui tam actions, and is designed for speed and credibility accordingly.
  • Internal reporters' protections under 18 U.S.C. § 1514A understood and respected.

4. Training and communication

  • Training is segmented by risk and role, not delivered uniformly.
  • Content uses the company's own anonymized incidents.
  • Managers receive separate training on receiving reports and on the retaliation prohibition.
  • Comprehension is tested, not merely completion.
  • Non-completion by high-risk personnel is treated as a finding.
  • Targeted training follows every substantiated incident for the affected population.
  • Communications reference specific incidents and decisions, not only values.

5. Third parties and transactions

  • A single onboarding workflow exists and cannot be bypassed — the finance system rejects payment to any counterparty not onboarded through it. [DECISIVE]
  • Risk tiering by geography, government interaction, function, and compensation structure.
  • Screening: sanctions, denied party, politically exposed persons, adverse media.
  • Questionnaire covering beneficial ownership, government-official connections, other clients, compensation basis, and subcontracting.
  • Every red flag documented with its resolution and approver. [DECISIVE]
  • Contract terms: anti-corruption and sanctions representations, audit rights, training obligations, termination for breach, subcontracting consent.
  • Payment controls: no third-country accounts, no cash, no undocumented success fees, invoices describing actual services.
  • Refresh cycle defined and met.
  • Anti-corruption exposure understood across 15 U.S.C. § 78dd-1, § 78dd-2, and § 78dd-3, including payments made through intermediaries.
  • M&A: pre-signing compliance diligence performed; contractual protections obtained; post-closing integration on a published timeline; testing within that timeline. [DECISIVE]

6. Resourcing and empowerment

  • Compliance headcount and budget documented as a ratio to revenue and to high-risk headcount.
  • The compliance officer has direct access to the board or audit committee, including at least annual time without management present. [DECISIVE]
  • Compliance has direct read access to transaction data in the ERP and payment systems. [DECISIVE]
  • Compliance is not compensated or evaluated by the business units it oversees.
  • There is a documented instance of the compliance function stopping or materially changing a business decision. [DECISIVE]
  • Escalations to compliance are logged, with outcomes.
  • Autonomy and seniority are sufficient for the function to be present in decisions, not consulted after them.

7. Testing and monitoring

  • A testing plan derives from the risk register, with method, frequency, sample size, and owner per control. [DECISIVE]
  • Methods include reperformance, sampling, analytics, walkthroughs, and interviews.
  • Analytics run at minimum: threshold-hugging; vendor master anomalies; third-country payment routing; round numbers; duplicates; rebate and discount outliers; expense patterns; manual journal entries; sales concentration.
  • Every analytic has a disposition workflow — no alert goes uninvestigated. [DECISIVE]
  • Alert tuning decisions documented.
  • Findings recorded with owner, remediation, and date.
  • Every finding retested after remediation. [DECISIVE]
  • Repeat findings tracked and escalated.
  • A testing program that has never found anything is treated as a defect, not a success.
  • Culture survey run annually and read by segment, tracking willingness to report, belief that action follows, pressure to compromise, and perceived consistency across levels.

8. Investigation

  • Preservation issued within hours, covering email, files, chat, messaging applications, and personal devices used for business. [DECISIVE]
  • Auto-deletion suspension verified technically with IT, not assumed. [DECISIVE]
  • Scoping documented: allegations, individuals, potential legal exposure, seniority of those implicated.
  • Outside counsel engaged where exposure is material or independence matters; privilege structure established at the outset.
  • Audit committee chair notified early on material matters.
  • Upjohn warnings delivered at every interview, documented, and repeated on changed circumstances.
  • Separate counsel offered where individual conduct is genuinely at issue; advancement and indemnification resolved on the charter, bylaws, and agreements.
  • Joint defense or common interest arrangements, if any, in writing with a termination mechanism.
  • No obstruction, including selective production, delay, or witness coaching — recognizing that 18 U.S.C. § 1001 reaches statements made during the investigation. [DECISIVE]

9. Root cause and remediation

  • Root cause analysis performed, not incident description. [DECISIVE]
  • Causes categorized: control design gap; operation failure; incentive misalignment; escalation failure; resourcing gap; data blindness; cultural factor.
  • Remediation designed to the causes, with owners and dates.
  • Remediation tested and the test documented. [DECISIVE]
  • Program changes fed back into the risk register, control set, testing plan, and training.
  • Discipline imposed consistently and reaching upward to supervisors and executives. [DECISIVE]
  • Reasoning documented for every disciplinary decision, including decisions not to discipline.
  • Compensation consequences applied: clawback, forfeiture of unvested awards, compliance modifiers in incentive plans. [DECISIVE]
  • Remediation completed before resolution wherever possible — the strongest monitor-avoidance argument available. [DECISIVE]

10. Board oversight

  • Committee charter names the company's mission-critical compliance risks specifically, not "compliance" generically — the lesson of Marchand v. Barnhill, 212 A.3d 805 (Del. 2019). [DECISIVE]
  • Reporting cadence set and met; annual deep dive on the risk assessment.
  • Reporting includes: register changes; testing performed and exception rates; report volume, cycle times, substantiation rates; discipline by seniority level; root cause analyses and resulting changes; repeat findings; third-party coverage; resourcing.
  • Compliance officer meets the committee without management at least annually.
  • Minutes record questions asked and directions given, not attendance — the evidence that defeats a claim under In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996) and Stone v. Ritter, 911 A.2d 362 (Del. 2006). [DECISIVE]
  • Escalation protocol requires management to bring specified matters to the committee.

11. Incident response decisions

  • Preservation complete and verified.
  • Scope and seniority assessed — recognizing that involvement of high-level personnel triggers a rebuttable presumption against program effectiveness under the Sentencing Guidelines. [DECISIVE]
  • Legal exposure mapped, including any strict-liability-flavored accounting exposure under 15 U.S.C. § 78m.
  • Voluntary self-disclosure decision made deliberately and early, with the declination framework in view and with awareness that a whistleblower can eliminate the option at any moment. [DECISIVE]
  • Cooperation posture defined: facts and documents produced promptly; individuals identified; privilege positions taken deliberately.
  • Collateral consequences assessed: debarment, exclusion, licensing, certification obligations under 15 U.S.C. § 7241 and 15 U.S.C. § 7262, and follow-on civil litigation.
  • Resolution options understood along the ladder: declination, non-prosecution agreement, deferred prosecution agreement, guilty plea — with judicial review of a DPA narrow under United States v. Fokker Services B.V., 818 F.3d 733 (D.C. Cir. 2016) and United States v. HSBC Bank USA, N.A., 863 F.3d 125 (2d Cir. 2017).
  • Monitor-avoidance posture assembled: contained misconduct; no senior involvement; completed and tested remediation; rebuilt function; functioning internal audit.

12. Documentation to be able to produce on demand

  • Current risk assessment and register.
  • Control matrix with owners.
  • Testing plan, testing results, findings, remediation, and retest evidence.
  • Policy set with adoption and revision dates.
  • Training records by segment, with comprehension results.
  • Third-party diligence files including red flag resolutions.
  • Case management export with cycle times and outcomes.
  • Discipline log by seniority with reasoning.
  • Root cause analyses and resulting program changes.
  • Compensation actions: clawbacks, forfeitures, modifiers applied.
  • Board and committee charters, agendas, materials, and minutes.
  • Culture survey results and trend.
  • Preservation notices and IT verification records.
  • Program budget and headcount history.

Related documents


This checklist is general information, not legal advice, and does not create an attorney-client relationship.