Document type: Checklist Practice area: Corporate — Compliance and Investigations Jurisdiction: United States (federal and Delaware) Last reviewed: 5 September 2026
How to use this checklist
Sections 1 through 5 track the first regulatory question — is the program well designed. Section 6 tracks the second — is it resourced and empowered. Sections 7 through 10 track the third and hardest — does it work in practice. Sections 11 and 12 are incident response.
Items marked [DECISIVE] are the ones that most often determine the outcome when something goes wrong.
1. Risk assessment
- A written risk assessment exists and is less than twelve months old. [DECISIVE]
- It was built from interviews across levels, including two levels below the executives.
- It used transaction data, not only interviews.
- Risks are stated concretely — naming the business practice, the counterparty type, and the jurisdiction — rather than as abstract categories. [DECISIVE]
- Inherent likelihood, impact, control strength, and residual risk are scored with documented reasoning.
- Mission-critical compliance risks are identified separately and explicitly.
- A risk register exists mapping each risk to a control, an owner, a test, the last test date, and the result. [DECISIVE]
- The register visibly drives the testing plan, the training plan, and the board agenda.
- Refresh triggers are defined: annual, plus acquisition, new market, new product, regulatory change, or incident.
2. Controls
- Every significant risk has a control, not merely a policy. [DECISIVE]
- Each control has a named owner in the business, not in compliance.
- System configurations enforce the controls where possible — payment blocks, approval workflows, screening at order entry, segregation of duties.
- Known bypasses identified and closed (manual journal entries, emergency vendor creation, drop-ship orders).
- Approval thresholds set and monitored for threshold-hugging.
- Books and records controls address account use, journal entry approval, and period-end manual entry review — recognizing that 15 U.S.C. § 78m imposes affirmative obligations independent of any underlying misconduct. [DECISIVE]
- Policies exist, are short, are in the right languages, and are located where the decision is made.
3. Reporting channel
- Multiple intake paths exist: hotline, web, email, direct to compliance, any manager, and a board channel.
- Anonymity is available where lawful, with two-way anonymous follow-up.
- A case management system logs every report with number, category, dates, assignment, findings, and closure. [DECISIVE]
- Published response commitments exist (acknowledge, triage, preliminary assessment) and are measured against actual performance.
- Triage criteria define what goes where and what escalates immediately to the audit committee.
- Investigation rigor is consistent regardless of the seniority of the accused. [DECISIVE]
- Retaliation control: every adverse employment action affecting a person who reported within the preceding [24] months requires compliance review before execution. [DECISIVE]
- Separation, confidentiality, and non-disparagement agreements expressly carve out communications with regulators. [DECISIVE]
- The channel is understood to compete with 15 U.S.C. § 78u-6 awards and 31 U.S.C. § 3729 qui tam actions, and is designed for speed and credibility accordingly.
- Internal reporters' protections under 18 U.S.C. § 1514A understood and respected.
4. Training and communication
- Training is segmented by risk and role, not delivered uniformly.
- Content uses the company's own anonymized incidents.
- Managers receive separate training on receiving reports and on the retaliation prohibition.
- Comprehension is tested, not merely completion.
- Non-completion by high-risk personnel is treated as a finding.
- Targeted training follows every substantiated incident for the affected population.
- Communications reference specific incidents and decisions, not only values.
5. Third parties and transactions
- A single onboarding workflow exists and cannot be bypassed — the finance system rejects payment to any counterparty not onboarded through it. [DECISIVE]
- Risk tiering by geography, government interaction, function, and compensation structure.
- Screening: sanctions, denied party, politically exposed persons, adverse media.
- Questionnaire covering beneficial ownership, government-official connections, other clients, compensation basis, and subcontracting.
- Every red flag documented with its resolution and approver. [DECISIVE]
- Contract terms: anti-corruption and sanctions representations, audit rights, training obligations, termination for breach, subcontracting consent.
- Payment controls: no third-country accounts, no cash, no undocumented success fees, invoices describing actual services.
- Refresh cycle defined and met.
- Anti-corruption exposure understood across 15 U.S.C. § 78dd-1, § 78dd-2, and § 78dd-3, including payments made through intermediaries.
- M&A: pre-signing compliance diligence performed; contractual protections obtained; post-closing integration on a published timeline; testing within that timeline. [DECISIVE]
6. Resourcing and empowerment
- Compliance headcount and budget documented as a ratio to revenue and to high-risk headcount.
- The compliance officer has direct access to the board or audit committee, including at least annual time without management present. [DECISIVE]
- Compliance has direct read access to transaction data in the ERP and payment systems. [DECISIVE]
- Compliance is not compensated or evaluated by the business units it oversees.
- There is a documented instance of the compliance function stopping or materially changing a business decision. [DECISIVE]
- Escalations to compliance are logged, with outcomes.
- Autonomy and seniority are sufficient for the function to be present in decisions, not consulted after them.
7. Testing and monitoring
- A testing plan derives from the risk register, with method, frequency, sample size, and owner per control. [DECISIVE]
- Methods include reperformance, sampling, analytics, walkthroughs, and interviews.
- Analytics run at minimum: threshold-hugging; vendor master anomalies; third-country payment routing; round numbers; duplicates; rebate and discount outliers; expense patterns; manual journal entries; sales concentration.
- Every analytic has a disposition workflow — no alert goes uninvestigated. [DECISIVE]
- Alert tuning decisions documented.
- Findings recorded with owner, remediation, and date.
- Every finding retested after remediation. [DECISIVE]
- Repeat findings tracked and escalated.
- A testing program that has never found anything is treated as a defect, not a success.
- Culture survey run annually and read by segment, tracking willingness to report, belief that action follows, pressure to compromise, and perceived consistency across levels.
8. Investigation
- Preservation issued within hours, covering email, files, chat, messaging applications, and personal devices used for business. [DECISIVE]
- Auto-deletion suspension verified technically with IT, not assumed. [DECISIVE]
- Scoping documented: allegations, individuals, potential legal exposure, seniority of those implicated.
- Outside counsel engaged where exposure is material or independence matters; privilege structure established at the outset.
- Audit committee chair notified early on material matters.
- Upjohn warnings delivered at every interview, documented, and repeated on changed circumstances.
- Separate counsel offered where individual conduct is genuinely at issue; advancement and indemnification resolved on the charter, bylaws, and agreements.
- Joint defense or common interest arrangements, if any, in writing with a termination mechanism.
- No obstruction, including selective production, delay, or witness coaching — recognizing that 18 U.S.C. § 1001 reaches statements made during the investigation. [DECISIVE]
9. Root cause and remediation
- Root cause analysis performed, not incident description. [DECISIVE]
- Causes categorized: control design gap; operation failure; incentive misalignment; escalation failure; resourcing gap; data blindness; cultural factor.
- Remediation designed to the causes, with owners and dates.
- Remediation tested and the test documented. [DECISIVE]
- Program changes fed back into the risk register, control set, testing plan, and training.
- Discipline imposed consistently and reaching upward to supervisors and executives. [DECISIVE]
- Reasoning documented for every disciplinary decision, including decisions not to discipline.
- Compensation consequences applied: clawback, forfeiture of unvested awards, compliance modifiers in incentive plans. [DECISIVE]
- Remediation completed before resolution wherever possible — the strongest monitor-avoidance argument available. [DECISIVE]
10. Board oversight
- Committee charter names the company's mission-critical compliance risks specifically, not "compliance" generically — the lesson of Marchand v. Barnhill, 212 A.3d 805 (Del. 2019). [DECISIVE]
- Reporting cadence set and met; annual deep dive on the risk assessment.
- Reporting includes: register changes; testing performed and exception rates; report volume, cycle times, substantiation rates; discipline by seniority level; root cause analyses and resulting changes; repeat findings; third-party coverage; resourcing.
- Compliance officer meets the committee without management at least annually.
- Minutes record questions asked and directions given, not attendance — the evidence that defeats a claim under In re Caremark International Inc. Derivative Litigation, 698 A.2d 959 (Del. Ch. 1996) and Stone v. Ritter, 911 A.2d 362 (Del. 2006). [DECISIVE]
- Escalation protocol requires management to bring specified matters to the committee.
11. Incident response decisions
- Preservation complete and verified.
- Scope and seniority assessed — recognizing that involvement of high-level personnel triggers a rebuttable presumption against program effectiveness under the Sentencing Guidelines. [DECISIVE]
- Legal exposure mapped, including any strict-liability-flavored accounting exposure under 15 U.S.C. § 78m.
- Voluntary self-disclosure decision made deliberately and early, with the declination framework in view and with awareness that a whistleblower can eliminate the option at any moment. [DECISIVE]
- Cooperation posture defined: facts and documents produced promptly; individuals identified; privilege positions taken deliberately.
- Collateral consequences assessed: debarment, exclusion, licensing, certification obligations under 15 U.S.C. § 7241 and 15 U.S.C. § 7262, and follow-on civil litigation.
- Resolution options understood along the ladder: declination, non-prosecution agreement, deferred prosecution agreement, guilty plea — with judicial review of a DPA narrow under United States v. Fokker Services B.V., 818 F.3d 733 (D.C. Cir. 2016) and United States v. HSBC Bank USA, N.A., 863 F.3d 125 (2d Cir. 2017).
- Monitor-avoidance posture assembled: contained misconduct; no senior involvement; completed and tested remediation; rebuilt function; functioning internal audit.
12. Documentation to be able to produce on demand
- Current risk assessment and register.
- Control matrix with owners.
- Testing plan, testing results, findings, remediation, and retest evidence.
- Policy set with adoption and revision dates.
- Training records by segment, with comprehension results.
- Third-party diligence files including red flag resolutions.
- Case management export with cycle times and outcomes.
- Discipline log by seniority with reasoning.
- Root cause analyses and resulting program changes.
- Compensation actions: clawbacks, forfeitures, modifiers applied.
- Board and committee charters, agendas, materials, and minutes.
- Culture survey results and trend.
- Preservation notices and IT verification records.
- Program budget and headcount history.
Related documents
- Corporate Compliance Programs: The ECCP, Monitorships, and What Regulators Actually Credit
- Designing and Testing a Compliance Program: A Practical Guide
- Compliance Program Toolkit: Risk Assessments, Testing Plans, and Remediation Records
- Internal Investigation and Upjohn Warning Checklist: A Practical Checklist
- The Foreign Corrupt Practices Act: Anti-Bribery, Books and Records, and Third-Party Risk
- Fiduciary Duties of Directors and Officers: The Business Judgment Rule, Loyalty, and Caremark Oversight
This checklist is general information, not legal advice, and does not create an attorney-client relationship.